# Latest

**URL:** https://discuss.elastic.co/latest.md?page=629

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 630

---

## [Use DiscoverGridFlyout of discover-plugin in custom plugin](https://discuss.elastic.co/t/use-discovergridflyout-of-discover-plugin-in-custom-plugin/336807)

<div class="topic-metadata">

**Author:** [@Sheereen](https://discuss.elastic.co/u/Sheereen)\
**Replies:** 2\
**Last updated:** [June 24, 2023, 9:47am UTC](https://discuss.elastic.co/t/use-discovergridflyout-of-discover-plugin-in-custom-plugin/336807 "2023-06-24T09:47:51Z")

</div>

Hi, I am developing a custom Kibana plugin in React. I want to use the DiscoverGridFlyout within the Discover plugin inside my plugin. I found this Github feature link for the same (\[Discover\] Extract DiscoverGridFlyou…

---

## [Nodes are offline](https://discuss.elastic.co/t/nodes-are-offline/335716)

<div class="topic-metadata">

**Author:** [@Siavash\_Fazli](https://discuss.elastic.co/u/Siavash_Fazli)\
**Replies:** 9\
**Last updated:** [June 24, 2023, 8:25am UTC](https://discuss.elastic.co/t/nodes-are-offline/335716 "2023-06-24T08:25:37Z")

</div>

Hi, dears. I deployed a 3-node elastic cluster with default docker-compose in the Elastic document. but expect the master node, other nodes are offline. Are there any additional settings that I have to do? also why m…

---

## [Supporting different calendars, like Jalali (persian) calendar](https://discuss.elastic.co/t/supporting-different-calendars-like-jalali-persian-calendar/336433)

<div class="topic-metadata">

**Author:** [@nevahid](https://discuss.elastic.co/u/nevahid)\
**Replies:** 5\
**Last updated:** [June 24, 2023, 4:40am UTC](https://discuss.elastic.co/t/supporting-different-calendars-like-jalali-persian-calendar/336433 "2023-06-24T04:40:20Z")

</div>

is it possible to filter dates based on different calendar type? i mean instead of Gregorian date, we use Jalali (Shamsi) calendar, where month names and days are different. i would be very grateful if you can help me. …

---

## [Integrations Page in Kibana is too slow and constantly have timeout erros](https://discuss.elastic.co/t/integrations-page-in-kibana-is-too-slow-and-constantly-have-timeout-erros/336785)

<div class="topic-metadata">

**Author:** [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Replies:** 2\
**Last updated:** [June 24, 2023, 2:41am UTC](https://discuss.elastic.co/t/integrations-page-in-kibana-is-too-slow-and-constantly-have-timeout-erros/336785 "2023-06-24T02:41:04Z")

</div>

Hello, Almost every time I need to use the Integration pages to add a new Integration to the Elastic Agent or update the current ones I have some issues with being too slow or even timing out. I started using Integrati…

---

## [.NET: Using newer NEST high-level client against previous version of Elasticsearch](https://discuss.elastic.co/t/net-using-newer-nest-high-level-client-against-previous-version-of-elasticsearch/336613)

<div class="topic-metadata">

**Author:** [@Thomas\_Doman](https://discuss.elastic.co/u/Thomas_Doman)\
**Replies:** 6\
**Last updated:** [June 23, 2023, 7:43pm UTC](https://discuss.elastic.co/t/net-using-newer-nest-high-level-client-against-previous-version-of-elasticsearch/336613 "2023-06-23T19:43:25Z")

</div>

NEST: 6.8.6 Elasticsearch: 6.8.23 We're looking to upgrade our Elasticsearch clusters now that we're on ECK (hallelujah!). Our .NET code uses NEST and I'd like to try the NEST 7.17.5 NuGet package without upgrading ou…

---

## [How to connect ES8.8 through TCP port & certificate in java?](https://discuss.elastic.co/t/how-to-connect-es8-8-through-tcp-port-certificate-in-java/336793)

<div class="topic-metadata">

**Author:** [@Jignesh\_Soni](https://discuss.elastic.co/u/Jignesh_Soni)\
**Replies:** 1\
**Last updated:** [June 23, 2023, 7:40pm UTC](https://discuss.elastic.co/t/how-to-connect-es8-8-through-tcp-port-certificate-in-java/336793 "2023-06-23T19:40:35Z")

</div>

Hi Experts, i am able to connect the ES7.17 through tcp port , but in ES 8.8 library there is no class to connect tcp port. Some code snippet is working in ES 7.17: Client getClient() { Settings settings = Settings.…

---

## [Kibana EVP\_DecryptFinal Error - OpenSSL Version?](https://discuss.elastic.co/t/kibana-evp-decryptfinal-error-openssl-version/336783)

<div class="topic-metadata">

**Author:** [@josh42](https://discuss.elastic.co/u/josh42)\
**Replies:** 1\
**Last updated:** [June 23, 2023, 6:22pm UTC](https://discuss.elastic.co/t/kibana-evp-decryptfinal-error-openssl-version/336783 "2023-06-23T18:22:49Z")

</div>

I'm trying to set up Kibana's server SSL and keep encountering an error related to decrypting the certificate. I created my certs through openssl, and Googling indicates an openssl mismatch might be causing this error. I…

---

## [\[ERROR\]\[logstash.filters.aggregate\]\[main\]Aggregate exception occurred {:error=\>#\<NoMethodError: undefined method \`+' for nil:NilClass\>](https://discuss.elastic.co/t/error-logstash-filters-aggregate-main-aggregate-exception-occurred-error-nomethoderror-undefined-method-for-nil-nilclass/336741)

<div class="topic-metadata">

**Author:** [@Ceyhun\_Quliyev](https://discuss.elastic.co/u/Ceyhun_Quliyev)\
**Replies:** 2\
**Last updated:** [June 23, 2023, 4:25pm UTC](https://discuss.elastic.co/t/error-logstash-filters-aggregate-main-aggregate-exception-occurred-error-nomethoderror-undefined-method-for-nil-nilclass/336741 "2023-06-23T16:25:51Z")

</div>

Dear forum members, We have encountered a problem and cannot solve it. I would be grateful if you could help us with a solution. Below I am providing a link to the configuration file itself and the error logs.

---

## [Access fields from input plugin (cloudwatch\_logs\_importer)](https://discuss.elastic.co/t/access-fields-from-input-plugin-cloudwatch-logs-importer/336585)

<div class="topic-metadata">

**Author:** [@Maarten\_Dekker](https://discuss.elastic.co/u/Maarten_Dekker)\
**Replies:** 19\
**Last updated:** [June 23, 2023, 4:13pm UTC](https://discuss.elastic.co/t/access-fields-from-input-plugin-cloudwatch-logs-importer/336585 "2023-06-23T16:13:27Z")

</div>

Hi, I am using the cloudwatch\_logs\_importer plugin to read and grok logs from cloudwatch. It all works fine, but I am facing issues to access a field which is created by the input module itself: \[cloudwatch\_logs\]\[log\_…

---

## [New node cannot join to the existing cluster](https://discuss.elastic.co/t/new-node-cannot-join-to-the-existing-cluster/336720)

<div class="topic-metadata">

**Author:** [@rachelyang](https://discuss.elastic.co/u/rachelyang)\
**Replies:** 5\
**Last updated:** [June 23, 2023, 3:28pm UTC](https://discuss.elastic.co/t/new-node-cannot-join-to-the-existing-cluster/336720 "2023-06-23T15:28:39Z")

</div>

I have two servers for elasticsearch. After I installed the elasticsearch on one server, I started the service and ran /usr/share/elasticsearch/bin/elasticsearch-create-enrollment-token -s node to generate an environmen…

---

## [Deployment disk usage](https://discuss.elastic.co/t/deployment-disk-usage/336778)

<div class="topic-metadata">

**Author:** [@pavlod](https://discuss.elastic.co/u/pavlod)\
**Replies:** 4\
**Last updated:** [June 23, 2023, 3:16pm UTC](https://discuss.elastic.co/t/deployment-disk-usage/336778 "2023-06-23T15:16:17Z")

</div>

Hello! I'm using Elastic deployment with apps: Elasticsearch, Kibana, APM, Fleet, Enterprise Search. (All these apps located on one disk). So I need to set up an alert of disk space (90%). How and where can I do it? …

---

## [Logstash won't start as deamon](https://discuss.elastic.co/t/logstash-wont-start-as-deamon/336629)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 3\
**Last updated:** [June 23, 2023, 2:51pm UTC](https://discuss.elastic.co/t/logstash-wont-start-as-deamon/336629 "2023-06-23T14:51:41Z")

</div>

I know I have seen this issue in past and was fixed by using different ls\_temp dir for logstash. but this time it won't work. here is error message. any idea? this dir /s1/log/logstash is wide open stat /s1/log/logst…

---

## [Prebuilt security rule not working with fleet architecture](https://discuss.elastic.co/t/prebuilt-security-rule-not-working-with-fleet-architecture/336779)

<div class="topic-metadata">

**Author:** [@kfdl](https://discuss.elastic.co/u/kfdl)\
**Replies:** 0\
**Last updated:** [June 23, 2023, 2:16pm UTC](https://discuss.elastic.co/t/prebuilt-security-rule-not-working-with-fleet-architecture/336779 "2023-06-23T14:16:31Z")

</div>

Hello All, first of all thank you for this product, your support and your time. :slight\_smile: I am using the Elastic Stack for a couple month to gather all the logs of my servers and i'm using the fleet server to enro…

---

## [ECS Format and Index Mappings](https://discuss.elastic.co/t/ecs-format-and-index-mappings/336740)

<div class="topic-metadata">

**Author:** [@lxk3](https://discuss.elastic.co/u/lxk3)\
**Replies:** 1\
**Last updated:** [June 23, 2023, 1:59pm UTC](https://discuss.elastic.co/t/ecs-format-and-index-mappings/336740 "2023-06-23T13:59:57Z")

</div>

Hello there, we want to use the ECS log format for our new applications. We already use datastreams with index templates and predefined mappings and I was wondering if we need to write a new mapping for ECS or if there …

---

## [Multiple tables as jdbc input in logstash pipeline](https://discuss.elastic.co/t/multiple-tables-as-jdbc-input-in-logstash-pipeline/336724)

<div class="topic-metadata">

**Author:** [@PodarcisMuralis](https://discuss.elastic.co/u/PodarcisMuralis)\
**Replies:** 4\
**Last updated:** [June 23, 2023, 1:58pm UTC](https://discuss.elastic.co/t/multiple-tables-as-jdbc-input-in-logstash-pipeline/336724 "2023-06-23T13:58:09Z")

</div>

I have 4 tables in oracle database and have a SQL query beginning with CTS (Common Table Expressions) which combines and creates a new single table. I want to create a pipeline using jdbc input and read date once in a …

---

## [How can change the data node to master node?](https://discuss.elastic.co/t/how-can-change-the-data-node-to-master-node/336770)

<div class="topic-metadata">

**Author:** [@merson](https://discuss.elastic.co/u/merson)\
**Replies:** 7\
**Last updated:** [June 23, 2023, 1:46pm UTC](https://discuss.elastic.co/t/how-can-change-the-data-node-to-master-node/336770 "2023-06-23T13:46:29Z")

</div>

I have 3 data node, so I want to change the one node for master and another two nodes for data nodes.

---

## [Duplicate events user log in winlogbeat using drop event filter](https://discuss.elastic.co/t/duplicate-events-user-log-in-winlogbeat-using-drop-event-filter/336536)

<div class="topic-metadata">

**Author:** [@Cruz](https://discuss.elastic.co/u/Cruz)\
**Replies:** 3\
**Last updated:** [June 23, 2023, 1:43pm UTC](https://discuss.elastic.co/t/duplicate-events-user-log-in-winlogbeat-using-drop-event-filter/336536 "2023-06-23T13:43:45Z")

</div>

Hello all, What I want to achieve is to remove the duplicate events. How should I do that? I am stuck here. Here is the scenario: When I successfully login into my lab computer there is the event ID 4672 that duplica…

---

## [How to pass the value of filter group, in the canvas expression editor](https://discuss.elastic.co/t/how-to-pass-the-value-of-filter-group-in-the-canvas-expression-editor/336773)

<div class="topic-metadata">

**Author:** [@bhavya](https://discuss.elastic.co/u/bhavya)\
**Replies:** 0\
**Last updated:** [June 23, 2023, 12:43pm UTC](https://discuss.elastic.co/t/how-to-pass-the-value-of-filter-group-in-the-canvas-expression-editor/336773 "2023-06-23T12:43:55Z")

</div>

I have created a dropdown in canvas workpad, having values of company.name field. The name of the filterGroup is customerGroup Lets say the values in the dropdown are: "xyz" and "ABC" I want to show the asset only if t…

---

## [Change index name within filebeats module file](https://discuss.elastic.co/t/change-index-name-within-filebeats-module-file/336772)

<div class="topic-metadata">

**Author:** [@jazzl0ver](https://discuss.elastic.co/u/jazzl0ver)\
**Replies:** 1\
**Last updated:** [June 23, 2023, 12:31pm UTC](https://discuss.elastic.co/t/change-index-name-within-filebeats-module-file/336772 "2023-06-23T12:31:02Z")

</div>

Hi, Filebeat version is 7.10.2 According to Configuring Input Type for Filebeat Module I was trying to do the same for the index: # cat /etc/filebeat/modules.d/haproxy.yml # Module: haproxy # Docs: https://www.elastic…

---

## [OpenShift 4 - Fleet and Elastic Agent](https://discuss.elastic.co/t/openshift-4-fleet-and-elastic-agent/336771)

<div class="topic-metadata">

**Author:** [@WannaBeGeekster](https://discuss.elastic.co/u/WannaBeGeekster)\
**Replies:** 0\
**Last updated:** [June 23, 2023, 12:26pm UTC](https://discuss.elastic.co/t/openshift-4-fleet-and-elastic-agent/336771 "2023-06-23T12:26:41Z")

</div>

Could someone post a full example of getting Fleet Server to work on OpenShift 4? I have cobbled together everything that I could but I am getting errors still and can't find anything about these errors. Gave correct s…

---

## [How to Remove Gaps between graphs, once hour filter is applied](https://discuss.elastic.co/t/how-to-remove-gaps-between-graphs-once-hour-filter-is-applied/336530)

<div class="topic-metadata">

**Author:** [@Arshukla](https://discuss.elastic.co/u/Arshukla)\
**Replies:** 9\
**Last updated:** [June 23, 2023, 12:17pm UTC](https://discuss.elastic.co/t/how-to-remove-gaps-between-graphs-once-hour-filter-is-applied/336530 "2023-06-23T12:17:20Z")

</div>

Hello Team, I have been trying to put filter of hour on my graphical dashboard, which I did by putting a scripted field of Hour, and the same I have added as filter on my graphical dashboard However, their are gaps …

---

## [Count arrays as an object](https://discuss.elastic.co/t/count-arrays-as-an-object/336626)

<div class="topic-metadata">

**Author:** [@elastic\_dude](https://discuss.elastic.co/u/elastic_dude)\
**Replies:** 1\
**Last updated:** [June 23, 2023, 11:57am UTC](https://discuss.elastic.co/t/count-arrays-as-an-object/336626 "2023-06-23T11:57:56Z")

</div>

Hi, I am struggling to get an aggregation to work. We have an array with multiple values and what I am trying to do is count (and return the values) how many documents have the exact same set of values in the array. The…

---

## [How can i write with red color?](https://discuss.elastic.co/t/how-can-i-write-with-red-color/336764)

<div class="topic-metadata">

**Author:** [@Hocine\_MEZOUGHI](https://discuss.elastic.co/u/Hocine_MEZOUGHI)\
**Replies:** 1\
**Last updated:** [June 23, 2023, 11:48am UTC](https://discuss.elastic.co/t/how-can-i-write-with-red-color/336764 "2023-06-23T11:48:36Z")

</div>

I have a WATCHER that calculates the percentage difference and I'd like to write this difference in red in the body of the email. Using like this : {{ecart}} My example doesn't work, what wrong ???? "actions": { "sen…

---

## [Winlogbeat ingest pipelines missing geoIP](https://discuss.elastic.co/t/winlogbeat-ingest-pipelines-missing-geoip/334575)

<div class="topic-metadata">

**Author:** [@Alexander\_A](https://discuss.elastic.co/u/Alexander_A)\
**Replies:** 5\
**Last updated:** [June 23, 2023, 11:51am UTC](https://discuss.elastic.co/t/winlogbeat-ingest-pipelines-missing-geoip/334575 "2023-06-23T11:51:07Z")

</div>

Winlogbeat ingest pipelines Security and Sysmon missing geoIP. It is on purpose? All filebeat ingest pipelines have geoIP enrichment and it seems strange that winlogbeat missing geoIP.

---

## [Winlogbeat stops sending logs](https://discuss.elastic.co/t/winlogbeat-stops-sending-logs/336756)

<div class="topic-metadata">

**Author:** [@Fursel](https://discuss.elastic.co/u/Fursel)\
**Replies:** 1\
**Last updated:** [June 23, 2023, 11:31am UTC](https://discuss.elastic.co/t/winlogbeat-stops-sending-logs/336756 "2023-06-23T11:31:57Z")

</div>

Hello, We are collecting events from DCs and somehow lately winlogbeat stopps sending them on multiple devices. I did set logging for debug logging.level: debug logging.to\_file: true logging.files: path: 'C:\\Progra…

---

## [Modifing eui basic table expanded rows](https://discuss.elastic.co/t/modifing-eui-basic-table-expanded-rows/336753)

<div class="topic-metadata">

**Author:** [@iljaskajrris](https://discuss.elastic.co/u/iljaskajrris)\
**Replies:** 0\
**Last updated:** [June 23, 2023, 8:56am UTC](https://discuss.elastic.co/t/modifing-eui-basic-table-expanded-rows/336753 "2023-06-23T08:56:41Z")

</div>

Hi all! I took euiBasicTable expanded rows, but ran into issue. Cant make any button clickable inside of expanded event. Can anybody help with that or give some directions? I just need the Table to be able to open contex…

---

## [Logstash s3 input reads file multiple times](https://discuss.elastic.co/t/logstash-s3-input-reads-file-multiple-times/336751)

<div class="topic-metadata">

**Author:** [@jpchev](https://discuss.elastic.co/u/jpchev)\
**Replies:** 0\
**Last updated:** [June 23, 2023, 8:52am UTC](https://discuss.elastic.co/t/logstash-s3-input-reads-file-multiple-times/336751 "2023-06-23T08:52:56Z")

</div>

hello, I have configured the following s3 input in logstash, and it keeps reading the same file from the given S3 bucket. I noticed that the given sincedb file ${DATA\_DIR}/.sincedb\_activities.txt is being used and it co…

---

## [Use case exception](https://discuss.elastic.co/t/use-case-exception/336750)

<div class="topic-metadata">

**Author:** [@PerfectSushi](https://discuss.elastic.co/u/PerfectSushi)\
**Replies:** 0\
**Last updated:** [June 23, 2023, 8:52am UTC](https://discuss.elastic.co/t/use-case-exception/336750 "2023-06-23T08:52:29Z")

</div>

Dear team, I am currently facing some challenges while attempting to create a correlated use case involving the prebuilt "Whoami Process Activity." The issue arises because we need to make an exception for a previous lo…

---

## [Elasticsearch 8 won't start on Centos 7](https://discuss.elastic.co/t/elasticsearch-8-wont-start-on-centos-7/336722)

<div class="topic-metadata">

**Author:** [@Geek2.0](https://discuss.elastic.co/u/Geek2.0)\
**Replies:** 4\
**Last updated:** [June 23, 2023, 8:06am UTC](https://discuss.elastic.co/t/elasticsearch-8-wont-start-on-centos-7/336722 "2023-06-23T08:06:26Z")

</div>

I have installed Elasticsearch 7.8 on centos 7 server and it was running normally. After uninstalling it and installing elasticsearch 8.8, I get the following error when trying to start it with the command sudo systemc…

---

## [Sort results by query string](https://discuss.elastic.co/t/sort-results-by-query-string/336743)

<div class="topic-metadata">

**Author:** [@samba](https://discuss.elastic.co/u/samba)\
**Replies:** 0\
**Last updated:** [June 23, 2023, 7:40am UTC](https://discuss.elastic.co/t/sort-results-by-query-string/336743 "2023-06-23T07:40:11Z")

</div>

Hello, It is possible to set sort order by querystring? What I mean is when a user searches pink chairs the results beggining with pink and containing chairs must appear first and followed by that contain the query str…

[Previous page](https://discuss.elastic.co/latest.md?page=628)

[Next page](https://discuss.elastic.co/latest.md?page=630)
