# Latest

**URL:** https://discuss.elastic.co/latest.md?page=678

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 679

---

## [Fleet server is offline](https://discuss.elastic.co/t/fleet-server-is-offline/333419)

<div class="topic-metadata">

**Author:** [@samiujan](https://discuss.elastic.co/u/samiujan)\
**Replies:** 0\
**Last updated:** [May 15, 2023, 8:04am UTC](https://discuss.elastic.co/t/fleet-server-is-offline/333419 "2023-05-15T08:04:19Z")

</div>

Hi I am trying to set up APM using Fleet on an on-prem EC2 instance After much back and forth, I got the agent installed and it's running on an unsecured endpoint I want to move it to a secure endpoint and have added …

---

## [Getting Could not find the data view error on kibana dashboard](https://discuss.elastic.co/t/getting-could-not-find-the-data-view-error-on-kibana-dashboard/332792)

<div class="topic-metadata">

**Author:** [@Sachchan](https://discuss.elastic.co/u/Sachchan)\
**Replies:** 26\
**Last updated:** [May 15, 2023, 7:59am UTC](https://discuss.elastic.co/t/getting-could-not-find-the-data-view-error-on-kibana-dashboard/332792 "2023-05-15T07:59:25Z")

</div>

Hi All, I am using kibana dashboards to visualize the data. but i am getting "Could not find the data view" error very frequently and when i refresh again, this error doesn't come. Please help in resolving this error. T…

---

## [While helm upgrade getting error elasticsearch 7.17.5](https://discuss.elastic.co/t/while-helm-upgrade-getting-error-elasticsearch-7-17-5/333417)

<div class="topic-metadata">

**Author:** [@shivaji\_laxmi](https://discuss.elastic.co/u/shivaji_laxmi)\
**Replies:** 0\
**Last updated:** [May 15, 2023, 7:57am UTC](https://discuss.elastic.co/t/while-helm-upgrade-getting-error-elasticsearch-7-17-5/333417 "2023-05-15T07:57:56Z")

</div>

I upgraded the kubernetes cluster from 1.24 to 1.25. When I try to add additional node in elasticsearch cluster. I am getting following error. $ helm upgrade esdata . -f esdata\_prod.yml -n dea-elk --debug --dry-run up…

---

## [Logstash/Kibana : time field incorrect](https://discuss.elastic.co/t/logstash-kibana-time-field-incorrect/333303)

<div class="topic-metadata">

**Author:** [@JackieLaFrite](https://discuss.elastic.co/u/JackieLaFrite)\
**Replies:** 2\
**Last updated:** [May 15, 2023, 7:51am UTC](https://discuss.elastic.co/t/logstash-kibana-time-field-incorrect/333303 "2023-05-15T07:51:30Z")

</div>

I've been stuck for 4 days on this problem. The logs that appear in Kibana have their field time changed (+2 hours) + the logs that appear in kibana are logs from two hours ago. It's currently 14h10, here is my last lo…

---

## [Error "Queue full" while sending data from Otel collector to APM](https://discuss.elastic.co/t/error-queue-full-while-sending-data-from-otel-collector-to-apm/333230)

<div class="topic-metadata">

**Author:** [@ar\_shashikumar](https://discuss.elastic.co/u/ar_shashikumar)\
**Replies:** 0\
**Last updated:** [May 11, 2023, 5:18pm UTC](https://discuss.elastic.co/t/error-queue-full-while-sending-data-from-otel-collector-to-apm/333230 "2023-05-11T17:18:49Z")

</div>

We have configured otlp/elastic with APM server in k8s v1.25. When we looked at Otel collector logs, it shows that queue is full. Any help is very much appreciated. 2023-05-11T16:26:19.200Z error exporterhelper…

---

## [Configure host for fleet server/APM agent policy](https://discuss.elastic.co/t/configure-host-for-fleet-server-apm-agent-policy/332507)

<div class="topic-metadata">

**Author:** [@samiujan](https://discuss.elastic.co/u/samiujan)\
**Replies:** 2\
**Last updated:** [May 15, 2023, 7:29am UTC](https://discuss.elastic.co/t/configure-host-for-fleet-server-apm-agent-policy/332507 "2023-05-15T07:29:43Z")

</div>

Hi I have installed Elastic/Kibana 8.7 and am running a Fleet server and APM - this is all running successfully on localhost Now I want to allow access to a NodeJS application on an EC2 and a web app running off S3/clo…

---

## [Logstash configuration when failing to handle message](https://discuss.elastic.co/t/logstash-configuration-when-failing-to-handle-message/333406)

<div class="topic-metadata">

**Author:** [@TheZadok42](https://discuss.elastic.co/u/TheZadok42)\
**Replies:** 0\
**Last updated:** [May 15, 2023, 7:02am UTC](https://discuss.elastic.co/t/logstash-configuration-when-failing-to-handle-message/333406 "2023-05-15T07:02:10Z")

</div>

Hi! Recently I started to integrate logstash into our infrastructure, and while reading the documentation I didn’t quite understand how to handle bad messages. My current flow is as follows: Application -\> rabbitmq -\> …

---

## [Autodetect\_column\_names is not working as expected in csv filter plugin](https://discuss.elastic.co/t/autodetect-column-names-is-not-working-as-expected-in-csv-filter-plugin/333269)

<div class="topic-metadata">

**Author:** [@vladislav](https://discuss.elastic.co/u/vladislav)\
**Replies:** 2\
**Last updated:** [May 15, 2023, 6:39am UTC](https://discuss.elastic.co/t/autodetect-column-names-is-not-working-as-expected-in-csv-filter-plugin/333269 "2023-05-15T06:39:13Z")

</div>

Hi, I have this logstash .conf file: input { file { path =\> "/eee/\*.csv" start\_position =\> "beginning" sincedb\_path =\> "/dev/null" } } filter { csv { autodetect\_column\_names =\> true } } And multi…

---

## [Data enrichment using logstash with translate plugin](https://discuss.elastic.co/t/data-enrichment-using-logstash-with-translate-plugin/333403)

<div class="topic-metadata">

**Author:** [@gpandey7](https://discuss.elastic.co/u/gpandey7)\
**Replies:** 0\
**Last updated:** [May 15, 2023, 6:37am UTC](https://discuss.elastic.co/t/data-enrichment-using-logstash-with-translate-plugin/333403 "2023-05-15T06:37:29Z")

</div>

I am trying to enrich the data before it gets indexed, I have tried the below methods but both are currently not working Using the elasticsearch plugin in filter input { kafka { bootstrap\_servers =\> "x…

---

## [Is there a way to plot trend on Opensource Dashobard 2.6](https://discuss.elastic.co/t/is-there-a-way-to-plot-trend-on-opensource-dashobard-2-6/333301)

<div class="topic-metadata">

**Author:** [@Priyanka\_Rajpal](https://discuss.elastic.co/u/Priyanka_Rajpal)\
**Replies:** 3\
**Last updated:** [May 15, 2023, 6:00am UTC](https://discuss.elastic.co/t/is-there-a-way-to-plot-trend-on-opensource-dashobard-2-6/333301 "2023-05-15T06:00:01Z")

</div>

I am using OpensearchDashboards which is a fork of kibana 7.10.2 opensource, is there a way to get a trend on that?

---

## [Winlogbeat 8.4.3 "Start-Service winlogbeat" error](https://discuss.elastic.co/t/winlogbeat-8-4-3-start-service-winlogbeat-error/331532)

<div class="topic-metadata">

**Author:** [@Banuka\_In\_A\_Shoe](https://discuss.elastic.co/u/Banuka_In_A_Shoe)\
**Replies:** 1\
**Last updated:** [May 15, 2023, 4:13am UTC](https://discuss.elastic.co/t/winlogbeat-8-4-3-start-service-winlogbeat-error/331532 "2023-05-15T04:13:31Z")

</div>

Hello, I'm installing winlogbeat on a windows server 2019 machine. I'm fairly certain the config files are ok as the following commands output a positive response. (Also my file/audit/metrics run fine on Linux) .\\winl…

---

## [Migrating from Hot to Hot-Cold Elastic Cluster using Snapshot and Restore](https://discuss.elastic.co/t/migrating-from-hot-to-hot-cold-elastic-cluster-using-snapshot-and-restore/332886)

<div class="topic-metadata">

**Author:** [@yago82](https://discuss.elastic.co/u/yago82)\
**Replies:** 3\
**Last updated:** [May 14, 2023, 11:40pm UTC](https://discuss.elastic.co/t/migrating-from-hot-to-hot-cold-elastic-cluster-using-snapshot-and-restore/332886 "2023-05-14T23:40:47Z")

</div>

Hi Elastic Community, We're considering migrating from a Elastic cluster (with only Hot nodes) to a hot-cold cluster to optimize performance and reduce hardware costs. Our question is, how will the cluster behave when w…

---

## [Does filebeat support ordered pubsub?](https://discuss.elastic.co/t/does-filebeat-support-ordered-pubsub/332835)

<div class="topic-metadata">

**Author:** [@iFamZ](https://discuss.elastic.co/u/iFamZ)\
**Replies:** 3\
**Last updated:** [May 14, 2023, 11:38pm UTC](https://discuss.elastic.co/t/does-filebeat-support-ordered-pubsub/332835 "2023-05-14T23:38:47Z")

</div>

I am working on a project that sends events (two types - open and closed) to an ordered pubsub (verified that the subscription is ordered with an ordering key). I am then consuming this data from the pubsub into my elast…

---

## [What are alternatives for query string to implement slope between phrases?](https://discuss.elastic.co/t/what-are-alternatives-for-query-string-to-implement-slope-between-phrases/333158)

<div class="topic-metadata">

**Author:** [@Eduard\_mart](https://discuss.elastic.co/u/Eduard_mart)\
**Replies:** 3\
**Last updated:** [May 14, 2023, 11:36pm UTC](https://discuss.elastic.co/t/what-are-alternatives-for-query-string-to-implement-slope-between-phrases/333158 "2023-05-14T23:36:29Z")

</div>

What are alternatives for query string to implement slope between phrases?

---

## [Kibana alert result link seems to be broken](https://discuss.elastic.co/t/kibana-alert-result-link-seems-to-be-broken/333170)

<div class="topic-metadata">

**Author:** [@ASHN](https://discuss.elastic.co/u/ASHN)\
**Replies:** 0\
**Last updated:** [May 11, 2023, 8:51am UTC](https://discuss.elastic.co/t/kibana-alert-result-link-seems-to-be-broken/333170 "2023-05-11T08:51:18Z")

</div>

Kibana version: 8.7.1 Elasticsearch version: 8.7.1 Issue: We were previously using Elastic 8.6.2. The Alert result link (obtained from action variable :{{context.link}}) for Elasticsearch query types used to be shorten…

---

## [About configuring the ELK Stack in centos7 server](https://discuss.elastic.co/t/about-configuring-the-elk-stack-in-centos7-server/333208)

<div class="topic-metadata">

**Author:** [@Anil\_Sai\_Pinnelli](https://discuss.elastic.co/u/Anil_Sai_Pinnelli)\
**Replies:** 1\
**Last updated:** [May 14, 2023, 11:34pm UTC](https://discuss.elastic.co/t/about-configuring-the-elk-stack-in-centos7-server/333208 "2023-05-14T23:34:32Z")

</div>

We are trying to Install ELK Stack in Centos7 server in order to pull the MySql data from the same centos7 server. Could You pls give us in detail instructions how to configure the Elasticsearch, Kibana and Logstash and …

---

## [Virtuel Deshboard](https://discuss.elastic.co/t/virtuel-deshboard/333308)

<div class="topic-metadata">

**Author:** [@Ali\_Trache](https://discuss.elastic.co/u/Ali_Trache)\
**Replies:** 0\
**Last updated:** [May 12, 2023, 1:20pm UTC](https://discuss.elastic.co/t/virtuel-deshboard/333308 "2023-05-12T13:20:03Z")

</div>

hello community, I installed and configured elastic then I configured logstach and I shouted an index afterwards I configured a VMware virtual machine to send and analyzed ESXI logs with Kibana how can I shout a virtual …

---

## [Uptime Monitors](https://discuss.elastic.co/t/uptime-monitors/333320)

<div class="topic-metadata">

**Author:** [@LeonardoCord](https://discuss.elastic.co/u/LeonardoCord)\
**Replies:** 0\
**Last updated:** [May 12, 2023, 3:21pm UTC](https://discuss.elastic.co/t/uptime-monitors/333320 "2023-05-12T15:21:27Z")

</div>

Me esta arrojando este error. Error: Batch request failed with status 503 \</\> at search\_interceptor\_SearchInterceptor.handleSearchError (https://172.16.101.71:5601/59020/bundles/plugin/data/kibana/data.plugin.js:1:38…

---

## [SnakeYAML vulnerability with latest Logstash version](https://discuss.elastic.co/t/snakeyaml-vulnerability-with-latest-logstash-version/333332)

<div class="topic-metadata">

**Author:** [@Nikhil\_Khurana](https://discuss.elastic.co/u/Nikhil_Khurana)\
**Replies:** 1\
**Last updated:** [May 14, 2023, 11:29pm UTC](https://discuss.elastic.co/t/snakeyaml-vulnerability-with-latest-logstash-version/333332 "2023-05-14T23:29:26Z")

</div>

Hi, In the latest version of Logstash, SnakeYAML dependency was bumped to 1.33 but it seems that is vulnerable as well. The vulnerability CVE-2022-1471 is a critical one with score of 9.8. Are there plans to bump it to…

---

## [APM .net response time](https://discuss.elastic.co/t/apm-net-response-time/333343)

<div class="topic-metadata">

**Author:** [@logisfan\_romik](https://discuss.elastic.co/u/logisfan_romik)\
**Replies:** 0\
**Last updated:** [May 13, 2023, 4:27am UTC](https://discuss.elastic.co/t/apm-net-response-time/333343 "2023-05-13T04:27:56Z")

</div>

Hi, Kibana version: 8.2.2 Elasticsearch version: 8 APM Server version: 8 APM Agent language and version: I want to know what the mean for HTTP 2.x.x for long time proccess... how i can trace the issue?

---

## [How to increase output efficiency in logstash to elastic search?](https://discuss.elastic.co/t/how-to-increase-output-efficiency-in-logstash-to-elastic-search/333291)

<div class="topic-metadata">

**Author:** [@Arjav](https://discuss.elastic.co/u/Arjav)\
**Replies:** 3\
**Last updated:** [May 14, 2023, 6:51pm UTC](https://discuss.elastic.co/t/how-to-increase-output-efficiency-in-logstash-to-elastic-search/333291 "2023-05-14T18:51:07Z")

</div>

I have a logstash configuration that has input for postgres database table that has 14 lakh records and an output to elasticsearch database that in setup on ec2 machine c5 x large, when i see documents formation for that…

---

## [Getting An unknown error occurred sending a bulk request to Elasticsearch](https://discuss.elastic.co/t/getting-an-unknown-error-occurred-sending-a-bulk-request-to-elasticsearch/333378)

<div class="topic-metadata">

**Author:** [@Manjiri](https://discuss.elastic.co/u/Manjiri)\
**Replies:** 1\
**Last updated:** [May 14, 2023, 5:33pm UTC](https://discuss.elastic.co/t/getting-an-unknown-error-occurred-sending-a-bulk-request-to-elasticsearch/333378 "2023-05-14T17:33:42Z")

</div>

After Starting the logstash the logs are fetching for 5 mins after that in logstash facing below error : An unknown error occurred sending a bulk request to Elasticsearch (will retry indefinitely) {:message=\> "incompati…

---

## [Prioritized a master node in ES cluster](https://discuss.elastic.co/t/prioritized-a-master-node-in-es-cluster/333350)

<div class="topic-metadata">

**Author:** [@ahmed.emad](https://discuss.elastic.co/u/ahmed.emad)\
**Replies:** 13\
**Last updated:** [May 14, 2023, 2:25pm UTC](https://discuss.elastic.co/t/prioritized-a-master-node-in-es-cluster/333350 "2023-05-14T14:25:22Z")

</div>

Hello, My ES Cluster contains 3 Master nodes (node-1, node-2, node-3), and nodes have a priority (99,98,97) in order so when node-1 goes down it elects node-2 as the new master node this is good till now, but when node-…

---

## [Best practice for data model of geo data - less objects with nested vs. more objects with duplication](https://discuss.elastic.co/t/best-practice-for-data-model-of-geo-data-less-objects-with-nested-vs-more-objects-with-duplication/333376)

<div class="topic-metadata">

**Author:** [@gmmorris](https://discuss.elastic.co/u/gmmorris)\
**Replies:** 0\
**Last updated:** [May 14, 2023, 11:48am UTC](https://discuss.elastic.co/t/best-practice-for-data-model-of-geo-data-less-objects-with-nested-vs-more-objects-with-duplication/333376 "2023-05-14T11:48:47Z")

</div>

Hello, my dear Elasticians, I miss you dearly. :wave: On my new adventure, I encountered a data modelling dilemma and thought I'd ask the experts what they think. We're ingesting large data sets of geospatial data and …

---

## [Configuring the same source container twice](https://discuss.elastic.co/t/configuring-the-same-source-container-twice/333258)

<div class="topic-metadata">

**Author:** [@Mhag](https://discuss.elastic.co/u/Mhag)\
**Replies:** 6\
**Last updated:** [May 13, 2023, 3:58pm UTC](https://discuss.elastic.co/t/configuring-the-same-source-container-twice/333258 "2023-05-13T15:58:15Z")

</div>

Hi, I need to filter events coming from the same source in filebeat level and tag them (filtred not filtred for ex) before sending them to logstash. And I wonder if there is some options to duplicate events (like clone…

---

## [Logstash: Logevent when shutting down but not when starting up](https://discuss.elastic.co/t/logstash-logevent-when-shutting-down-but-not-when-starting-up/333146)

<div class="topic-metadata">

**Author:** [@bitnapper](https://discuss.elastic.co/u/bitnapper)\
**Replies:** 5\
**Last updated:** [May 14, 2023, 10:54am UTC](https://discuss.elastic.co/t/logstash-logevent-when-shutting-down-but-not-when-starting-up/333146 "2023-05-14T10:54:50Z")

</div>

Hi, simple question. Logstash produces a log-event when shutting down but not when starting up. Can I make it do that without activating the whol debug log? Regards

---

## [How to construct geo\_point field from separate fields of latitude and longitude from Kafka?](https://discuss.elastic.co/t/how-to-construct-geo-point-field-from-separate-fields-of-latitude-and-longitude-from-kafka/333370)

<div class="topic-metadata">

**Author:** [@Jagath\_Prasanga](https://discuss.elastic.co/u/Jagath_Prasanga)\
**Replies:** 1\
**Last updated:** [May 14, 2023, 10:29am UTC](https://discuss.elastic.co/t/how-to-construct-geo-point-field-from-separate-fields-of-latitude-and-longitude-from-kafka/333370 "2023-05-14T10:29:17Z")

</div>

How to construct geo\_point field in logstash from Kafka input? This is my logstash config file. But Kibana not recognizing as a geo\_point field. input { kafka { bootstrap\_servers =\> "localhost:9095" top…

---

## [Fleet server does not have a liveness probe, thus it cannot be auto-restarted even if it fails](https://discuss.elastic.co/t/fleet-server-does-not-have-a-liveness-probe-thus-it-cannot-be-auto-restarted-even-if-it-fails/333371)

<div class="topic-metadata">

**Author:** [@fzyzcjy](https://discuss.elastic.co/u/fzyzcjy)\
**Replies:** 0\
**Last updated:** [May 14, 2023, 5:21am UTC](https://discuss.elastic.co/t/fleet-server-does-not-have-a-liveness-probe-thus-it-cannot-be-auto-restarted-even-if-it-fails/333371 "2023-05-14T05:21:43Z")

</div>

Hi thanks for elastic stack! However, Fleet server does not have a liveness probe (when deployed via ECK), thus it cannot be auto-restarted even if it fails.

---

## [Difference duration calculation between start and end time to show in table](https://discuss.elastic.co/t/difference-duration-calculation-between-start-and-end-time-to-show-in-table/330137)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 1\
**Last updated:** [May 14, 2023, 4:34am UTC](https://discuss.elastic.co/t/difference-duration-calculation-between-start-and-end-time-to-show-in-table/330137 "2023-05-14T04:34:03Z")

</div>

Hello All, I'd like to know how can I calculate the duration difference between start execution-end execution(Date format) and only get the duration to show in third column. How can this be done?,backend only provides …

---

## [Could not able to install ELK in windows11](https://discuss.elastic.co/t/could-not-able-to-install-elk-in-windows11/333369)

<div class="topic-metadata">

**Author:** [@priyanka\_g](https://discuss.elastic.co/u/priyanka_g)\
**Replies:** 1\
**Last updated:** [May 14, 2023, 3:47am UTC](https://discuss.elastic.co/t/could-not-able-to-install-elk-in-windows11/333369 "2023-05-14T03:47:52Z")

</div>

Hi Team, As i need to do pattern analysis for log files. i had downloaded Elasticsearch, Kibana and Logstack. But when i gave "elasticsearch.bat" in the command prompt, it is not getting installed properly, instead i…

[Previous page](https://discuss.elastic.co/latest.md?page=677)

[Next page](https://discuss.elastic.co/latest.md?page=679)
