# Latest

**URL:** https://discuss.elastic.co/latest.md?page=625

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 626

---

## [Elastic 8.X license](https://discuss.elastic.co/t/elastic-8-x-license/337052)

<div class="topic-metadata">

**Author:** [@Norsu296](https://discuss.elastic.co/u/Norsu296)\
**Replies:** 0\
**Last updated:** [June 28, 2023, 8:23am UTC](https://discuss.elastic.co/t/elastic-8-x-license/337052 "2023-06-28T08:23:25Z")

</div>

Hello, I'm trying to use elastic 8.8.0 on kubernetes with authentication using file realm, but it doesn;t work. In previous version (7.17) it was working, I didn't change anything in configuration. I checked password sh…

---

## [Total hits showing up as 0, but documents exist. 6.3 Rest high level client, 7.1 cluster](https://discuss.elastic.co/t/total-hits-showing-up-as-0-but-documents-exist-6-3-rest-high-level-client-7-1-cluster/337006)

<div class="topic-metadata">

**Author:** [@Hi\_Jonk](https://discuss.elastic.co/u/Hi_Jonk)\
**Replies:** 3\
**Last updated:** [June 28, 2023, 7:29am UTC](https://discuss.elastic.co/t/total-hits-showing-up-as-0-but-documents-exist-6-3-rest-high-level-client-7-1-cluster/337006 "2023-06-28T07:29:55Z")

</div>

Hi, I had a cluster that was running on ES v6.7 with a REST high level client v6.3. We want to upgrade, so as per this suggestion: Clarify high level REST client compatibility between 6 and 7 created a test cluster at …

---

## [How to connect to Kafka using filebeat with PLAINTEXT SecurityProtocol?](https://discuss.elastic.co/t/how-to-connect-to-kafka-using-filebeat-with-plaintext-securityprotocol/336996)

<div class="topic-metadata">

**Author:** [@wymli](https://discuss.elastic.co/u/wymli)\
**Replies:** 3\
**Last updated:** [June 28, 2023, 7:06am UTC](https://discuss.elastic.co/t/how-to-connect-to-kafka-using-filebeat-with-plaintext-securityprotocol/336996 "2023-06-28T07:06:15Z")

</div>

At present, the security-protocols of kafka mainly include the following PLAINTEXT, SSL, SASL\_PLAINTEXT, SASL\_SSL. But I checked the kafka-output documentation: Configure the Kafka output | Filebeat Reference \[8.8\] | Ela…

---

## [Face issues regarding data visualization](https://discuss.elastic.co/t/face-issues-regarding-data-visualization/337043)

<div class="topic-metadata">

**Author:** [@Rushi\_Bagul](https://discuss.elastic.co/u/Rushi_Bagul)\
**Replies:** 0\
**Last updated:** [June 28, 2023, 6:30am UTC](https://discuss.elastic.co/t/face-issues-regarding-data-visualization/337043 "2023-06-28T06:30:56Z")

</div>

I have face challenges regarding data visualization in kibana dashboard because I am new on elasticsearch platform so help me for provided data. "parameter": { "name": "Disk Usage", "code": "DISK\_USAGE" }, "resource…

---

## [Kibana dashboard visualisation slowness while accessing the dashboard -](https://discuss.elastic.co/t/kibana-dashboard-visualisation-slowness-while-accessing-the-dashboard/336943)

<div class="topic-metadata">

**Author:** [@Praveen\_kr](https://discuss.elastic.co/u/Praveen_kr)\
**Replies:** 1\
**Last updated:** [June 28, 2023, 6:30am UTC](https://discuss.elastic.co/t/kibana-dashboard-visualisation-slowness-while-accessing-the-dashboard/336943 "2023-06-28T06:30:05Z")

</div>

Hello , We are using 7.17 version Elasticsearch and Kibana, We are facing browser locks up issue when access dashboard in our environment. While loading the dashboard visualisation is very slow for example : last 30 d…

---

## [CancelException with AsyncBulkLoad (Python helper)](https://discuss.elastic.co/t/cancelexception-with-asyncbulkload-python-helper/337038)

<div class="topic-metadata">

**Author:** [@ionFreeman](https://discuss.elastic.co/u/ionFreeman)\
**Replies:** 0\
**Last updated:** [June 28, 2023, 5:58am UTC](https://discuss.elastic.co/t/cancelexception-with-asyncbulkload-python-helper/337038 "2023-06-28T05:58:19Z")

</div>

Hello! I have a little action generator, actually a bunch of coroutines I stich together with aiostream.merge(). I pass it into the AsyncBulkLoad. I haven't reproduced the behavior when I have a small number of test acti…

---

## [Elastic node crashing due to java.lang.OutOfMemoryError: Java heap space](https://discuss.elastic.co/t/elastic-node-crashing-due-to-java-lang-outofmemoryerror-java-heap-space/337034)

<div class="topic-metadata">

**Author:** [@sasvmware](https://discuss.elastic.co/u/sasvmware)\
**Replies:** 0\
**Last updated:** [June 28, 2023, 5:22am UTC](https://discuss.elastic.co/t/elastic-node-crashing-due-to-java-lang-outofmemoryerror-java-heap-space/337034 "2023-06-28T05:22:56Z")

</div>

Hi Elasticsearch nodes are crashing due to java.lang.OutOfMemoryError: Java heap space. We have 10 GB memory in each node and as per formula total memory/2 -1 we have set JVM as 4. ava.lang.OutOfMemoryError: Java heap…

---

## [How to solve kibana report?](https://discuss.elastic.co/t/how-to-solve-kibana-report/337033)

<div class="topic-metadata">

**Author:** [@Ethan\_Park](https://discuss.elastic.co/u/Ethan_Park)\
**Replies:** 1\
**Last updated:** [June 28, 2023, 4:26am UTC](https://discuss.elastic.co/t/how-to-solve-kibana-report/337033 "2023-06-28T04:26:49Z")

</div>

I am getting the following error while trying to generate PNG,PDF report from Kibana. Kibana\_Error error 1 {"service":{"node":{"roles":\["background\_tasks","ui"\]}},"ecs":{"version":"8.6.0"},"@timestamp":"2023-06-21T14:28…

---

## [How to configure filebeat log format to human readable instead of json?](https://discuss.elastic.co/t/how-to-configure-filebeat-log-format-to-human-readable-instead-of-json/337032)

<div class="topic-metadata">

**Author:** [@wymli](https://discuss.elastic.co/u/wymli)\
**Replies:** 1\
**Last updated:** [June 28, 2023, 3:55am UTC](https://discuss.elastic.co/t/how-to-configure-filebeat-log-format-to-human-readable-instead-of-json/337032 "2023-06-28T03:55:48Z")

</div>

With -e option, Filebeat version 7.9.1 will output logs in this human-readable way. e.g. 2023-06-28T11:51:10.059 + 0800 INFO \[publisher\] pipeline/retry.go: 223 done But filebeat version 8.8.1 does not, outputs the lo…

---

## [How to migrate data older than 30 day from a cluster to another cluster](https://discuss.elastic.co/t/how-to-migrate-data-older-than-30-day-from-a-cluster-to-another-cluster/337029)

<div class="topic-metadata">

**Author:** [@Tai\_Nguyen\_Huu](https://discuss.elastic.co/u/Tai_Nguyen_Huu)\
**Replies:** 0\
**Last updated:** [June 28, 2023, 2:48am UTC](https://discuss.elastic.co/t/how-to-migrate-data-older-than-30-day-from-a-cluster-to-another-cluster/337029 "2023-06-28T02:48:51Z")

</div>

Hi guys, I have a elasticsearch cluster, I wan to migrate data older than 30 day from a cluster to another cluster by automatic .

---

## [How to check total required heap for ES 8.8](https://discuss.elastic.co/t/how-to-check-total-required-heap-for-es-8-8/336821)

<div class="topic-metadata">

**Author:** [@Geunmoon\_Oh](https://discuss.elastic.co/u/Geunmoon_Oh)\
**Replies:** 13\
**Last updated:** [June 28, 2023, 2:46am UTC](https://discuss.elastic.co/t/how-to-check-total-required-heap-for-es-8-8/336821 "2023-06-28T02:46:06Z")

</div>

To set my ES node's heap minimum, I referenced Size your shards (Size your shards | Elasticsearch Guide \[8.8\] | Elastic). "total\_deduplicated\_mapping\_size" : "4.1kb“ "total\_estimated\_overhead" : “13.5mb“ "extra heap f…

---

## [How to Integration with Intersystems' IRIS database](https://discuss.elastic.co/t/how-to-integration-with-intersystems-iris-database/337025)

<div class="topic-metadata">

**Author:** [@tomming](https://discuss.elastic.co/u/tomming)\
**Replies:** 0\
**Last updated:** [June 28, 2023, 1:26am UTC](https://discuss.elastic.co/t/how-to-integration-with-intersystems-iris-database/337025 "2023-06-28T01:26:58Z")

</div>

Need help Integration with Intersystems' IRIS database.

---

## [ES migration from 6.8 to 7.17. Data type change in template for "date" type](https://discuss.elastic.co/t/es-migration-from-6-8-to-7-17-data-type-change-in-template-for-date-type/337022)

<div class="topic-metadata">

**Author:** [@Abhilashsr2008](https://discuss.elastic.co/u/Abhilashsr2008)\
**Replies:** 0\
**Last updated:** [June 27, 2023, 11:19pm UTC](https://discuss.elastic.co/t/es-migration-from-6-8-to-7-17-data-type-change-in-template-for-date-type/337022 "2023-06-27T23:19:59Z")

</div>

Hi Team We are planning to move from ES 6.8 to 7.17 server migration . But in 7.17 -ve values are not supported for date field. So am thinking to change the index template for that specific field from date to long type …

---

## [New to ELK & Kibana, Error Message: "security\_exception: missing authentication credentials for REST request "](https://discuss.elastic.co/t/new-to-elk-kibana-error-message-security-exception-missing-authentication-credentials-for-rest-request/336961)

<div class="topic-metadata">

**Author:** [@General-Trident](https://discuss.elastic.co/u/General-Trident)\
**Replies:** 2\
**Last updated:** [June 27, 2023, 8:14pm UTC](https://discuss.elastic.co/t/new-to-elk-kibana-error-message-security-exception-missing-authentication-credentials-for-rest-request/336961 "2023-06-27T20:14:18Z")

</div>

I'm new to ELK & Kibana. Haven't made any recommendable configs apart from just installing the instances (which are only Elasticsearch & Kibana so far). Elasticsearch status is ready and running, but I still can't access…

---

## [Unable to access kibana despite creating azure elastic ISV service with owner subscription](https://discuss.elastic.co/t/unable-to-access-kibana-despite-creating-azure-elastic-isv-service-with-owner-subscription/336916)

<div class="topic-metadata">

**Author:** [@Francis\_Salvin](https://discuss.elastic.co/u/Francis_Salvin)\
**Replies:** 4\
**Last updated:** [June 27, 2023, 8:14pm UTC](https://discuss.elastic.co/t/unable-to-access-kibana-despite-creating-azure-elastic-isv-service-with-owner-subscription/336916 "2023-06-27T20:14:04Z")

</div>

I am working on deploying azure elastic ISV service and using it with apps deployed in AKS cluster. Deployed successfully, but any elastic task I do after that is prompted for approval from admin (like accessing kibana) …

---

## [Making API POST request in Kibana plugin](https://discuss.elastic.co/t/making-api-post-request-in-kibana-plugin/337003)

<div class="topic-metadata">

**Author:** [@trosagnant](https://discuss.elastic.co/u/trosagnant)\
**Replies:** 1\
**Last updated:** [June 27, 2023, 7:32pm UTC](https://discuss.elastic.co/t/making-api-post-request-in-kibana-plugin/337003 "2023-06-27T19:32:49Z")

</div>

Hello everyone, I'm trying to create a simple Kibana plugin which should send \_update\_by\_query request to elasticsearch, with values to updated provided by GUI in said plugin, but I can't quite grasp how making API call…

---

## [Gathering Top Values Through Elk API](https://discuss.elastic.co/t/gathering-top-values-through-elk-api/337019)

<div class="topic-metadata">

**Author:** [@hi\_xavier](https://discuss.elastic.co/u/hi_xavier)\
**Replies:** 0\
**Last updated:** [June 27, 2023, 6:52pm UTC](https://discuss.elastic.co/t/gathering-top-values-through-elk-api/337019 "2023-06-27T18:52:15Z")

</div>

Hi, Is it possible, with the combination of Elk API and Aggregations , to gather top values. For example, the top 5 error messages from a set of results?

---

## [Which nodes to have logstash send to cluster](https://discuss.elastic.co/t/which-nodes-to-have-logstash-send-to-cluster/337018)

<div class="topic-metadata">

**Author:** [@eh2021-elastic](https://discuss.elastic.co/u/eh2021-elastic)\
**Replies:** 0\
**Last updated:** [June 27, 2023, 6:37pm UTC](https://discuss.elastic.co/t/which-nodes-to-have-logstash-send-to-cluster/337018 "2023-06-27T18:37:00Z")

</div>

I have an elastic 7.16 cluster that consist of 4 dedicated masterand 16 data nodes. I have logstash sending syslog data from various network systems, firewalls, etc and just noticed the logstash config on some devices di…

---

## [Pipeline error "pipeline-id" :exception=\>#\<Psych::DisallowedClass: Tried to load unspecified class: Time](https://discuss.elastic.co/t/pipeline-error-pipeline-id-exception-psych-tried-to-load-unspecified-class-time/336786)

<div class="topic-metadata">

**Author:** [@Gelinski](https://discuss.elastic.co/u/Gelinski)\
**Replies:** 2\
**Last updated:** [June 27, 2023, 6:29pm UTC](https://discuss.elastic.co/t/pipeline-error-pipeline-id-exception-psych-tried-to-load-unspecified-class-time/336786 "2023-06-27T18:29:20Z")

</div>

Hello folks, I have a logstash pipeline that is using a jdbc input and is configured with a schedule (0/1 \* \* \* \*) and after change its schedule to any other schedule the following error starts to happen: \[2023-06-23T…

---

## [Unwanted metrics](https://discuss.elastic.co/t/unwanted-metrics/336885)

<div class="topic-metadata">

**Author:** [@rchmiel\_fp](https://discuss.elastic.co/u/rchmiel_fp)\
**Replies:** 5\
**Last updated:** [June 27, 2023, 6:02pm UTC](https://discuss.elastic.co/t/unwanted-metrics/336885 "2023-06-27T18:02:38Z")

</div>

Hello, I have a working .NET based system utilizing APM 7.17.9 and data streams. Lastly we implemented filter to remove logging transactions for \[OPTION\] requests which works but we still get metrics logged for those re…

---

## [Configure limit.conf for ElasticSearch server](https://discuss.elastic.co/t/configure-limit-conf-for-elasticsearch-server/336930)

<div class="topic-metadata">

**Author:** [@TomTom](https://discuss.elastic.co/u/TomTom)\
**Replies:** 3\
**Last updated:** [June 27, 2023, 12:43pm UTC](https://discuss.elastic.co/t/configure-limit-conf-for-elasticsearch-server/336930 "2023-06-27T12:43:19Z")

</div>

The Elasticsearch documentation says that I should configure nofile and nproc for better performance. But the documentation is a bit confusing. First, do I set it to the "elastic" user that was created by Elasticsearch…

---

## [Soar in elastic](https://discuss.elastic.co/t/soar-in-elastic/334425)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 4\
**Last updated:** [June 27, 2023, 5:25pm UTC](https://discuss.elastic.co/t/soar-in-elastic/334425 "2023-06-27T17:25:21Z")

</div>

I understand there is a way to create a case and assign to someone when an alert is triggered. But SOAR means automatic remediation. The documentation says 'Easily automate your team’s security incident response with Ela…

---

## [\[App Search\] - Facet Adjustment](https://discuss.elastic.co/t/app-search-facet-adjustment/336953)

<div class="topic-metadata">

**Author:** [@aisyaharifin](https://discuss.elastic.co/u/aisyaharifin)\
**Replies:** 1\
**Last updated:** [June 27, 2023, 4:08pm UTC](https://discuss.elastic.co/t/app-search-facet-adjustment/336953 "2023-06-27T16:08:51Z")

</div>

Hello, I want to ask, how can I adjust the Facet to keep the selection of user instead reset it every single time user search new thing? It seems like supposed when user already filter by for example SERVICE item type a…

---

## [Potential memory leak issue with filebeat and metricbeat](https://discuss.elastic.co/t/potential-memory-leak-issue-with-filebeat-and-metricbeat/334353)

<div class="topic-metadata">

**Author:** [@kbujold\_wr](https://discuss.elastic.co/u/kbujold_wr)\
**Replies:** 8\
**Last updated:** [June 27, 2023, 4:01pm UTC](https://discuss.elastic.co/t/potential-memory-leak-issue-with-filebeat-and-metricbeat/334353 "2023-06-27T16:01:27Z")

</div>

Since upgrading from ELK 7.17.1 to ELK 8.6.2 (and even with ELK 8.7.1) we are experiencing OOMKilled on filebeat and metricbeat pods. We had no issues with ELK 7.17.1. Increasing the resources allocations does not resolv…

---

## [BACnet - ingest data from field devices](https://discuss.elastic.co/t/bacnet-ingest-data-from-field-devices/337015)

<div class="topic-metadata">

**Author:** [@Ostaseski](https://discuss.elastic.co/u/Ostaseski)\
**Replies:** 0\
**Last updated:** [June 27, 2023, 3:46pm UTC](https://discuss.elastic.co/t/bacnet-ingest-data-from-field-devices/337015 "2023-06-27T15:46:00Z")

</div>

I cannot read the responses on how to ingest data from field devices that talk Modbus TCP and BACnet IP to Elastic Logstash. Were there any suggestions or perhaps an update? Any help would be appreciated. Thanks

---

## [Preventing/identifying credit card breach in elastic using SIEM](https://discuss.elastic.co/t/preventing-identifying-credit-card-breach-in-elastic-using-siem/337014)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 0\
**Last updated:** [June 27, 2023, 3:45pm UTC](https://discuss.elastic.co/t/preventing-identifying-credit-card-breach-in-elastic-using-siem/337014 "2023-06-27T15:45:09Z")

</div>

Hi! I see elastic has a rich array of security features (SIEM, security analytics, endpoint detection, etc). Is there a way to identify/detect if credit card details were crawled by hackers for online transactions? Gi…

---

## ["target\_prefix" equivalent for ingest pipeline?](https://discuss.elastic.co/t/target-prefix-equivalent-for-ingest-pipeline/337009)

<div class="topic-metadata">

**Author:** [@andrew.klaassen](https://discuss.elastic.co/u/andrew.klaassen)\
**Replies:** 2\
**Last updated:** [June 27, 2023, 3:28pm UTC](https://discuss.elastic.co/t/target-prefix-equivalent-for-ingest-pipeline/337009 "2023-06-27T15:28:19Z")

</div>

The filebeat dissect processor has a handy "target\_prefix" option, which allows everything it extracts to be placed under a common prefix. Is there any equivalent for the dissect or grok processors in an ingest pipeline…

---

## [Enrich index with data found in another index](https://discuss.elastic.co/t/enrich-index-with-data-found-in-another-index/336966)

<div class="topic-metadata">

**Author:** [@stobbe](https://discuss.elastic.co/u/stobbe)\
**Replies:** 1\
**Last updated:** [June 27, 2023, 2:50pm UTC](https://discuss.elastic.co/t/enrich-index-with-data-found-in-another-index/336966 "2023-06-27T14:50:29Z")

</div>

Hello, What is the best way to add a field to an existing indexm where the value is filled with data from an other index. E.g. most commont example you have an index with a name field amd you want to add an email addr…

---

## [Elastic search cluster red primary shards missing](https://discuss.elastic.co/t/elastic-search-cluster-red-primary-shards-missing/337004)

<div class="topic-metadata">

**Author:** [@Nilesh\_Jethwani](https://discuss.elastic.co/u/Nilesh_Jethwani)\
**Replies:** 1\
**Last updated:** [June 27, 2023, 2:21pm UTC](https://discuss.elastic.co/t/elastic-search-cluster-red-primary-shards-missing/337004 "2023-06-27T14:21:31Z")

</div>

Kibana is showing elastic health as red primary shards missing I have single node cluster. How can i fix this red status ?

---

## [Dynamic instances of Elastic Agent](https://discuss.elastic.co/t/dynamic-instances-of-elastic-agent/337005)

<div class="topic-metadata">

**Author:** [@hti](https://discuss.elastic.co/u/hti)\
**Replies:** 0\
**Last updated:** [June 27, 2023, 2:14pm UTC](https://discuss.elastic.co/t/dynamic-instances-of-elastic-agent/337005 "2023-06-27T14:14:11Z")

</div>

Hello, we are spawning multiple Windows Server instances from a golden image. These instances get destroyed and recreated daily. For log collection we installed and enrolled the Elastic Agent in the golden image. We do…

[Previous page](https://discuss.elastic.co/latest.md?page=624)

[Next page](https://discuss.elastic.co/latest.md?page=626)
