# Latest

**URL:** https://discuss.elastic.co/latest.md?page=708

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 709

---

## [Expand existing lens visualization / Create a new lens visualization](https://discuss.elastic.co/t/expand-existing-lens-visualization-create-a-new-lens-visualization/329804)

<div class="topic-metadata">

**Author:** [@LucasE](https://discuss.elastic.co/u/LucasE)\
**Replies:** 6\
**Last updated:** [April 18, 2023, 7:42am UTC](https://discuss.elastic.co/t/expand-existing-lens-visualization-create-a-new-lens-visualization/329804 "2023-04-18T07:42:49Z")

</div>

Hello everyone, I'm using Kibana 8.3.3 My objective is to take the Table from the DashBoard Lens visualization editor and create a new type of visualization called TableM by creating a plugin in Kibana. This table wil…

---

## [Metricbeat error: failed to get docker stats: Cannot connect to the Docker daemon at unix:///run/podman/io.podman](https://discuss.elastic.co/t/metricbeat-error-failed-to-get-docker-stats-cannot-connect-to-the-docker-daemon-at-unix-run-podman-io-podman/329995)

<div class="topic-metadata">

**Author:** [@Usama\_Tariq](https://discuss.elastic.co/u/Usama_Tariq)\
**Replies:** 2\
**Last updated:** [April 18, 2023, 6:34am UTC](https://discuss.elastic.co/t/metricbeat-error-failed-to-get-docker-stats-cannot-connect-to-the-docker-daemon-at-unix-run-podman-io-podman/329995 "2023-04-18T06:34:43Z")

</div>

Hi all. I am facing an issue when trying to get docker metrics via podman. I am getting the following error: "failed to get docker stats: Cannot connect to the Docker daemon at unix:///run/podman/io.podman. Is the docke…

---

## [Use variable in logstash config](https://discuss.elastic.co/t/use-variable-in-logstash-config/330092)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 2\
**Last updated:** [April 18, 2023, 6:20am UTC](https://discuss.elastic.co/t/use-variable-in-logstash-config/330092 "2023-04-18T06:20:52Z")

</div>

Hi I have logstash input like below, how can i set variable for "cpu" (it is name of table in database) and it has different values like "mem, disk,i/o,...". need to pass name of table as variable instead of define mul…

---

## [GRAYLOG WITH OPENSEACH](https://discuss.elastic.co/t/graylog-with-openseach/330151)

<div class="topic-metadata">

**Author:** [@jomaguca](https://discuss.elastic.co/u/jomaguca)\
**Replies:** 3\
**Last updated:** [April 18, 2023, 6:06am UTC](https://discuss.elastic.co/t/graylog-with-openseach/330151 "2023-04-18T06:06:24Z")

</div>

Hi everyone I am using graylog with opnsearsh and I have a doubt to use filebeat, metricbeat etc because what is the version on all them to use with opensearch? Best regards.

---

## [Kibana 8.7 does not show the time values when clicking the timeslider control](https://discuss.elastic.co/t/kibana-8-7-does-not-show-the-time-values-when-clicking-the-timeslider-control/330098)

<div class="topic-metadata">

**Author:** [@Shreesh\_Narayanan](https://discuss.elastic.co/u/Shreesh_Narayanan)\
**Replies:** 2\
**Last updated:** [April 18, 2023, 4:10am UTC](https://discuss.elastic.co/t/kibana-8-7-does-not-show-the-time-values-when-clicking-the-timeslider-control/330098 "2023-04-18T04:10:09Z")

</div>

Hi Folks, My timeslider input control does not show the time value as the ticker progresses, i dont see any errors on logs for this . I tried changing the dark BG to default as a test , and the results are the sa…

---

## [How many times (interval/period) do metrics send to elasticsearch? Where i can see these information?](https://discuss.elastic.co/t/how-many-times-interval-period-do-metrics-send-to-elasticsearch-where-i-can-see-these-information/329851)

<div class="topic-metadata">

**Author:** [@Swathi12](https://discuss.elastic.co/u/Swathi12)\
**Replies:** 1\
**Last updated:** [April 18, 2023, 3:39am UTC](https://discuss.elastic.co/t/how-many-times-interval-period-do-metrics-send-to-elasticsearch-where-i-can-see-these-information/329851 "2023-04-18T03:39:34Z")

</div>

Hello community, how can i see in which interval the metrics from a cluster is sending to elasticsearch? what is this "period" in metricbeat-kubernetes.yml saying ? templates: - config: - m…

---

## [\<ECK\>Kibana 8.7.0 error login](https://discuss.elastic.co/t/eck-kibana-8-7-0-error-login/330181)

<div class="topic-metadata">

**Author:** [@Teresajw](https://discuss.elastic.co/u/Teresajw)\
**Replies:** 0\
**Last updated:** [April 18, 2023, 2:07am UTC](https://discuss.elastic.co/t/eck-kibana-8-7-0-error-login/330181 "2023-04-18T02:07:17Z")

</div>

Kibana can not login :cold\_face: :cold\_face: :cold\_face: When I deployed the es cluster and kibana using Elastic Cloud on Kubernetes, the cluster was deployed successfully and in good health, but kibana could not log in…

---

## [Kibana plugin development: Error when creating plugin in Kibana 8.6](https://discuss.elastic.co/t/kibana-plugin-development-error-when-creating-plugin-in-kibana-8-6/329264)

<div class="topic-metadata">

**Author:** [@dms6978](https://discuss.elastic.co/u/dms6978)\
**Replies:** 6\
**Last updated:** [April 18, 2023, 2:27am UTC](https://discuss.elastic.co/t/kibana-plugin-development-error-when-creating-plugin-in-kibana-8-6/329264 "2023-04-18T02:27:54Z")

</div>

When I create and run plugins, the following error occurs. Refused to execute script from 'http://localhost:5601/mvk/9007199254740991/bundles/plugin/helloKibana/1.0.0/helloKibana.plugin.js' because its MIME type ('appl…

---

## [SSL Certificate problem : Unable to get local issuer certificate](https://discuss.elastic.co/t/ssl-certificate-problem-unable-to-get-local-issuer-certificate/330125)

<div class="topic-metadata">

**Author:** [@dinbabs](https://discuss.elastic.co/u/dinbabs)\
**Replies:** 4\
**Last updated:** [April 18, 2023, 1:18am UTC](https://discuss.elastic.co/t/ssl-certificate-problem-unable-to-get-local-issuer-certificate/330125 "2023-04-18T01:18:21Z")

</div>

Hi, I have deployed standalone Elasticsearch in one of the VM instance of Google Cloud(GCP). The client(Manychat) which I use to connect to Elasticsearch only supports https, so I did the configurations to run Elastics…

---

## [Logstash filter to extract key/values from curl result](https://discuss.elastic.co/t/logstash-filter-to-extract-key-values-from-curl-result/330083)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 1\
**Last updated:** [April 18, 2023, 1:00am UTC](https://discuss.elastic.co/t/logstash-filter-to-extract-key-values-from-curl-result/330083 "2023-04-18T01:00:52Z")

</div>

Hi Here is the result of curl command that I need to extract key/values (columns,values) and here is the key/value that i need to send to elastic { "series": { "time": "2023-04-16T07:58:40Z", "cpu": "cpu-…

---

## [Sysmon events not getting to SOC kibana or hunt - connection issues](https://discuss.elastic.co/t/sysmon-events-not-getting-to-soc-kibana-or-hunt-connection-issues/327966)

<div class="topic-metadata">

**Author:** [@iqworks](https://discuss.elastic.co/u/iqworks)\
**Replies:** 23\
**Last updated:** [April 17, 2023, 11:47pm UTC](https://discuss.elastic.co/t/sysmon-events-not-getting-to-soc-kibana-or-hunt-connection-issues/327966 "2023-04-17T23:47:57Z")

</div>

Hi, i am using elasticsearch 8.6.2, Winlogbeat 8.6.2 and sysmon 74 I am trying the ELK system. The data gets into sysmon ok. There are probably many reasons. I was pointing to output.logstash because as I understand …

---

## [Subject query data of restaurants by given location topic that we desire for a year](https://discuss.elastic.co/t/subject-query-data-of-restaurants-by-given-location-topic-that-we-desire-for-a-year/330167)

<div class="topic-metadata">

**Author:** [@Nonchaianon](https://discuss.elastic.co/u/Nonchaianon)\
**Replies:** 1\
**Last updated:** [April 17, 2023, 10:15pm UTC](https://discuss.elastic.co/t/subject-query-data-of-restaurants-by-given-location-topic-that-we-desire-for-a-year/330167 "2023-04-17T22:15:42Z")

</div>

Dear elasticsearch technical I’am developer Food delivery platform We desire to improve performance query data of restaurants by given location Condition -50,000 restaurant -200 km^2 -queries 200,000 times per day …

---

## [Help with data management, I have an index with a size of 119GB, what can I do?](https://discuss.elastic.co/t/help-with-data-management-i-have-an-index-with-a-size-of-119gb-what-can-i-do/329866)

<div class="topic-metadata">

**Author:** [@Mary2022](https://discuss.elastic.co/u/Mary2022)\
**Replies:** 1\
**Last updated:** [April 17, 2023, 10:00pm UTC](https://discuss.elastic.co/t/help-with-data-management-i-have-an-index-with-a-size-of-119gb-what-can-i-do/329866 "2023-04-17T22:00:36Z")

</div>

I have an index with a size of 119GB that is causing performance issues when search the data. My first thought was to use an index policy to expire old documents but soon I learned the lifecycle policy only works for t…

---

## [Elastic search docker image - Jar hell error](https://discuss.elastic.co/t/elastic-search-docker-image-jar-hell-error/329767)

<div class="topic-metadata">

**Author:** [@priya\_dhana](https://discuss.elastic.co/u/priya_dhana)\
**Replies:** 11\
**Last updated:** [April 17, 2023, 12:55am UTC](https://discuss.elastic.co/t/elastic-search-docker-image-jar-hell-error/329767 "2023-04-17T00:55:27Z")

</div>

I am using docker.elastic.co/elasticsearch/elasticsearch:5.6.16 as base image and trying to upgrade the jackson packages to resolve Critical CVE. Dockerfile: # https://github.com/elastic/elasticsearch-docker FROM dock…

---

## [BulkIngester: Received \`not\_x\_content\_exception\` when adding json](https://discuss.elastic.co/t/bulkingester-received-not-x-content-exception-when-adding-json/329812)

<div class="topic-metadata">

**Author:** [@ALX\_DM](https://discuss.elastic.co/u/ALX_DM)\
**Replies:** 0\
**Last updated:** [April 12, 2023, 8:34am UTC](https://discuss.elastic.co/t/bulkingester-received-not-x-content-exception-when-adding-json/329812 "2023-04-12T08:34:09Z")

</div>

In the new BulkIngester, how to add json data? I have this json: { "time": "2023-04-13T02:44:16.1782763Z", "user\_id": 1, "user\_name": "admin", "host\_name": "localhost:5567", "type": "PRODUCT\_DELETE", "long\_…

---

## [Initiating a port scan](https://discuss.elastic.co/t/initiating-a-port-scan/329939)

<div class="topic-metadata">

**Author:** [@Infael](https://discuss.elastic.co/u/Infael)\
**Replies:** 1\
**Last updated:** [April 17, 2023, 9:46pm UTC](https://discuss.elastic.co/t/initiating-a-port-scan/329939 "2023-04-17T21:46:23Z")

</div>

I need to scan all ports on my network. I have not been able to figure this out. I am very new to Elastic. Thanks! Michael

---

## [Editing runtime fields for remote index stopped working](https://discuss.elastic.co/t/editing-runtime-fields-for-remote-index-stopped-working/329953)

<div class="topic-metadata">

**Author:** [@erik\_n](https://discuss.elastic.co/u/erik_n)\
**Replies:** 3\
**Last updated:** [April 17, 2023, 9:39pm UTC](https://discuss.elastic.co/t/editing-runtime-fields-for-remote-index-stopped-working/329953 "2023-04-17T21:39:21Z")

</div>

Hello! I had a few runtime fields working with a cluster against data in a remote cluster, and since upgrading both from 7.15 to 8.6 I'm unable to edit them or create new ones. I ran into this when trying to fix usages…

---

## [I am using the Sysmon-\> logstash -\> elasticsearch (ELK) architecture issues](https://discuss.elastic.co/t/i-am-using-the-sysmon-logstash-elasticsearch-elk-architecture-issues/330076)

<div class="topic-metadata">

**Author:** [@iqworks](https://discuss.elastic.co/u/iqworks)\
**Replies:** 0\
**Last updated:** [April 15, 2023, 11:14pm UTC](https://discuss.elastic.co/t/i-am-using-the-sysmon-logstash-elasticsearch-elk-architecture-issues/330076 "2023-04-15T23:14:36Z")

</div>

Hi, I am trying to use sysmon to logstash to elasticsearch. After advice from others in this forum, I finally came up with a combination of parms and processing that at least shows me data from my laptop IP in kibana. T…

---

## [Kibana not connecting on browser](https://discuss.elastic.co/t/kibana-not-connecting-on-browser/330148)

<div class="topic-metadata">

**Author:** [@Cyberpwc](https://discuss.elastic.co/u/Cyberpwc)\
**Replies:** 1\
**Last updated:** [April 17, 2023, 9:09pm UTC](https://discuss.elastic.co/t/kibana-not-connecting-on-browser/330148 "2023-04-17T21:09:20Z")

</div>

Hi, I'm new to the ELK stack and currently trying to configure Kibana however I am encountering an error regarding some security authentication issue. This is the Kibana log showing the error: Apr 17 16:56:52 CyberELK …

---

## [How to test Elasticsearch rules?](https://discuss.elastic.co/t/how-to-test-elasticsearch-rules/329448)

<div class="topic-metadata">

**Author:** [@iojas](https://discuss.elastic.co/u/iojas)\
**Replies:** 1\
**Last updated:** [April 17, 2023, 7:23pm UTC](https://discuss.elastic.co/t/how-to-test-elasticsearch-rules/329448 "2023-04-17T19:23:34Z")

</div>

I have successfully installed the elastic-agent on Kubernetes cluster and see them showing up in the fleet. I turned on bunch of rules, I see them as enabled. now I want to be able to trigger one of those rules. somethi…

---

## [Error starting watcher](https://discuss.elastic.co/t/error-starting-watcher/330143)

<div class="topic-metadata">

**Author:** [@6igwig](https://discuss.elastic.co/u/6igwig)\
**Replies:** 1\
**Last updated:** [April 17, 2023, 6:34pm UTC](https://discuss.elastic.co/t/error-starting-watcher/330143 "2023-04-17T18:34:28Z")

</div>

We upgraded to 8.7.0 yesterday, since then none of our watchers have executed. We just keep getting this message in the elastic logs: error starting watcher I tried deleting the extra .watcher-history-\* indices via upda…

---

## [Limiting data in object properties coming to browser from elastic search](https://discuss.elastic.co/t/limiting-data-in-object-properties-coming-to-browser-from-elastic-search/329958)

<div class="topic-metadata">

**Author:** [@Akaash\_Mukherjee](https://discuss.elastic.co/u/Akaash_Mukherjee)\
**Replies:** 6\
**Last updated:** [April 17, 2023, 6:33pm UTC](https://discuss.elastic.co/t/limiting-data-in-object-properties-coming-to-browser-from-elastic-search/329958 "2023-04-17T18:33:07Z")

</div>

Hi, We are currently pulling large amounts of data from Elasticsearch for reporting products in our software. For our larger clients this means sending a large amount of data to the browser which is then loaded into a r…

---

## [Kibana 8.7 expensive queries](https://discuss.elastic.co/t/kibana-8-7-expensive-queries/330120)

<div class="topic-metadata">

**Author:** [@Jonas\_S](https://discuss.elastic.co/u/Jonas_S)\
**Replies:** 3\
**Last updated:** [April 17, 2023, 6:32pm UTC](https://discuss.elastic.co/t/kibana-8-7-expensive-queries/330120 "2023-04-17T18:32:35Z")

</div>

Hello, after upgrading Elastic and Kibana to 8.7 i get reports from users that they are seeing this: Combined with missing values in the control. If they type the value they are missing in the search field of the con…

---

## [Kibana 8.7 Control Sort](https://discuss.elastic.co/t/kibana-8-7-control-sort/329758)

<div class="topic-metadata">

**Author:** [@Jonas\_S](https://discuss.elastic.co/u/Jonas_S)\
**Replies:** 4\
**Last updated:** [April 17, 2023, 4:30pm UTC](https://discuss.elastic.co/t/kibana-8-7-control-sort/329758 "2023-04-17T16:30:35Z")

</div>

Hello, i just checked out the new sorting functionallity for controls. The default setting is to sort desc by doc count I want asc alphabetically on every control. How can i change that in an easy way? I could not …

---

## [Are runtime multi-fields possible?](https://discuss.elastic.co/t/are-runtime-multi-fields-possible/330153)

<div class="topic-metadata">

**Author:** [@nisow95612](https://discuss.elastic.co/u/nisow95612)\
**Replies:** 1\
**Last updated:** [April 17, 2023, 4:44pm UTC](https://discuss.elastic.co/t/are-runtime-multi-fields-possible/330153 "2023-04-17T16:44:48Z")

</div>

Is it possible to have a runtime mapping with a subfield? I mean, so I get fields like "field.keyword" and "field.text" like multi-fields, but at same time this is runtime mapping . I like elasticsearch dynamic mapping,…

---

## [Internal monitoring and log indices have "live forever" ILM policies](https://discuss.elastic.co/t/internal-monitoring-and-log-indices-have-live-forever-ilm-policies/330072)

<div class="topic-metadata">

**Author:** [@ppine7](https://discuss.elastic.co/u/ppine7)\
**Replies:** 2\
**Last updated:** [April 17, 2023, 4:32pm UTC](https://discuss.elastic.co/t/internal-monitoring-and-log-indices-have-live-forever-ilm-policies/330072 "2023-04-17T16:32:21Z")

</div>

Hi! I was investigating an issue with too much retained data in our ES cloud cluster and realized that a lot of it comes from the internal monitoring and log indices. Specifically, the following indices with correspondi…

---

## [Kibana left side changes on right side's variable click](https://discuss.elastic.co/t/kibana-left-side-changes-on-right-sides-variable-click/329708)

<div class="topic-metadata">

**Author:** [@Fiza](https://discuss.elastic.co/u/Fiza)\
**Replies:** 4\
**Last updated:** [April 17, 2023, 6:53am UTC](https://discuss.elastic.co/t/kibana-left-side-changes-on-right-sides-variable-click/329708 "2023-04-17T06:53:22Z")

</div>

Hello, I am learning about Kibana and its features so I wanted to know whether Kibana support the feature of having dependent visualization. Something like if I click on a variable or link present in right side then lef…

---

## [Unable to load APM Errors due to new error: Fielddata is disabled on \[error.grouping\_key\]](https://discuss.elastic.co/t/unable-to-load-apm-errors-due-to-new-error-fielddata-is-disabled-on-error-grouping-key/329460)

<div class="topic-metadata">

**Author:** [@pocketcolin](https://discuss.elastic.co/u/pocketcolin)\
**Replies:** 3\
**Last updated:** [April 17, 2023, 3:43pm UTC](https://discuss.elastic.co/t/unable-to-load-apm-errors-due-to-new-error-fielddata-is-disabled-on-error-grouping-key/329460 "2023-04-17T15:43:53Z")

</div>

I realize there are a fair number of other topics with a very similar error, but this feels different due to the fact that it's the Observability APM that is triggering this exception. I just went to my APM in Elastic Cl…

---

## [Visualize List files from logs](https://discuss.elastic.co/t/visualize-list-files-from-logs/327944)

<div class="topic-metadata">

**Author:** [@Oniriel](https://discuss.elastic.co/u/Oniriel)\
**Replies:** 4\
**Last updated:** [April 17, 2023, 3:38pm UTC](https://discuss.elastic.co/t/visualize-list-files-from-logs/327944 "2023-04-17T15:38:46Z")

</div>

Hi, I have an index that I try to create visualization on for monitoring. Some of the logs have the following structure TEXT - path of a file - TEXT the same file can appear multiple time in the logs I can successful…

---

## [Elasticsearch Transformed index and its dashboard](https://discuss.elastic.co/t/elasticsearch-transformed-index-and-its-dashboard/329827)

<div class="topic-metadata">

**Author:** [@rvadiga](https://discuss.elastic.co/u/rvadiga)\
**Replies:** 3\
**Last updated:** [April 17, 2023, 3:33pm UTC](https://discuss.elastic.co/t/elasticsearch-transformed-index-and-its-dashboard/329827 "2023-04-17T15:33:46Z")

</div>

Hi, I am building a Kibana dashboard using an transformed index. What I have observed is for every field change in ES transform, I need to create a new dashboard as object is deleted when deleting the ES transform. C…

[Previous page](https://discuss.elastic.co/latest.md?page=707)

[Next page](https://discuss.elastic.co/latest.md?page=709)
