# Latest

**URL:** https://discuss.elastic.co/latest.md?page=679

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 680

---

## [Kibana in a Docker container](https://discuss.elastic.co/t/kibana-in-a-docker-container/333295)

<div class="topic-metadata">

**Author:** [@GrigoryPtashko](https://discuss.elastic.co/u/GrigoryPtashko)\
**Replies:** 1\
**Last updated:** [May 13, 2023, 5:04pm UTC](https://discuss.elastic.co/t/kibana-in-a-docker-container/333295 "2023-05-13T17:04:51Z")

</div>

Hello. I'm setting up the ELK stack in Docker containers. Elasticsearch, Kibana, Filebeats, Logstash all in their own containers. One thing I cannot understand is whether I have to make a persistent volume for Kibana? F…

---

## [SentinelOne integration GeoIP database error](https://discuss.elastic.co/t/sentinelone-integration-geoip-database-error/333262)

<div class="topic-metadata">

**Author:** [@Anton\_H](https://discuss.elastic.co/u/Anton_H)\
**Replies:** 2\
**Last updated:** [May 13, 2023, 2:34pm UTC](https://discuss.elastic.co/t/sentinelone-integration-geoip-database-error/333262 "2023-05-13T14:34:44Z")

</div>

Hello, We use the SentinelOne integration through fleet in our Elastic Cloud environment. Events are being received and processed. The issue is we get "\_geoip\_database\_unavailable\_GeoLite2-City.mmdb" errors on all age…

---

## [Integration Ingest pipeline not executed when logstash ouptut is activated for Agent Policy (Fleet)](https://discuss.elastic.co/t/integration-ingest-pipeline-not-executed-when-logstash-ouptut-is-activated-for-agent-policy-fleet/332936)

<div class="topic-metadata">

**Author:** [@mehdi-lamrani](https://discuss.elastic.co/u/mehdi-lamrani)\
**Replies:** 3\
**Last updated:** [May 13, 2023, 1:12pm UTC](https://discuss.elastic.co/t/integration-ingest-pipeline-not-executed-when-logstash-ouptut-is-activated-for-agent-policy-fleet/332936 "2023-05-13T13:12:27Z")

</div>

8.7 here For some obscure reason, when I add a pipeline to an integration via Custom configurations (lower red rectangle in first screen below), it is not triggered when the policy integration output is set to logstash…

---

## [Logstash Limits](https://discuss.elastic.co/t/logstash-limits/331353)

<div class="topic-metadata">

**Author:** [@shushuu](https://discuss.elastic.co/u/shushuu)\
**Replies:** 4\
**Last updated:** [May 13, 2023, 12:32pm UTC](https://discuss.elastic.co/t/logstash-limits/331353 "2023-05-13T12:32:13Z")

</div>

Hi, We would like to use Logstash to receive log messages from multiple services (nxlog) and send them further to Elastic. i.e. using this architecture - but with nxlog instead of Beats: What are the limits of a si…

---

## [Custom Sample data - same sata reoccuring every week](https://discuss.elastic.co/t/custom-sample-data-same-sata-reoccuring-every-week/333348)

<div class="topic-metadata">

**Author:** [@Rnx](https://discuss.elastic.co/u/Rnx)\
**Replies:** 0\
**Last updated:** [May 13, 2023, 12:27pm UTC](https://discuss.elastic.co/t/custom-sample-data-same-sata-reoccuring-every-week/333348 "2023-05-13T12:27:51Z")

</div>

How to achieve a configuration in an Elasticsearch/Kibana, which will handle my custom sample data to be shown as reoccurring for, lets say, every week? Just like the essential "Kibana Sample Data" - these are clearly li…

---

## [Unique Doc related to one \`field\`](https://discuss.elastic.co/t/unique-doc-related-to-one-field/333344)

<div class="topic-metadata">

**Author:** [@\_zogaj](https://discuss.elastic.co/u/_zogaj)\
**Replies:** 0\
**Last updated:** [May 13, 2023, 6:02am UTC](https://discuss.elastic.co/t/unique-doc-related-to-one-field/333344 "2023-05-13T06:02:38Z")

</div>

Hey, I am using pagination and i want to filter duplicated doc related to one field. For the moment i am trying it with Collapse functionality to filter duplicated and with Cardinality aggregation to get the total unique…

---

## [Increase heap size of Elastic Cluster in dev tools](https://discuss.elastic.co/t/increase-heap-size-of-elastic-cluster-in-dev-tools/333165)

<div class="topic-metadata">

**Author:** [@Sandeep\_Raju](https://discuss.elastic.co/u/Sandeep_Raju)\
**Replies:** 1\
**Last updated:** [May 13, 2023, 4:56am UTC](https://discuss.elastic.co/t/increase-heap-size-of-elastic-cluster-in-dev-tools/333165 "2023-05-13T04:56:25Z")

</div>

Hi all, I'm trying to increase Elastic RAM alloted to Elastic. I know i have to change -Xmx=1G -Xms=1G in jvm options file. But I have access only to elastic and kibana. Is there a way to increase in dev tools or a…

---

## [Run ELK with docker compose](https://discuss.elastic.co/t/run-elk-with-docker-compose/332969)

<div class="topic-metadata">

**Author:** [@Fatiha](https://discuss.elastic.co/u/Fatiha)\
**Replies:** 7\
**Last updated:** [May 12, 2023, 11:29pm UTC](https://discuss.elastic.co/t/run-elk-with-docker-compose/332969 "2023-05-12T23:29:56Z")

</div>

Hi everyone I want to run the ELK 8.7.0 using docker compose I create the docker-compose.yml file with this configuration : version: '3' services: mysql: container\_name: mysql hostname: mysql image: 'm…

---

## [Automation adding the password for basic security step #2 in Elasticsearch 7](https://discuss.elastic.co/t/automation-adding-the-password-for-basic-security-step-2-in-elasticsearch-7/333335)

<div class="topic-metadata">

**Author:** [@Chuck\_Reynolds](https://discuss.elastic.co/u/Chuck_Reynolds)\
**Replies:** 5\
**Last updated:** [May 12, 2023, 8:05pm UTC](https://discuss.elastic.co/t/automation-adding-the-password-for-basic-security-step-2-in-elasticsearch-7/333335 "2023-05-12T20:05:31Z")

</div>

How can I automate step 2 and pass a password to the following 2 commands? ./bin/elasticsearch-keystore add xpack.security.transport.ssl.keystore.secure\_password. ./bin/elasticsearch-keystore add xpack.security.transpo…

---

## [Suricata Logs Not Received by Elastic Cloud](https://discuss.elastic.co/t/suricata-logs-not-received-by-elastic-cloud/333334)

<div class="topic-metadata">

**Author:** [@Tim\_Mobley](https://discuss.elastic.co/u/Tim_Mobley)\
**Replies:** 0\
**Last updated:** [May 12, 2023, 6:19pm UTC](https://discuss.elastic.co/t/suricata-logs-not-received-by-elastic-cloud/333334 "2023-05-12T18:19:11Z")

</div>

I have set up both the 'Windows' and 'Suricata' integrations, using the same Agent Policy. Both integrations are showing that my client machine is connected. On the client, I have installed the Elastic Agent, however onl…

---

## [Tema integration message formatting for alert](https://discuss.elastic.co/t/tema-integration-message-formatting-for-alert/333321)

<div class="topic-metadata">

**Author:** [@Gaston\_Beltramelli](https://discuss.elastic.co/u/Gaston_Beltramelli)\
**Replies:** 1\
**Last updated:** [May 12, 2023, 6:04pm UTC](https://discuss.elastic.co/t/tema-integration-message-formatting-for-alert/333321 "2023-05-12T18:04:06Z")

</div>

Hello everyone! I need help for formatting an alert to TEAMS integration, i've been trying to add a new line in the message but i couldn´t find much info about t in kibana i set up this Alerta para {{context.group}} {…

---

## [Aggregations count vs hits count](https://discuss.elastic.co/t/aggregations-count-vs-hits-count/332648)

<div class="topic-metadata">

**Author:** [@NNI](https://discuss.elastic.co/u/NNI)\
**Replies:** 3\
**Last updated:** [May 12, 2023, 5:01pm UTC](https://discuss.elastic.co/t/aggregations-count-vs-hits-count/332648 "2023-05-12T17:01:11Z")

</div>

Hi I would like to concern on aggregations count for explain in more details But for the sake of presenting the case a little background : I have cluster contains with 3 master nodes, 3 ingest nodes, 3 data nodes so t…

---

## [Show which tokens were not found in full text search](https://discuss.elastic.co/t/show-which-tokens-were-not-found-in-full-text-search/333331)

<div class="topic-metadata">

**Author:** [@kadermetov](https://discuss.elastic.co/u/kadermetov)\
**Replies:** 0\
**Last updated:** [May 12, 2023, 4:48pm UTC](https://discuss.elastic.co/t/show-which-tokens-were-not-found-in-full-text-search/333331 "2023-05-12T16:48:34Z")

</div>

Hello, beautiful community! Is there a way to determine which words (tokens) in a phrase was or wasn't found during full text search. I need it to make something like Google does: Under each query result it shows wh…

---

## [An error occurred during rule execution: message: "Parse Error: Header overflow"](https://discuss.elastic.co/t/an-error-occurred-during-rule-execution-message-parse-error-header-overflow/330017)

<div class="topic-metadata">

**Author:** [@kmz161](https://discuss.elastic.co/u/kmz161)\
**Replies:** 1\
**Last updated:** [May 12, 2023, 4:23pm UTC](https://discuss.elastic.co/t/an-error-occurred-during-rule-execution-message-parse-error-header-overflow/330017 "2023-05-12T16:23:03Z")

</div>

Hello! I have problem with Security Rules. This issue only affects the Threshold rules How can I fix issue? P.S. Elastic 7.17

---

## [Elastic prebuilt rules not executed](https://discuss.elastic.co/t/elastic-prebuilt-rules-not-executed/330816)

<div class="topic-metadata">

**Author:** [@amatol1515](https://discuss.elastic.co/u/amatol1515)\
**Replies:** 1\
**Last updated:** [May 12, 2023, 4:03pm UTC](https://discuss.elastic.co/t/elastic-prebuilt-rules-not-executed/330816 "2023-05-12T16:03:55Z")

</div>

Hi Some of prebuilt rules not executed e.q. Execution result screen But when I duplicate this rules it works Execution results of Duplicated rule

---

## [About ELK STack](https://discuss.elastic.co/t/about-elk-stack/333296)

<div class="topic-metadata">

**Author:** [@Anil\_Sai\_Pinnelli](https://discuss.elastic.co/u/Anil_Sai_Pinnelli)\
**Replies:** 1\
**Last updated:** [May 12, 2023, 3:54pm UTC](https://discuss.elastic.co/t/about-elk-stack/333296 "2023-05-12T15:54:55Z")

</div>

Commands to link Mysql DB to elasticsearch using logstash. I am having one configuration file but, it did'nt worked for me!! input { jdbc { jdbc\_driver\_library =\> "/root/mysql-connector-java-5.1.30-bin.jar" jdbc\_dri…

---

## [After add xpack.security.enabled,my kibana does not work](https://discuss.elastic.co/t/after-add-xpack-security-enabled-my-kibana-does-not-work/333253)

<div class="topic-metadata">

**Author:** [@Dadaguai](https://discuss.elastic.co/u/Dadaguai)\
**Replies:** 8\
**Last updated:** [May 12, 2023, 1:48pm UTC](https://discuss.elastic.co/t/after-add-xpack-security-enabled-my-kibana-does-not-work/333253 "2023-05-12T13:48:22Z")

</div>

my elasticsearch.yml as follows: http.host: 0.0.0.0 http.cors.enabled: true http.cors.allow-origin: "\*" network.host: 172.17.0.9 discovery.type: single-node http.port: 9200 action.auto\_create\_index: true http.cors.allow…

---

## [Verify internode communication is using TLS](https://discuss.elastic.co/t/verify-internode-communication-is-using-tls/332975)

<div class="topic-metadata">

**Author:** [@mikewillis](https://discuss.elastic.co/u/mikewillis)\
**Replies:** 5\
**Last updated:** [May 12, 2023, 2:51pm UTC](https://discuss.elastic.co/t/verify-internode-communication-is-using-tls/332975 "2023-05-12T14:51:18Z")

</div>

Having set up TLS for internode communication per is there a way to confirm that is is being used? E.g. is there something specific that gets written to the log during start up when it's in use, or is there something t…

---

## [How to determine the bottleneck between Filebeat and ES?](https://discuss.elastic.co/t/how-to-determine-the-bottleneck-between-filebeat-and-es/333272)

<div class="topic-metadata">

**Author:** [@hjazz6](https://discuss.elastic.co/u/hjazz6)\
**Replies:** 2\
**Last updated:** [May 12, 2023, 2:48pm UTC](https://discuss.elastic.co/t/how-to-determine-the-bottleneck-between-filebeat-and-es/333272 "2023-05-12T14:48:01Z")

</div>

Hi, I'm trying to determine the bottleneck for my Netflow setup, to see if I can further optimize the performance. I am ingesting Netflow traffic into a Linux server running both filebeat and elasticsearch 7.1.4. I'm u…

---

## [Upgrade Elastic and Kibana from 7.17 to 8.7 - S](https://discuss.elastic.co/t/upgrade-elastic-and-kibana-from-7-17-to-8-7-s/333036)

<div class="topic-metadata">

**Author:** [@charlot\_Attard](https://discuss.elastic.co/u/charlot_Attard)\
**Replies:** 6\
**Last updated:** [May 12, 2023, 2:32pm UTC](https://discuss.elastic.co/t/upgrade-elastic-and-kibana-from-7-17-to-8-7-s/333036 "2023-05-12T14:32:53Z")

</div>

Hello, We are in the process of migrating our Elasticsearch and Kibana from 7.17 to 8.7. We are facing an issue where after upgrading Elasticsearch works out fine but when starting Kibana we are seeing these errors. "A…

---

## [CSV Response Data Format from SQL Rest API](https://discuss.elastic.co/t/csv-response-data-format-from-sql-rest-api/333224)

<div class="topic-metadata">

**Author:** [@Akaash\_Mukherjee](https://discuss.elastic.co/u/Akaash_Mukherjee)\
**Replies:** 2\
**Last updated:** [May 12, 2023, 2:20pm UTC](https://discuss.elastic.co/t/csv-response-data-format-from-sql-rest-api/333224 "2023-05-12T14:20:12Z")

</div>

Hi, I was told in a previous post: that Elasticsearch cannot return csv as response data: Then I found this: I've been trying to play around with it, but must admit I'm a little lost. I have a Kibana query that lo…

---

## [ScrollID is coming as null](https://discuss.elastic.co/t/scrollid-is-coming-as-null/330938)

<div class="topic-metadata">

**Author:** [@suresh\_chaudhari](https://discuss.elastic.co/u/suresh_chaudhari)\
**Replies:** 5\
**Last updated:** [May 12, 2023, 1:47pm UTC](https://discuss.elastic.co/t/scrollid-is-coming-as-null/330938 "2023-05-12T13:47:59Z")

</div>

I am using elastic8. with java client. I first used elasticclient.search() request this returned scrollId then i used same scrollID to call client.scroll(scrollID) api however the first call elasticclient.search() i…

---

## [Multithreading in Kafka input plugin for Filebeat](https://discuss.elastic.co/t/multithreading-in-kafka-input-plugin-for-filebeat/333309)

<div class="topic-metadata">

**Author:** [@Hichem](https://discuss.elastic.co/u/Hichem)\
**Replies:** 0\
**Last updated:** [May 12, 2023, 1:33pm UTC](https://discuss.elastic.co/t/multithreading-in-kafka-input-plugin-for-filebeat/333309 "2023-05-12T13:33:11Z")

</div>

I'm using the Filebeat Kafka input plugin to consume data from Kafka and send it to Elastic. I noticed Filebeat starts 1 consumer thread only. Is there a way to increase the number of consumers? I tried changing the ma…

---

## [3 Node Elasticsearch cluster is failing repeatedly with error: this node is unhealthy: health check failed due to broken node lock](https://discuss.elastic.co/t/3-node-elasticsearch-cluster-is-failing-repeatedly-with-error-this-node-is-unhealthy-health-check-failed-due-to-broken-node-lock/333234)

<div class="topic-metadata">

**Author:** [@akansha.agarwal1](https://discuss.elastic.co/u/akansha.agarwal1)\
**Replies:** 3\
**Last updated:** [May 12, 2023, 1:17pm UTC](https://discuss.elastic.co/t/3-node-elasticsearch-cluster-is-failing-repeatedly-with-error-this-node-is-unhealthy-health-check-failed-due-to-broken-node-lock/333234 "2023-05-12T13:17:16Z")

</div>

Hi All, I am stuck in a very weird situation. My 3-node ES cluster is failing after 8-10 days abruptly with error: \[WARN \]\[o.e.c.c.ClusterFormationFailureHelper\] \[elasticsearch-0.es-service\] this node is unhealthy: he…

---

## [Create a new index when document has a particular field?](https://discuss.elastic.co/t/create-a-new-index-when-document-has-a-particular-field/333307)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 1\
**Last updated:** [May 12, 2023, 1:06pm UTC](https://discuss.elastic.co/t/create-a-new-index-when-document-has-a-particular-field/333307 "2023-05-12T13:06:15Z")

</div>

Is it possible to create a new index everytime my document has a particular field updated? say all docs with 'tenant':"100" are part of one index and if a document comes with a field "tenant":101, a new index is created…

---

## [Index Thread Pools](https://discuss.elastic.co/t/index-thread-pools/333302)

<div class="topic-metadata">

**Author:** [@Mohit\_Munjal](https://discuss.elastic.co/u/Mohit_Munjal)\
**Replies:** 1\
**Last updated:** [May 12, 2023, 12:54pm UTC](https://discuss.elastic.co/t/index-thread-pools/333302 "2023-05-12T12:54:34Z")

</div>

My objective is to calculate how many index requests can a elasticsearch cluster hold in it's queue before starting rejecting it. My elasticsearch cluster(v6.8) has 8 data nodes of r5.xlarge instance i.e. 4 vCPU's. In …

---

## [How many resources should I have per data?](https://discuss.elastic.co/t/how-many-resources-should-i-have-per-data/333305)

<div class="topic-metadata">

**Author:** [@SamuelSMendes](https://discuss.elastic.co/u/SamuelSMendes)\
**Replies:** 0\
**Last updated:** [May 12, 2023, 12:59pm UTC](https://discuss.elastic.co/t/how-many-resources-should-i-have-per-data/333305 "2023-05-12T12:59:47Z")

</div>

My team has changed from On Premisse into the Cloud and as we are now centralizing all of our content into the same place I would like to estimate the resource power we need to escalate per GB generated a day (or maybe t…

---

## [Invalid NEST response built from a successful (404) low level call on GET:](https://discuss.elastic.co/t/invalid-nest-response-built-from-a-successful-404-low-level-call-on-get/333044)

<div class="topic-metadata">

**Author:** [@LhamoDev](https://discuss.elastic.co/u/LhamoDev)\
**Replies:** 6\
**Last updated:** [May 12, 2023, 12:23pm UTC](https://discuss.elastic.co/t/invalid-nest-response-built-from-a-successful-404-low-level-call-on-get/333044 "2023-05-12T12:23:28Z")

</div>

Hello I'm doing a Get Request in my code: var response = await Repository.ElasticClient.GetAsync\<Reservation\>(maskId).ConfigureAwait(false); And I'm getting this as a response: Invalid NEST response built from a succ…

---

## [Using Contains string or "wildcard" in filter button](https://discuss.elastic.co/t/using-contains-string-or-wildcard-in-filter-button/333247)

<div class="topic-metadata">

**Author:** [@Sandeep\_Raju](https://discuss.elastic.co/u/Sandeep_Raju)\
**Replies:** 1\
**Last updated:** [May 12, 2023, 11:28am UTC](https://discuss.elastic.co/t/using-contains-string-or-wildcard-in-filter-button/333247 "2023-05-12T11:28:25Z")

</div>

Hi all, I'm trying to use "wildcard" option in filter as shown below i.e location.keyword : \*PASO\* show me any string that contains PASO string anywhere in the word. I know I can use in KQL in search bar or DSL quer…

---

## [ILM leaves empty shards of 225bytes](https://discuss.elastic.co/t/ilm-leaves-empty-shards-of-225bytes/333252)

<div class="topic-metadata">

**Author:** [@Lin\_Yu](https://discuss.elastic.co/u/Lin_Yu)\
**Replies:** 1\
**Last updated:** [May 12, 2023, 11:27am UTC](https://discuss.elastic.co/t/ilm-leaves-empty-shards-of-225bytes/333252 "2023-05-12T11:27:52Z")

</div>

Hello, I'm using elastcisearch v8.5 and filebeat. My question is : How could i solve 0 bytes shard keep rolling over? How to delete 0bytes shards? How to set up ILM correctly? This is the configuration of filebeat.y…

[Previous page](https://discuss.elastic.co/latest.md?page=678)

[Next page](https://discuss.elastic.co/latest.md?page=680)
