# Latest

**URL:** https://discuss.elastic.co/latest.md?page=645

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 646

---

## [Anyone please help me for How to make flyaway for elastic search with node js?](https://discuss.elastic.co/t/anyone-please-help-me-for-how-to-make-flyaway-for-elastic-search-with-node-js/335707)

<div class="topic-metadata">

**Author:** [@faiyaz\_18](https://discuss.elastic.co/u/faiyaz_18)\
**Replies:** 4\
**Last updated:** [June 12, 2023, 12:33pm UTC](https://discuss.elastic.co/t/anyone-please-help-me-for-how-to-make-flyaway-for-elastic-search-with-node-js/335707 "2023-06-12T12:33:33Z")

</div>

Elastic search

---

## [Fail to checkin to fleet-server](https://discuss.elastic.co/t/fail-to-checkin-to-fleet-server/334210)

<div class="topic-metadata">

**Author:** [@ethical20](https://discuss.elastic.co/u/ethical20)\
**Replies:** 16\
**Last updated:** [June 12, 2023, 12:33pm UTC](https://discuss.elastic.co/t/fail-to-checkin-to-fleet-server/334210 "2023-06-12T12:33:16Z")

</div>

Hi All, I have successfully enrolled my remote server/machine into my Fleet server and I can see my metrics and logs coming thru. The issue is that at the beginning of the enrollment the status of the agent in kiban…

---

## [Rally 2.8.0](https://discuss.elastic.co/t/rally-2-8-0/335769)

<div class="topic-metadata">

**Author:** [@gbanasiak](https://discuss.elastic.co/u/gbanasiak)\
**Replies:** 0\
**Last updated:** [June 12, 2023, 12:11pm UTC](https://discuss.elastic.co/t/rally-2-8-0/335769 "2023-06-12T12:11:32Z")

</div>

Rally 2.8.0 has just been released. The new release brings support for Python 3.11. Highlights #1683: Upgrade Elasticsearch client to 8.6.1 #1669: Upgrade ES Client to 8.x Enhancements #1727: Allow configuring…

---

## [Cannot post document to TimeSeries DataStream after upgrade from 8.6.2 to 8.7.1](https://discuss.elastic.co/t/cannot-post-document-to-timeseries-datastream-after-upgrade-from-8-6-2-to-8-7-1/335313)

<div class="topic-metadata">

**Author:** [@VietDuc](https://discuss.elastic.co/u/VietDuc)\
**Replies:** 14\
**Last updated:** [June 12, 2023, 11:39am UTC](https://discuss.elastic.co/t/cannot-post-document-to-timeseries-datastream-after-upgrade-from-8-6-2-to-8-7-1/335313 "2023-06-12T11:39:57Z")

</div>

Hi everyone, We had some Timeseries DataStream in version 8.6.2 and we have just upgraded our cluster to version 8.7.1. However, after the upgrade, new documents cannot be posted to those TSDS and we got the following e…

---

## [Which storage type should I use for Elasticsearch?](https://discuss.elastic.co/t/which-storage-type-should-i-use-for-elasticsearch/335511)

<div class="topic-metadata">

**Author:** [@Yasser\_Alsawy](https://discuss.elastic.co/u/Yasser_Alsawy)\
**Replies:** 1\
**Last updated:** [June 12, 2023, 11:33am UTC](https://discuss.elastic.co/t/which-storage-type-should-i-use-for-elasticsearch/335511 "2023-06-12T11:33:59Z")

</div>

I'm installing elasticsearch and needs 2 TB storage for shipping from filesystem log files using beats and logstash. What is the proper storage type as per our required design (frequent writes, many nodes and less read) …

---

## [Which table to use/how to filter columns in aggreagtion based data table](https://discuss.elastic.co/t/which-table-to-use-how-to-filter-columns-in-aggreagtion-based-data-table/334209)

<div class="topic-metadata">

**Author:** [@Jonas\_S](https://discuss.elastic.co/u/Jonas_S)\
**Replies:** 1\
**Last updated:** [June 12, 2023, 11:18am UTC](https://discuss.elastic.co/t/which-table-to-use-how-to-filter-columns-in-aggreagtion-based-data-table/334209 "2023-06-12T11:18:57Z")

</div>

Hello, i'm using Kibana 8.7.0 and i have data in this form: {id: 1, valueToFilterBy: 0, valueToSum: 10, stringValue: "someString1"}, {id: 1, valueToFilterBy: 0, valueToSum: 20, stringValue: "someString2"}, {id: 1, va…

---

## [Kibana Table Visualisation CPU](https://discuss.elastic.co/t/kibana-table-visualisation-cpu/334968)

<div class="topic-metadata">

**Author:** [@rl0ne](https://discuss.elastic.co/u/rl0ne)\
**Replies:** 4\
**Last updated:** [June 12, 2023, 10:20am UTC](https://discuss.elastic.co/t/kibana-table-visualisation-cpu/334968 "2023-06-12T10:20:43Z")

</div>

Hello Everyone , Kibana 7.16 Need help to understand if it possible to create a table in Kibana to display servers where CPU above 80% for 5 minutes ( not a single event in 5 minutes but during 5 minutes ). So I can se…

---

## [Kibana failing to start due to unable to verify the first certificate](https://discuss.elastic.co/t/kibana-failing-to-start-due-to-unable-to-verify-the-first-certificate/335608)

<div class="topic-metadata">

**Author:** [@Sudhir\_Batchu](https://discuss.elastic.co/u/Sudhir_Batchu)\
**Replies:** 1\
**Last updated:** [June 12, 2023, 9:58am UTC](https://discuss.elastic.co/t/kibana-failing-to-start-due-to-unable-to-verify-the-first-certificate/335608 "2023-06-12T09:58:16Z")

</div>

Hi need help in fixing this ES version 8.8 Kibana version 8.8 Here is Kibana logs Jun 09 08:28:10 ip-100-90-3-56.us-west-2.compute.internal kibana\[20111\]: \[2023-06-09T08:28:10.667+00:00\]\[INFO \]\[plugins.screenshotting…

---

## [Error when developing plugin in Kibana 8.9 (master branch) and 8.6](https://discuss.elastic.co/t/error-when-developing-plugin-in-kibana-8-9-master-branch-and-8-6/335742)

<div class="topic-metadata">

**Author:** [@Sheereen](https://discuss.elastic.co/u/Sheereen)\
**Replies:** 1\
**Last updated:** [June 12, 2023, 9:19am UTC](https://discuss.elastic.co/t/error-when-developing-plugin-in-kibana-8-9-master-branch-and-8-6/335742 "2023-06-12T09:19:16Z")

</div>

Hi, I was working on a custom plugin in 8.5.3. It was working fine. Even new plugin generation, etc... all were smooth in 8.5.3. I had tried the same on 8.6... and now in 8.9. In both these versions, I just generated a…

---

## [Filebeat: How to edit apache module ingest pipeline](https://discuss.elastic.co/t/filebeat-how-to-edit-apache-module-ingest-pipeline/335749)

<div class="topic-metadata">

**Author:** [@Akshaychdev](https://discuss.elastic.co/u/Akshaychdev)\
**Replies:** 0\
**Last updated:** [June 12, 2023, 9:17am UTC](https://discuss.elastic.co/t/filebeat-how-to-edit-apache-module-ingest-pipeline/335749 "2023-06-12T09:17:09Z")

</div>

Using Elasticsearch and Kibana 7.17 with Filebeat and Filebeat-apache module to index apache access and error logs to elasticsearch. I need to add some more filtering to Apache Error log message, for that prepared the n…

---

## [Is is possible to disable clock skew adjustment for APM dashboard (kibana)](https://discuss.elastic.co/t/is-is-possible-to-disable-clock-skew-adjustment-for-apm-dashboard-kibana/335737)

<div class="topic-metadata">

**Author:** [@Xumin\_Zhou](https://discuss.elastic.co/u/Xumin_Zhou)\
**Replies:** 1\
**Last updated:** [June 12, 2023, 6:49am UTC](https://discuss.elastic.co/t/is-is-possible-to-disable-clock-skew-adjustment-for-apm-dashboard-kibana/335737 "2023-06-12T06:49:53Z")

</div>

As the title says. First-hand information (real readout) is important for monitoring and tracing. There're a lot of problems not solved with this adjustment, for example, it does not preserve the relative positions of …

---

## [ConnectionRefusedError: \[Errno 111\] Connection refused error while running rally for an existing elastic cluster](https://discuss.elastic.co/t/connectionrefusederror-errno-111-connection-refused-error-while-running-rally-for-an-existing-elastic-cluster/335333)

<div class="topic-metadata">

**Author:** [@Swathi\_Kakumanu](https://discuss.elastic.co/u/Swathi_Kakumanu)\
**Replies:** 3\
**Last updated:** [June 12, 2023, 6:37am UTC](https://discuss.elastic.co/t/connectionrefusederror-errno-111-connection-refused-error-while-running-rally-for-an-existing-elastic-cluster/335333 "2023-06-12T06:37:12Z")

</div>

Hi, I am new to rally and trying to run the benchmark for the existing cluster. I have 3 K8's nodes (1 master,2 worker) 192.168.105.116 192.168.105.117 192.168.105.118 I have created an Elasticsearch cluster on top…

---

## [Add unique value for each fields](https://discuss.elastic.co/t/add-unique-value-for-each-fields/335695)

<div class="topic-metadata">

**Author:** [@sevbans](https://discuss.elastic.co/u/sevbans)\
**Replies:** 6\
**Last updated:** [June 11, 2023, 9:26pm UTC](https://discuss.elastic.co/t/add-unique-value-for-each-fields/335695 "2023-06-11T21:26:30Z")

</div>

I have a index something like this: All countries' names, along with their populations, exist in my index. Since Kibana does not allow us to use the countries' normal names, I have to add unique country codes such as…

---

## [How can I add add an extra field to all documents indexed by beats](https://discuss.elastic.co/t/how-can-i-add-add-an-extra-field-to-all-documents-indexed-by-beats/335622)

<div class="topic-metadata">

**Author:** [@Carlos\_T](https://discuss.elastic.co/u/Carlos_T)\
**Replies:** 6\
**Last updated:** [June 11, 2023, 4:24pm UTC](https://discuss.elastic.co/t/how-can-i-add-add-an-extra-field-to-all-documents-indexed-by-beats/335622 "2023-06-11T16:24:54Z")

</div>

Hi all. Lets imagine that I have a single elasticsearch cluster to store document from two different companies Company1 has server1 server2 and server3 Company2 has server1 server2 and server3 For me the easier…

---

## [Metrics do nothing in my file](https://discuss.elastic.co/t/metrics-do-nothing-in-my-file/335700)

<div class="topic-metadata">

**Author:** [@javierelastic](https://discuss.elastic.co/u/javierelastic)\
**Replies:** 2\
**Last updated:** [June 11, 2023, 10:35am UTC](https://discuss.elastic.co/t/metrics-do-nothing-in-my-file/335700 "2023-06-11T10:35:19Z")

</div>

I am trying to count the number of logs that appear in my file. Now I am using a file with logs as an example, but later I will use a syslog, and I want it to count the logs that arrive in 2 minutes. if \[msgFinal\] =~…

---

## [URL Drilldown - How to pass specific column value](https://discuss.elastic.co/t/url-drilldown-how-to-pass-specific-column-value/335719)

<div class="topic-metadata">

**Author:** [@azulgrana](https://discuss.elastic.co/u/azulgrana)\
**Replies:** 0\
**Last updated:** [June 11, 2023, 10:32am UTC](https://discuss.elastic.co/t/url-drilldown-how-to-pass-specific-column-value/335719 "2023-06-11T10:32:22Z")

</div>

Hi there, I have a table with 3 fields. Id, IOC, Severity. And I have a set of drilldowns to perform an IOC search against virustotal, Whois and map the Id to an internal app. I'm using {{event.value}} across all the dr…

---

## [Too many open files](https://discuss.elastic.co/t/too-many-open-files/335677)

<div class="topic-metadata">

**Author:** [@lchqlchq](https://discuss.elastic.co/u/lchqlchq)\
**Replies:** 4\
**Last updated:** [June 11, 2023, 7:36am UTC](https://discuss.elastic.co/t/too-many-open-files/335677 "2023-06-11T07:36:32Z")

</div>

i have a three node es7.4 cluster without data. choose one node,ifdown the network，and es filehandler increasing quickly until the ulimit filehandler fills up。the new added filehandler point the same socket id as:ll /pro…

---

## [How to add \_size mapping to index template in elasticsearch?](https://discuss.elastic.co/t/how-to-add-size-mapping-to-index-template-in-elasticsearch/335432)

<div class="topic-metadata">

**Author:** [@Amirhossein\_eidy](https://discuss.elastic.co/u/Amirhossein_eidy)\
**Replies:** 6\
**Last updated:** [June 11, 2023, 6:54am UTC](https://discuss.elastic.co/t/how-to-add-size-mapping-to-index-template-in-elasticsearch/335432 "2023-06-11T06:54:38Z")

</div>

Hi friends I have installed size mapping plugin and I added it to Kibana meta fields too I could successfully enable "\_size" in Elasticsearch via bellow command and see the result in kibana PUT logstash-2023-06-06 { …

---

## [What are the benefits of using sync reindexing API instead of async reindexing API?](https://discuss.elastic.co/t/what-are-the-benefits-of-using-sync-reindexing-api-instead-of-async-reindexing-api/335712)

<div class="topic-metadata">

**Author:** [@sanskarfc](https://discuss.elastic.co/u/sanskarfc)\
**Replies:** 0\
**Last updated:** [June 11, 2023, 6:22am UTC](https://discuss.elastic.co/t/what-are-the-benefits-of-using-sync-reindexing-api-instead-of-async-reindexing-api/335712 "2023-06-11T06:22:04Z")

</div>

What are the benefits of using sync reindexing API instead of async reindexing API? If the size of the documents is in multiple GBs, it looks like it is always better to use async API instead of sync API :thinking:

---

## [Convert 2 nodes with roles \[data\] to \[data\_hot, data\_content\] and \[warm\]](https://discuss.elastic.co/t/convert-2-nodes-with-roles-data-to-data-hot-data-content-and-warm/335685)

<div class="topic-metadata">

**Author:** [@kaismax](https://discuss.elastic.co/u/kaismax)\
**Replies:** 1\
**Last updated:** [June 11, 2023, 2:51am UTC](https://discuss.elastic.co/t/convert-2-nodes-with-roles-data-to-data-hot-data-content-and-warm/335685 "2023-06-11T02:51:26Z")

</div>

Salut, Elastic Fulks My production cluster is set up as follows: 1 master node two data nodes \[data\] 1 coordinator I want to convert the 2 data nodes to first one to \[data\_content,data\_hot\]. second one to \[data\_war…

---

## [How to filter against a wildcard name of a field?](https://discuss.elastic.co/t/how-to-filter-against-a-wildcard-name-of-a-field/335693)

<div class="topic-metadata">

**Author:** [@Wpq](https://discuss.elastic.co/u/Wpq)\
**Replies:** 2\
**Last updated:** [June 10, 2023, 7:54pm UTC](https://discuss.elastic.co/t/how-to-filter-against-a-wildcard-name-of-a-field/335693 "2023-06-10T19:54:31Z")

</div>

I have documents that have fields such as vulns.something\_1.a vulns.something\_1.b the element something\_1 may change between documents some documents have the vulns entries, and some do not. My problem: I would like …

---

## [How to add hostname to logs from syslog or snmp source if they don't include only IP, no hostname](https://discuss.elastic.co/t/how-to-add-hostname-to-logs-from-syslog-or-snmp-source-if-they-dont-include-only-ip-no-hostname/335691)

<div class="topic-metadata">

**Author:** [@PackElend](https://discuss.elastic.co/u/PackElend)\
**Replies:** 2\
**Last updated:** [June 10, 2023, 2:54pm UTC](https://discuss.elastic.co/t/how-to-add-hostname-to-logs-from-syslog-or-snmp-source-if-they-dont-include-only-ip-no-hostname/335691 "2023-06-10T14:54:40Z")

</div>

Hello, I'm aware of How to add hostname to logs that normally do not contain hostname? but that is not applicable to my case. My router's firewall sends syslog message but they only contain the IP of the host causing t…

---

## [Price of Entreprise license on prem](https://discuss.elastic.co/t/price-of-entreprise-license-on-prem/335532)

<div class="topic-metadata">

**Author:** [@kaismax](https://discuss.elastic.co/u/kaismax)\
**Replies:** 6\
**Last updated:** [June 10, 2023, 2:11pm UTC](https://discuss.elastic.co/t/price-of-entreprise-license-on-prem/335532 "2023-06-10T14:11:16Z")

</div>

I want to use the searchable snapshot capability in my on-premises 7.17.9 cluster; what is the cost of the enterprise license?

---

## [ApiError(406, 'Content-Type header \[application/vnd.elasticsearch+json; compatible-with=8\] is not supported',](https://discuss.elastic.co/t/apierror-406-content-type-header-application-vnd-elasticsearch-json-compatible-with-8-is-not-supported/334579)

<div class="topic-metadata">

**Author:** [@Anand\_Konagala](https://discuss.elastic.co/u/Anand_Konagala)\
**Replies:** 8\
**Last updated:** [June 10, 2023, 1:11pm UTC](https://discuss.elastic.co/t/apierror-406-content-type-header-application-vnd-elasticsearch-json-compatible-with-8-is-not-supported/334579 "2023-06-10T13:11:23Z")

</div>

Hii.. ApiError(406, 'Content-Type header \[application/vnd.elasticsearch+json; compatible-with=8\] is not supported', 'Content-Type header \[application/vnd.elasticsearch+json; compatible-with=8\] is not supported') When I…

---

## [Elasticsearch is not starting on windows with installer](https://discuss.elastic.co/t/elasticsearch-is-not-starting-on-windows-with-installer/335675)

<div class="topic-metadata">

**Author:** [@Nilesh\_Brahmkshatriy](https://discuss.elastic.co/u/Nilesh_Brahmkshatriy)\
**Replies:** 2\
**Last updated:** [June 10, 2023, 10:38am UTC](https://discuss.elastic.co/t/elasticsearch-is-not-starting-on-windows-with-installer/335675 "2023-06-10T10:38:43Z")

</div>

We have installed the elasticsearch version 7.0.1 in windows 11 but not starting the service. Can you please help us to solve the issue?

---

## [Elasticsearch in RKE in running status but not active](https://discuss.elastic.co/t/elasticsearch-in-rke-in-running-status-but-not-active/335655)

<div class="topic-metadata">

**Author:** [@Mhvrke](https://discuss.elastic.co/u/Mhvrke)\
**Replies:** 10\
**Last updated:** [June 10, 2023, 6:10am UTC](https://discuss.elastic.co/t/elasticsearch-in-rke-in-running-status-but-not-active/335655 "2023-06-10T06:10:38Z")

</div>

Hi! I need help with the following escenario: I’m running Elasticsearch in cluster mode in 3 worker nodes in RKE. Suddenly stopped from working and Kibana went down as Elasticsearch presents 503 error service unavailable…

---

## [Setting multinode elk cluster](https://discuss.elastic.co/t/setting-multinode-elk-cluster/335165)

<div class="topic-metadata">

**Author:** [@rajeshri](https://discuss.elastic.co/u/rajeshri)\
**Replies:** 2\
**Last updated:** [June 10, 2023, 6:05am UTC](https://discuss.elastic.co/t/setting-multinode-elk-cluster/335165 "2023-06-10T06:05:25Z")

</div>

cluster.name: my-cluster node.name: master-1 path.data: /var/lib/elasticsearch path.logs: /var/log/elasticsearch network.host: 172.31.82.55 http.port: 9200 discovery.seed\_hosts: \["172.31.82.55", "172.31.86.217"\] c…

---

## [How to add \_size mapping to index legacy template in elasticsearch?](https://discuss.elastic.co/t/how-to-add-size-mapping-to-index-legacy-template-in-elasticsearch/335672)

<div class="topic-metadata">

**Author:** [@Amirhossein\_eidy](https://discuss.elastic.co/u/Amirhossein_eidy)\
**Replies:** 1\
**Last updated:** [June 10, 2023, 5:16am UTC](https://discuss.elastic.co/t/how-to-add-size-mapping-to-index-legacy-template-in-elasticsearch/335672 "2023-06-10T05:16:38Z")

</div>

Hi friends I have installed size mapping plugin and I added it to Kibana meta fields too I could successfully enable "\_size" in Elasticsearch via bellow command and see the result in kibana PUT logstash-2023-06-06 { …

---

## [Elastic Store Data](https://discuss.elastic.co/t/elastic-store-data/335624)

<div class="topic-metadata">

**Author:** [@Suleman\_Ahmed](https://discuss.elastic.co/u/Suleman_Ahmed)\
**Replies:** 1\
**Last updated:** [June 9, 2023, 10:49pm UTC](https://discuss.elastic.co/t/elastic-store-data/335624 "2023-06-09T22:49:25Z")

</div>

Hello! I am new to elastic and wanted to know that Elastic store data in indexes or in text? Will be greateful if refer to any documentation link. Thanks Suleman

---

## [Read segments directly from the snapshot](https://discuss.elastic.co/t/read-segments-directly-from-the-snapshot/335122)

<div class="topic-metadata">

**Author:** [@Ariel\_Zach](https://discuss.elastic.co/u/Ariel_Zach)\
**Replies:** 10\
**Last updated:** [June 9, 2023, 10:46pm UTC](https://discuss.elastic.co/t/read-segments-directly-from-the-snapshot/335122 "2023-06-09T22:46:00Z")

</div>

Hello, I'm trying to read Lucene files (segments) directly from the files generated in the snapshot, but I'm encountering errors. Could you guide me on how to do it? Thank you.

[Previous page](https://discuss.elastic.co/latest.md?page=644)

[Next page](https://discuss.elastic.co/latest.md?page=646)
