# Latest

**URL:** https://discuss.elastic.co/latest.md?page=661

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 662

---

## [Create network usage graph](https://discuss.elastic.co/t/create-network-usage-graph/333904)

<div class="topic-metadata">

**Author:** [@Mark\_Collins](https://discuss.elastic.co/u/Mark_Collins)\
**Replies:** 1\
**Last updated:** [May 30, 2023, 2:27pm UTC](https://discuss.elastic.co/t/create-network-usage-graph/333904 "2023-05-30T14:27:12Z")

</div>

Sorry if this has been asked before but I am monitoring some of our network switches via snmp call every 30 seconds and logstash The information I am getting back from the switches is the cumlative bytes on the network …

---

## [Events get dropped by restricting api key (winlogbeat & kibana) - Help plz](https://discuss.elastic.co/t/events-get-dropped-by-restricting-api-key-winlogbeat-kibana-help-plz/329403)

<div class="topic-metadata">

**Author:** [@Martesch](https://discuss.elastic.co/u/Martesch)\
**Replies:** 5\
**Last updated:** [May 30, 2023, 2:23pm UTC](https://discuss.elastic.co/t/events-get-dropped-by-restricting-api-key-winlogbeat-kibana-help-plz/329403 "2023-05-30T14:23:45Z")

</div>

hello everyone i need help. this is about the fact that i noticed that in our kibana, which collects our windows event logs certain logs are missing, and this since a certain date, from 31.01.23 to 01.02.23 the amount o…

---

## [I have taken the Logs source of OpenCTI to make threatIntelligence but there is an error when displaying](https://discuss.elastic.co/t/i-have-taken-the-logs-source-of-opencti-to-make-threatintelligence-but-there-is-an-error-when-displaying/333746)

<div class="topic-metadata">

**Author:** [@Hoang\_Vu](https://discuss.elastic.co/u/Hoang_Vu)\
**Replies:** 0\
**Last updated:** [May 18, 2023, 8:55am UTC](https://discuss.elastic.co/t/i-have-taken-the-logs-source-of-opencti-to-make-threatintelligence-but-there-is-an-error-when-displaying/333746 "2023-05-18T08:55:05Z")

</div>

Before, I took MISP logs to do threatIntelligence but after I switch to Open CTI the same error shows again

---

## [How to write Kibana update query in java](https://discuss.elastic.co/t/how-to-write-kibana-update-query-in-java/333662)

<div class="topic-metadata">

**Author:** [@sarthik](https://discuss.elastic.co/u/sarthik)\
**Replies:** 0\
**Last updated:** [May 17, 2023, 1:28pm UTC](https://discuss.elastic.co/t/how-to-write-kibana-update-query-in-java/333662 "2023-05-17T13:28:08Z")

</div>

Hi team, My requirement is to update a document for a particular index. I have constructed the query in Kibana using KQL, but I am unable to convert the same into java API client, so that I can call from my java code. …

---

## [Filebeat unable to find match for dissect pattern](https://discuss.elastic.co/t/filebeat-unable-to-find-match-for-dissect-pattern/333856)

<div class="topic-metadata">

**Author:** [@obol89](https://discuss.elastic.co/u/obol89)\
**Replies:** 2\
**Last updated:** [May 30, 2023, 1:38pm UTC](https://discuss.elastic.co/t/filebeat-unable-to-find-match-for-dissect-pattern/333856 "2023-05-30T13:38:03Z")

</div>

Hi Everyone, I couldn't find a reason, why Filebeat is going into the loop with "Unable to find match for dissect pattern" when it reaches the end of the file with filestream input mode. I'm parsing multiple very simila…

---

## [Could anyone please suggest how to configure ILM policy to an index](https://discuss.elastic.co/t/could-anyone-please-suggest-how-to-configure-ilm-policy-to-an-index/333658)

<div class="topic-metadata">

**Author:** [@snalaband](https://discuss.elastic.co/u/snalaband)\
**Replies:** 1\
**Last updated:** [May 30, 2023, 1:35pm UTC](https://discuss.elastic.co/t/could-anyone-please-suggest-how-to-configure-ilm-policy-to-an-index/333658 "2023-05-30T13:35:05Z")

</div>

I want to configure ILM policy for an index could anyone please suggest best practice to create ILM policy

---

## [Add filter for Elastic rules](https://discuss.elastic.co/t/add-filter-for-elastic-rules/333643)

<div class="topic-metadata">

**Author:** [@Sara\_YB](https://discuss.elastic.co/u/Sara_YB)\
**Replies:** 1\
**Last updated:** [May 30, 2023, 1:14pm UTC](https://discuss.elastic.co/t/add-filter-for-elastic-rules/333643 "2023-05-30T13:14:09Z")

</div>

I am trying to add some filters to one of the created rules in kibana 8.6. Before adding any filters, it is showing that there are 173 monitors as indicated below: When I add one filter only, the outcome changes of c…

---

## [Kibana compare two logs based on a log value](https://discuss.elastic.co/t/kibana-compare-two-logs-based-on-a-log-value/334525)

<div class="topic-metadata">

**Author:** [@mkan](https://discuss.elastic.co/u/mkan)\
**Replies:** 2\
**Last updated:** [May 30, 2023, 12:40pm UTC](https://discuss.elastic.co/t/kibana-compare-two-logs-based-on-a-log-value/334525 "2023-05-30T12:40:24Z")

</div>

i have logs that contains a run\_id and type of operation, for each unique run\_id there are two possibilities for operation so it looks like this: "run\_id": \["123"\], "operation": \["a"\] "run\_id": \["123"\], "operation": \["…

---

## [Data not showing for wazuh agents](https://discuss.elastic.co/t/data-not-showing-for-wazuh-agents/333448)

<div class="topic-metadata">

**Author:** [@uahmad](https://discuss.elastic.co/u/uahmad)\
**Replies:** 1\
**Last updated:** [May 30, 2023, 12:48pm UTC](https://discuss.elastic.co/t/data-not-showing-for-wazuh-agents/333448 "2023-05-30T12:48:34Z")

</div>

Hello, I am facing issue where data for wazuh agents is not being shown. Elasticsearch throws the following error: \[2023-05-15T10:52:45,968\]\[WARN \]\[o.e.x.t.t.TransformIndexer\] \[elasticsearch\] \[endpoint.metadata\_united…

---

## [Monitoring indices configuration](https://discuss.elastic.co/t/monitoring-indices-configuration/334661)

<div class="topic-metadata">

**Author:** [@Itay\_Bittan](https://discuss.elastic.co/u/Itay_Bittan)\
**Replies:** 1\
**Last updated:** [May 30, 2023, 12:44pm UTC](https://discuss.elastic.co/t/monitoring-indices-configuration/334661 "2023-05-30T12:44:56Z")

</div>

Hi all! We are running ECK and we are trying to implement the best practices (metrics/metricbeat) and use a small dedicated cluster for monitoring. Before separation, with monitoring enabled, we had a 7 special indices…

---

## [Getting error in logstash](https://discuss.elastic.co/t/getting-error-in-logstash/334646)

<div class="topic-metadata">

**Author:** [@Sachchan](https://discuss.elastic.co/u/Sachchan)\
**Replies:** 3\
**Last updated:** [May 30, 2023, 11:54am UTC](https://discuss.elastic.co/t/getting-error-in-logstash/334646 "2023-05-30T11:54:15Z")

</div>

Hi Team, Getting below error in logstash very frequently. please help in resolving this. \[2023-05-30T13:13:06,480\]\[ERROR\]\[logstash.outputs.elasticsearch\]\[CBC-only-4\]\[72644810f48942e01d7ac6fc35e066a073591417c6633c6aa1fb4…

---

## [AWS Lambda with OpenTelemetry/dotnet - No data in the “Metrics” section](https://discuss.elastic.co/t/aws-lambda-with-opentelemetry-dotnet-no-data-in-the-metrics-section/331058)

<div class="topic-metadata">

**Author:** [@javaripa](https://discuss.elastic.co/u/javaripa)\
**Replies:** 5\
**Last updated:** [May 30, 2023, 11:31am UTC](https://discuss.elastic.co/t/aws-lambda-with-opentelemetry-dotnet-no-data-in-the-metrics-section/331058 "2023-05-30T11:31:18Z")

</div>

Kibana version: 8.6.1 Elasticsearch version: 8.6.1 APM Server version: 8.6.1 Fresh install or upgraded from other version? Fresh installation Description of the problem including expected versus actual behavior. Ple…

---

## [Calculating percentage in visualization per a specific field and not the regular one](https://discuss.elastic.co/t/calculating-percentage-in-visualization-per-a-specific-field-and-not-the-regular-one/334153)

<div class="topic-metadata">

**Author:** [@Halfon](https://discuss.elastic.co/u/Halfon)\
**Replies:** 6\
**Last updated:** [May 30, 2023, 11:08am UTC](https://discuss.elastic.co/t/calculating-percentage-in-visualization-per-a-specific-field-and-not-the-regular-one/334153 "2023-05-30T11:08:59Z")

</div>

Greetings! Apologies for the subject, I could not find a better way to summerize my question. I'm using Kibana for analysis, and I have tried to create a visualization that shows the percentage of each HTTP method per d…

---

## [There is no setting to disable SSL verification in watcher http input](https://discuss.elastic.co/t/there-is-no-setting-to-disable-ssl-verification-in-watcher-http-input/333469)

<div class="topic-metadata">

**Author:** [@Disha\_Bodade](https://discuss.elastic.co/u/Disha_Bodade)\
**Replies:** 1\
**Last updated:** [May 30, 2023, 11:08am UTC](https://discuss.elastic.co/t/there-is-no-setting-to-disable-ssl-verification-in-watcher-http-input/333469 "2023-05-30T11:08:23Z")

</div>

Hi Team, I am using elasticsearch watcher http input to read list of values. but when I configured its showing "type": "s\_s\_l\_handshake\_exception", "reason": "PKIX path building failed: sun.security.provide…

---

## [Synonym order with unique filter breaks search](https://discuss.elastic.co/t/synonym-order-with-unique-filter-breaks-search/334647)

<div class="topic-metadata">

**Author:** [@kuseman](https://discuss.elastic.co/u/kuseman)\
**Replies:** 3\
**Last updated:** [May 30, 2023, 10:58am UTC](https://discuss.elastic.co/t/synonym-order-with-unique-filter-breaks-search/334647 "2023-05-30T10:58:28Z")

</div>

Hi, have a weird issue with synonyms along with a unique token filter that I cannot get my head around. MVP: Settings: { "settings": { "index": { …

---

## [Insecure param does not complete disable verification](https://discuss.elastic.co/t/insecure-param-does-not-complete-disable-verification/334673)

<div class="topic-metadata">

**Author:** [@kmahyyg](https://discuss.elastic.co/u/kmahyyg)\
**Replies:** 0\
**Last updated:** [May 30, 2023, 10:49am UTC](https://discuss.elastic.co/t/insecure-param-does-not-complete-disable-verification/334673 "2023-05-30T10:49:44Z")

</div>

I use --insecure when enrolling agent into fleet server in development environment. With some unable-to-say restrictions, this development environment cannot connect to CRL server. However, in current environment, the c…

---

## [Url response time](https://discuss.elastic.co/t/url-response-time/334672)

<div class="topic-metadata">

**Author:** [@Vignesh\_Bose](https://discuss.elastic.co/u/Vignesh_Bose)\
**Replies:** 0\
**Last updated:** [May 30, 2023, 10:36am UTC](https://discuss.elastic.co/t/url-response-time/334672 "2023-05-30T10:36:30Z")

</div>

Hi Am using elastic in k8s I need set an alert that if the URL() response time is more than 0.5 sec then it should send an alert to mail, How to configure it.If it can be achieved by costume query can you share the synt…

---

## [Retrieve data directly from Elasticsearch index in React App](https://discuss.elastic.co/t/retrieve-data-directly-from-elasticsearch-index-in-react-app/334365)

<div class="topic-metadata">

**Author:** [@Thomas\_Makrigiannis](https://discuss.elastic.co/u/Thomas_Makrigiannis)\
**Replies:** 3\
**Last updated:** [May 30, 2023, 10:19am UTC](https://discuss.elastic.co/t/retrieve-data-directly-from-elasticsearch-index-in-react-app/334365 "2023-05-30T10:19:09Z")

</div>

Hi, everyone. I am new to elasticsearch and I really need your help. i have construced a react app that simulates a search engine. My app uses node.js and express. I have built both a server and a client. In the app I r…

---

## [Can we use Approximate kNN algorithm other than Hierarchical Navigable Small World Algorithm?](https://discuss.elastic.co/t/can-we-use-approximate-knn-algorithm-other-than-hierarchical-navigable-small-world-algorithm/333533)

<div class="topic-metadata">

**Author:** [@hikarut](https://discuss.elastic.co/u/hikarut)\
**Replies:** 2\
**Last updated:** [May 30, 2023, 9:48am UTC](https://discuss.elastic.co/t/can-we-use-approximate-knn-algorithm-other-than-hierarchical-navigable-small-world-algorithm/333533 "2023-05-30T09:48:15Z")

</div>

Hi All, We have to construct a search system which contains 30 millions+ dense vectors. However, Naive kNN algorithm can not be applied to this scale of data. And, Hierarchical Navigable Small World Algorithm, which e…

---

## [Impact on cluster after expiration of Platinum license](https://discuss.elastic.co/t/impact-on-cluster-after-expiration-of-platinum-license/334656)

<div class="topic-metadata">

**Author:** [@Seemant\_Bind](https://discuss.elastic.co/u/Seemant_Bind)\
**Replies:** 1\
**Last updated:** [May 30, 2023, 9:30am UTC](https://discuss.elastic.co/t/impact-on-cluster-after-expiration-of-platinum-license/334656 "2023-05-30T09:30:33Z")

</div>

Hi, Currently we have a cluster of 3 Elasticsearch nodes with Platinum license, just I wanted to know if my platinum subscription expires and downgrade to basic version, what would be the impact in the Elasticsearch clu…

---

## [Netflow from some Huawei AR devices aren't captured](https://discuss.elastic.co/t/netflow-from-some-huawei-ar-devices-arent-captured/334657)

<div class="topic-metadata">

**Author:** [@Sandeepa\_Kariyawasam](https://discuss.elastic.co/u/Sandeepa_Kariyawasam)\
**Replies:** 0\
**Last updated:** [May 30, 2023, 9:13am UTC](https://discuss.elastic.co/t/netflow-from-some-huawei-ar-devices-arent-captured/334657 "2023-05-30T09:13:28Z")

</div>

I have multiple devices sending netflow towards my filebeat server and filebeat haven't captured data from some devices. These devices are Huawei AR model and even though netflow data are visible here, they seems to be m…

---

## [Add multiline codec issue on logstash](https://discuss.elastic.co/t/add-multiline-codec-issue-on-logstash/334217)

<div class="topic-metadata">

**Author:** [@raymond0516](https://discuss.elastic.co/u/raymond0516)\
**Replies:** 5\
**Last updated:** [May 30, 2023, 9:06am UTC](https://discuss.elastic.co/t/add-multiline-codec-issue-on-logstash/334217 "2023-05-30T09:06:30Z")

</div>

Errors came out if I added multiline under "filter", but it works if I have added under "input". Anyone can give me hints? input { file { path =\> "/tmp/input.log" #codec =\> multiline { # pattern =\> "^%{TIME…

---

## [Filebeat autodiscover mode is flooding my kubernetes API](https://discuss.elastic.co/t/filebeat-autodiscover-mode-is-flooding-my-kubernetes-api/333648)

<div class="topic-metadata">

**Author:** [@NeVraX](https://discuss.elastic.co/u/NeVraX)\
**Replies:** 5\
**Last updated:** [May 30, 2023, 8:48am UTC](https://discuss.elastic.co/t/filebeat-autodiscover-mode-is-flooding-my-kubernetes-api/333648 "2023-05-30T08:48:17Z")

</div>

Hello, I'm working on a managed kubernetes cluster with a cloud provider which offers limited K8S API performance (slow master nodes). I have installed filebeat 8.5.1 with the official Helm chart. They say that my fil…

---

## [Configuration Logstash 8.6.1 for monitoring VMWare server](https://discuss.elastic.co/t/configuration-logstash-8-6-1-for-monitoring-vmware-server/334593)

<div class="topic-metadata">

**Author:** [@gaetano](https://discuss.elastic.co/u/gaetano)\
**Replies:** 2\
**Last updated:** [May 30, 2023, 8:22am UTC](https://discuss.elastic.co/t/configuration-logstash-8-6-1-for-monitoring-vmware-server/334593 "2023-05-30T08:22:53Z")

</div>

I'm trying to send VMWare server parameters to Elastic Search node 8.6.1 passing by Logstash 8.6.1. I obtained string in get option using Paessler MIB Importer. I downloaded MIB file in official site of VMWare. Thi…

---

## [Elasticsearch not working after Upgrading from version 7.17 to 8.5.1 (Using Helm Chart)](https://discuss.elastic.co/t/elasticsearch-not-working-after-upgrading-from-version-7-17-to-8-5-1-using-helm-chart/334639)

<div class="topic-metadata">

**Author:** [@devbrat9415](https://discuss.elastic.co/u/devbrat9415)\
**Replies:** 0\
**Last updated:** [May 30, 2023, 6:30am UTC](https://discuss.elastic.co/t/elasticsearch-not-working-after-upgrading-from-version-7-17-to-8-5-1-using-helm-chart/334639 "2023-05-30T06:30:46Z")

</div>

We are upgrading Elasticsearch version 7.17 to 8.5.1 to Kubernetes along with logstash and Kibana . We don't necessary want to remove PVC, because it will lead to a data loss. While upgrading we continuously getting ERRO…

---

## [{"statusCode":429,"message":"circuit\_breaking\_exception: \[circuit\_breaking\_exception\] Reason: \[parent\] Data too large, data for \[\<http\_request\>\] would be \[1052991986/1004.2mb\], which is larger than the limit of \[805306368/768mb\], real usage: \[1052991848/1](https://discuss.elastic.co/t/statuscode-429-message-circuit-breaking-exception-circuit-breaking-exception-reason-parent-data-too-large-data-for-http-request-would-be-1052991986-1004-2mb-which-is-larger-than-the-limit-of-805306368-768mb-real-usage-1052991848-1/334343)

<div class="topic-metadata">

**Author:** [@purna](https://discuss.elastic.co/u/purna)\
**Replies:** 10\
**Last updated:** [May 30, 2023, 6:05am UTC](https://discuss.elastic.co/t/statuscode-429-message-circuit-breaking-exception-circuit-breaking-exception-reason-parent-data-too-large-data-for-http-request-would-be-1052991986-1004-2mb-which-is-larger-than-the-limit-of-805306368-768mb-real-usage-1052991848-1/334343 "2023-05-30T06:05:12Z")

</div>

please help me , How to resloved this issue

---

## [Word\_delimiter hyphen remove but retain](https://discuss.elastic.co/t/word-delimiter-hyphen-remove-but-retain/333074)

<div class="topic-metadata">

**Author:** [@Damian](https://discuss.elastic.co/u/Damian)\
**Replies:** 2\
**Last updated:** [May 30, 2023, 4:40am UTC](https://discuss.elastic.co/t/word-delimiter-hyphen-remove-but-retain/333074 "2023-05-30T04:40:40Z")

</div>

Hi I would like to retain the hyphen in between the words but remove at the beginning or at the end of the word. For word -ecigarette I would like the hyphen to be removed and search for "ecigarette" return a result, h…

---

## [What are least and most usage estimates](https://discuss.elastic.co/t/what-are-least-and-most-usage-estimates/334630)

<div class="topic-metadata">

**Author:** [@kpachar](https://discuss.elastic.co/u/kpachar)\
**Replies:** 2\
**Last updated:** [May 30, 2023, 3:25am UTC](https://discuss.elastic.co/t/what-are-least-and-most-usage-estimates/334630 "2023-05-30T03:25:11Z")

</div>

Hello everyone, The node stats API returns least\_usage\_estimate and most\_usage\_estimate. What are these, and how are they different from total? Thank you

---

## [How to install X-PACK in elasticsearch-5.4.3 in windows](https://discuss.elastic.co/t/how-to-install-x-pack-in-elasticsearch-5-4-3-in-windows/334628)

<div class="topic-metadata">

**Author:** [@Ekta](https://discuss.elastic.co/u/Ekta)\
**Replies:** 6\
**Last updated:** [May 30, 2023, 2:19am UTC](https://discuss.elastic.co/t/how-to-install-x-pack-in-elasticsearch-5-4-3-in-windows/334628 "2023-05-30T02:19:52Z")

</div>

how to install and configure x-pack in elasticsearch-5.4.3 ? os: widows server

---

## [Logstash pipeline configuration - extract metrics from message field](https://discuss.elastic.co/t/logstash-pipeline-configuration-extract-metrics-from-message-field/334597)

<div class="topic-metadata">

**Author:** [@Piotr\_Maciejek](https://discuss.elastic.co/u/Piotr_Maciejek)\
**Replies:** 0\
**Last updated:** [May 29, 2023, 2:56pm UTC](https://discuss.elastic.co/t/logstash-pipeline-configuration-extract-metrics-from-message-field/334597 "2023-05-29T14:56:29Z")

</div>

Hi! I want to confgure logstash pipeline. I got many logs in bulk format: ex of one log entry: {"index":{"\_index":"orchestrator-index","\_id":"xxx"}} {"message":"@metrics Exception count: 10","level":"Information","lo…

[Previous page](https://discuss.elastic.co/latest.md?page=660)

[Next page](https://discuss.elastic.co/latest.md?page=662)
