# Latest

**URL:** https://discuss.elastic.co/latest.md?page=624

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 625

---

## [Elasticsearch Query setting date conditions](https://discuss.elastic.co/t/elasticsearch-query-setting-date-conditions/335554)

<div class="topic-metadata">

**Author:** [@DavidGreensfelder](https://discuss.elastic.co/u/DavidGreensfelder)\
**Replies:** 1\
**Last updated:** [June 28, 2023, 8:13pm UTC](https://discuss.elastic.co/t/elasticsearch-query-setting-date-conditions/335554 "2023-06-28T20:13:57Z")

</div>

I am setting up Alerting Rules under Rules and Connections. My query works great, but I need to not see the alerts during the maintenance window from 9 pm to 5 am. Here is my query: { "query" : { "bool" : { …

---

## [Anyone embed a Kibana chart in a Grafana dash?](https://discuss.elastic.co/t/anyone-embed-a-kibana-chart-in-a-grafana-dash/337127)

<div class="topic-metadata">

**Author:** [@rsk0](https://discuss.elastic.co/u/rsk0)\
**Replies:** 0\
**Last updated:** [June 28, 2023, 7:24pm UTC](https://discuss.elastic.co/t/anyone-embed-a-kibana-chart-in-a-grafana-dash/337127 "2023-06-28T19:24:11Z")

</div>

We'd love our engineers to be able to see our Grafana-served metrics alongside our Kibana-served logs visualizations. It seems like it should be possible. Has anyone done this?

---

## [Lost Machine Learning Capability in the Training Lab](https://discuss.elastic.co/t/lost-machine-learning-capability-in-the-training-lab/337126)

<div class="topic-metadata">

**Author:** [@ltan](https://discuss.elastic.co/u/ltan)\
**Replies:** 0\
**Last updated:** [June 28, 2023, 7:00pm UTC](https://discuss.elastic.co/t/lost-machine-learning-capability-in-the-training-lab/337126 "2023-06-28T19:00:28Z")

</div>

HiVersion: \<And which particular version?\> Hi, I have an issue with my Training Lab. It was fine initially until I had it reset due to some issues with my environment. But, it was fixed. After the reset, I seem to have…

---

## [How to check the default value of \`dynamic\_date\_formats\` and other mapping settings?](https://discuss.elastic.co/t/how-to-check-the-default-value-of-dynamic-date-formats-and-other-mapping-settings/337125)

<div class="topic-metadata">

**Author:** [@Mike\_Z](https://discuss.elastic.co/u/Mike_Z)\
**Replies:** 0\
**Last updated:** [June 28, 2023, 6:53pm UTC](https://discuss.elastic.co/t/how-to-check-the-default-value-of-dynamic-date-formats-and-other-mapping-settings/337125 "2023-06-28T18:53:04Z")

</div>

New to Elasticsearch, and I am wondering how to check the current value of dynamic\_date\_formats. The online document, here, provides an example of setting customized value, but I did not find how to check its value. P…

---

## [Cluster shards unbalanced and keep moving shards around after upgrade to 8.8.1](https://discuss.elastic.co/t/cluster-shards-unbalanced-and-keep-moving-shards-around-after-upgrade-to-8-8-1/336573)

<div class="topic-metadata">

**Author:** [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Replies:** 18\
**Last updated:** [June 28, 2023, 3:56pm UTC](https://discuss.elastic.co/t/cluster-shards-unbalanced-and-keep-moving-shards-around-after-upgrade-to-8-8-1/336573 "2023-06-28T15:56:20Z")

</div>

Hello, Yesterday we upgraded our cluster from 8.5.1 to 8.8.1 and now the shards are unbalacend between the nodes and the cluster keeps moving shards around to try to balance it. I have a hot/warm architecture with 4 ho…

---

## [Is it possible to send pfsense syslogs from firewall to elastic agent on windows 11 home to my discover page?](https://discuss.elastic.co/t/is-it-possible-to-send-pfsense-syslogs-from-firewall-to-elastic-agent-on-windows-11-home-to-my-discover-page/337020)

<div class="topic-metadata">

**Author:** [@synthallthetime](https://discuss.elastic.co/u/synthallthetime)\
**Replies:** 0\
**Last updated:** [June 27, 2023, 6:55pm UTC](https://discuss.elastic.co/t/is-it-possible-to-send-pfsense-syslogs-from-firewall-to-elastic-agent-on-windows-11-home-to-my-discover-page/337020 "2023-06-27T18:55:48Z")

</div>

Hi there, I'm looking to see if it's possible to configure pfsense to send its syslogs into the pfsense integrations addin into my elastic agent on my windows 11 home endpoint. I have managed to set up logging for sysm…

---

## [SearchUI get all results from autocomplete](https://discuss.elastic.co/t/searchui-get-all-results-from-autocomplete/336564)

<div class="topic-metadata">

**Author:** [@adrian\_es](https://discuss.elastic.co/u/adrian_es)\
**Replies:** 7\
**Last updated:** [June 28, 2023, 3:53pm UTC](https://discuss.elastic.co/t/searchui-get-all-results-from-autocomplete/336564 "2023-06-28T15:53:03Z")

</div>

Hello! I'm trying to replace my current search bar, located in the header of my React app, using SearchBox from SearchUI. When a user clicks a match I use onSelectAutocomplete to apply some custom logic to decide what …

---

## [Unable to do match query with new Java API client](https://discuss.elastic.co/t/unable-to-do-match-query-with-new-java-api-client/337065)

<div class="topic-metadata">

**Author:** [@p4charu](https://discuss.elastic.co/u/p4charu)\
**Replies:** 4\
**Last updated:** [June 28, 2023, 2:37pm UTC](https://discuss.elastic.co/t/unable-to-do-match-query-with-new-java-api-client/337065 "2023-06-28T14:37:03Z")

</div>

Hello! I am trying to do a match query similar to one below: "query": { "bool": { "must": \[ { "match": { "detected.tag": "chair" } } \] } } } This query gives me expec…

---

## [Store apm agent log in file](https://discuss.elastic.co/t/store-apm-agent-log-in-file/337099)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 0\
**Last updated:** [June 28, 2023, 2:33pm UTC](https://discuss.elastic.co/t/store-apm-agent-log-in-file/337099 "2023-06-28T14:33:41Z")

</div>

Hi Normally APM work like this: APMAgent\>APMServer\>Elastic\>kibana 1-Is it possible to store APMAgent log in file after that import in Elastic? Like this APMAgent\>file 2-Then feed log file to APMServer file\>APMServe…

---

## [Missing some machine learning jobs](https://discuss.elastic.co/t/missing-some-machine-learning-jobs/335678)

<div class="topic-metadata">

**Author:** [@queried1](https://discuss.elastic.co/u/queried1)\
**Replies:** 1\
**Last updated:** [June 28, 2023, 2:28pm UTC](https://discuss.elastic.co/t/missing-some-machine-learning-jobs/335678 "2023-06-28T14:28:40Z")

</div>

Hello! Recently I noticed that some ML jobs that start with "v3..." are missing. I can find other jobs that start with "v2..." under Machine Learning \> Anomaly Detection \> Jobs, but not "v3...". Some rules complain tha…

---

## [Docker integration not collecting logs](https://discuss.elastic.co/t/docker-integration-not-collecting-logs/337096)

<div class="topic-metadata">

**Author:** [@glenbot](https://discuss.elastic.co/u/glenbot)\
**Replies:** 0\
**Last updated:** [June 28, 2023, 2:12pm UTC](https://discuss.elastic.co/t/docker-integration-not-collecting-logs/337096 "2023-06-28T14:12:44Z")

</div>

The docker integration is collecting metrics perfectly but not logs. Versions: Agent: 8.7.1 Docker Integration: 2.6.0 I have tried changing the container log path to: /var/lib/docker/containers//-json.log and /var…

---

## [Rsyslog logs stop when any security is enabled](https://discuss.elastic.co/t/rsyslog-logs-stop-when-any-security-is-enabled/335869)

<div class="topic-metadata">

**Author:** [@Ryan\_Caputo](https://discuss.elastic.co/u/Ryan_Caputo)\
**Replies:** 7\
**Last updated:** [June 28, 2023, 2:04pm UTC](https://discuss.elastic.co/t/rsyslog-logs-stop-when-any-security-is-enabled/335869 "2023-06-28T14:04:29Z")

</div>

I have installed ELK 7.17.10 with podman, it works until I turn on security, even minimal security seems to block rsyslog from being received. What am I missing?

---

## [Elastic-agent visualizations in non-default space](https://discuss.elastic.co/t/elastic-agent-visualizations-in-non-default-space/337088)

<div class="topic-metadata">

**Author:** [@lduvnjak](https://discuss.elastic.co/u/lduvnjak)\
**Replies:** 0\
**Last updated:** [June 28, 2023, 1:44pm UTC](https://discuss.elastic.co/t/elastic-agent-visualizations-in-non-default-space/337088 "2023-06-28T13:44:20Z")

</div>

Hello Everyone, Is there any way to make the visualizations which are automatically created upon applying an Integration to an Agent Policy, be created in a space other than Default. This would be interesting for us so…

---

## [ES goes out of heap when issuing clusterstats (caused by CompletionStats)](https://discuss.elastic.co/t/es-goes-out-of-heap-when-issuing-clusterstats-caused-by-completionstats/336866)

<div class="topic-metadata">

**Author:** [@mgsag](https://discuss.elastic.co/u/mgsag)\
**Replies:** 11\
**Last updated:** [June 28, 2023, 1:21pm UTC](https://discuss.elastic.co/t/es-goes-out-of-heap-when-issuing-clusterstats-caused-by-completionstats/336866 "2023-06-28T13:21:56Z")

</div>

We observed this behavior in several of our production ElasticSearches and we were also able to reproduce it locally. If a database contains a lot of data for the completion-suggester, issuing a "\_cluster/stats?pretty"…

---

## [I want to know why the indices.id\_field\_data.enabled configuration is turned off by default](https://discuss.elastic.co/t/i-want-to-know-why-the-indices-id-field-data-enabled-configuration-is-turned-off-by-default/336834)

<div class="topic-metadata">

**Author:** [@gaorui](https://discuss.elastic.co/u/gaorui)\
**Replies:** 1\
**Last updated:** [June 28, 2023, 1:12pm UTC](https://discuss.elastic.co/t/i-want-to-know-why-the-indices-id-field-data-enabled-configuration-is-turned-off-by-default/336834 "2023-06-28T13:12:43Z")

</div>

I have a 200 million index, and I need to find out about 1 million of them based on certain conditions. I used the scroll api to query before, but I found that in the 8.x version, the scroll api is no longer recommended,…

---

## [Configuration on a two Kibana cluster](https://discuss.elastic.co/t/configuration-on-a-two-kibana-cluster/337084)

<div class="topic-metadata">

**Author:** [@DyRS\_16](https://discuss.elastic.co/u/DyRS_16)\
**Replies:** 0\
**Last updated:** [June 28, 2023, 1:01pm UTC](https://discuss.elastic.co/t/configuration-on-a-two-kibana-cluster/337084 "2023-06-28T13:01:41Z")

</div>

Hi community, I have tested a Kibana cluster of two nodes behind a load balancer and it worked without any problem. There are a few settings that the documentation specified to be changed, but I didn't: Settings that m…

---

## [Cant' find an example of how Elastic.Serilog.Sinks works with json configuration file](https://discuss.elastic.co/t/cant-find-an-example-of-how-elastic-serilog-sinks-works-with-json-configuration-file/337078)

<div class="topic-metadata">

**Author:** [@pantonis](https://discuss.elastic.co/u/pantonis)\
**Replies:** 0\
**Last updated:** [June 28, 2023, 12:27pm UTC](https://discuss.elastic.co/t/cant-find-an-example-of-how-elastic-serilog-sinks-works-with-json-configuration-file/337078 "2023-06-28T12:27:48Z")

</div>

I cannot find an example of how Elastic.Serilog.Sinks works with a json configuration file. It seems that serilog json configuration file does not work with this library. any example of how a json file looks like would…

---

## [Agent stopped talking to Fleet](https://discuss.elastic.co/t/agent-stopped-talking-to-fleet/337074)

<div class="topic-metadata">

**Author:** [@willsy](https://discuss.elastic.co/u/willsy)\
**Replies:** 0\
**Last updated:** [June 28, 2023, 12:10pm UTC](https://discuss.elastic.co/t/agent-stopped-talking-to-fleet/337074 "2023-06-28T12:10:46Z")

</div>

After sucessfully adding various fleet agents to my fleet server aftr a few days all of them stopped, including the fleet server itself. I have the log file of the agent so just wondering if someone can point me in the r…

---

## [Alerting in Marvel (or any other way)](https://discuss.elastic.co/t/alerting-in-marvel-or-any-other-way/337071)

<div class="topic-metadata">

**Author:** [@Mark\_S](https://discuss.elastic.co/u/Mark_S)\
**Replies:** 0\
**Last updated:** [June 28, 2023, 12:01pm UTC](https://discuss.elastic.co/t/alerting-in-marvel-or-any-other-way/337071 "2023-06-28T12:01:36Z")

</div>

Is it possible to create alerts for various metrics (eg JVM usage, nodes volume usage, etc?) There have been similar questions a couple of years ago but I did not find a positive answer. Perhaps installing also Promethe…

---

## [Remove the date select filter only for a specific dashboard](https://discuss.elastic.co/t/remove-the-date-select-filter-only-for-a-specific-dashboard/337042)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 1\
**Last updated:** [June 28, 2023, 11:42am UTC](https://discuss.elastic.co/t/remove-the-date-select-filter-only-for-a-specific-dashboard/337042 "2023-06-28T11:42:55Z")

</div>

Hi, Is it possible to remove the date select filter from only a specific dashboard in kibana? i want to display static data without any date change. is it possible?

---

## [Beats 8.7.x has disappeared in the Beats Release Notes?!](https://discuss.elastic.co/t/beats-8-7-x-has-disappeared-in-the-beats-release-notes/337066)

<div class="topic-metadata">

**Author:** [@bjosve](https://discuss.elastic.co/u/bjosve)\
**Replies:** 1\
**Last updated:** [June 28, 2023, 11:39am UTC](https://discuss.elastic.co/t/beats-8-7-x-has-disappeared-in-the-beats-release-notes/337066 "2023-06-28T11:39:25Z")

</div>

Hi, It seems as Beats 8.7.x has disappeared in the Beats Release Notes. Is this a mistake or a note to avoid Beats 8.7? Best Regards, Bjorn Svensson

---

## [Elastic Search Error after altering/modifying the elasticsearch.yml file](https://discuss.elastic.co/t/elastic-search-error-after-altering-modifying-the-elasticsearch-yml-file/337031)

<div class="topic-metadata">

**Author:** [@Zu\_kun](https://discuss.elastic.co/u/Zu_kun)\
**Replies:** 4\
**Last updated:** [June 28, 2023, 11:37am UTC](https://discuss.elastic.co/t/elastic-search-error-after-altering-modifying-the-elasticsearch-yml-file/337031 "2023-06-28T11:37:42Z")

</div>

Hi, I have installed Elasticsearch version 7.17.7 on ubuntu and I have noticed an issue whenever I alter or modify the elasticsearch.yml file within /etc/elasticsearch, In the elasticsearch.yml file, I want to bind the…

---

## [Elasticsearch with Docker](https://discuss.elastic.co/t/elasticsearch-with-docker/337068)

<div class="topic-metadata">

**Author:** [@anderstr1](https://discuss.elastic.co/u/anderstr1)\
**Replies:** 1\
**Last updated:** [June 28, 2023, 11:30am UTC](https://discuss.elastic.co/t/elasticsearch-with-docker/337068 "2023-06-28T11:30:39Z")

</div>

We have already set up Elasticsearch version 7.10.2 using the official docker image, and our single-node cluster is running fine. We need to use this specific Elasticsearch version since it is required by the Mediawiki a…

---

## [Increasing Rows per Page Limit in Kibana 8.6.2](https://discuss.elastic.co/t/increasing-rows-per-page-limit-in-kibana-8-6-2/336780)

<div class="topic-metadata">

**Author:** [@7a6b6f](https://discuss.elastic.co/u/7a6b6f)\
**Replies:** 5\
**Last updated:** [June 28, 2023, 10:55am UTC](https://discuss.elastic.co/t/increasing-rows-per-page-limit-in-kibana-8-6-2/336780 "2023-06-28T10:55:33Z")

</div>

Hello fellow forum members, I have been using Kibana version 8.6.2 for my data analysis needs and have come across a query regarding the "Rows per Page" limit in the Discover category of the advanced settings. By def…

---

## [Dose Low Level Rest Client not cause the same connection pressure as Transport Client](https://discuss.elastic.co/t/dose-low-level-rest-client-not-cause-the-same-connection-pressure-as-transport-client/337056)

<div class="topic-metadata">

**Author:** [@emmning](https://discuss.elastic.co/u/emmning)\
**Replies:** 2\
**Last updated:** [June 28, 2023, 10:08am UTC](https://discuss.elastic.co/t/dose-low-level-rest-client-not-cause-the-same-connection-pressure-as-transport-client/337056 "2023-06-28T10:08:38Z")

</div>

We are using flink to write data to ES cluster.The transport client is used as the client in the flink task and the sniffer is configured.Each parallism of flink task will create a transport client, and each transport cl…

---

## [Empty aggregations, ES 6.7 nodes, RHLC upgraded from v6.3 to v6.8](https://discuss.elastic.co/t/empty-aggregations-es-6-7-nodes-rhlc-upgraded-from-v6-3-to-v6-8/337062)

<div class="topic-metadata">

**Author:** [@Hi\_Jonk](https://discuss.elastic.co/u/Hi_Jonk)\
**Replies:** 0\
**Last updated:** [June 28, 2023, 9:37am UTC](https://discuss.elastic.co/t/empty-aggregations-es-6-7-nodes-rhlc-upgraded-from-v6-3-to-v6-8/337062 "2023-06-28T09:37:50Z")

</div>

As part of a rolling upgrade, I am trying upgrade my high level client from v6.3 to v6.8 while talking to v6.7 nodes. Search is working fine, however, the aggregation queries we were using with the v6.3 client have stopp…

---

## [Tabs in kibana dashboard?](https://discuss.elastic.co/t/tabs-in-kibana-dashboard/337041)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 5\
**Last updated:** [June 28, 2023, 9:35am UTC](https://discuss.elastic.co/t/tabs-in-kibana-dashboard/337041 "2023-06-28T09:35:13Z")

</div>

Hi, is it possible to add tabs in a kibana dashboard? with different visualizations in different tabs?

---

## [Data transfer from logstash to kibana](https://discuss.elastic.co/t/data-transfer-from-logstash-to-kibana/337055)

<div class="topic-metadata">

**Author:** [@kazuo](https://discuss.elastic.co/u/kazuo)\
**Replies:** 1\
**Last updated:** [June 28, 2023, 8:49am UTC](https://discuss.elastic.co/t/data-transfer-from-logstash-to-kibana/337055 "2023-06-28T08:49:05Z")

</div>

Hello, Output drop occurs in L2SW when transferring data from logstash to kibana. Are there any parameters that control data transfer with logstash? Thank you in advance

---

## [Monitoring Elastic Agent integration logs](https://discuss.elastic.co/t/monitoring-elastic-agent-integration-logs/337054)

<div class="topic-metadata">

**Author:** [@DyRS\_16](https://discuss.elastic.co/u/DyRS_16)\
**Replies:** 0\
**Last updated:** [June 28, 2023, 8:40am UTC](https://discuss.elastic.co/t/monitoring-elastic-agent-integration-logs/337054 "2023-06-28T08:40:43Z")

</div>

Hi community, I would like to monitor when there is an integration that stopped sending logs during a certain period of time. Something similar to the "Missing monitoring data" from the Stack Monitoring, but applied to …

---

## [Read a date of a file to add this property in Logstash to send a ElasticSearch](https://discuss.elastic.co/t/read-a-date-of-a-file-to-add-this-property-in-logstash-to-send-a-elasticsearch/335359)

<div class="topic-metadata">

**Author:** [@AlejandroVindel](https://discuss.elastic.co/u/AlejandroVindel)\
**Replies:** 2\
**Last updated:** [June 28, 2023, 8:36am UTC](https://discuss.elastic.co/t/read-a-date-of-a-file-to-add-this-property-in-logstash-to-send-a-elasticsearch/335359 "2023-06-28T08:36:09Z")

</div>

HI, I am collecting files with Logstash and sending them to an Elasticsearch database. But I'm running into the problem that I can't pick up the date that file was created or last modified. I'm working on Linux, and wh…

[Previous page](https://discuss.elastic.co/latest.md?page=623)

[Next page](https://discuss.elastic.co/latest.md?page=625)
