# Latest

**URL:** https://discuss.elastic.co/latest.md?page=675

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 676

---

## [Mismatch between Elastic Query Aggretion and Kibana Visualize Function](https://discuss.elastic.co/t/mismatch-between-elastic-query-aggretion-and-kibana-visualize-function/333619)

<div class="topic-metadata">

**Author:** [@phong\_elastic](https://discuss.elastic.co/u/phong_elastic)\
**Replies:** 1\
**Last updated:** [May 17, 2023, 4:29am UTC](https://discuss.elastic.co/t/mismatch-between-elastic-query-aggretion-and-kibana-visualize-function/333619 "2023-05-17T04:29:42Z")

</div>

Hello everyone. I'm trying create a table that have the same data like the table in Lens Visualization by using the Elasticsearch Query. I'm confusing cause there's is a different between the data I get by the query an…

---

## [Logstash Syslog Input - Capture the Connecting Host's IP Address](https://discuss.elastic.co/t/logstash-syslog-input-capture-the-connecting-hosts-ip-address/333602)

<div class="topic-metadata">

**Author:** [@m52](https://discuss.elastic.co/u/m52)\
**Replies:** 4\
**Last updated:** [May 17, 2023, 4:16am UTC](https://discuss.elastic.co/t/logstash-syslog-input-capture-the-connecting-hosts-ip-address/333602 "2023-05-17T04:16:35Z")

</div>

Hi, Newbie to Logstash here and could use some assistance regarding the Syslog input connector. I currently have the Syslog connector working successfully, but noticed the JSON output has a host.ip element that always…

---

## [Auditbeat - User Attribution](https://discuss.elastic.co/t/auditbeat-user-attribution/333620)

<div class="topic-metadata">

**Author:** [@gunlomboy](https://discuss.elastic.co/u/gunlomboy)\
**Replies:** 0\
**Last updated:** [May 17, 2023, 3:53am UTC](https://discuss.elastic.co/t/auditbeat-user-attribution/333620 "2023-05-17T03:53:01Z")

</div>

Hi, We are running auditbeat with the auditd module using standard auditd.rules. We are seeing the events in our Elasticsearch instance, however there is no user attribution tied to the events. It's great that we are …

---

## [Ingest data from 3 databases](https://discuss.elastic.co/t/ingest-data-from-3-databases/330624)

<div class="topic-metadata">

**Author:** [@baba72210](https://discuss.elastic.co/u/baba72210)\
**Replies:** 4\
**Last updated:** [May 17, 2023, 3:45am UTC](https://discuss.elastic.co/t/ingest-data-from-3-databases/330624 "2023-05-17T03:45:39Z")

</div>

Hi everyone, I have a project where I need to index data from 3 differents databases to be able to search for revelant information. I have a Cassandra, a MSSQL and a mongoDB. Do you think it would be possible to use the…

---

## [Elasticsearch createTranslogSyncProcessor part of source code, log level Setting is not appropriate?](https://discuss.elastic.co/t/elasticsearch-createtranslogsyncprocessor-part-of-source-code-log-level-setting-is-not-appropriate/332539)

<div class="topic-metadata">

**Author:** [@yujie\_wang](https://discuss.elastic.co/u/yujie_wang)\
**Replies:** 1\
**Last updated:** [May 17, 2023, 3:21am UTC](https://discuss.elastic.co/t/elasticsearch-createtranslogsyncprocessor-part-of-source-code-log-level-setting-is-not-appropriate/332539 "2023-05-17T03:21:16Z")

</div>

Hi, Recently, I've been reading the source code of the latest version (8.7.1) of Elasticsearch and I have a question about the log level settings that I can't figure out. I noticed that the "failed to sync translog" is…

---

## [java.lang.IllegalArgumentException: unknown setting \[node.data\] please check that any required plugins are installed, or check the breaking changes documentation for removed settings](https://discuss.elastic.co/t/java-lang-illegalargumentexception-unknown-setting-node-data-please-check-that-any-required-plugins-are-installed-or-check-the-breaking-changes-documentation-for-removed-settings/333558)

<div class="topic-metadata">

**Author:** [@tungnx1](https://discuss.elastic.co/u/tungnx1)\
**Replies:** 2\
**Last updated:** [May 17, 2023, 2:55am UTC](https://discuss.elastic.co/t/java-lang-illegalargumentexception-unknown-setting-node-data-please-check-that-any-required-plugins-are-installed-or-check-the-breaking-changes-documentation-for-removed-settings/333558 "2023-05-17T02:55:06Z")

</div>

help !!! i setup Cluster Elasticsearch. After config file elasticsearch.yml node.name: es-data-1 node.data: true Log: java.lang.IllegalArgumentException: unknown setting \[node.data\] please check that any required pl…

---

## [Winlogbeat mapping to OCSF](https://discuss.elastic.co/t/winlogbeat-mapping-to-ocsf/333605)

<div class="topic-metadata">

**Author:** [@Zachary\_Schmerber](https://discuss.elastic.co/u/Zachary_Schmerber)\
**Replies:** 0\
**Last updated:** [May 16, 2023, 9:03pm UTC](https://discuss.elastic.co/t/winlogbeat-mapping-to-ocsf/333605 "2023-05-16T21:03:40Z")

</div>

Hello, I am trying to find a way to remove the ECS mappings that defaults in winlogbeats and move to OCSF mapping. Anyone know where the logic for the ECS transformations lives or have a repo for winlogbeat that dose not…

---

## [Upgraded go version for 2.7.x](https://discuss.elastic.co/t/upgraded-go-version-for-2-7-x/333608)

<div class="topic-metadata">

**Author:** [@zpear](https://discuss.elastic.co/u/zpear)\
**Replies:** 1\
**Last updated:** [May 16, 2023, 11:58pm UTC](https://discuss.elastic.co/t/upgraded-go-version-for-2-7-x/333608 "2023-05-16T23:58:39Z")

</div>

Hi all, I'm currently running ECK 2.7.0 but noticed a critical injection cve, CVE-2023-24538, that's brought in from the version of golang ECK runs with. I see since then, the go version has been updated (Update docker.i…

---

## [Kibana and logstash can't run using docker-compose](https://discuss.elastic.co/t/kibana-and-logstash-cant-run-using-docker-compose/333566)

<div class="topic-metadata">

**Author:** [@Fatiha](https://discuss.elastic.co/u/Fatiha)\
**Replies:** 1\
**Last updated:** [May 16, 2023, 11:48pm UTC](https://discuss.elastic.co/t/kibana-and-logstash-cant-run-using-docker-compose/333566 "2023-05-16T23:48:35Z")

</div>

hi ,hello everyone I run the elastic and logstash and kibana and mysql containers using docker-compose this the configuration that i use in my docker-compose file version: '3' services: mysql: container\_name: mysql ho…

---

## [Logstash cannot identify config file, it stops after starting , i am using docker desktop](https://discuss.elastic.co/t/logstash-cannot-identify-config-file-it-stops-after-starting-i-am-using-docker-desktop/333613)

<div class="topic-metadata">

**Author:** [@sakshi1](https://discuss.elastic.co/u/sakshi1)\
**Replies:** 0\
**Last updated:** [May 16, 2023, 10:45pm UTC](https://discuss.elastic.co/t/logstash-cannot-identify-config-file-it-stops-after-starting-i-am-using-docker-desktop/333613 "2023-05-16T22:45:14Z")

</div>

so , i wrote an elasticsearch.yaml , which contains the configuration of elasticsearch, kibana and logstash. i will just attach the text version: '3.3' services: elasticsearch: image: docker.elastic.co/elasticsear…

---

## [Create a rule without a query](https://discuss.elastic.co/t/create-a-rule-without-a-query/333314)

<div class="topic-metadata">

**Author:** [@WhiteOwl](https://discuss.elastic.co/u/WhiteOwl)\
**Replies:** 1\
**Last updated:** [May 16, 2023, 10:14pm UTC](https://discuss.elastic.co/t/create-a-rule-without-a-query/333314 "2023-05-16T22:14:25Z")

</div>

Hello, is it possible to create a rule that does not have a query? For example, if I want a rule to fire off every 4-6hrs for analyst to perform a specific task, is that possible?

---

## [No persistent volumes available for this claim on kubernetes](https://discuss.elastic.co/t/no-persistent-volumes-available-for-this-claim-on-kubernetes/333607)

<div class="topic-metadata">

**Author:** [@Resul\_Zoroglu](https://discuss.elastic.co/u/Resul_Zoroglu)\
**Replies:** 0\
**Last updated:** [May 16, 2023, 9:08pm UTC](https://discuss.elastic.co/t/no-persistent-volumes-available-for-this-claim-on-kubernetes/333607 "2023-05-16T21:08:53Z")

</div>

I'm trying to set up elasticsearch on kubernetes with Helm(helm install elasticsearch elastic/elasticsearch -n efk). I get the error "no persistent volumes available for this claim and no storage class is set". In my ku…

---

## [How to create the Multiple Index for each Apache Webserver](https://discuss.elastic.co/t/how-to-create-the-multiple-index-for-each-apache-webserver/333492)

<div class="topic-metadata">

**Author:** [@sanjeev1895](https://discuss.elastic.co/u/sanjeev1895)\
**Replies:** 1\
**Last updated:** [May 16, 2023, 8:21pm UTC](https://discuss.elastic.co/t/how-to-create-the-multiple-index-for-each-apache-webserver/333492 "2023-05-16T20:21:01Z")

</div>

Hi, I'm a new to ELK stack. Can anyone advice me for my below doubt. For example, I have a two apache webserver and I installed filebeat on that and I enabled apache module. Also I configured apache.conf file in logsta…

---

## [Error in Multiline parser of timestamp](https://discuss.elastic.co/t/error-in-multiline-parser-of-timestamp/333598)

<div class="topic-metadata">

**Author:** [@stefws](https://discuss.elastic.co/u/stefws)\
**Replies:** 0\
**Last updated:** [May 16, 2023, 7:39pm UTC](https://discuss.elastic.co/t/error-in-multiline-parser-of-timestamp/333598 "2023-05-16T19:39:48Z")

</div>

Having an issue with a multiline parser in one of own filebeat instance type of Redhat AMQ log which puzzles me, so any hints are appreciated, TIA. See all events dropped in filebeat log due to error like this: {\\"type…

---

## [Index Retention by Filesize](https://discuss.elastic.co/t/index-retention-by-filesize/333489)

<div class="topic-metadata">

**Author:** [@Chacko42](https://discuss.elastic.co/u/Chacko42)\
**Replies:** 3\
**Last updated:** [May 16, 2023, 7:25pm UTC](https://discuss.elastic.co/t/index-retention-by-filesize/333489 "2023-05-16T19:25:39Z")

</div>

Hi Community, we are currently building up a logging infrastructure for our network stuff. The plan is like with switching or firewall logs, to let the logs rotate, as soon as the configured disk space is full. I had a …

---

## [Kibana dashboard filters that recognize multiple views?](https://discuss.elastic.co/t/kibana-dashboard-filters-that-recognize-multiple-views/333507)

<div class="topic-metadata">

**Author:** [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Replies:** 4\
**Last updated:** [May 16, 2023, 6:31pm UTC](https://discuss.elastic.co/t/kibana-dashboard-filters-that-recognize-multiple-views/333507 "2023-05-16T18:31:01Z")

</div>

I created a dashboard that shows visualizations . Each visualization references a different Kibana data view. And each kibana data view references a different index. For example, let's say I have two indices with the f…

---

## [ThreatIntel Module - missing field \[otx.id\] when calculating fingerprint](https://discuss.elastic.co/t/threatintel-module-missing-field-otx-id-when-calculating-fingerprint/330928)

<div class="topic-metadata">

**Author:** [@jlopezsec](https://discuss.elastic.co/u/jlopezsec)\
**Replies:** 3\
**Last updated:** [May 16, 2023, 6:15pm UTC](https://discuss.elastic.co/t/threatintel-module-missing-field-otx-id-when-calculating-fingerprint/330928 "2023-05-16T18:15:37Z")

</div>

Dear Elastic community, I am encountering an error in the Threat Intel module of Elastic where I am receiving the following message: "missing field \[otx.id\] when calculating fingerprint." After researching the error, I …

---

## [Elastic APM for Xamarin Forms](https://discuss.elastic.co/t/elastic-apm-for-xamarin-forms/333593)

<div class="topic-metadata">

**Author:** [@OscarFilho](https://discuss.elastic.co/u/OscarFilho)\
**Replies:** 0\
**Last updated:** [May 16, 2023, 6:01pm UTC](https://discuss.elastic.co/t/elastic-apm-for-xamarin-forms/333593 "2023-05-16T18:01:12Z")

</div>

I hava a mobile application developed in Xamarin Forms (C#). Anyone knows if are there some solution of elastic apm implementation on this type of application (Xamarin Forms C#)???

---

## [Potential logs loss on a WEC server via Winlogbeat](https://discuss.elastic.co/t/potential-logs-loss-on-a-wec-server-via-winlogbeat/331561)

<div class="topic-metadata">

**Author:** [@rpe](https://discuss.elastic.co/u/rpe)\
**Replies:** 1\
**Last updated:** [May 16, 2023, 2:58pm UTC](https://discuss.elastic.co/t/potential-logs-loss-on-a-wec-server-via-winlogbeat/331561 "2023-05-16T14:58:53Z")

</div>

Hello, I deployed a WEC with a customer to forward its Windows logs to our SIEM, following the Elastic WEC Server cookbook. However, after synchronizing with the customer, he generated some events that we didn't receiv…

---

## [Csv parse failure](https://discuss.elastic.co/t/csv-parse-failure/333049)

<div class="topic-metadata">

**Author:** [@Hanni](https://discuss.elastic.co/u/Hanni)\
**Replies:** 9\
**Last updated:** [May 16, 2023, 2:45pm UTC](https://discuss.elastic.co/t/csv-parse-failure/333049 "2023-05-16T14:45:10Z")

</div>

Hello, I'm trying to parse a CSV file with Logstash, but I'm encountering a CSV parse failure. Can you please help me?

---

## [Mutate -\> Copy is not working as expected](https://discuss.elastic.co/t/mutate-copy-is-not-working-as-expected/333541)

<div class="topic-metadata">

**Author:** [@FALEN](https://discuss.elastic.co/u/FALEN)\
**Replies:** 1\
**Last updated:** [May 16, 2023, 2:42pm UTC](https://discuss.elastic.co/t/mutate-copy-is-not-working-as-expected/333541 "2023-05-16T14:42:54Z")

</div>

Im working on some json data, transforming and remapping fields add\_field, rename plugins are working as expected But whenever im using copy, output does not include these \[events\]\[date\], \[env\]\[app\] fields. But does in…

---

## [How to create dynamic Query DSL for Includes](https://discuss.elastic.co/t/how-to-create-dynamic-query-dsl-for-includes/333581)

<div class="topic-metadata">

**Author:** [@Koi\_Kin](https://discuss.elastic.co/u/Koi_Kin)\
**Replies:** 0\
**Last updated:** [May 16, 2023, 2:38pm UTC](https://discuss.elastic.co/t/how-to-create-dynamic-query-dsl-for-includes/333581 "2023-05-16T14:38:20Z")

</div>

I have this query: .Search\<Person\>("person", s =\> s .Index("person") .Source(s =\> s .Includes(i =\> i .Fields( f =\> f.Id, ) ) ) .Query(q =\> q …

---

## [Loadbalancing config in Kibana](https://discuss.elastic.co/t/loadbalancing-config-in-kibana/333464)

<div class="topic-metadata">

**Author:** [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Replies:** 4\
**Last updated:** [May 16, 2023, 1:31pm UTC](https://discuss.elastic.co/t/loadbalancing-config-in-kibana/333464 "2023-05-16T13:31:36Z")

</div>

Hi All, Filebeat output has an ability to be configured with load balancing config as follows: output.logstash: hosts: \["hostA:5044","hostB:5044","hostC:5044"\] loadbalance: true Do we have a similar set up for K…

---

## [Mulitple Filebeat Instances](https://discuss.elastic.co/t/mulitple-filebeat-instances/330792)

<div class="topic-metadata">

**Author:** [@BoKu](https://discuss.elastic.co/u/BoKu)\
**Replies:** 9\
**Last updated:** [May 16, 2023, 12:44pm UTC](https://discuss.elastic.co/t/mulitple-filebeat-instances/330792 "2023-05-16T12:44:24Z")

</div>

Hello, i did setup two filebeat instances on a linux server. One for Syslog and the PANW-Module and the other for the F5-Module. The Syslog/PANW Filebeat was the first one, i did change the index to a different one, bu…

---

## [Curator not can find indecies](https://discuss.elastic.co/t/curator-not-can-find-indecies/333465)

<div class="topic-metadata">

**Author:** [@alon\_carmelly](https://discuss.elastic.co/u/alon_carmelly)\
**Replies:** 6\
**Last updated:** [May 16, 2023, 12:28pm UTC](https://discuss.elastic.co/t/curator-not-can-find-indecies/333465 "2023-05-16T12:28:27Z")

</div>

I have an issue with deleting indexes! this is my Action file: actions: 1: action: delete\_indices description: \>- Delete indices. Find which to delete by first limiting the list to logstash- prefi…

---

## [Add a quick range based on server time to Kibana Time filter quick ranges](https://discuss.elastic.co/t/add-a-quick-range-based-on-server-time-to-kibana-time-filter-quick-ranges/333564)

<div class="topic-metadata">

**Author:** [@gizem](https://discuss.elastic.co/u/gizem)\
**Replies:** 1\
**Last updated:** [May 16, 2023, 12:07pm UTC](https://discuss.elastic.co/t/add-a-quick-range-based-on-server-time-to-kibana-time-filter-quick-ranges/333564 "2023-05-16T12:07:14Z")

</div>

Hello, I want to add a quick range based on server time to Kibana. For example: \<{ "from": "now-15m", "to": "now", "display": "Last 15 minutes" }, /\> 'now' is set by client time. But if client time is wrong, filt…

---

## [Can Snapshots save index in a limited time](https://discuss.elastic.co/t/can-snapshots-save-index-in-a-limited-time/333553)

<div class="topic-metadata">

**Author:** [@Skairik](https://discuss.elastic.co/u/Skairik)\
**Replies:** 4\
**Last updated:** [May 16, 2023, 12:04pm UTC](https://discuss.elastic.co/t/can-snapshots-save-index-in-a-limited-time/333553 "2023-05-16T12:04:17Z")

</div>

Hello everyone, I would like to know if it is possible to set up a snapshot policy that retrieves for example indexes only from the last 7 days. For example, I save my logs from my active directory with this format: in…

---

## [\[macOS 10.15.7\] Cannot execute filebeat, auditbeat, or metricbeat](https://discuss.elastic.co/t/macos-10-15-7-cannot-execute-filebeat-auditbeat-or-metricbeat/333471)

<div class="topic-metadata">

**Author:** [@Coolgum15](https://discuss.elastic.co/u/Coolgum15)\
**Replies:** 2\
**Last updated:** [May 16, 2023, 11:32am UTC](https://discuss.elastic.co/t/macos-10-15-7-cannot-execute-filebeat-auditbeat-or-metricbeat/333471 "2023-05-16T11:32:05Z")

</div>

Cannot run any of these beats. Same error for all of them (below). Using default configuration, except outputting to logstash server. The logstash server is functional, and my Linux beats are outputting to it just fine. …

---

## [Elastic search usermanagement with out using tls](https://discuss.elastic.co/t/elastic-search-usermanagement-with-out-using-tls/333550)

<div class="topic-metadata">

**Author:** [@MahithaSarala](https://discuss.elastic.co/u/MahithaSarala)\
**Replies:** 0\
**Last updated:** [May 16, 2023, 9:36am UTC](https://discuss.elastic.co/t/elastic-search-usermanagement-with-out-using-tls/333550 "2023-05-16T09:36:25Z")

</div>

Hi Team, Currently i'm deploying elasticsearch 7.14 version , added usermangement with tls certs , its deploying but while accesing elasticsearch its not asking credentials , But i have added secrets for namespace. \< …

---

## [Aggregations: How to get number of combinations](https://discuss.elastic.co/t/aggregations-how-to-get-number-of-combinations/333560)

<div class="topic-metadata">

**Author:** [@es\_make](https://discuss.elastic.co/u/es_make)\
**Replies:** 0\
**Last updated:** [May 16, 2023, 11:24am UTC](https://discuss.elastic.co/t/aggregations-how-to-get-number-of-combinations/333560 "2023-05-16T11:24:11Z")

</div>

Hello, Let's say we have a simple ES index having two fields: "name" (string) and "expired" (boolean) in one nested object "products" (array). Each product name can be mentioned only once in each document. Here's the e…

[Previous page](https://discuss.elastic.co/latest.md?page=674)

[Next page](https://discuss.elastic.co/latest.md?page=676)
