# Latest

**URL:** https://discuss.elastic.co/latest.md?page=652

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 653

---

## [How to calculate percentage of a field over all documents present in index](https://discuss.elastic.co/t/how-to-calculate-percentage-of-a-field-over-all-documents-present-in-index/334544)

<div class="topic-metadata">

**Author:** [@Amit\_Charkha](https://discuss.elastic.co/u/Amit_Charkha)\
**Replies:** 5\
**Last updated:** [June 6, 2023, 4:54am UTC](https://discuss.elastic.co/t/how-to-calculate-percentage-of-a-field-over-all-documents-present-in-index/334544 "2023-06-06T04:54:48Z")

</div>

how to calculate percentage of a field log\_count over all documents present in index.

---

## [Why docker run elasticsearch working well and docker compose up stuck on starting, i am confused](https://discuss.elastic.co/t/why-docker-run-elasticsearch-working-well-and-docker-compose-up-stuck-on-starting-i-am-confused/335132)

<div class="topic-metadata">

**Author:** [@Wuxy-Bleu](https://discuss.elastic.co/u/Wuxy-Bleu)\
**Replies:** 2\
**Last updated:** [June 6, 2023, 4:52am UTC](https://discuss.elastic.co/t/why-docker-run-elasticsearch-working-well-and-docker-compose-up-stuck-on-starting-i-am-confused/335132 "2023-06-06T04:52:05Z")

</div>

docker run -it -p 9201:9200 -p 9301:9300 --network elastic --name es2 -e discovery.type=single-node -e cluster.routing.allocation.disk.watermark.high=95% -e cluster.routing.allocation.disk.watermark.low=90% elasticsearch…

---

## [There is a problem with elastic agent pushing logstash](https://discuss.elastic.co/t/there-is-a-problem-with-elastic-agent-pushing-logstash/335265)

<div class="topic-metadata">

**Author:** [@xqaiviwjxzw](https://discuss.elastic.co/u/xqaiviwjxzw)\
**Replies:** 0\
**Last updated:** [June 6, 2023, 4:49am UTC](https://discuss.elastic.co/t/there-is-a-problem-with-elastic-agent-pushing-logstash/335265 "2023-06-06T04:49:20Z")

</div>

By changing the original strategy of the elastic agent to push the log to Elasticsearch to push to the new strategy to push to logstash, why the log is still in the original Elasticsearch, but not pushed to the new lo…

---

## [Enable CORS on Kibana](https://discuss.elastic.co/t/enable-cors-on-kibana/334084)

<div class="topic-metadata">

**Author:** [@Shreyansh\_Jain](https://discuss.elastic.co/u/Shreyansh_Jain)\
**Replies:** 12\
**Last updated:** [June 6, 2023, 4:33am UTC](https://discuss.elastic.co/t/enable-cors-on-kibana/334084 "2023-06-06T04:33:58Z")

</div>

Hi all, I am using kibana version v 7.17.9 I am trying to use this api endpoint to generate cookies in my front end angular application : "/internal/security/login". But while making a post call from my web application…

---

## [Single-node. Manage Lifecycle Policy](https://discuss.elastic.co/t/single-node-manage-lifecycle-policy/334347)

<div class="topic-metadata">

**Author:** [@Thales\_Eduardo](https://discuss.elastic.co/u/Thales_Eduardo)\
**Replies:** 5\
**Last updated:** [June 6, 2023, 4:29am UTC](https://discuss.elastic.co/t/single-node-manage-lifecycle-policy/334347 "2023-06-06T04:29:14Z")

</div>

I have an elk siem (single node) version 8.7.1 in production. On it is a 5TB data partition with about 90% disk usage. I would like to allow lifecycle policies to rotate data every 180 days (6 months). It's possible? W…

---

## [Indexing requests and time goes high on 1 node in cluster](https://discuss.elastic.co/t/indexing-requests-and-time-goes-high-on-1-node-in-cluster/334491)

<div class="topic-metadata">

**Author:** [@tarund](https://discuss.elastic.co/u/tarund)\
**Replies:** 1\
**Last updated:** [June 6, 2023, 4:28am UTC](https://discuss.elastic.co/t/indexing-requests-and-time-goes-high-on-1-node-in-cluster/334491 "2023-06-06T04:28:49Z")

</div>

Hi Team I am using ES 7.17.1. Pushing logs from Fluent to 5 node cluster. Enabled xpack monitoring on ES. we observe that sometime during the day the indexing requests & indexing time goes very high on a single node. So…

---

## [TLS error after fresh install of elastic search](https://discuss.elastic.co/t/tls-error-after-fresh-install-of-elastic-search/335264)

<div class="topic-metadata">

**Author:** [@antarr](https://discuss.elastic.co/u/antarr)\
**Replies:** 3\
**Last updated:** [June 6, 2023, 2:36am UTC](https://discuss.elastic.co/t/tls-error-after-fresh-install-of-elastic-search/335264 "2023-06-06T02:36:34Z")

</div>

I'm trying to get Elasticsearch working on Ubuntu 22. I've uninstalled it a few times but keep getting an SSL error when testing using curl. I've tried 7.17, 7.10, and 8.8. uninstall sudo apt-get remove --purge elastic…

---

## [Push Logs from Elastic Search to Alien Vault USM Anywhere](https://discuss.elastic.co/t/push-logs-from-elastic-search-to-alien-vault-usm-anywhere/334781)

<div class="topic-metadata">

**Author:** [@Zu\_kun](https://discuss.elastic.co/u/Zu_kun)\
**Replies:** 4\
**Last updated:** [June 6, 2023, 2:16am UTC](https://discuss.elastic.co/t/push-logs-from-elastic-search-to-alien-vault-usm-anywhere/334781 "2023-06-06T02:16:58Z")

</div>

Hi, I'm a legit noob when it comes to ELK so my questions might not make sense or will probably have some obvious answers to it. Getting straight to the point, I want to pull the logs from my on premises Elasticsearch …

---

## [Dynamic data (no code) scenario strategy](https://discuss.elastic.co/t/dynamic-data-no-code-scenario-strategy/334870)

<div class="topic-metadata">

**Author:** [@Zak\_Sesti](https://discuss.elastic.co/u/Zak_Sesti)\
**Replies:** 1\
**Last updated:** [June 6, 2023, 1:38am UTC](https://discuss.elastic.co/t/dynamic-data-no-code-scenario-strategy/334870 "2023-06-06T01:38:52Z")

</div>

I use ES for searching of my basic CRUD constructs. But now we need to expand to help us search, sort, paginate our no-code constructs. These are json documents that have 100% dynamic fields. Some rough numbers: We …

---

## [Integration Elastic Security with Microsoft Sentinel available?](https://discuss.elastic.co/t/integration-elastic-security-with-microsoft-sentinel-available/335025)

<div class="topic-metadata">

**Author:** [@Jeronimodus](https://discuss.elastic.co/u/Jeronimodus)\
**Replies:** 6\
**Last updated:** [June 6, 2023, 1:20am UTC](https://discuss.elastic.co/t/integration-elastic-security-with-microsoft-sentinel-available/335025 "2023-06-06T01:20:39Z")

</div>

Hello all, I am looking for a way to import alerts and possibly more data from Sentinel into Elastic Security. I do not see an integration available for this. Is there someone who can confirm that this does not exist an…

---

## [Can't use ApiKey to update rule](https://discuss.elastic.co/t/cant-use-apikey-to-update-rule/335235)

<div class="topic-metadata">

**Author:** [@A\_Mightiev](https://discuss.elastic.co/u/A_Mightiev)\
**Replies:** 0\
**Last updated:** [June 5, 2023, 2:51pm UTC](https://discuss.elastic.co/t/cant-use-apikey-to-update-rule/335235 "2023-06-05T14:51:33Z")

</div>

I'm trying to update alerting rules in kibana, if I create an apikey, I can see the rules, and I can authenticate, but when trying to update an alerting rule, it gives me this error: {"statusCode":400,"error":"Bad Reque…

---

## [Profile API](https://discuss.elastic.co/t/profile-api/335217)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 1\
**Last updated:** [June 6, 2023, 1:06am UTC](https://discuss.elastic.co/t/profile-api/335217 "2023-06-06T01:06:58Z")

</div>

I ran the profile API for my query that took 15s to run. I have a very big json as output. I am unable to determine why it is taking 15s. Can someone help me read or what to look for in the output of \_profile?

---

## [JDBC input error when using schedule without last run](https://discuss.elastic.co/t/jdbc-input-error-when-using-schedule-without-last-run/335243)

<div class="topic-metadata">

**Author:** [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Replies:** 3\
**Last updated:** [June 5, 2023, 10:19pm UTC](https://discuss.elastic.co/t/jdbc-input-error-when-using-schedule-without-last-run/335243 "2023-06-05T22:19:11Z")

</div>

Hi, I need to query a database every 1 minute and get all the results of the query, so I use schedule but no last\_run\_metadata\_path. logstash give an error, but still que the data indexed in ES. logstash look for this…

---

## [ILM not deleting data](https://discuss.elastic.co/t/ilm-not-deleting-data/335204)

<div class="topic-metadata">

**Author:** [@Vitor\_Nilson](https://discuss.elastic.co/u/Vitor_Nilson)\
**Replies:** 2\
**Last updated:** [June 5, 2023, 10:11pm UTC](https://discuss.elastic.co/t/ilm-not-deleting-data/335204 "2023-06-05T22:11:26Z")

</div>

Hello, I'm trying to set a ILM to an index, but it's not deleting old data. This is my ILM: PUT \_ilm/policy/kong\_lifecycle { "policy": { "phases": { "hot": { "min\_age": "0ms", "actions": { …

---

## [Metricbeat Promethes merging queries](https://discuss.elastic.co/t/metricbeat-promethes-merging-queries/334704)

<div class="topic-metadata">

**Author:** [@evileric77](https://discuss.elastic.co/u/evileric77)\
**Replies:** 2\
**Last updated:** [June 5, 2023, 8:59pm UTC](https://discuss.elastic.co/t/metricbeat-promethes-merging-queries/334704 "2023-06-05T20:59:19Z")

</div>

This has been mentioned before here: But as there is no resolution there I'm posting here and will open an issue on github shortly. With the Prometheus module if you define 2 items that leverage the module, metricbeat …

---

## [ES 8.6.2 - puzzling "Authentication of \[elastic\] was terminated by realm \[reserved\] - failed to authenticate user \[elastic\]"?](https://discuss.elastic.co/t/es-8-6-2-puzzling-authentication-of-elastic-was-terminated-by-realm-reserved-failed-to-authenticate-user-elastic/335152)

<div class="topic-metadata">

**Author:** [@mrodent](https://discuss.elastic.co/u/mrodent)\
**Replies:** 3\
**Last updated:** [June 5, 2023, 8:01pm UTC](https://discuss.elastic.co/t/es-8-6-2-puzzling-authentication-of-elastic-was-terminated-by-realm-reserved-failed-to-authenticate-user-elastic/335152 "2023-06-05T20:01:41Z")

</div>

I am aware this error has come up before, but please note the version, 8.6.2. Most of the others are about v7. So far I have found the whole configuration of 8.6.2. much more of a challenge (from the security PoV) than v…

---

## [Unable to apply memory lock to deploy elastic 8 on k8s](https://discuss.elastic.co/t/unable-to-apply-memory-lock-to-deploy-elastic-8-on-k8s/334897)

<div class="topic-metadata">

**Author:** [@rsingh\_2023](https://discuss.elastic.co/u/rsingh_2023)\
**Replies:** 4\
**Last updated:** [June 5, 2023, 8:08pm UTC](https://discuss.elastic.co/t/unable-to-apply-memory-lock-to-deploy-elastic-8-on-k8s/334897 "2023-06-05T20:08:51Z")

</div>

I am running into issues with deploying elastic version 8.7 on kubernetes (k8s) I am using this docker image for elastic version 8.7 I have enabled bootstrap memory\_lock as "true" but I see these error logs in my elast…

---

## [Does it use more storage with "fields" mapping?](https://discuss.elastic.co/t/does-it-use-more-storage-with-fields-mapping/334883)

<div class="topic-metadata">

**Author:** [@linkerc](https://discuss.elastic.co/u/linkerc)\
**Replies:** 4\
**Last updated:** [June 5, 2023, 6:43pm UTC](https://discuss.elastic.co/t/does-it-use-more-storage-with-fields-mapping/334883 "2023-06-05T18:43:22Z")

</div>

"some\_label" : { "type" : "keyword", "fields" : { "keyword" : { "type" : "keyword", "ignore\_above" : 256 } } } Supposed I have a …

---

## [In Kibana's Maps, selecting time range narrows map points, but not vice versa](https://discuss.elastic.co/t/in-kibanas-maps-selecting-time-range-narrows-map-points-but-not-vice-versa/334467)

<div class="topic-metadata">

**Author:** [@Mathemaphysics](https://discuss.elastic.co/u/Mathemaphysics)\
**Replies:** 9\
**Last updated:** [June 5, 2023, 6:22pm UTC](https://discuss.elastic.co/t/in-kibanas-maps-selecting-time-range-narrows-map-points-but-not-vice-versa/334467 "2023-06-05T18:22:36Z")

</div>

I've been able to successfully query and plot documents with geo\_points in maps in Kibana alongside time series plots of other data in standard fashion. When I select the time range in a time series plot, it correctly na…

---

## [Help optimize my query](https://discuss.elastic.co/t/help-optimize-my-query/335250)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 1\
**Last updated:** [June 5, 2023, 5:44pm UTC](https://discuss.elastic.co/t/help-optimize-my-query/335250 "2023-06-05T17:44:52Z")

</div>

I have this query: "query": { "bool": { "filter": { "bool": { "must": \[ { "range": { "movies-date": { "gt": "2018", "lt": "2022" } } }, given that this is a must query, does it make sense to move the range …

---

## [When/how often/from where does "filebeat setup -e" need to be run?](https://discuss.elastic.co/t/when-how-often-from-where-does-filebeat-setup-e-need-to-be-run/335246)

<div class="topic-metadata">

**Author:** [@andrew.klaassen](https://discuss.elastic.co/u/andrew.klaassen)\
**Replies:** 2\
**Last updated:** [June 5, 2023, 4:45pm UTC](https://discuss.elastic.co/t/when-how-often-from-where-does-filebeat-setup-e-need-to-be-run/335246 "2023-06-05T16:45:31Z")

</div>

I'm trying to wrap my head around "filebeat setup -e". Let's say I've already got filebeat up and running with a couple of modules, and I want to roll out a new module to a bunch of servers. Which of these would make s…

---

## [Cloud Provider - need change](https://discuss.elastic.co/t/cloud-provider-need-change/335113)

<div class="topic-metadata">

**Author:** [@Eduardo\_Maia](https://discuss.elastic.co/u/Eduardo_Maia)\
**Replies:** 3\
**Last updated:** [June 5, 2023, 3:13pm UTC](https://discuss.elastic.co/t/cloud-provider-need-change/335113 "2023-06-05T15:13:49Z")

</div>

Hi, my enterprise use Elasticsearch and your first Provider was Google(GCP) and after change to Azure, when decide to change the cloud provider to Google again, we didn't get. And the problem is appear only Azure, and n…

---

## [Log4j2 vulnerability mitigation](https://discuss.elastic.co/t/log4j2-vulnerability-mitigation/335213)

<div class="topic-metadata">

**Author:** [@mostafaelsayed](https://discuss.elastic.co/u/mostafaelsayed)\
**Replies:** 6\
**Last updated:** [June 5, 2023, 3:33pm UTC](https://discuss.elastic.co/t/log4j2-vulnerability-mitigation/335213 "2023-06-05T15:33:18Z")

</div>

Hello all, I was checking the actions needed from our side in the ELK cluster to mitigate the Log4j2 vulnerability found in Dec 2021. we are using 7.9.2 for all ELK components. After investigating and checking the below…

---

## [Considering using L4 or kafka](https://discuss.elastic.co/t/considering-using-l4-or-kafka/335238)

<div class="topic-metadata">

**Author:** [@a01066278824](https://discuss.elastic.co/u/a01066278824)\
**Replies:** 1\
**Last updated:** [June 5, 2023, 3:15pm UTC](https://discuss.elastic.co/t/considering-using-l4-or-kafka/335238 "2023-06-05T15:15:30Z")

</div>

im considering two ways. first, using L4 between Beats and logstash. second, using Kafka between beats and logstahs. which way is more effective one? and im wondering if is it possible Beats - Kafka - L4 - Logstash. …

---

## [iIhave problems Fleet daemonset collect kubernetes container logs](https://discuss.elastic.co/t/iihave-problems-fleet-daemonset-collect-kubernetes-container-logs/335239)

<div class="topic-metadata">

**Author:** [@hanhee](https://discuss.elastic.co/u/hanhee)\
**Replies:** 0\
**Last updated:** [June 5, 2023, 3:10pm UTC](https://discuss.elastic.co/t/iihave-problems-fleet-daemonset-collect-kubernetes-container-logs/335239 "2023-06-05T15:10:11Z")

</div>

hello i have some problems operating elastic-agent with fleet i did the settings elastic-agent usging kubernetes daemonset and kubernetes integration in fleet and that setting works normally without problems but sud…

---

## [Primary shard storage bottleneck](https://discuss.elastic.co/t/primary-shard-storage-bottleneck/335197)

<div class="topic-metadata">

**Author:** [@Hoang\_Vu](https://discuss.elastic.co/u/Hoang_Vu)\
**Replies:** 6\
**Last updated:** [June 5, 2023, 3:05pm UTC](https://discuss.elastic.co/t/primary-shard-storage-bottleneck/335197 "2023-06-05T15:05:05Z")

</div>

Hi everyone, I want to ask why the primary shard indexes for 1 day are only stored on 1 Hot3 node. Causing the Hot3 node to get a high CPU boost and denying the bulk request from the Coordination node that controls my fo…

---

## [Using Environment Variables in Elastic Synthetics](https://discuss.elastic.co/t/using-environment-variables-in-elastic-synthetics/334997)

<div class="topic-metadata">

**Author:** [@DougR](https://discuss.elastic.co/u/DougR)\
**Replies:** 8\
**Last updated:** [June 5, 2023, 1:40pm UTC](https://discuss.elastic.co/t/using-environment-variables-in-elastic-synthetics/334997 "2023-06-05T13:40:50Z")

</div>

TL;DR How do I force Elastic Synthetics to use environment variables defined in the pod environment? Use Case I am in the process of migrating our synthetic monitoring framework to Elastic Synthetics. I'm currently usin…

---

## [How to change Data type Runtime and change filter type range slider to dropdown list](https://discuss.elastic.co/t/how-to-change-data-type-runtime-and-change-filter-type-range-slider-to-dropdown-list/335179)

<div class="topic-metadata">

**Author:** [@PappuSingh](https://discuss.elastic.co/u/PappuSingh)\
**Replies:** 1\
**Last updated:** [June 5, 2023, 2:15pm UTC](https://discuss.elastic.co/t/how-to-change-data-type-runtime-and-change-filter-type-range-slider-to-dropdown-list/335179 "2023-06-05T14:15:55Z")

</div>

Hi, How to change data type long to String and Range slider to the dropdown list. Please find attached a snap for your reference.

---

## [Exiting: error loading config file: yaml: line 26: did not find expected key](https://discuss.elastic.co/t/exiting-error-loading-config-file-yaml-line-26-did-not-find-expected-key/334250)

<div class="topic-metadata">

**Author:** [@FredMir](https://discuss.elastic.co/u/FredMir)\
**Replies:** 8\
**Last updated:** [June 5, 2023, 1:47pm UTC](https://discuss.elastic.co/t/exiting-error-loading-config-file-yaml-line-26-did-not-find-expected-key/334250 "2023-06-05T13:47:56Z")

</div>

I installed filebeat-7.16.3-x86\_64.rpm on a different server and trying to send output logs to logstash but I receive this error when try to run filebeat. Also, when trying to enable modules I get the same error. Would y…

---

## [What's the efficient way to filter and transfer data from Elastic](https://discuss.elastic.co/t/whats-the-efficient-way-to-filter-and-transfer-data-from-elastic/335006)

<div class="topic-metadata">

**Author:** [@Monkey\_D\_Luffy1](https://discuss.elastic.co/u/Monkey_D_Luffy1)\
**Replies:** 1\
**Last updated:** [June 5, 2023, 1:23pm UTC](https://discuss.elastic.co/t/whats-the-efficient-way-to-filter-and-transfer-data-from-elastic/335006 "2023-06-05T13:23:43Z")

</div>

I have an Elastic Index which has 100 million documents inside it and I want to understand whats the efficient way of writing a python script to filter values and then transfer the filtered values to a SQL storage ?

[Previous page](https://discuss.elastic.co/latest.md?page=651)

[Next page](https://discuss.elastic.co/latest.md?page=653)
