# Latest

**URL:** https://discuss.elastic.co/latest.md?page=695

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 696

---

## [Failed to assign role via role mapping API ldap realm](https://discuss.elastic.co/t/failed-to-assign-role-via-role-mapping-api-ldap-realm/331039)

<div class="topic-metadata">

**Author:** [@GaetanCia](https://discuss.elastic.co/u/GaetanCia)\
**Replies:** 0\
**Last updated:** [April 28, 2023, 9:59am UTC](https://discuss.elastic.co/t/failed-to-assign-role-via-role-mapping-api-ldap-realm/331039 "2023-04-28T09:59:04Z")

</div>

Hi, I have issue to assign a role via the role-mapping setting. I tried to assign a role to a certain group of people who connect from the ldap realm. If i use the native role mapping file, it work fine My role\_mappi…

---

## [2 instances of Filebeat on same Linux server output to same ES](https://discuss.elastic.co/t/2-instances-of-filebeat-on-same-linux-server-output-to-same-es/331010)

<div class="topic-metadata">

**Author:** [@hjazz6](https://discuss.elastic.co/u/hjazz6)\
**Replies:** 3\
**Last updated:** [April 28, 2023, 9:15am UTC](https://discuss.elastic.co/t/2-instances-of-filebeat-on-same-linux-server-output-to-same-es/331010 "2023-04-28T09:15:09Z")

</div>

Hi, I have a Linux server running Filebeat 8.3.3 taking Netflow as input and writing it out to ES on another server. As the Netflow load is much more than what Filebeat can handle, I'm thinking of splitting the Netflow …

---

## [Elasticsearch how do I properly monitor performance? Is there a good tool? is there a free alternative to datadog?](https://discuss.elastic.co/t/elasticsearch-how-do-i-properly-monitor-performance-is-there-a-good-tool-is-there-a-free-alternative-to-datadog/331028)

<div class="topic-metadata">

**Author:** [@Eduard\_mart](https://discuss.elastic.co/u/Eduard_mart)\
**Replies:** 1\
**Last updated:** [April 28, 2023, 8:28am UTC](https://discuss.elastic.co/t/elasticsearch-how-do-i-properly-monitor-performance-is-there-a-good-tool-is-there-a-free-alternative-to-datadog/331028 "2023-04-28T08:28:14Z")

</div>

Elasticsearch how do I properly monitor performance? Is there a good tool? is there a free alternative to datadog?

---

## [ILM policy created and applied but it's not deleting the data](https://discuss.elastic.co/t/ilm-policy-created-and-applied-but-its-not-deleting-the-data/330727)

<div class="topic-metadata">

**Author:** [@elasticlog](https://discuss.elastic.co/u/elasticlog)\
**Replies:** 4\
**Last updated:** [April 28, 2023, 8:27am UTC](https://discuss.elastic.co/t/ilm-policy-created-and-applied-but-its-not-deleting-the-data/330727 "2023-04-28T08:27:45Z")

</div>

Hello Experts, I have created the ILM policy and applied to the index . but still it is not deleting the old file. is there anythin i miss or need to add. Please guide me. PUT \_ilm/policy/delete-old-indices { "policy…

---

## [How do I check why my search query takes too long? Is there something like Explain command in SQL databases?](https://discuss.elastic.co/t/how-do-i-check-why-my-search-query-takes-too-long-is-there-something-like-explain-command-in-sql-databases/331029)

<div class="topic-metadata">

**Author:** [@Eduard\_mart](https://discuss.elastic.co/u/Eduard_mart)\
**Replies:** 1\
**Last updated:** [April 28, 2023, 8:26am UTC](https://discuss.elastic.co/t/how-do-i-check-why-my-search-query-takes-too-long-is-there-something-like-explain-command-in-sql-databases/331029 "2023-04-28T08:26:05Z")

</div>

How do I check why my search query takes too long? Is there something like Explain command in SQL databases?

---

## [Error updating Security Data View](https://discuss.elastic.co/t/error-updating-security-data-view/331027)

<div class="topic-metadata">

**Author:** [@TheMadmax](https://discuss.elastic.co/u/TheMadmax)\
**Replies:** 0\
**Last updated:** [April 28, 2023, 8:17am UTC](https://discuss.elastic.co/t/error-updating-security-data-view/331027 "2023-04-28T08:17:08Z")

</div>

I am facing an error on my kibana: Error updating Security Data View { "name": "AbortError", "body": null, "message": "The operation was aborted. ", "stack": "o@https://kibana.xxxxxx:5403/59020/bundles/kbn-ui-sh…

---

## [Globla Time Filter for Lens Visualisation](https://discuss.elastic.co/t/globla-time-filter-for-lens-visualisation/330881)

<div class="topic-metadata">

**Author:** [@deepack86](https://discuss.elastic.co/u/deepack86)\
**Replies:** 2\
**Last updated:** [April 28, 2023, 8:13am UTC](https://discuss.elastic.co/t/globla-time-filter-for-lens-visualisation/330881 "2023-04-28T08:13:15Z")

</div>

Hi! I want to make a canvas pad with much lens visualisation. There is globaltimefilter to set the date an time for all lens. If i set a date and time the lens visualtion doesn't scale the time axis The code for the …

---

## [Search after example in java8](https://discuss.elastic.co/t/search-after-example-in-java8/330969)

<div class="topic-metadata">

**Author:** [@suresh\_chaudhari](https://discuss.elastic.co/u/suresh_chaudhari)\
**Replies:** 2\
**Last updated:** [April 28, 2023, 8:07am UTC](https://discuss.elastic.co/t/search-after-example-in-java8/330969 "2023-04-28T08:07:34Z")

</div>

I cant follow example mentioned in rest api documentation.Elastic java client is really tough to understand. Can some one share how to use searchafter api with java tutorial. There is some sort field we need to share w…

---

## [Question around setting proper ds / index / ilm](https://discuss.elastic.co/t/question-around-setting-proper-ds-index-ilm/330709)

<div class="topic-metadata">

**Author:** [@alexsamad](https://discuss.elastic.co/u/alexsamad)\
**Replies:** 6\
**Last updated:** [April 28, 2023, 7:04am UTC](https://discuss.elastic.co/t/question-around-setting-proper-ds-index-ilm/330709 "2023-04-28T07:04:14Z")

</div>

Hi new to ES, i have 12 node cluster and its purpose is to capture all of the logs from apps in our 14 env - lets call them dev1-14. each env has 6 apps server and 2 rp and 2 geodes and jmp box - so 11 servers. on the a…

---

## [Logstash is not showing base64 encoded data for pdf's extracted from urls](https://discuss.elastic.co/t/logstash-is-not-showing-base64-encoded-data-for-pdfs-extracted-from-urls/330386)

<div class="topic-metadata">

**Author:** [@Disha\_Bodade](https://discuss.elastic.co/u/Disha_Bodade)\
**Replies:** 5\
**Last updated:** [April 28, 2023, 6:58am UTC](https://discuss.elastic.co/t/logstash-is-not-showing-base64-encoded-data-for-pdfs-extracted-from-urls/330386 "2023-04-28T06:58:36Z")

</div>

Hi Team, I am using logstash http filter to get pdf from url and extract it. http filter has downloaded pdf and extracted its content on target\_field. But the contents are not proper and also its not base64 encoded. Ho…

---

## [How to create new array by using existing list of strings field in logstash ruby filter](https://discuss.elastic.co/t/how-to-create-new-array-by-using-existing-list-of-strings-field-in-logstash-ruby-filter/330761)

<div class="topic-metadata">

**Author:** [@Disha\_Bodade](https://discuss.elastic.co/u/Disha_Bodade)\
**Replies:** 2\
**Last updated:** [April 28, 2023, 4:57am UTC](https://discuss.elastic.co/t/how-to-create-new-array-by-using-existing-list-of-strings-field-in-logstash-ruby-filter/330761 "2023-04-28T04:57:00Z")

</div>

Hi Team, I have three arrays created from xml in logstash content.REFERENCE: \[PXXXX, TECHNICAL\_SUPPORT\] content.ROOT: \[INTERNAL\_PRODUCT\_OR\_APPLICATION, TOPICS\] I have to create a result array from above inputs if roo…

---

## [Customize APM agent to monitor whichever application I want](https://discuss.elastic.co/t/customize-apm-agent-to-monitor-whichever-application-i-want/330999)

<div class="topic-metadata">

**Author:** [@JasonREC](https://discuss.elastic.co/u/JasonREC)\
**Replies:** 0\
**Last updated:** [April 28, 2023, 3:42am UTC](https://discuss.elastic.co/t/customize-apm-agent-to-monitor-whichever-application-i-want/330999 "2023-04-28T03:42:53Z")

</div>

Hi all, I currenly have a server that runs 3 PHP application, and when I installed the PHP elastic agent extension without changing my PHP source code, its already automatically montiored all of my PHP app and sent the …

---

## [Elastic machine learning - question about Anomaly Explorer](https://discuss.elastic.co/t/elastic-machine-learning-question-about-anomaly-explorer/330780)

<div class="topic-metadata">

**Author:** [@JasonREC](https://discuss.elastic.co/u/JasonREC)\
**Replies:** 2\
**Last updated:** [April 28, 2023, 3:14am UTC](https://discuss.elastic.co/t/elastic-machine-learning-question-about-anomaly-explorer/330780 "2023-04-28T03:14:03Z")

</div>

Hi, I am new to Elastic machine learning. I input some data about users access a product API endpoint, and I have set up 2 influncers, which are the user name and product brand name. I make one user enormously to acces…

---

## [Empty alerts in Palo Alto Cortex XDR Integration](https://discuss.elastic.co/t/empty-alerts-in-palo-alto-cortex-xdr-integration/330997)

<div class="topic-metadata">

**Author:** [@dhsmf](https://discuss.elastic.co/u/dhsmf)\
**Replies:** 0\
**Last updated:** [April 28, 2023, 2:05am UTC](https://discuss.elastic.co/t/empty-alerts-in-palo-alto-cortex-xdr-integration/330997 "2023-04-28T02:05:56Z")

</div>

I'm planning to use Palo Alto Cortex XDR Integration to ingest alerts for our analyses. It looks that the Integration often brings almost empty alerts (without file hash, process info and so on, showing reply: 0). Is it …

---

## [Service names](https://discuss.elastic.co/t/service-names/329265)

<div class="topic-metadata">

**Author:** [@rsk0](https://discuss.elastic.co/u/rsk0)\
**Replies:** 1\
**Last updated:** [April 27, 2023, 11:21pm UTC](https://discuss.elastic.co/t/service-names/329265 "2023-04-27T23:21:13Z")

</div>

Howdy, ECS developers and ontology fans, I have some thoughts and questions: In the service.\* field set I feel there are two distinct “naming” purposes I want to achieve. I want a unique identifier I can use to collat…

---

## [Can't install Elastic Agent on MacOS Ventura (13.3.1) - Symlink](https://discuss.elastic.co/t/cant-install-elastic-agent-on-macos-ventura-13-3-1-symlink/330665)

<div class="topic-metadata">

**Author:** [@maof97](https://discuss.elastic.co/u/maof97)\
**Replies:** 6\
**Last updated:** [April 27, 2023, 9:44pm UTC](https://discuss.elastic.co/t/cant-install-elastic-agent-on-macos-ventura-13-3-1-symlink/330665 "2023-04-27T21:44:29Z")

</div>

Hey guys, I can't install elastic agent on my new MacBook running MacOS Ventura 13.3.1. Installing I get the following message: martin@Martins-MacBook-Pro-14 elastic-agent-8.7.0-darwin-aarch64 % sudo ./elastic-agent in…

---

## [Failed installing file:///tmp/analysis-phonetic-7.17.7.zip](https://discuss.elastic.co/t/failed-installing-file-tmp-analysis-phonetic-7-17-7-zip/330988)

<div class="topic-metadata">

**Author:** [@markedperf](https://discuss.elastic.co/u/markedperf)\
**Replies:** 0\
**Last updated:** [April 27, 2023, 9:39pm UTC](https://discuss.elastic.co/t/failed-installing-file-tmp-analysis-phonetic-7-17-7-zip/330988 "2023-04-27T21:39:54Z")

</div>

I am trying to install the analysis-phonetic plugin from a downloaded .zip file. I have copied the files to the local filesystem /tmp directory and inside the container to the /tmp directory. Below is the dockerfile th…

---

## [Definition of plugin "runtimeFields" not found and may have failed to load](https://discuss.elastic.co/t/definition-of-plugin-runtimefields-not-found-and-may-have-failed-to-load/330556)

<div class="topic-metadata">

**Author:** [@Alfredo\_Casanova](https://discuss.elastic.co/u/Alfredo_Casanova)\
**Replies:** 2\
**Last updated:** [April 27, 2023, 7:17pm UTC](https://discuss.elastic.co/t/definition-of-plugin-runtimefields-not-found-and-may-have-failed-to-load/330556 "2023-04-27T19:17:34Z")

</div>

Hi. I just had to reboot my box and now when i submit my password in kibana i'm getting this message. my log file says not about it. Obviously i've tried "clearing my session" as suggested but it did't work.

---

## [Take\_over option not working - logs being reharvested after filebeat restart](https://discuss.elastic.co/t/take-over-option-not-working-logs-being-reharvested-after-filebeat-restart/330983)

<div class="topic-metadata">

**Author:** [@ian.springer-sf](https://discuss.elastic.co/u/ian.springer-sf)\
**Replies:** 5\
**Last updated:** [April 27, 2023, 6:45pm UTC](https://discuss.elastic.co/t/take-over-option-not-working-logs-being-reharvested-after-filebeat-restart/330983 "2023-04-27T18:45:35Z")

</div>

I followed the migration guide to migrate my log inputs to filestream inputs, including adding a unique id and setting the "take\_over" option to true. However, upon restarting the filebeat service, all of the logs are re…

---

## [Upscaling Elastic Cloud Instance using Azure CLI](https://discuss.elastic.co/t/upscaling-elastic-cloud-instance-using-azure-cli/330947)

<div class="topic-metadata">

**Author:** [@Jacob\_Concrete](https://discuss.elastic.co/u/Jacob_Concrete)\
**Replies:** 1\
**Last updated:** [April 27, 2023, 6:40pm UTC](https://discuss.elastic.co/t/upscaling-elastic-cloud-instance-using-azure-cli/330947 "2023-04-27T18:40:38Z")

</div>

Hello, I am trying to automate a process of Elastic installation on Azure. One of the steps is to upscale Elasticsearch from 2 zone 240GB storage 8GB RAM to 3 zone 870 GB Storage 29GB RAM after the deployment is created…

---

## [Watcher - trying to print all document hits from search results](https://discuss.elastic.co/t/watcher-trying-to-print-all-document-hits-from-search-results/330978)

<div class="topic-metadata">

**Author:** [@vee](https://discuss.elastic.co/u/vee)\
**Replies:** 1\
**Last updated:** [April 27, 2023, 6:16pm UTC](https://discuss.elastic.co/t/watcher-trying-to-print-all-document-hits-from-search-results/330978 "2023-04-27T18:16:38Z")

</div>

Hi, trying to create a watcher to just print all hits on the message field which matches a particular string. All I was able to get to is print individual hits by using this pattern in the actions to send email: Message…

---

## [Logstash on windows sends data directly to the security onion SOC, not elasticsearch on windows?](https://discuss.elastic.co/t/logstash-on-windows-sends-data-directly-to-the-security-onion-soc-not-elasticsearch-on-windows/330985)

<div class="topic-metadata">

**Author:** [@iqworks](https://discuss.elastic.co/u/iqworks)\
**Replies:** 0\
**Last updated:** [April 27, 2023, 6:09pm UTC](https://discuss.elastic.co/t/logstash-on-windows-sends-data-directly-to-the-security-onion-soc-not-elasticsearch-on-windows/330985 "2023-04-27T18:09:06Z")

</div>

Hi, I am still learning about the sysmon data going to security onion. It seems that using elasticsearch on windows handles only windows data and does not send the data to security onion kibana. You can download kibana…

---

## [Filebeat Module Postgresql](https://discuss.elastic.co/t/filebeat-module-postgresql/330860)

<div class="topic-metadata">

**Author:** [@Giancarlo\_Huapaya\_Ra](https://discuss.elastic.co/u/Giancarlo_Huapaya_Ra)\
**Replies:** 8\
**Last updated:** [April 27, 2023, 5:04pm UTC](https://discuss.elastic.co/t/filebeat-module-postgresql/330860 "2023-04-27T17:04:25Z")

</div>

Hello everyone, Please I need your help, I have problems with the Postgresql module filbeat, at the time of viewing the log I see that I get the following error message: \[2023-04-26 09:20:02.534 -05 \[2828024\] u\_sistema…

---

## [Elastic metric count to percentage](https://discuss.elastic.co/t/elastic-metric-count-to-percentage/330806)

<div class="topic-metadata">

**Author:** [@Prathamesh\_S\_Pai](https://discuss.elastic.co/u/Prathamesh_S_Pai)\
**Replies:** 3\
**Last updated:** [April 27, 2023, 5:01pm UTC](https://discuss.elastic.co/t/elastic-metric-count-to-percentage/330806 "2023-04-27T17:01:04Z")

</div>

I am using metric visualization type in kibana. In Metric section, I have used 'count' aggregation and in bucket section, i have used 'terms' aggregation with field 'executionStatus.keyword' and clicked on 'update' butt…

---

## [Handling ambiguous field names in search query](https://discuss.elastic.co/t/handling-ambiguous-field-names-in-search-query/329941)

<div class="topic-metadata">

**Author:** [@denvaar](https://discuss.elastic.co/u/denvaar)\
**Replies:** 1\
**Last updated:** [April 27, 2023, 4:59pm UTC](https://discuss.elastic.co/t/handling-ambiguous-field-names-in-search-query/329941 "2023-04-27T16:59:25Z")

</div>

I have a query that I run against multiple indices. Some of the indices being searched share some common field names, and I'm not sure what the best way to differentiate between them would be. I can get the desired resu…

---

## [Export Users Data Traffic](https://discuss.elastic.co/t/export-users-data-traffic/330937)

<div class="topic-metadata">

**Author:** [@Mursel](https://discuss.elastic.co/u/Mursel)\
**Replies:** 1\
**Last updated:** [April 27, 2023, 4:58pm UTC](https://discuss.elastic.co/t/export-users-data-traffic/330937 "2023-04-27T16:58:47Z")

</div>

Hello everyone. I want to export all users' Traffic Data. How can I do ?

---

## [Custom Charting](https://discuss.elastic.co/t/custom-charting/330968)

<div class="topic-metadata">

**Author:** [@dawiro](https://discuss.elastic.co/u/dawiro)\
**Replies:** 1\
**Last updated:** [April 27, 2023, 4:57pm UTC](https://discuss.elastic.co/t/custom-charting/330968 "2023-04-27T16:57:55Z")

</div>

Hi, Is it possible to create a chart which shows data for today overlaid against the same data from yesterday in order to compare patterns and volumes? Thx D

---

## [Discovery.seed\_hosts and cluster.initial\_master\_nodes](https://discuss.elastic.co/t/discovery-seed-hosts-and-cluster-initial-master-nodes/330945)

<div class="topic-metadata">

**Author:** [@mikewillis](https://discuss.elastic.co/u/mikewillis)\
**Replies:** 2\
**Last updated:** [April 27, 2023, 4:43pm UTC](https://discuss.elastic.co/t/discovery-seed-hosts-and-cluster-initial-master-nodes/330945 "2023-04-27T16:43:40Z")

</div>

I'm struggling to understand the discovery settings now that discovery.zen.minimum\_master\_nodes has gone away. (where current is 8.7) says that discovery.seed\_hosts Provides a list of the addresses of the master-el…

---

## [Kibana Embedding URL](https://discuss.elastic.co/t/kibana-embedding-url/330876)

<div class="topic-metadata">

**Author:** [@Venkatesh\_Guruprasad](https://discuss.elastic.co/u/Venkatesh_Guruprasad)\
**Replies:** 1\
**Last updated:** [April 27, 2023, 4:25pm UTC](https://discuss.elastic.co/t/kibana-embedding-url/330876 "2023-04-27T16:25:17Z")

</div>

We are using Elastic Cloud currently. We are enabling embedded URL's of Kibana dashboards in our app. We want to just show the filters applied panel in the embedded URL. This is the scenario where users apply a filter on…

---

## [\[NEW\] Openshift 4 - Fleet and Elastic Agent permission denied](https://discuss.elastic.co/t/new-openshift-4-fleet-and-elastic-agent-permission-denied/330841)

<div class="topic-metadata">

**Author:** [@demon86rm](https://discuss.elastic.co/u/demon86rm)\
**Replies:** 2\
**Last updated:** [April 27, 2023, 3:56pm UTC](https://discuss.elastic.co/t/new-openshift-4-fleet-and-elastic-agent-permission-denied/330841 "2023-04-27T15:56:32Z")

</div>

Hi, I'd like to reopen the old post from splitmessage88 as I'm facing the exact same issue while trying to configure an Elastic Agent on an ARO cluster. I've followed all the existing instructions for deploy the ECK ope…

[Previous page](https://discuss.elastic.co/latest.md?page=694)

[Next page](https://discuss.elastic.co/latest.md?page=696)
