# Latest

**URL:** https://discuss.elastic.co/latest.md?page=701

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 702

---

## [How can i elasticsearch 2.4.6 jdbc client jar file?](https://discuss.elastic.co/t/how-can-i-elasticsearch-2-4-6-jdbc-client-jar-file/330594)

<div class="topic-metadata">

**Author:** [@a89541457](https://discuss.elastic.co/u/a89541457)\
**Replies:** 2\
**Last updated:** [April 24, 2023, 5:02am UTC](https://discuss.elastic.co/t/how-can-i-elasticsearch-2-4-6-jdbc-client-jar-file/330594 "2023-04-24T05:02:31Z")

</div>

there is no ES 2.4.6 jdbc client jar file... i want to connect elasticsearch 2.4.6 via datagrip. but i fail with this message "This version of the JDBC driver is only compatible with Elasticsearch version 7.10 or new…

---

## [Is Garbage Collection monitoring still needed in ES 6.8](https://discuss.elastic.co/t/is-garbage-collection-monitoring-still-needed-in-es-6-8/330582)

<div class="topic-metadata">

**Author:** [@Praveen\_Banthia](https://discuss.elastic.co/u/Praveen_Banthia)\
**Replies:** 6\
**Last updated:** [April 24, 2023, 5:16am UTC](https://discuss.elastic.co/t/is-garbage-collection-monitoring-still-needed-in-es-6-8/330582 "2023-04-24T05:16:18Z")

</div>

I was reading an old article We are on ES version 6.8 and Java 11 or higher . Is this checking for garbage collection metrics even needed anymore. My assumption G1 GC is fast enough that even with max recommended si…

---

## [Question about DNS in a "regular" network](https://discuss.elastic.co/t/question-about-dns-in-a-regular-network/330596)

<div class="topic-metadata">

**Author:** [@GKre](https://discuss.elastic.co/u/GKre)\
**Replies:** 0\
**Last updated:** [April 24, 2023, 4:49am UTC](https://discuss.elastic.co/t/question-about-dns-in-a-regular-network/330596 "2023-04-24T04:49:58Z")

</div>

Hello, after collecting a lot of data from my firewall i wonder about the "structure" of the data in my network. What i found out in the past - there's more than 50 % of the overall traffic caused by DNS. My sonicwall…

---

## [Filter message log in logstash](https://discuss.elastic.co/t/filter-message-log-in-logstash/330524)

<div class="topic-metadata">

**Author:** [@kibana\_dev\_iko](https://discuss.elastic.co/u/kibana_dev_iko)\
**Replies:** 1\
**Last updated:** [April 24, 2023, 2:37am UTC](https://discuss.elastic.co/t/filter-message-log-in-logstash/330524 "2023-04-24T02:37:04Z")

</div>

i want to add filter to logstash to convert message to json format this is my example API response \< HTTP 200 - body: {"result": \[{"status": {"code": -18, "message": "No permission for the resource"}, "url": "/os/hi"}\]…

---

## [Reporting Diagnostics tool fails on capture screenshot](https://discuss.elastic.co/t/reporting-diagnostics-tool-fails-on-capture-screenshot/330080)

<div class="topic-metadata">

**Author:** [@sblack](https://discuss.elastic.co/u/sblack)\
**Replies:** 1\
**Last updated:** [April 23, 2023, 10:59pm UTC](https://discuss.elastic.co/t/reporting-diagnostics-tool-fails-on-capture-screenshot/330080 "2023-04-23T22:59:32Z")

</div>

I ran the Reporting Diagnostics tool and after sometime, the following error is displayed: Something isn't working properly. There was a problem running the diagnostic: Error For additional debugging information, I …

---

## [What aggrigation should I use to achieve this](https://discuss.elastic.co/t/what-aggrigation-should-i-use-to-achieve-this/330206)

<div class="topic-metadata">

**Author:** [@Bishnu\_Sahu](https://discuss.elastic.co/u/Bishnu_Sahu)\
**Replies:** 0\
**Last updated:** [April 18, 2023, 9:14am UTC](https://discuss.elastic.co/t/what-aggrigation-should-i-use-to-achieve-this/330206 "2023-04-18T09:14:45Z")

</div>

Here my index mapping:- { "settings": { "number\_of\_shards": 1 }, "mappings": { "properties": { "timestamp": { "type": "date" }, "leadId": { "type": "keyword" }, …

---

## [Error of ELK stack memory overflow on Windows Server 2012](https://discuss.elastic.co/t/error-of-elk-stack-memory-overflow-on-windows-server-2012/330518)

<div class="topic-metadata">

**Author:** [@DuanTran](https://discuss.elastic.co/u/DuanTran)\
**Replies:** 1\
**Last updated:** [April 23, 2023, 10:38pm UTC](https://discuss.elastic.co/t/error-of-elk-stack-memory-overflow-on-windows-server-2012/330518 "2023-04-23T22:38:11Z")

</div>

I am happy to meet everyone. I am currently in great need of help from Elastic experts. When using ELK on Windows Server 2012, the OpenJVM processes of Elasticsearch and Logstash occupy up to 80% of the system. I have be…

---

## [Kibana cannot connect to the Elastic Package Registry, which provides Elastic Agent integrations](https://discuss.elastic.co/t/kibana-cannot-connect-to-the-elastic-package-registry-which-provides-elastic-agent-integrations/330580)

<div class="topic-metadata">

**Author:** [@mehdi-lamrani](https://discuss.elastic.co/u/mehdi-lamrani)\
**Replies:** 0\
**Last updated:** [April 23, 2023, 1:21pm UTC](https://discuss.elastic.co/t/kibana-cannot-connect-to-the-elastic-package-registry-which-provides-elastic-agent-integrations/330580 "2023-04-23T13:21:01Z")

</div>

There are a few posts noting this error message, without a solution. In case somebody stumbles upon it : This message may be very misleading, in case you did not activate xpack security First, check your service logs…

---

## [Not able to see index log file in elastic search](https://discuss.elastic.co/t/not-able-to-see-index-log-file-in-elastic-search/330571)

<div class="topic-metadata">

**Author:** [@sks](https://discuss.elastic.co/u/sks)\
**Replies:** 1\
**Last updated:** [April 23, 2023, 8:06pm UTC](https://discuss.elastic.co/t/not-able-to-see-index-log-file-in-elastic-search/330571 "2023-04-23T20:06:46Z")

</div>

I am sending this log file web\_access.log 54.36.149.41 - - \[22/Jan/2019:03:56:14 +0330\] "GET /filter/27|13%20%D9%85%DA%AF%D8%A7%D9%BE%DB%8C%DA%A9%D8%B3%D9%84,27|%DA%A9%D9%85%D8%AA%D8%B1%20%D8%A7%D8%B2%205%20%D9%85%DA%A…

---

## [Logstash is not able to connect to workplace search](https://discuss.elastic.co/t/logstash-is-not-able-to-connect-to-workplace-search/330585)

<div class="topic-metadata">

**Author:** [@Disha\_Bodade](https://discuss.elastic.co/u/Disha_Bodade)\
**Replies:** 0\
**Last updated:** [April 23, 2023, 5:27pm UTC](https://discuss.elastic.co/t/logstash-is-not-able-to-connect-to-workplace-search/330585 "2023-04-23T17:27:44Z")

</div>

Hi Team, I have added workplace search as a output plugin. output { elastic\_workplace\_search { source =\> "6555639ee4f75566c32f4298" access\_token =\> "efzq36opkajivo13judz65n9" url =\> "https://153.1.16.10:3…

---

## [Failed to start kibana.service - Kibana](https://discuss.elastic.co/t/failed-to-start-kibana-service-kibana/329630)

<div class="topic-metadata">

**Author:** [@Afif\_Haziq](https://discuss.elastic.co/u/Afif_Haziq)\
**Replies:** 4\
**Last updated:** [April 23, 2023, 5:14pm UTC](https://discuss.elastic.co/t/failed-to-start-kibana-service-kibana/329630 "2023-04-23T17:14:41Z")

</div>

Hi, im newbie so im not quite sure what im currently doing. few hours ago ive configured the kibana server. after i reopened the kali purple in my virtualbox the kibana server failed to start and i dont know what and how…

---

## [Handle Json file](https://discuss.elastic.co/t/handle-json-file/330562)

<div class="topic-metadata">

**Author:** [@Ashraf123](https://discuss.elastic.co/u/Ashraf123)\
**Replies:** 2\
**Last updated:** [April 23, 2023, 3:35pm UTC](https://discuss.elastic.co/t/handle-json-file/330562 "2023-04-23T15:35:54Z")

</div>

Hello All, I have the following Json file collected by logstash. The problem I'm facing is with Item ID as it add json nested object with for each item. The problem I can't build dashboards for these items with this str…

---

## [Need help adding Fleet server](https://discuss.elastic.co/t/need-help-adding-fleet-server/330565)

<div class="topic-metadata">

**Author:** [@Tanner\_Sutherlin](https://discuss.elastic.co/u/Tanner_Sutherlin)\
**Replies:** 18\
**Last updated:** [April 23, 2023, 2:52pm UTC](https://discuss.elastic.co/t/need-help-adding-fleet-server/330565 "2023-04-23T14:52:11Z")

</div>

I've installed the fleet server on my virtual Ubuntu version 22 machine but I can't get the fleet server to show in Kibana. I checked Ubuntu elastic-agent service and it was showing inactive so I started it with "systemc…

---

## [ES nodes fail to ping with ports open and Telnet'able](https://discuss.elastic.co/t/es-nodes-fail-to-ping-with-ports-open-and-telnetable/330581)

<div class="topic-metadata">

**Author:** [@111238](https://discuss.elastic.co/u/111238)\
**Replies:** 4\
**Last updated:** [April 23, 2023, 2:25pm UTC](https://discuss.elastic.co/t/es-nodes-fail-to-ping-with-ports-open-and-telnetable/330581 "2023-04-23T14:25:11Z")

</div>

Hi there! Weirdly, still did not find a solution to a problem. I'm creating a new cluster right now (v6.8.6). And all nodes only see themselves. All of them set up to be master and have discovery.zen.minimum\_master\_no…

---

## [Elasticsearch cluster planning/sizing](https://discuss.elastic.co/t/elasticsearch-cluster-planning-sizing/330579)

<div class="topic-metadata">

**Author:** [@bentzy](https://discuss.elastic.co/u/bentzy)\
**Replies:** 1\
**Last updated:** [April 23, 2023, 1:49pm UTC](https://discuss.elastic.co/t/elasticsearch-cluster-planning-sizing/330579 "2023-04-23T13:49:32Z")

</div>

I want to deploy Elasticsearch with ECK to enable search in a large production GitLab Cluster. I read that Elasticsearch cluster size should be 0.5 of the total of all repos(0.5 \* 2TB). I ask about the ES cluster plannin…

---

## [Random fields in "Available fields" in Kibana discover](https://discuss.elastic.co/t/random-fields-in-available-fields-in-kibana-discover/330498)

<div class="topic-metadata">

**Author:** [@rkelastic](https://discuss.elastic.co/u/rkelastic)\
**Replies:** 2\
**Last updated:** [April 23, 2023, 12:16pm UTC](https://discuss.elastic.co/t/random-fields-in-available-fields-in-kibana-discover/330498 "2023-04-23T12:16:40Z")

</div>

I am using a filebeat instance to read data from azure blob storage and see the visualisation in kibana. In Discover tab in kibana, under the "Available fields" section, it is showing list of fields which are not there …

---

## [Kibana tries to connect to 169.254.169.254:80](https://discuss.elastic.co/t/kibana-tries-to-connect-to-169-254-169-254-80/327353)

<div class="topic-metadata">

**Author:** [@nisow95612](https://discuss.elastic.co/u/nisow95612)\
**Replies:** 19\
**Last updated:** [April 23, 2023, 7:43am UTC](https://discuss.elastic.co/t/kibana-tries-to-connect-to-169-254-169-254-80/327353 "2023-04-23T07:43:51Z")

</div>

Hello elastic community, any idea why Kibana tries to connect to 169.254.169.254:80 for first 5-6 minutes after I start it? I noticed this with version 7.17.9, but I think it was like this at least for all 7.17.X versi…

---

## [How to implement data stream splitting for multiple types in Logstash's Java plugin?](https://discuss.elastic.co/t/how-to-implement-data-stream-splitting-for-multiple-types-in-logstashs-java-plugin/330569)

<div class="topic-metadata">

**Author:** [@woxinfeishi](https://discuss.elastic.co/u/woxinfeishi)\
**Replies:** 0\
**Last updated:** [April 23, 2023, 2:32am UTC](https://discuss.elastic.co/t/how-to-implement-data-stream-splitting-for-multiple-types-in-logstashs-java-plugin/330569 "2023-04-23T02:32:42Z")

</div>

When using the logstash-input-rabbitmq plugin, multiple service logs can be collected by specifying different types in the same Logstash configuration file. Now I want to implement a Java version of the Logstash-input-ro…

---

## [Api\_key privilege](https://discuss.elastic.co/t/api-key-privilege/330558)

<div class="topic-metadata">

**Author:** [@7Alex7](https://discuss.elastic.co/u/7Alex7)\
**Replies:** 0\
**Last updated:** [April 22, 2023, 6:53pm UTC](https://discuss.elastic.co/t/api-key-privilege/330558 "2023-04-22T18:53:33Z")

</div>

I will use Search in my projects but would like to test it before buying. Projects need temporary credentials functionality. The Api\_key looks good for this. One more restriction is that the user must be able to create …

---

## [Calling Elastic search from remote server via https](https://discuss.elastic.co/t/calling-elastic-search-from-remote-server-via-https/330254)

<div class="topic-metadata">

**Author:** [@neil.maffitt](https://discuss.elastic.co/u/neil.maffitt)\
**Replies:** 12\
**Last updated:** [April 22, 2023, 10:48am UTC](https://discuss.elastic.co/t/calling-elastic-search-from-remote-server-via-https/330254 "2023-04-22T10:48:37Z")

</div>

This works fine on local machine curl --cacert /etc/elasticsearch/certs/http\_ca.crt -u elastic: https://localhost:9200 This does not work remotely curl --cacert /etc/elasticsearch/certs/http\_ca.crt -u elastic: https:/…

---

## [Elasticsearch connection issue](https://discuss.elastic.co/t/elasticsearch-connection-issue/330480)

<div class="topic-metadata">

**Author:** [@Buddha](https://discuss.elastic.co/u/Buddha)\
**Replies:** 6\
**Last updated:** [April 22, 2023, 10:29am UTC](https://discuss.elastic.co/t/elasticsearch-connection-issue/330480 "2023-04-22T10:29:30Z")

</div>

Hello, A bit of a noob on certs stuff and I had a previous question where I think I was complicating things to solve a connection issue to my Elasticsearch deployment: The following is an image and an error message: …

---

## [How to handle default value for logstash pipeline efficiently?](https://discuss.elastic.co/t/how-to-handle-default-value-for-logstash-pipeline-efficiently/330335)

<div class="topic-metadata">

**Author:** [@Hatef\_Alipour](https://discuss.elastic.co/u/Hatef_Alipour)\
**Replies:** 2\
**Last updated:** [April 22, 2023, 8:19am UTC](https://discuss.elastic.co/t/how-to-handle-default-value-for-logstash-pipeline-efficiently/330335 "2023-04-22T08:19:22Z")

</div>

I have a logstash pipeline that its filter part looks like this: filter { if condition { prune { blacklist\_names =\> \["^cat\[1-8\]$","^classifier.version$","^accessory\_check$"\] …

---

## [Visualize count of messages for a specific key (ID) within a time window](https://discuss.elastic.co/t/visualize-count-of-messages-for-a-specific-key-id-within-a-time-window/330545)

<div class="topic-metadata">

**Author:** [@Florian\_Braun](https://discuss.elastic.co/u/Florian_Braun)\
**Replies:** 0\
**Last updated:** [April 21, 2023, 10:08pm UTC](https://discuss.elastic.co/t/visualize-count-of-messages-for-a-specific-key-id-within-a-time-window/330545 "2023-04-21T22:08:37Z")

</div>

In my dataset I get a large amount of messages, each providing an update to an object with a unique ID. What I would like to visualize is how frequent these updates are for each unique ID, more specifically, how often d…

---

## [Sysmon events not getting into the SOC and kibana](https://discuss.elastic.co/t/sysmon-events-not-getting-into-the-soc-and-kibana/330543)

<div class="topic-metadata">

**Author:** [@iqworks](https://discuss.elastic.co/u/iqworks)\
**Replies:** 0\
**Last updated:** [April 21, 2023, 9:16pm UTC](https://discuss.elastic.co/t/sysmon-events-not-getting-into-the-soc-and-kibana/330543 "2023-04-21T21:16:30Z")

</div>

Hi, I have been trying to get my sysmon events to show up in kibana. Does anyone know if there is a debugging check list that I could follow? I uninstalled and sysmon and winlogbeat. I went into the sysmon.yml and I se…

---

## [Can I move my sysmon service to another folder](https://discuss.elastic.co/t/can-i-move-my-sysmon-service-to-another-folder/330542)

<div class="topic-metadata">

**Author:** [@iqworks](https://discuss.elastic.co/u/iqworks)\
**Replies:** 1\
**Last updated:** [April 21, 2023, 8:55pm UTC](https://discuss.elastic.co/t/can-i-move-my-sysmon-service-to-another-folder/330542 "2023-04-21T20:55:11Z")

</div>

When I install sysmon, I can put it in the sysmon folder that I choose. But why does the service reside in C:\\WINDOWS\\Sysmon.exe instead of where I would rather have it? thanks again for any advice or suggestions

---

## [Enhanced data table-Add image and on click it should download the log/excel file](https://discuss.elastic.co/t/enhanced-data-table-add-image-and-on-click-it-should-download-the-log-excel-file/330315)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 3\
**Last updated:** [April 21, 2023, 8:02pm UTC](https://discuss.elastic.co/t/enhanced-data-table-add-image-and-on-click-it-should-download-the-log-excel-file/330315 "2023-04-21T20:02:18Z")

</div>

Hello @fbaligand , 1)Could you plz let me know if its possible to add image instead of hyperlink to download something? In below image i have achived this through using enhanced table and as per my requirement my inten…

---

## [Regression? Metricbeat dies immediately if kibana isn't running yet (or is still starting)](https://discuss.elastic.co/t/regression-metricbeat-dies-immediately-if-kibana-isnt-running-yet-or-is-still-starting/328756)

<div class="topic-metadata">

**Author:** [@archon810](https://discuss.elastic.co/u/archon810)\
**Replies:** 3\
**Last updated:** [April 21, 2023, 6:24pm UTC](https://discuss.elastic.co/t/regression-metricbeat-dies-immediately-if-kibana-isnt-running-yet-or-is-still-starting/328756 "2023-04-21T18:24:56Z")

</div>

This used to work in v7, but broken in v8, which we upgraded to recently. Restarting kibana and then restarting metricbeat, like so: systemctl restart elasticsearch && systemctl restart kibana && systemctl restart metr…

---

## [PDF From Watcher is returning blank visualizations](https://discuss.elastic.co/t/pdf-from-watcher-is-returning-blank-visualizations/330539)

<div class="topic-metadata">

**Author:** [@swhittenburg](https://discuss.elastic.co/u/swhittenburg)\
**Replies:** 1\
**Last updated:** [April 21, 2023, 4:52pm UTC](https://discuss.elastic.co/t/pdf-from-watcher-is-returning-blank-visualizations/330539 "2023-04-21T16:52:25Z")

</div>

I set up a custom watcher to send me an email of a pdf of a dashboard every x minutes. I had it set to 5 minutes and the pdf would send correctly a couple times and then would be blank, then would be fine again. I'm assu…

---

## [How to delete a runtime field?](https://discuss.elastic.co/t/how-to-delete-a-runtime-field/330526)

<div class="topic-metadata">

**Author:** [@mukesh\_pallapothu](https://discuss.elastic.co/u/mukesh_pallapothu)\
**Replies:** 1\
**Last updated:** [April 21, 2023, 4:47pm UTC](https://discuss.elastic.co/t/how-to-delete-a-runtime-field/330526 "2023-04-21T16:47:04Z")

</div>

I am trying to use runtime fields instead of scripted fields and have created one, which I no longer need. Is there any API or from GUI I can delete the runtime fields ?

---

## [Cross index kibana dashboard](https://discuss.elastic.co/t/cross-index-kibana-dashboard/330538)

<div class="topic-metadata">

**Author:** [@George\_ML](https://discuss.elastic.co/u/George_ML)\
**Replies:** 0\
**Last updated:** [April 21, 2023, 4:46pm UTC](https://discuss.elastic.co/t/cross-index-kibana-dashboard/330538 "2023-04-21T16:46:01Z")

</div>

Hello, I am trying to build a dashboard that pulls information from multiple indices. While both indices have the same data, the formatting is different, for example: On index logstash, i have the property resourceId,…

[Previous page](https://discuss.elastic.co/latest.md?page=700)

[Next page](https://discuss.elastic.co/latest.md?page=702)
