# Latest

**URL:** https://discuss.elastic.co/latest.md?page=696

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 697

---

## [How to color a header in table lens](https://discuss.elastic.co/t/how-to-color-a-header-in-table-lens/330851)

<div class="topic-metadata">

**Author:** [@fatousouleymane.mben](https://discuss.elastic.co/u/fatousouleymane.mben)\
**Replies:** 3\
**Last updated:** [April 27, 2023, 3:36pm UTC](https://discuss.elastic.co/t/how-to-color-a-header-in-table-lens/330851 "2023-04-27T15:36:43Z")

</div>

how to color a header in table lens

---

## [Kibana not updating index in Discover](https://discuss.elastic.co/t/kibana-not-updating-index-in-discover/330885)

<div class="topic-metadata">

**Author:** [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Replies:** 11\
**Last updated:** [April 27, 2023, 3:30pm UTC](https://discuss.elastic.co/t/kibana-not-updating-index-in-discover/330885 "2023-04-27T15:30:19Z")

</div>

Hi All, I see this issue where Kibana is not updating index on the "Discover" page while there is a definite increase in the size of the related index. Also for some reason Discover page shows data with one hour interva…

---

## [Return JSON Array of Arrays from elastic](https://discuss.elastic.co/t/return-json-array-of-arrays-from-elastic/330971)

<div class="topic-metadata">

**Author:** [@Akaash\_Mukherjee](https://discuss.elastic.co/u/Akaash_Mukherjee)\
**Replies:** 4\
**Last updated:** [April 27, 2023, 3:23pm UTC](https://discuss.elastic.co/t/return-json-array-of-arrays-from-elastic/330971 "2023-04-27T15:23:10Z")

</div>

Hi, We've noticed that the overhead of the JSON object structure is creating some performance problems for us. One of the largest parts of this overhead is the repetitiveness of the object properties in each object. We'…

---

## [Protobuf data decode issue](https://discuss.elastic.co/t/protobuf-data-decode-issue/330976)

<div class="topic-metadata">

**Author:** [@Nithingowda](https://discuss.elastic.co/u/Nithingowda)\
**Replies:** 0\
**Last updated:** [April 27, 2023, 3:21pm UTC](https://discuss.elastic.co/t/protobuf-data-decode-issue/330976 "2023-04-27T15:21:12Z")

</div>

Here is the code to read the protobuf data from pubsub and decode in logstash but we are unable to decode the protobuf data. Code: input { google\_pubsub { project\_id =\> "project\_id" topic =\> "topic…

---

## [Can logstash.yml can be reloaded?](https://discuss.elastic.co/t/can-logstash-yml-can-be-reloaded/330942)

<div class="topic-metadata">

**Author:** [@prashant1](https://discuss.elastic.co/u/prashant1)\
**Replies:** 2\
**Last updated:** [April 27, 2023, 2:42pm UTC](https://discuss.elastic.co/t/can-logstash-yml-can-be-reloaded/330942 "2023-04-27T14:42:34Z")

</div>

We have deployed logstash in kubernetes platform. For one usecase we want to update queue.page\_capacity: 64mb to 1mb. So if we update these changes it can't be reloaded until restart. So is there any way so that this ca…

---

## [Logstash startup error-) Could not load FFI Provider: (NotImplementedError) FFI not available](https://discuss.elastic.co/t/logstash-startup-error-could-not-load-ffi-provider-notimplementederror-ffi-not-available/330904)

<div class="topic-metadata">

**Author:** [@karthic](https://discuss.elastic.co/u/karthic)\
**Replies:** 1\
**Last updated:** [April 27, 2023, 2:40pm UTC](https://discuss.elastic.co/t/logstash-startup-error-could-not-load-ffi-provider-notimplementederror-ffi-not-available/330904 "2023-04-27T14:40:32Z")

</div>

Tried to load logstash in a Centos environment \[INFO \]\[logstash.runner \] JVM bootstrap flags: \[-Xms1g, -Xmx1g, -Djava.awt.headless=true, -Dfile.encoding=UTF-8, -Djruby.compile.invokedynamic=true, -XX:+HeapDumpO…

---

## [Collect logs from multiple machine, what needs to be installed?](https://discuss.elastic.co/t/collect-logs-from-multiple-machine-what-needs-to-be-installed/330833)

<div class="topic-metadata">

**Author:** [@Jay\_Timbadia](https://discuss.elastic.co/u/Jay_Timbadia)\
**Replies:** 5\
**Last updated:** [April 27, 2023, 1:53pm UTC](https://discuss.elastic.co/t/collect-logs-from-multiple-machine-what-needs-to-be-installed/330833 "2023-04-27T13:53:56Z")

</div>

Continuing the discussion from How to collect the logs from multiple machines to my server efficiently?: Hi @jsoriano, really followed the chat. Just one thing, I have logs placed in different machine, so should I insta…

---

## [ESET Protect Cloud logs](https://discuss.elastic.co/t/eset-protect-cloud-logs/330925)

<div class="topic-metadata">

**Author:** [@rodmontgt](https://discuss.elastic.co/u/rodmontgt)\
**Replies:** 2\
**Last updated:** [April 27, 2023, 1:50pm UTC](https://discuss.elastic.co/t/eset-protect-cloud-logs/330925 "2023-04-27T13:50:24Z")

</div>

Hi everyone, I've been playing around with logtash for days but still have not found a solution for this, my ESET console is configured to send syslog/BSD logs but I am getting this odd character set in my logstash inst…

---

## [Failed to start Logstash - S3 output plugin is not working](https://discuss.elastic.co/t/failed-to-start-logstash-s3-output-plugin-is-not-working/330096)

<div class="topic-metadata">

**Author:** [@WonhyeongCho](https://discuss.elastic.co/u/WonhyeongCho)\
**Replies:** 4\
**Last updated:** [April 27, 2023, 1:46pm UTC](https://discuss.elastic.co/t/failed-to-start-logstash-s3-output-plugin-is-not-working/330096 "2023-04-27T13:46:17Z")

</div>

Hi. I'm using Logstash. I recently upgraded Logstash to version 8.7.0, but it's not working. I'm getting an error message. Failed to execute action {:action=\>LogStash::PipelineAction::Create/pipeline\_id:OSQUERY, :excep…

---

## [Observability Engineer 7.9 - Lab 5.4 unable to get petclinic-react to appear](https://discuss.elastic.co/t/observability-engineer-7-9-lab-5-4-unable-to-get-petclinic-react-to-appear/328661)

<div class="topic-metadata">

**Author:** [@deccman](https://discuss.elastic.co/u/deccman)\
**Replies:** 11\
**Last updated:** [April 27, 2023, 1:23pm UTC](https://discuss.elastic.co/t/observability-engineer-7-9-lab-5-4-unable-to-get-petclinic-react-to-appear/328661 "2023-04-27T13:23:37Z")

</div>

Course: Elastic Observability Engineer Version: 7.9 Question: I have not been successful with getting petclinic-react to appear in the list of Services in APM. I can get the other three services to appear fine in APM…

---

## [Enterprise Search not working](https://discuss.elastic.co/t/enterprise-search-not-working/330691)

<div class="topic-metadata">

**Author:** [@neil.maffitt](https://discuss.elastic.co/u/neil.maffitt)\
**Replies:** 3\
**Last updated:** [April 27, 2023, 12:56pm UTC](https://discuss.elastic.co/t/enterprise-search-not-working/330691 "2023-04-27T12:56:58Z")

</div>

I have Elastic Search 8.6.2 working and can log into kibana web UI 8.6.2 but I can't get Enterprise Search 8.6.2 to work. Seeing this in the app-server.log it make mention of localhost:5601 which I coming from kibana b…

---

## [File input plugin is treating the line as plain string eventhough the input is json](https://discuss.elastic.co/t/file-input-plugin-is-treating-the-line-as-plain-string-eventhough-the-input-is-json/330713)

<div class="topic-metadata">

**Author:** [@djrshn2346](https://discuss.elastic.co/u/djrshn2346)\
**Replies:** 10\
**Last updated:** [April 27, 2023, 12:48pm UTC](https://discuss.elastic.co/t/file-input-plugin-is-treating-the-line-as-plain-string-eventhough-the-input-is-json/330713 "2023-04-27T12:48:22Z")

</div>

File input plugin is treating the line as plain string eventhough the input is json. Output in Opensearch is : { "\_index" : "sample-logs-2023.04.24", "\_type" : "\_doc", "\_id" : "ui9PsocBICgSyzdw…

---

## [Network scan](https://discuss.elastic.co/t/network-scan/330717)

<div class="topic-metadata">

**Author:** [@TheMadmax](https://discuss.elastic.co/u/TheMadmax)\
**Replies:** 2\
**Last updated:** [April 27, 2023, 12:39pm UTC](https://discuss.elastic.co/t/network-scan/330717 "2023-04-27T12:39:30Z")

</div>

Hello, I try to create a rule to detect a network scan. For example, generate an alert if more than 10 unique destinations have been accessed from the same source IP within 1 minute. but I don't see how to indicate …

---

## [Kibana too many docvalue\_fields issue](https://discuss.elastic.co/t/kibana-too-many-docvalue-fields-issue/329981)

<div class="topic-metadata">

**Author:** [@Prakash111](https://discuss.elastic.co/u/Prakash111)\
**Replies:** 2\
**Last updated:** [April 27, 2023, 11:36am UTC](https://discuss.elastic.co/t/kibana-too-many-docvalue-fields-issue/329981 "2023-04-27T11:36:05Z")

</div>

I'm getting too many docvalue\_fields error in Kibana. PUT /index\_name\_log-\*/\_settings { "index.max\_docvalue\_fields\_search" : "10000000" } by this way we can increase limit, but can I know which log line causing this…

---

## [Cannot deploy ECK 2.7.0 with PSP](https://discuss.elastic.co/t/cannot-deploy-eck-2-7-0-with-psp/330743)

<div class="topic-metadata">

**Author:** [@sebastianboelling](https://discuss.elastic.co/u/sebastianboelling)\
**Replies:** 3\
**Last updated:** [April 27, 2023, 11:09am UTC](https://discuss.elastic.co/t/cannot-deploy-eck-2-7-0-with-psp/330743 "2023-04-27T11:09:33Z")

</div>

Hi, I tried to deploy ECK 2.7.0 on my Tanzu Kubernetes environment and get the following error message: Warning Failed 5m6s (x2 over 5m7s) kubelet Error: container has runAsNonRoot and image will run a…

---

## [Bucket Selector Aggregation to eliminate null buckets](https://discuss.elastic.co/t/bucket-selector-aggregation-to-eliminate-null-buckets/330943)

<div class="topic-metadata">

**Author:** [@Silver137](https://discuss.elastic.co/u/Silver137)\
**Replies:** 0\
**Last updated:** [April 27, 2023, 10:58am UTC](https://discuss.elastic.co/t/bucket-selector-aggregation-to-eliminate-null-buckets/330943 "2023-04-27T10:58:29Z")

</div>

I'm trying to use the Bucket Selector aggregation to eliminate Null values from other pipeline aggregations without success First Try of null checking: "bucket\_filter": { "bucket\_selector": { "buc…

---

## [ElasticSearch 8.7 initial single node setting fails](https://discuss.elastic.co/t/elasticsearch-8-7-initial-single-node-setting-fails/330870)

<div class="topic-metadata">

**Author:** [@Pfiffikus](https://discuss.elastic.co/u/Pfiffikus)\
**Replies:** 2\
**Last updated:** [April 27, 2023, 7:22am UTC](https://discuss.elastic.co/t/elasticsearch-8-7-initial-single-node-setting-fails/330870 "2023-04-27T07:22:09Z")

</div>

I get elasticsearch-create-enrollment-token -s kibana ERROR: Failed to determine the health of the cluster. Unexpected http status \[401\] for xpack: security: authc: realms: file: file1: …

---

## [Extracting Detection Rule](https://discuss.elastic.co/t/extracting-detection-rule/330549)

<div class="topic-metadata">

**Author:** [@Aliz6](https://discuss.elastic.co/u/Aliz6)\
**Replies:** 1\
**Last updated:** [April 27, 2023, 10:49am UTC](https://discuss.elastic.co/t/extracting-detection-rule/330549 "2023-04-27T10:49:20Z")

</div>

Hi there, I was wondering if there is a way to extract all of the detection use cases (built-in and custom) in an excel sheet rather a json format file. Any suggestions would be helpful. Thanks.

---

## [Execute a script inside a core application added by a plugin](https://discuss.elastic.co/t/execute-a-script-inside-a-core-application-added-by-a-plugin/330755)

<div class="topic-metadata">

**Author:** [@LucasE](https://discuss.elastic.co/u/LucasE)\
**Replies:** 1\
**Last updated:** [April 27, 2023, 9:58am UTC](https://discuss.elastic.co/t/execute-a-script-inside-a-core-application-added-by-a-plugin/330755 "2023-04-27T09:58:29Z")

</div>

Hello everyone, I'm using Kibana v8.3.3 and i'm trying to modify the DOM of my dashboard. For this I tried to use a chrome extension and it worked but I want to explore another option. I tried creating a SPA and embed…

---

## [Domain gets resolved to IP before cert verification](https://discuss.elastic.co/t/domain-gets-resolved-to-ip-before-cert-verification/330935)

<div class="topic-metadata">

**Author:** [@Octelly](https://discuss.elastic.co/u/Octelly)\
**Replies:** 0\
**Last updated:** [April 27, 2023, 9:52am UTC](https://discuss.elastic.co/t/domain-gets-resolved-to-ip-before-cert-verification/330935 "2023-04-27T09:52:31Z")

</div>

I have a Step-CA instance from which I obtain certificates through lego's CLI. The CA is trusted on all nodes system-wide and the certificates are generated for their domains. Elasticsearch is configured to use these dom…

---

## [Updating Custom HTTP ingestion results in a 504 error](https://discuss.elastic.co/t/updating-custom-http-ingestion-results-in-a-504-error/330879)

<div class="topic-metadata">

**Author:** [@chenderson](https://discuss.elastic.co/u/chenderson)\
**Replies:** 1\
**Last updated:** [April 27, 2023, 9:46am UTC](https://discuss.elastic.co/t/updating-custom-http-ingestion-results-in-a-504-error/330879 "2023-04-27T09:46:27Z")

</div>

I have added an integration to my stack running in Azure Kubernetes using the "Custom HTTP" integration. When I first create the integration everything works as expected and documents are ingested when I send them to th…

---

## [Using Sort API via Elastic.Clients.Elasticsearch 8.1.0 .NET](https://discuss.elastic.co/t/using-sort-api-via-elastic-clients-elasticsearch-8-1-0-net/330908)

<div class="topic-metadata">

**Author:** [@felix-stnr](https://discuss.elastic.co/u/felix-stnr)\
**Replies:** 2\
**Last updated:** [April 27, 2023, 9:37am UTC](https://discuss.elastic.co/t/using-sort-api-via-elastic-clients-elasticsearch-8-1-0-net/330908 "2023-04-27T09:37:32Z")

</div>

I have an Elasticsearch cluster, which contains an index called persons. I want to query and sort the documents of the index using the latest Elasticsearch client for .NET (Elastic.Clients.Elasticsearch 8.1.0 .NET). The …

---

## [Knn to show results for 'Other Locations you may like'](https://discuss.elastic.co/t/knn-to-show-results-for-other-locations-you-may-like/330933)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 0\
**Last updated:** [April 27, 2023, 9:29am UTC](https://discuss.elastic.co/t/knn-to-show-results-for-other-locations-you-may-like/330933 "2023-04-27T09:29:40Z")

</div>

I want to create Proximity Search/Reccomendation with Location data. so my search results should have results - 'Other Locations you may like'. My data has Geo ID and Pincode for Location data. I was thinking of creati…

---

## [Best practice for running Elastic Agents in EKS](https://discuss.elastic.co/t/best-practice-for-running-elastic-agents-in-eks/330931)

<div class="topic-metadata">

**Author:** [@mikkoc](https://discuss.elastic.co/u/mikkoc)\
**Replies:** 0\
**Last updated:** [April 27, 2023, 9:16am UTC](https://discuss.elastic.co/t/best-practice-for-running-elastic-agents-in-eks/330931 "2023-04-27T09:16:11Z")

</div>

Hello, We run Elastic Agents via Fleet in our EKS cluster, as DaemonSet, with about 20 nodes. We want to monitor and collect AWS Cloudwatch metrics, in addition to Kubernetes logs on each node. How do we go about inst…

---

## [How to parse API HTTP output data](https://discuss.elastic.co/t/how-to-parse-api-http-output-data/330829)

<div class="topic-metadata">

**Author:** [@sonirajil](https://discuss.elastic.co/u/sonirajil)\
**Replies:** 2\
**Last updated:** [April 27, 2023, 9:00am UTC](https://discuss.elastic.co/t/how-to-parse-api-http-output-data/330829 "2023-04-27T09:00:03Z")

</div>

Hello Team, I am running an API to get servicestatus data which looks like : { "recordcount": 11906, "servicestatus": \[ { "host\_name": "unixteam.abc.com", "service\_description": …

---

## [Retrieve the value of ca\_trusted\_fingerprint](https://discuss.elastic.co/t/retrieve-the-value-of-ca-trusted-fingerprint/330923)

<div class="topic-metadata">

**Author:** [@Jaud](https://discuss.elastic.co/u/Jaud)\
**Replies:** 0\
**Last updated:** [April 27, 2023, 8:43am UTC](https://discuss.elastic.co/t/retrieve-the-value-of-ca-trusted-fingerprint/330923 "2023-04-27T08:43:06Z")

</div>

Hello here. I was trying to configure my kibana and I've deleted the ca\_trusted\_fingerprint value. I searched online for any solution but I founded nothing. Do you know where can I found this value? Thank for reading …

---

## [Elasticsearch.Net.UnexpectedElasticsearchClientException: expected:'{', actual:'\[', at offset:13520](https://discuss.elastic.co/t/elasticsearch-net-unexpectedelasticsearchclientexception-expected-actual-at-offset-13520/330290)

<div class="topic-metadata">

**Author:** [@LhamoDev](https://discuss.elastic.co/u/LhamoDev)\
**Replies:** 6\
**Last updated:** [April 27, 2023, 8:23am UTC](https://discuss.elastic.co/t/elasticsearch-net-unexpectedelasticsearchclientexception-expected-actual-at-offset-13520/330290 "2023-04-27T08:23:08Z")

</div>

Hello I am updating a project to a the new NEST version: 7.17 But keep getting this error from the logging: Elasticsearch.Net.UnexpectedElasticsearchClientException: expected:'{', actual:'\[', at offset:13520 ---\> Elas…

---

## [Wrong documents' count after inserting](https://discuss.elastic.co/t/wrong-documents-count-after-inserting/330284)

<div class="topic-metadata">

**Author:** [@Gregory\_Kovalchuk](https://discuss.elastic.co/u/Gregory_Kovalchuk)\
**Replies:** 4\
**Last updated:** [April 27, 2023, 8:07am UTC](https://discuss.elastic.co/t/wrong-documents-count-after-inserting/330284 "2023-04-27T08:07:51Z")

</div>

Hello, please help, I inserted data with spark several times but the count was all the time bigger than expected, how it can be? The version of ES is 8.5.0. The query that I used to check: GET index/\_count.

---

## [Help on instrumenting AppDynamics Java Agent into Elasticsearch](https://discuss.elastic.co/t/help-on-instrumenting-appdynamics-java-agent-into-elasticsearch/330836)

<div class="topic-metadata">

**Author:** [@marcosrossem](https://discuss.elastic.co/u/marcosrossem)\
**Replies:** 1\
**Last updated:** [April 27, 2023, 8:00am UTC](https://discuss.elastic.co/t/help-on-instrumenting-appdynamics-java-agent-into-elasticsearch/330836 "2023-04-27T08:00:38Z")

</div>

Hi everyone! Currently we are trying to instrument the Java agent of AppDynamics in a Elasticsearch running on Kubernetes. We had a few access denied errors when the Appdynamics agent tried to monitor Elasticsearch, bu…

---

## ["sync" command in Transform API](https://discuss.elastic.co/t/sync-command-in-transform-api/328960)

<div class="topic-metadata">

**Author:** [@SEUNGHYO](https://discuss.elastic.co/u/SEUNGHYO)\
**Replies:** 6\
**Last updated:** [April 27, 2023, 7:52am UTC](https://discuss.elastic.co/t/sync-command-in-transform-api/328960 "2023-04-27T07:52:28Z")

</div>

When a new document is indexed I want to implement a transform instance in which the transform index (dest) is updated every period of "frequency". This is the query I executed. PUT \_transform/test\_transform\_instance …

[Previous page](https://discuss.elastic.co/latest.md?page=695)

[Next page](https://discuss.elastic.co/latest.md?page=697)
