# Latest

**URL:** https://discuss.elastic.co/latest.md?page=674

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 675

---

## [Painless Script Error, Creating New Variable on Data View](https://discuss.elastic.co/t/painless-script-error-creating-new-variable-on-data-view/333599)

<div class="topic-metadata">

**Author:** [@marscar](https://discuss.elastic.co/u/marscar)\
**Replies:** 1\
**Last updated:** [May 17, 2023, 3:59pm UTC](https://discuss.elastic.co/t/painless-script-error-creating-new-variable-on-data-view/333599 "2023-05-17T15:59:42Z")

</div>

Hello! I am trying to create a new variable on a Data View using this painless script, but when trying to save, I am getting the generic error "Invalid Painless Script". The error also tells be to fix the highlighted err…

---

## [How do Searchable Snapshot snapshots get cleaned up?](https://discuss.elastic.co/t/how-do-searchable-snapshot-snapshots-get-cleaned-up/329831)

<div class="topic-metadata">

**Author:** [@BenB196](https://discuss.elastic.co/u/BenB196)\
**Replies:** 15\
**Last updated:** [May 17, 2023, 3:54pm UTC](https://discuss.elastic.co/t/how-do-searchable-snapshot-snapshots-get-cleaned-up/329831 "2023-05-17T15:54:36Z")

</div>

Hello All, I was curious if anyone knew the answer to the question: How do searchable snapshot snapshots get cleaned up. To explain the question a bit more, I'll use the below example: I have: A snapshot reposito…

---

## [How to integrate in-house ticketing tool with ELK using API's](https://discuss.elastic.co/t/how-to-integrate-in-house-ticketing-tool-with-elk-using-apis/333645)

<div class="topic-metadata">

**Author:** [@DhananjayPatil](https://discuss.elastic.co/u/DhananjayPatil)\
**Replies:** 1\
**Last updated:** [May 17, 2023, 3:42pm UTC](https://discuss.elastic.co/t/how-to-integrate-in-house-ticketing-tool-with-elk-using-apis/333645 "2023-05-17T15:42:41Z")

</div>

Hi Everyone, I am currently working on integrating our in-house ticketing tool with ELK. Specifically, I would like to fetch data from ELK and automatically create incidents in our ticketing tool when specific conditions…

---

## [DEPRECATED: Treating the CommonName field on X.509 certificates as a host name when no Subject Alternative Names are present is going to be removed](https://discuss.elastic.co/t/deprecated-treating-the-commonname-field-on-x-509-certificates-as-a-host-name-when-no-subject-alternative-names-are-present-is-going-to-be-removed/333326)

<div class="topic-metadata">

**Author:** [@silentfilm](https://discuss.elastic.co/u/silentfilm)\
**Replies:** 2\
**Last updated:** [May 17, 2023, 3:28pm UTC](https://discuss.elastic.co/t/deprecated-treating-the-commonname-field-on-x-509-certificates-as-a-host-name-when-no-subject-alternative-names-are-present-is-going-to-be-removed/333326 "2023-05-17T15:28:30Z")

</div>

I am getting the following deprecation warning in both filebeat and metricbeat. I am currently using ES 7.17.9, but will be upgrading to 8.x soon: DEPRECATED: Treating the CommonName field on X.509 certificates as a ho…

---

## [Is it possible to have multiple SQL queries into the Expression Editor?](https://discuss.elastic.co/t/is-it-possible-to-have-multiple-sql-queries-into-the-expression-editor/333596)

<div class="topic-metadata">

**Author:** [@SamuelSMendes](https://discuss.elastic.co/u/SamuelSMendes)\
**Replies:** 1\
**Last updated:** [May 17, 2023, 3:15pm UTC](https://discuss.elastic.co/t/is-it-possible-to-have-multiple-sql-queries-into-the-expression-editor/333596 "2023-05-17T15:15:42Z")

</div>

For the context, I have a query that brings me data from the last 24hous. And would like to have a second column which will deal only with information from the last 6minutes. The thing is, if I do both like: @timestamp…

---

## [How to upgrade ELK on docker from 8.4.3 to 8.7.0](https://discuss.elastic.co/t/how-to-upgrade-elk-on-docker-from-8-4-3-to-8-7-0/331352)

<div class="topic-metadata">

**Author:** [@Thales\_Eduardo](https://discuss.elastic.co/u/Thales_Eduardo)\
**Replies:** 2\
**Last updated:** [May 17, 2023, 2:48pm UTC](https://discuss.elastic.co/t/how-to-upgrade-elk-on-docker-from-8-4-3-to-8-7-0/331352 "2023-05-17T14:48:21Z")

</div>

I have an elastdocker (elk version 8.4.3) in production for some time and I would like to upgrade the elk version (8.4.3 to 8.7.0). Volumes are configured on the instance to use persistent storage. The procedure would …

---

## [EFK Stack on Kubernetes - Collecting logs from default namespace](https://discuss.elastic.co/t/efk-stack-on-kubernetes-collecting-logs-from-default-namespace/333672)

<div class="topic-metadata">

**Author:** [@daniela09](https://discuss.elastic.co/u/daniela09)\
**Replies:** 0\
**Last updated:** [May 17, 2023, 2:31pm UTC](https://discuss.elastic.co/t/efk-stack-on-kubernetes-collecting-logs-from-default-namespace/333672 "2023-05-17T14:31:22Z")

</div>

Hi, I am using EFK stack on Kubernetes, I want to configure fluentd to collect logs from one specific namespace, the default namespace. This is my fleuntd config file: \<label @FLUENT\_LOG\> \<match fluent.\*\*\> …

---

## [Getting Logstash output cannot be used with Fleet Server integration in Fleet Server Policy. Please create a new ElasticSearch output](https://discuss.elastic.co/t/getting-logstash-output-cannot-be-used-with-fleet-server-integration-in-fleet-server-policy-please-create-a-new-elasticsearch-output/330980)

<div class="topic-metadata">

**Author:** [@mehdi-lamrani](https://discuss.elastic.co/u/mehdi-lamrani)\
**Replies:** 5\
**Last updated:** [May 17, 2023, 2:24pm UTC](https://discuss.elastic.co/t/getting-logstash-output-cannot-be-used-with-fleet-server-integration-in-fleet-server-policy-please-create-a-new-elasticsearch-output/330980 "2023-05-17T14:24:34Z")

</div>

This is pretty straightforward as you can see : I get this after trying to configure a logstash output on Fleet and going through all the steps. I dont know what to do with this error message as it does not make sens…

---

## [Logstash config - Kafka and CEF](https://discuss.elastic.co/t/logstash-config-kafka-and-cef/333669)

<div class="topic-metadata">

**Author:** [@elizZ](https://discuss.elastic.co/u/elizZ)\
**Replies:** 0\
**Last updated:** [May 17, 2023, 2:18pm UTC](https://discuss.elastic.co/t/logstash-config-kafka-and-cef/333669 "2023-05-17T14:18:23Z")

</div>

Hi, I have a Logstash input of Kafka(codec cef), that consumes arcsight CEF format events from a kafka topic and writes it to elastic with 'elasticsearch' output I have an issue when some of the events have multiline f…

---

## [Logstash - Syslog Output - Custom message](https://discuss.elastic.co/t/logstash-syslog-output-custom-message/333668)

<div class="topic-metadata">

**Author:** [@Nandhini\_Viswanathan](https://discuss.elastic.co/u/Nandhini_Viswanathan)\
**Replies:** 0\
**Last updated:** [May 17, 2023, 2:07pm UTC](https://discuss.elastic.co/t/logstash-syslog-output-custom-message/333668 "2023-05-17T14:07:31Z")

</div>

Hi, Reopening for Discussion. I'm working with Logstash - Syslog Output and I've found problem with custom field message. I'm using Elasticstack 7.10.2 I've installed logstash syslog-output plugin version 3.0.5. /usr…

---

## [Issue to setup Fleet Server](https://discuss.elastic.co/t/issue-to-setup-fleet-server/333209)

<div class="topic-metadata">

**Author:** [@Shoeb\_Masum](https://discuss.elastic.co/u/Shoeb_Masum)\
**Replies:** 3\
**Last updated:** [May 17, 2023, 1:48pm UTC](https://discuss.elastic.co/t/issue-to-setup-fleet-server/333209 "2023-05-17T13:48:49Z")

</div>

Continuing the discussion from How to get started with Elastic APM?: @Wave I've taken two VM as suggested - VM1 (elasticsearch, kibana): 192.168.1.41 VM2 (Fleet Elastic Agent): 192.168.1.42 I've install Elasticsearc…

---

## [Logstash JDBC insert after select completes](https://discuss.elastic.co/t/logstash-jdbc-insert-after-select-completes/333660)

<div class="topic-metadata">

**Author:** [@tommycahir](https://discuss.elastic.co/u/tommycahir)\
**Replies:** 0\
**Last updated:** [May 17, 2023, 1:06pm UTC](https://discuss.elastic.co/t/logstash-jdbc-insert-after-select-completes/333660 "2023-05-17T13:06:51Z")

</div>

Hey All Just looking to understand if there is some way that I can run a SQL INSERT before and after a SELECT statement in the filter section to update a tracking table in the DB to say that the select query has started…

---

## [Failed to obtain node locks, tried \[/usr/share/elasticsearch/data\]; maybe these locations are not writable or multiple nodes were started](https://discuss.elastic.co/t/failed-to-obtain-node-locks-tried-usr-share-elasticsearch-data-maybe-these-locations-are-not-writable-or-multiple-nodes-were-started/333657)

<div class="topic-metadata">

**Author:** [@Resul\_Zoroglu](https://discuss.elastic.co/u/Resul_Zoroglu)\
**Replies:** 0\
**Last updated:** [May 17, 2023, 12:54pm UTC](https://discuss.elastic.co/t/failed-to-obtain-node-locks-tried-usr-share-elasticsearch-data-maybe-these-locations-are-not-writable-or-multiple-nodes-were-started/333657 "2023-05-17T12:54:40Z")

</div>

I installed elasticsearch on kubernetes using helm. elasticsearch version: 8.5.1 pods do not stand up. Error in pods log: {"@timestamp":"2023-05-17T12:50:32.223Z", "log.level":"ERROR", "message":"fatal exception while…

---

## [Syslog Ingest Pipeline not targeting data](https://discuss.elastic.co/t/syslog-ingest-pipeline-not-targeting-data/333204)

<div class="topic-metadata">

**Author:** [@Ryan\_Downey](https://discuss.elastic.co/u/Ryan_Downey)\
**Replies:** 4\
**Last updated:** [May 17, 2023, 12:30pm UTC](https://discuss.elastic.co/t/syslog-ingest-pipeline-not-targeting-data/333204 "2023-05-17T12:30:13Z")

</div>

We're trying to utilize ingest pipelines for some of our Filebeat data and the pipeline doesn't seem to processing any events. We've run this through the grok parser and that provides us with the correct output so I'm n…

---

## [Can I reload after a setting change in elasticsearch.yml?](https://discuss.elastic.co/t/can-i-reload-after-a-setting-change-in-elasticsearch-yml/333565)

<div class="topic-metadata">

**Author:** [@GenSSC](https://discuss.elastic.co/u/GenSSC)\
**Replies:** 6\
**Last updated:** [May 16, 2023, 2:40pm UTC](https://discuss.elastic.co/t/can-i-reload-after-a-setting-change-in-elasticsearch-yml/333565 "2023-05-16T14:40:30Z")

</div>

Is there a way to only reload the settings and not the whole stack ?

---

## [Working days - how to find](https://discuss.elastic.co/t/working-days-how-to-find/332404)

<div class="topic-metadata">

**Author:** [@TheyCallMeTrinity](https://discuss.elastic.co/u/TheyCallMeTrinity)\
**Replies:** 8\
**Last updated:** [May 17, 2023, 11:54am UTC](https://discuss.elastic.co/t/working-days-how-to-find/332404 "2023-05-17T11:54:04Z")

</div>

Hi, I have a problem. I'm getting data from the api which lists the rooms that users have booked. Each room has set working days and hours. I need to make a table where the Average real resource usage will be calculat…

---

## [Fortigate Issues](https://discuss.elastic.co/t/fortigate-issues/333653)

<div class="topic-metadata">

**Author:** [@sourcreamnormanbates](https://discuss.elastic.co/u/sourcreamnormanbates)\
**Replies:** 0\
**Last updated:** [May 17, 2023, 11:20am UTC](https://discuss.elastic.co/t/fortigate-issues/333653 "2023-05-17T11:20:12Z")

</div>

I have deployed the Fortigate integration using Fleet to one of my Elastic Agents. When I run tcpdump, I see a lot of UDP traffic on the host running the agent. However; I don't see any of that data in Elastic. I'm ev…

---

## [How to monitor transactions which pass through Rabbit MQ, producer & consumer are python clients](https://discuss.elastic.co/t/how-to-monitor-transactions-which-pass-through-rabbit-mq-producer-consumer-are-python-clients/332647)

<div class="topic-metadata">

**Author:** [@Dixit](https://discuss.elastic.co/u/Dixit)\
**Replies:** 4\
**Last updated:** [May 17, 2023, 11:03am UTC](https://discuss.elastic.co/t/how-to-monitor-transactions-which-pass-through-rabbit-mq-producer-consumer-are-python-clients/332647 "2023-05-17T11:03:30Z")

</div>

Hi All, I want to "trace" distributed transactions which pass through "Rabbit MQ" through the Application. The clients for Rabbit MQ are written in python 2.x & Python 3,.x to consume and produce messages. When in Elas…

---

## [Snapshots retention policy sans snapshots automatiques](https://discuss.elastic.co/t/snapshots-retention-policy-sans-snapshots-automatiques/333386)

<div class="topic-metadata">

**Author:** [@DataXavier](https://discuss.elastic.co/u/DataXavier)\
**Replies:** 4\
**Last updated:** [May 17, 2023, 9:55am UTC](https://discuss.elastic.co/t/snapshots-retention-policy-sans-snapshots-automatiques/333386 "2023-05-17T09:55:08Z")

</div>

Bonjour, Je travaille sur un projet basé sur Elasticsearch. J'ai besoin de créer des snapshots manuellement avec des metadata. Je voudrais mettre une retention policy sur ces snapshots. J'ai essayé avec SLM mais il sem…

---

## [CAPACITY test over the years for STORAGE RAM and so](https://discuss.elastic.co/t/capacity-test-over-the-years-for-storage-ram-and-so/333644)

<div class="topic-metadata">

**Author:** [@Dor\_Steinberg](https://discuss.elastic.co/u/Dor_Steinberg)\
**Replies:** 0\
**Last updated:** [May 17, 2023, 9:34am UTC](https://discuss.elastic.co/t/capacity-test-over-the-years-for-storage-ram-and-so/333644 "2023-05-17T09:34:52Z")

</div>

i have number of indexes I would be happy to know if there is a certain formula or what is the correct way to determine how much CAPACITY is needed in 4 years thanks for the help

---

## [How to show zero value in len](https://discuss.elastic.co/t/how-to-show-zero-value-in-len/333517)

<div class="topic-metadata">

**Author:** [@tonyaw](https://discuss.elastic.co/u/tonyaw)\
**Replies:** 4\
**Last updated:** [May 17, 2023, 9:21am UTC](https://discuss.elastic.co/t/how-to-show-zero-value-in-len/333517 "2023-05-17T09:21:33Z")

</div>

I had a search result which has non-zero per 2 hours. I want to use Lens to show a sawtooth graph per hour(contains both non-zero value and zero value). May I ask how to configure it? Currently, I got a straight line re…

---

## [I want to put my grok inside if else block of logstash I want the fields to be displayed in kibana it's executing but not displaying the actual fields](https://discuss.elastic.co/t/i-want-to-put-my-grok-inside-if-else-block-of-logstash-i-want-the-fields-to-be-displayed-in-kibana-its-executing-but-not-displaying-the-actual-fields/333637)

<div class="topic-metadata">

**Author:** [@sudhir\_singh](https://discuss.elastic.co/u/sudhir_singh)\
**Replies:** 0\
**Last updated:** [May 17, 2023, 8:48am UTC](https://discuss.elastic.co/t/i-want-to-put-my-grok-inside-if-else-block-of-logstash-i-want-the-fields-to-be-displayed-in-kibana-its-executing-but-not-displaying-the-actual-fields/333637 "2023-05-17T08:48:56Z")

</div>

filter { if \[IgmpSnooping\] == "%IGMPSNOOPING-6-NO\_IGMP\_QUERIER" { grok { match =\> { "message" =\> "\<%{INT:priority:int}\>%{SYSLOGTIMESTAMP:timestamp}\\s+%{HOSTNAME:device\_name}\\s+\\IgmpSnooping:\\s+%{DATA:IgmpSnooping}\\…

---

## [Grok filter working in online debuggers but not in actual implementation](https://discuss.elastic.co/t/grok-filter-working-in-online-debuggers-but-not-in-actual-implementation/333428)

<div class="topic-metadata">

**Author:** [@roman-tasi](https://discuss.elastic.co/u/roman-tasi)\
**Replies:** 3\
**Last updated:** [May 17, 2023, 8:35am UTC](https://discuss.elastic.co/t/grok-filter-working-in-online-debuggers-but-not-in-actual-implementation/333428 "2023-05-17T08:35:10Z")

</div>

This seems to give \_grokparsefailure a hundred percent of the time: if \[event\]\[action\]=="Process Creation" { grok { match =\> { "winlog.event\_data.NewProcessName" =\> "(?\<directory\>.\*)\\\\(?\<exe…

---

## [Count filtering visualization](https://discuss.elastic.co/t/count-filtering-visualization/333527)

<div class="topic-metadata">

**Author:** [@clmtb](https://discuss.elastic.co/u/clmtb)\
**Replies:** 7\
**Last updated:** [May 17, 2023, 8:06am UTC](https://discuss.elastic.co/t/count-filtering-visualization/333527 "2023-05-17T08:06:51Z")

</div>

Hi all, I am trying to create a pretty simple visualization in Kibana in TSVB Table, with the count of different fields but with a filter applied. To be more precise, I want to get the count of every values higher than …

---

## [Ignore\_z\_value is not supported](https://discuss.elastic.co/t/ignore-z-value-is-not-supported/333571)

<div class="topic-metadata">

**Author:** [@gabi939](https://discuss.elastic.co/u/gabi939)\
**Replies:** 2\
**Last updated:** [May 17, 2023, 7:45am UTC](https://discuss.elastic.co/t/ignore-z-value-is-not-supported/333571 "2023-05-17T07:45:05Z")

</div>

Elasticsearch Version 7.7.0 Java Version 1.8.0\_252 OS Version Ubuntu 18.04 Problem Description According to: I should be able to use parameter ignore\_z\_value to ignore z values indexed to geo\_point field. But it do…

---

## [How the trace methods works in java agent?](https://discuss.elastic.co/t/how-the-trace-methods-works-in-java-agent/333622)

<div class="topic-metadata">

**Author:** [@AbhijithCV](https://discuss.elastic.co/u/AbhijithCV)\
**Replies:** 2\
**Last updated:** [May 17, 2023, 7:44am UTC](https://discuss.elastic.co/t/how-the-trace-methods-works-in-java-agent/333622 "2023-05-17T07:44:21Z")

</div>

Hi, I would like to know how the trace methods work in java agent which creates spans for each method invoked during a transaction. How does the agent keep track of which functions belongs to which transaction, as the…

---

## [Guidance on mapping and query](https://discuss.elastic.co/t/guidance-on-mapping-and-query/333592)

<div class="topic-metadata">

**Author:** [@ichbindermike](https://discuss.elastic.co/u/ichbindermike)\
**Replies:** 2\
**Last updated:** [May 17, 2023, 6:55am UTC](https://discuss.elastic.co/t/guidance-on-mapping-and-query/333592 "2023-05-17T06:55:27Z")

</div>

I have a question on what might be the best approach to structure my data. I have 8 indices that each contain about 4-7 fields (different ones), but I would like to search across all indices and multiple of those fields.…

---

## [Logstash new record](https://discuss.elastic.co/t/logstash-new-record/333629)

<div class="topic-metadata">

**Author:** [@m3bgwad](https://discuss.elastic.co/u/m3bgwad)\
**Replies:** 0\
**Last updated:** [May 17, 2023, 6:53am UTC](https://discuss.elastic.co/t/logstash-new-record/333629 "2023-05-17T06:53:52Z")

</div>

How to handle the logstash configuration in the case when I run the JDBC query and then there are no results through 1 to 10 minutes, if there is no result I need to generate a new record to store it in as document in th…

---

## [Elasticsearch snapshot/restore to s3](https://discuss.elastic.co/t/elasticsearch-snapshot-restore-to-s3/330517)

<div class="topic-metadata">

**Author:** [@sraman](https://discuss.elastic.co/u/sraman)\
**Replies:** 30\
**Last updated:** [May 17, 2023, 5:27am UTC](https://discuss.elastic.co/t/elasticsearch-snapshot-restore-to-s3/330517 "2023-05-17T05:27:31Z")

</div>

Hi, I have installed elasticsearch 8.6.2 & kibana 8.6.2 on the same standalone server for testing purpose. Planning to place the data snapshot to S3 and restore, but facing issues while creating the repository(it's not…

---

## [GeoIP filter missing some ECS fields](https://discuss.elastic.co/t/geoip-filter-missing-some-ecs-fields/333339)

<div class="topic-metadata">

**Author:** [@roman-tasi](https://discuss.elastic.co/u/roman-tasi)\
**Replies:** 7\
**Last updated:** [May 17, 2023, 5:18am UTC](https://discuss.elastic.co/t/geoip-filter-missing-some-ecs-fields/333339 "2023-05-17T05:18:00Z")

</div>

I am using the GeoIP Logstash filter and it seems to not have some desired fields for example \[mmdb\]\[isp\]. Overall it has no as or mmdb fields, as well as some other random fields. It does have all the geo fields however…

[Previous page](https://discuss.elastic.co/latest.md?page=673)

[Next page](https://discuss.elastic.co/latest.md?page=675)
