# Latest

**URL:** https://discuss.elastic.co/latest.md?page=623

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 624

---

## [Kibana upgrade is getting failed](https://discuss.elastic.co/t/kibana-upgrade-is-getting-failed/337061)

<div class="topic-metadata">

**Author:** [@Vicky\_Thakor](https://discuss.elastic.co/u/Vicky_Thakor)\
**Replies:** 1\
**Last updated:** [June 29, 2023, 2:21pm UTC](https://discuss.elastic.co/t/kibana-upgrade-is-getting-failed/337061 "2023-06-29T14:21:48Z")

</div>

A few days back our kibana stopped working and elastic.co asking for an upgrade of Kibana. I tried kibana upgrade but it's not working can someone please help? Its production grade issue

---

## [Setting "logging.dest" is deprecated](https://discuss.elastic.co/t/setting-logging-dest-is-deprecated/337100)

<div class="topic-metadata">

**Author:** [@GuillaumeBA](https://discuss.elastic.co/u/GuillaumeBA)\
**Replies:** 1\
**Last updated:** [June 29, 2023, 1:37pm UTC](https://discuss.elastic.co/t/setting-logging-dest-is-deprecated/337100 "2023-06-29T13:37:50Z")

</div>

Hi I'm trying to upgrade my ELK from 7.16.2 to 8.x and i'm facing this last critical error : I have already replaced the "logging.dest:" in kibana.yml by the parameters I have founded in the upgrade assistant for ELK…

---

## [Only one instance of metricbeat/filebeat can connect to elastic](https://discuss.elastic.co/t/only-one-instance-of-metricbeat-filebeat-can-connect-to-elastic/337200)

<div class="topic-metadata">

**Author:** [@marcin8352](https://discuss.elastic.co/u/marcin8352)\
**Replies:** 0\
**Last updated:** [June 29, 2023, 1:19pm UTC](https://discuss.elastic.co/t/only-one-instance-of-metricbeat-filebeat-can-connect-to-elastic/337200 "2023-06-29T13:19:57Z")

</div>

Hello, I have an issue connecting 2 machines to elasticsearch. I have 2 redundant machines in azure which have the same software installed, both have metricbeat and filebeat installed which works just fine. Lets call t…

---

## [Unable to access Elasticsearch connected to company server via Python](https://discuss.elastic.co/t/unable-to-access-elasticsearch-connected-to-company-server-via-python/335288)

<div class="topic-metadata">

**Author:** [@cyl](https://discuss.elastic.co/u/cyl)\
**Replies:** 4\
**Last updated:** [June 29, 2023, 1:09pm UTC](https://discuss.elastic.co/t/unable-to-access-elasticsearch-connected-to-company-server-via-python/335288 "2023-06-29T13:09:01Z")

</div>

Hi Elastic community! :smiley: I have just started using Elastic and Kibana as my company has opted for this tech stack to store much of our data. To analyse the data, I would prefer the use of Python, and hence have b…

---

## [Kafka to Logstash](https://discuss.elastic.co/t/kafka-to-logstash/337173)

<div class="topic-metadata">

**Author:** [@Shalinicts](https://discuss.elastic.co/u/Shalinicts)\
**Replies:** 4\
**Last updated:** [June 29, 2023, 12:58pm UTC](https://discuss.elastic.co/t/kafka-to-logstash/337173 "2023-06-29T12:58:33Z")

</div>

Hi Team , In Logstash I can see below error for pipeline having input as Kafka (Oracle Cloud) It fails to connect and then discover . Any idea on what needs to be checked. Once it is stable automatically, we gets data…

---

## [Kibana service failing in version 7.16.3 after importing saved\_objects from 7.9.2](https://discuss.elastic.co/t/kibana-service-failing-in-version-7-16-3-after-importing-saved-objects-from-7-9-2/337156)

<div class="topic-metadata">

**Author:** [@Stephy\_Jacob](https://discuss.elastic.co/u/Stephy_Jacob)\
**Replies:** 2\
**Last updated:** [June 29, 2023, 12:32pm UTC](https://discuss.elastic.co/t/kibana-service-failing-in-version-7-16-3-after-importing-saved-objects-from-7-9-2/337156 "2023-06-29T12:32:09Z")

</div>

Hello, I am trying to upgrade elasticsearch and kibana to 7.16.3 from version 7.9.2. Below are the steps executed. Created a new elasticsearch cluster with 7.16.3 version of elasticsearch and 7.16.3 version of Kibana…

---

## [Logstash 8 cannot run with JRE](https://discuss.elastic.co/t/logstash-8-cannot-run-with-jre/337171)

<div class="topic-metadata">

**Author:** [@sxwnhxwx](https://discuss.elastic.co/u/sxwnhxwx)\
**Replies:** 1\
**Last updated:** [June 29, 2023, 12:22pm UTC](https://discuss.elastic.co/t/logstash-8-cannot-run-with-jre/337171 "2023-06-29T12:22:36Z")

</div>

When I start logstash 8 with jre, it is failed , jdk is ok Logstash 7 works fine with jre logstash version：8.8.1 jre version: 11.0.18 testing configuration： input{ stdin{} } output{ stdout{} } The error message is…

---

## [Documentation - Wildcard query DSL](https://discuss.elastic.co/t/documentation-wildcard-query-dsl/337182)

<div class="topic-metadata">

**Author:** [@Pawel123](https://discuss.elastic.co/u/Pawel123)\
**Replies:** 2\
**Last updated:** [June 29, 2023, 11:32am UTC](https://discuss.elastic.co/t/documentation-wildcard-query-dsl/337182 "2023-06-29T11:32:08Z")

</div>

Running on ES 7.10.0. Sending a search query with "case\_insensitive" parameter: Getting response \[wildcard\] query does not support \[case\_insensitive\] as in documentation -\> Wildcard query | Elasticsearch Guide \[8.8\] |…

---

## [Simple search doesnt work](https://discuss.elastic.co/t/simple-search-doesnt-work/337092)

<div class="topic-metadata">

**Author:** [@Dach](https://discuss.elastic.co/u/Dach)\
**Replies:** 4\
**Last updated:** [June 29, 2023, 11:21am UTC](https://discuss.elastic.co/t/simple-search-doesnt-work/337092 "2023-06-29T11:21:08Z")

</div>

When i do this search, my product is well find : { "query": { "bool": { "must": \[ { "match": { "pickRef": "630203" } }, { "match": { "id": 56139 } }, { "match": { "name.fr": "ENVELOPP…

---

## [NullPointerException when performing a Completion Suggester query with synonym analyzer, v8.5](https://discuss.elastic.co/t/nullpointerexception-when-performing-a-completion-suggester-query-with-synonym-analyzer-v8-5/336674)

<div class="topic-metadata">

**Author:** [@jacoMet](https://discuss.elastic.co/u/jacoMet)\
**Replies:** 3\
**Last updated:** [June 29, 2023, 10:47am UTC](https://discuss.elastic.co/t/nullpointerexception-when-performing-a-completion-suggester-query-with-synonym-analyzer-v8-5/336674 "2023-06-29T10:47:37Z")

</div>

I need to be able to perform Completion Suggest queries that are context dependent. When executing the query below: POST synonym\_file\_test/\_search { "\_source": "suggest", "suggest": { "my-suggest": { "prefix…

---

## [Use aggregate filter of logatash to find dynamic task-id](https://discuss.elastic.co/t/use-aggregate-filter-of-logatash-to-find-dynamic-task-id/337177)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 0\
**Last updated:** [June 29, 2023, 10:33am UTC](https://discuss.elastic.co/t/use-aggregate-filter-of-logatash-to-find-dynamic-task-id/337177 "2023-06-29T10:33:22Z")

</div>

Hi I want to use aggregate filter to find dynamic task-id https://www.elastic.co/guide/en/logstash/current/plugins-filters-aggregate.html Here is the scenario I have log like below need to extract "Send&Receive dura…

---

## [Certified Analyst practice exam issues](https://discuss.elastic.co/t/certified-analyst-practice-exam-issues/335221)

<div class="topic-metadata">

**Author:** [@Auckinston](https://discuss.elastic.co/u/Auckinston)\
**Replies:** 10\
**Last updated:** [June 29, 2023, 10:28am UTC](https://discuss.elastic.co/t/certified-analyst-practice-exam-issues/335221 "2023-06-29T10:28:54Z")

</div>

Course: Version: \<7.1x\> Question: Identical issue reported by many users previously, the VM build is outdated/bad. Based on the instruction provided: IMPORTANT: You need to define index patterns for the following in…

---

## [Cannot read properties of undefined (reading 'call') at o (kbn-ui-shared-deps-npm.dll.js:1:388) - when installing plugin in 8.8.1 and 8.5.3](https://discuss.elastic.co/t/cannot-read-properties-of-undefined-reading-call-at-o-kbn-ui-shared-deps-npm-dll-js388-when-installing-plugin-in-8-8-1-and-8-5-3/336894)

<div class="topic-metadata">

**Author:** [@Sheereen](https://discuss.elastic.co/u/Sheereen)\
**Replies:** 1\
**Last updated:** [June 29, 2023, 10:01am UTC](https://discuss.elastic.co/t/cannot-read-properties-of-undefined-reading-call-at-o-kbn-ui-shared-deps-npm-dll-js388-when-installing-plugin-in-8-8-1-and-8-5-3/336894 "2023-06-29T10:01:05Z")

</div>

Hi, I am developing a custom plugin using React, in Kibana main branch. I did yarn build for 8.5.3 and 8.8.1 versions of Kibana, and installed the same in the respective versions. But in both the versions, I get the f…

---

## [useNavigate() and useSearchParams() gives Object(...) is not a function error](https://discuss.elastic.co/t/usenavigate-and-usesearchparams-gives-object-is-not-a-function-error/336955)

<div class="topic-metadata">

**Author:** [@Sheereen](https://discuss.elastic.co/u/Sheereen)\
**Replies:** 1\
**Last updated:** [June 29, 2023, 9:59am UTC](https://discuss.elastic.co/t/usenavigate-and-usesearchparams-gives-object-is-not-a-function-error/336955 "2023-06-29T09:59:45Z")

</div>

Hi, I am developing a custom plugin using React in Kibana main branch (8.9). When I use useSearchParams() or useNavigate() from react-router v6, I get an error in the browser saying Object(...) is not a function. But w…

---

## [Fleet server configuration file](https://discuss.elastic.co/t/fleet-server-configuration-file/337163)

<div class="topic-metadata">

**Author:** [@willsy](https://discuss.elastic.co/u/willsy)\
**Replies:** 1\
**Last updated:** [June 29, 2023, 9:34am UTC](https://discuss.elastic.co/t/fleet-server-configuration-file/337163 "2023-06-29T09:34:26Z")

</div>

My elastic agents are still sending information to elasticsearch however they are showing as unhealthy or inactive with my fleet server. On the troubleshooting it suggested to run this command; curl -f http://:8220/api…

---

## [Index historical time-series data into a data stream - ILM](https://discuss.elastic.co/t/index-historical-time-series-data-into-a-data-stream-ilm/337167)

<div class="topic-metadata">

**Author:** [@qcha](https://discuss.elastic.co/u/qcha)\
**Replies:** 0\
**Last updated:** [June 29, 2023, 8:51am UTC](https://discuss.elastic.co/t/index-historical-time-series-data-into-a-data-stream-ilm/337167 "2023-06-29T08:51:54Z")

</div>

Hi everyone, My use case is the following : I have continuously produced time-series data + one year history (both outside Elastic). I want to index them into Elastic in such a way that data is deleted after one year (a…

---

## [Mssql server connectivity issue with logstash](https://discuss.elastic.co/t/mssql-server-connectivity-issue-with-logstash/337165)

<div class="topic-metadata">

**Author:** [@Nawab\_Zaidi](https://discuss.elastic.co/u/Nawab_Zaidi)\
**Replies:** 0\
**Last updated:** [June 29, 2023, 7:56am UTC](https://discuss.elastic.co/t/mssql-server-connectivity-issue-with-logstash/337165 "2023-06-29T07:56:22Z")

</div>

I am trying to fetch data from MSSQL with the following mssql.conf script in config directory input { jdbc { jdbc\_driver\_class =\> "com.microsoft.sqlserver.jdbc.SQLServerDriver" jdbc\_driver\_library =\> "" jdbc\_connect…

---

## [Calculate total duration](https://discuss.elastic.co/t/calculate-total-duration/337148)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 0\
**Last updated:** [June 29, 2023, 5:00am UTC](https://discuss.elastic.co/t/calculate-total-duration/337148 "2023-06-29T05:00:19Z")

</div>

Hi How can I calculate duration of below log: 2021-07-15 00:00:01,869 INFO CUS.AbCD-AppService1-1234567 \[AppListener\] Receive Packet\[00\*\]: Kafka\[AppService1.APP1\] 2021-07-15 00:00:01,988 INFO CUS.AbCD-AppService1-1234…

---

## [Calculate transaction duration](https://discuss.elastic.co/t/calculate-transaction-duration/337147)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 0\
**Last updated:** [June 29, 2023, 4:53am UTC](https://discuss.elastic.co/t/calculate-transaction-duration/337147 "2023-06-29T04:53:54Z")

</div>

Hi i have log file like this: 2021-07-15 00:00:01,869 INFO client.InEE-server1-1234567 \[AppListener\] Receive Message\[A123\]: Q\[p1.APP\], IID\[null\], Cookie\[{"NODE\_SRC":"server0"}\] 2021-07-15 00:00:01,871 INFO client.InEE…

---

## [Find time gaps](https://discuss.elastic.co/t/find-time-gaps/337146)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 0\
**Last updated:** [June 29, 2023, 4:44am UTC](https://discuss.elastic.co/t/find-time-gaps/337146 "2023-06-29T04:44:33Z")

</div>

Hi i have log like this, need to find where unusuall time gap between "Packet Processed" and "Send Packet" that exist this is normal 001 2021-10-25 08:59:50,725 INFO CUS.AbCD-VW2-1234567890 \[FlowProcessorService\] Packe…

---

## [Find transaction in log](https://discuss.elastic.co/t/find-transaction-in-log/337143)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 0\
**Last updated:** [June 29, 2023, 4:34am UTC](https://discuss.elastic.co/t/find-transaction-in-log/337143 "2023-06-29T04:34:49Z")

</div>

Hi I have log like below need to extract "Send&Receive duration" and "send that has not respond". this is send 2021-07-15 00:00:01,800 INFO CUST.InAB-ServerApp-1234567 \[MyService\] Packet Processed: A\[50\] B\[0000211\] t…

---

## [Heartbeat on Kubernetes cluster](https://discuss.elastic.co/t/heartbeat-on-kubernetes-cluster/337140)

<div class="topic-metadata">

**Author:** [@jam\_mahmoudi](https://discuss.elastic.co/u/jam_mahmoudi)\
**Replies:** 0\
**Last updated:** [June 29, 2023, 4:17am UTC](https://discuss.elastic.co/t/heartbeat-on-kubernetes-cluster/337140 "2023-06-29T04:17:24Z")

</div>

Hi guys I have a question How should I define a heartbeat to monitor all pods in a Kubernetes cluster? Do I only need to install and configure Heartbeat on the worker nodes, or do I need to install and configure it on…

---

## [Segments info In Indics Stats](https://discuss.elastic.co/t/segments-info-in-indics-stats/337133)

<div class="topic-metadata">

**Author:** [@Geunmoon\_Oh](https://discuss.elastic.co/u/Geunmoon_Oh)\
**Replies:** 0\
**Last updated:** [June 28, 2023, 11:14pm UTC](https://discuss.elastic.co/t/segments-info-in-indics-stats/337133 "2023-06-28T23:14:37Z")

</div>

I use ES 8.6. I created a lot indexes and added a lot data. but i don't know why segments's memory\_in\_bytes is zero. Can the value be always zero In ES 8.6 ???

---

## [If there are multiple \`order\`, what is the priority?](https://discuss.elastic.co/t/if-there-are-multiple-order-what-is-the-priority/337045)

<div class="topic-metadata">

**Author:** [@kimjinyoung](https://discuss.elastic.co/u/kimjinyoung)\
**Replies:** 2\
**Last updated:** [June 28, 2023, 11:51pm UTC](https://discuss.elastic.co/t/if-there-are-multiple-order-what-is-the-priority/337045 "2023-06-28T23:51:25Z")

</div>

Hello, I'm using a translation because I can't speak English, so please teach me gently. Currently, I have something I would like to ask the order, so I am in a community. GET /\_search { "track\_scores": true, "sort" :…

---

## [Problem with data field in logstash](https://discuss.elastic.co/t/problem-with-data-field-in-logstash/336875)

<div class="topic-metadata">

**Author:** [@KarlWolf](https://discuss.elastic.co/u/KarlWolf)\
**Replies:** 2\
**Last updated:** [June 28, 2023, 11:19pm UTC](https://discuss.elastic.co/t/problem-with-data-field-in-logstash/336875 "2023-06-28T23:19:01Z")

</div>

hi, I have a strange case regarding my Logstash process. I'm having a filebeat which sends file-log to Logstash. That file log is updated from old proxy system in the following manner: logs from 15 minutes are gathere…

---

## [Kibana not working// Elasticsearch host](https://discuss.elastic.co/t/kibana-not-working-elasticsearch-host/336929)

<div class="topic-metadata">

**Author:** [@yash2](https://discuss.elastic.co/u/yash2)\
**Replies:** 8\
**Last updated:** [June 28, 2023, 11:03pm UTC](https://discuss.elastic.co/t/kibana-not-working-elasticsearch-host/336929 "2023-06-28T23:03:50Z")

</div>

Can anyone help me here, i have been trying to set up Wazuh to work with ELK stack, having Filebeat to send the logs to Kibana for visualization. Just to begin with here\`s my elasticsearch .yml file : network.host: 19…

---

## [ECK on Kubernetes Agents Retrying to connect every 10 mins](https://discuss.elastic.co/t/eck-on-kubernetes-agents-retrying-to-connect-every-10-mins/337132)

<div class="topic-metadata">

**Author:** [@Fikrat\_Karimli](https://discuss.elastic.co/u/Fikrat_Karimli)\
**Replies:** 0\
**Last updated:** [June 28, 2023, 11:05pm UTC](https://discuss.elastic.co/t/eck-on-kubernetes-agents-retrying-to-connect-every-10-mins/337132 "2023-06-28T23:05:10Z")

</div>

Hi, I set up ECK on GKE and spun up Elasticsearch, Kibana and Fleet server with ingress Nginx along with Letsencrypt certs. Everything works perfect expect agent is checking in every 10 mins. It is trying connect but fa…

---

## [Kafka Codec Avro Plugin Polling Frequency](https://discuss.elastic.co/t/kafka-codec-avro-plugin-polling-frequency/337121)

<div class="topic-metadata">

**Author:** [@fine\_porcupine](https://discuss.elastic.co/u/fine_porcupine)\
**Replies:** 1\
**Last updated:** [June 28, 2023, 10:52pm UTC](https://discuss.elastic.co/t/kafka-codec-avro-plugin-polling-frequency/337121 "2023-06-28T22:52:25Z")

</div>

I'm planning on using the Codec Avro Plugin to deserialize incoming events from SQS. However, requests to the Kafka schema registry are rate-limited to 25 queries/second when using an HTTP URI. How frequently does this …

---

## [Linux install of Filebeat under different directory](https://discuss.elastic.co/t/linux-install-of-filebeat-under-different-directory/337130)

<div class="topic-metadata">

**Author:** [@paolovalladolid](https://discuss.elastic.co/u/paolovalladolid)\
**Replies:** 2\
**Last updated:** [June 28, 2023, 9:56pm UTC](https://discuss.elastic.co/t/linux-install-of-filebeat-under-different-directory/337130 "2023-06-28T21:56:07Z")

</div>

Hi all, In the past I've followed the Filebeat installation instructions for RPM installation on Linux verbatim without issue. But now we have a machine that lacks space under /etc, so we want to install it under /opt …

---

## [Unable to Access Kibana Dashboard](https://discuss.elastic.co/t/unable-to-access-kibana-dashboard/337027)

<div class="topic-metadata">

**Author:** [@vdashora](https://discuss.elastic.co/u/vdashora)\
**Replies:** 4\
**Last updated:** [June 28, 2023, 8:40pm UTC](https://discuss.elastic.co/t/unable-to-access-kibana-dashboard/337027 "2023-06-28T20:40:41Z")

</div>

We are unable to access our Kibana dashboard. The docker daemon was down, but we ssh into our slave and rebooted everything. URL: http://ivtscenarios1.fyre.ibm.com:5601/app/dashboards#/view/d1f9c740-cf59-11ed-b98d-1da6f…

[Previous page](https://discuss.elastic.co/latest.md?page=622)

[Next page](https://discuss.elastic.co/latest.md?page=624)
