# Latest

**URL:** https://discuss.elastic.co/latest.md?page=715

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 716

---

## [ELK on AWS](https://discuss.elastic.co/t/elk-on-aws/329819)

<div class="topic-metadata">

**Author:** [@Ankita\_Pachauri](https://discuss.elastic.co/u/Ankita_Pachauri)\
**Replies:** 0\
**Last updated:** [April 12, 2023, 9:25am UTC](https://discuss.elastic.co/t/elk-on-aws/329819 "2023-04-12T09:25:14Z")

</div>

Hi Team, We did install elk \[3 elastic nodes and 2 kibana nodes on us-east-1a,us-east-1b\] on AWS. We are trying to access Kibana dashboard via NLB with ACM\[AWS certificate Manager\] ,but somehow when I am starting kiba…

---

## [Elastic user password change in kubernetes secret](https://discuss.elastic.co/t/elastic-user-password-change-in-kubernetes-secret/329328)

<div class="topic-metadata">

**Author:** [@basavarajvn0513](https://discuss.elastic.co/u/basavarajvn0513)\
**Replies:** 2\
**Last updated:** [April 12, 2023, 9:18am UTC](https://discuss.elastic.co/t/elastic-user-password-change-in-kubernetes-secret/329328 "2023-04-12T09:18:19Z")

</div>

I have elasticsearch ,kiabana,logstash,filebeat in kuberentes. All use the same elasatic username and password as ENV variables from the secret .yaml. I want to change the password for the elastic user . After I change …

---

## [How elasticsearch distribute the requests from client](https://discuss.elastic.co/t/how-elasticsearch-distribute-the-requests-from-client/329815)

<div class="topic-metadata">

**Author:** [@qksjdhi1212](https://discuss.elastic.co/u/qksjdhi1212)\
**Replies:** 1\
**Last updated:** [April 12, 2023, 8:53am UTC](https://discuss.elastic.co/t/how-elasticsearch-distribute-the-requests-from-client/329815 "2023-04-12T08:53:27Z")

</div>

I want to know the whole process where elasticsearch distribute the request received from client server (logstash, application, fluentd etc.) does the master node in cluster just assign the request to the most stable no…

---

## [Are there any guidelines to estimate how many snapshots can be handled by elasticsearch with specific amount of memory/cpu](https://discuss.elastic.co/t/are-there-any-guidelines-to-estimate-how-many-snapshots-can-be-handled-by-elasticsearch-with-specific-amount-of-memory-cpu/329811)

<div class="topic-metadata">

**Author:** [@Vivek\_Shinde](https://discuss.elastic.co/u/Vivek_Shinde)\
**Replies:** 0\
**Last updated:** [April 12, 2023, 8:29am UTC](https://discuss.elastic.co/t/are-there-any-guidelines-to-estimate-how-many-snapshots-can-be-handled-by-elasticsearch-with-specific-amount-of-memory-cpu/329811 "2023-04-12T08:29:34Z")

</div>

HI - I am looking for any data or estimates if we can derive about retaining the snapshots based on size of the cluster. E.g. If we have a smaller elastic cluster with 2G of memory allocation, and SLM with each 15 min s…

---

## [Kibana Uptime monitors broken after migrating to another cluster](https://discuss.elastic.co/t/kibana-uptime-monitors-broken-after-migrating-to-another-cluster/329727)

<div class="topic-metadata">

**Author:** [@George\_ML](https://discuss.elastic.co/u/George_ML)\
**Replies:** 3\
**Last updated:** [April 12, 2023, 8:15am UTC](https://discuss.elastic.co/t/kibana-uptime-monitors-broken-after-migrating-to-another-cluster/329727 "2023-04-12T08:15:29Z")

</div>

Hello, I have recently migrated to another cluster, but I have restored the snapshot after the cluster creation. Because of this, I think some encryption keys for the encrypted saved objects have been changed. This cau…

---

## [Logstash plugin install : Error socket closed](https://discuss.elastic.co/t/logstash-plugin-install-error-socket-closed/328243)

<div class="topic-metadata">

**Author:** [@Julien069](https://discuss.elastic.co/u/Julien069)\
**Replies:** 22\
**Last updated:** [April 12, 2023, 7:50am UTC](https://discuss.elastic.co/t/logstash-plugin-install-error-socket-closed/328243 "2023-04-12T07:50:09Z")

</div>

Hi , I want to install a Stormshield plugin for Logstash I tried bin/logstash-plugin install --no-verify logstash-filter-SNS I have "ERROR : Something went wrong when installalling bin/logstash-filter-SNS , message s…

---

## [Elasticsearch 8.7, "master\_not\_discovered\_exception" error](https://discuss.elastic.co/t/elasticsearch-8-7-master-not-discovered-exception-error/329495)

<div class="topic-metadata">

**Author:** [@Jyotsna\_Bhati](https://discuss.elastic.co/u/Jyotsna_Bhati)\
**Replies:** 6\
**Last updated:** [April 12, 2023, 6:32am UTC](https://discuss.elastic.co/t/elasticsearch-8-7-master-not-discovered-exception-error/329495 "2023-04-12T06:32:54Z")

</div>

Upgraded elasticsearch from 7.17 to 8.7. Elasticsearch service is running but not able to discover other nodes. Ran: curl -XGET "localhost:9200/\_cluster/state?filter\_path=version,nodes,metadata.cluster\_coordination&p…

---

## [Anonymous access is denied in kibana?](https://discuss.elastic.co/t/anonymous-access-is-denied-in-kibana/329799)

<div class="topic-metadata">

**Author:** [@Shreesh\_Narayanan](https://discuss.elastic.co/u/Shreesh_Narayanan)\
**Replies:** 1\
**Last updated:** [April 12, 2023, 6:29am UTC](https://discuss.elastic.co/t/anonymous-access-is-denied-in-kibana/329799 "2023-04-12T06:29:09Z")

</div>

Hi Folks, I have 3 node elasticsearch , 2 logstash nodes and 1 kibana node . Do i mention all three elasticsearch nodes in kibana.yml's "elasticsearch.hosts" config line ? . It was working when i had just the master el…

---

## [Cannt find dependency for CommonAnalysisPlugin](https://discuss.elastic.co/t/cannt-find-dependency-for-commonanalysisplugin/329798)

<div class="topic-metadata">

**Author:** [@yeziblo](https://discuss.elastic.co/u/yeziblo)\
**Replies:** 1\
**Last updated:** [April 12, 2023, 6:05am UTC](https://discuss.elastic.co/t/cannt-find-dependency-for-commonanalysisplugin/329798 "2023-04-12T06:05:08Z")

</div>

Hello everyone, I am currently trying to upgrade my Elasticsearch version from 7.8.1 to 7.17.4. However, after the upgrade, I encountered an error in my project: Cannot resolve symbol 'CommonAnalysisPlugin In Elastics…

---

## [Full tracing with response times per class instead of Service only](https://discuss.elastic.co/t/full-tracing-with-response-times-per-class-instead-of-service-only/329744)

<div class="topic-metadata">

**Author:** [@dannystommen](https://discuss.elastic.co/u/dannystommen)\
**Replies:** 2\
**Last updated:** [April 12, 2023, 6:03am UTC](https://discuss.elastic.co/t/full-tracing-with-response-times-per-class-instead-of-service-only/329744 "2023-04-12T06:03:17Z")

</div>

Hi, When looking at traces, I can see exactly which APIs are slowing down requests when having a chain of API calls. So for example, Service A \> Service B \> Service C. I can see how many time the request spent in Servi…

---

## [Duration time between logs](https://discuss.elastic.co/t/duration-time-between-logs/329757)

<div class="topic-metadata">

**Author:** [@justme123](https://discuss.elastic.co/u/justme123)\
**Replies:** 2\
**Last updated:** [April 12, 2023, 5:54am UTC](https://discuss.elastic.co/t/duration-time-between-logs/329757 "2023-04-12T05:54:21Z")

</div>

Hi Everyone ! I'm new to elastic and kibana and I have some troubles with duration time between log event. I have 2 logs that i get via SNMP Trap : referenceNumber : 123456 alarmType: 2 @timestamp : 2023-04-11T09:…

---

## [Elasticsearch](https://discuss.elastic.co/t/elasticsearch/329426)

<div class="topic-metadata">

**Author:** [@MahithaSarala](https://discuss.elastic.co/u/MahithaSarala)\
**Replies:** 2\
**Last updated:** [April 12, 2023, 5:23am UTC](https://discuss.elastic.co/t/elasticsearch/329426 "2023-04-12T05:23:51Z")

</div>

Hi team, How to deploy metric beats for elasticsearch and kibana using ECK, Is there any document for this . because not able to see all logs for kibana and elasticsearch . Could you help on this

---

## [Waiting for the transport certificates](https://discuss.elastic.co/t/waiting-for-the-transport-certificates/329789)

<div class="topic-metadata">

**Author:** [@SeibertronSS](https://discuss.elastic.co/u/SeibertronSS)\
**Replies:** 2\
**Last updated:** [April 12, 2023, 5:21am UTC](https://discuss.elastic.co/t/waiting-for-the-transport-certificates/329789 "2023-04-12T05:21:35Z")

</div>

Hi, I followed ECK's documentation to install elasticsearch using Elastic Operator. My elasticsearch pod is stuck in Init state when I use the provided quick start, here is a snippet of its log Starting init script Link…

---

## [I am unable to run Kibana 8.6.1 from browser](https://discuss.elastic.co/t/i-am-unable-to-run-kibana-8-6-1-from-browser/329137)

<div class="topic-metadata">

**Author:** [@Aysh14](https://discuss.elastic.co/u/Aysh14)\
**Replies:** 8\
**Last updated:** [April 12, 2023, 5:10am UTC](https://discuss.elastic.co/t/i-am-unable-to-run-kibana-8-6-1-from-browser/329137 "2023-04-12T05:10:38Z")

</div>

Hi Team, I am unable to connect to kibana from browser. I have installed Kibana, 8.6.1 . I am getting HTTP/1.1 302 Found when I do a curl on the URL from the VM , but unable to get response when I try to access from br…

---

## [Kube State Metrics stop reporting / Potential Leader Election issue](https://discuss.elastic.co/t/kube-state-metrics-stop-reporting-potential-leader-election-issue/329794)

<div class="topic-metadata">

**Author:** [@RichardMatthews](https://discuss.elastic.co/u/RichardMatthews)\
**Replies:** 0\
**Last updated:** [April 12, 2023, 4:00am UTC](https://discuss.elastic.co/t/kube-state-metrics-stop-reporting-potential-leader-election-issue/329794 "2023-04-12T04:00:19Z")

</div>

Hey, I am having an issue with collecting data from kube state metrics where it will randomly stop coming through into Kibana and all that seems to help is restarting the elastic-agents until it starts to come back. I …

---

## [ElasticSearch delete model with force does not work](https://discuss.elastic.co/t/elasticsearch-delete-model-with-force-does-not-work/329781)

<div class="topic-metadata">

**Author:** [@Diogo\_Moura](https://discuss.elastic.co/u/Diogo_Moura)\
**Replies:** 0\
**Last updated:** [April 11, 2023, 10:23pm UTC](https://discuss.elastic.co/t/elasticsearch-delete-model-with-force-does-not-work/329781 "2023-04-11T22:23:17Z")

</div>

According to the documentation here https://www.elastic.co/guide/en/elasticsearch/reference/8.6/delete-trained-models.html#ml-delete-trained-models-query-parms it is possible to use the parameter "force" to force the de…

---

## [Bulk alerting configuration](https://discuss.elastic.co/t/bulk-alerting-configuration/327511)

<div class="topic-metadata">

**Author:** [@rossw](https://discuss.elastic.co/u/rossw)\
**Replies:** 5\
**Last updated:** [April 11, 2023, 9:13pm UTC](https://discuss.elastic.co/t/bulk-alerting-configuration/327511 "2023-04-11T21:13:48Z")

</div>

Afternoon, We are using the alerting functionality inside the Elastic Security toolset, and we have turned on about 100-odd rules. We have created email and webhook integrations and have started to tune the data being …

---

## [How to properly add an ngram tokenizer via Nest](https://discuss.elastic.co/t/how-to-properly-add-an-ngram-tokenizer-via-nest/329777)

<div class="topic-metadata">

**Author:** [@jfavaro](https://discuss.elastic.co/u/jfavaro)\
**Replies:** 0\
**Last updated:** [April 11, 2023, 9:05pm UTC](https://discuss.elastic.co/t/how-to-properly-add-an-ngram-tokenizer-via-nest/329777 "2023-04-11T21:05:22Z")

</div>

We have an existing Elastic version 8.3.3 with a .Net implementation using Nest 7.17.5. I've been trying to add a new field utitlizing an ngram tokenizer but whenever I add the code to my analyzers the existing full\_aut…

---

## [FortiMail logs are being combined in TCP input](https://discuss.elastic.co/t/fortimail-logs-are-being-combined-in-tcp-input/329768)

<div class="topic-metadata">

**Author:** [@6igwig](https://discuss.elastic.co/u/6igwig)\
**Replies:** 4\
**Last updated:** [April 11, 2023, 7:12pm UTC](https://discuss.elastic.co/t/fortimail-logs-are-being-combined-in-tcp-input/329768 "2023-04-11T19:12:53Z")

</div>

I have configured a tcp input in logstash to receive FortiMail logs. I believe the logs are losing their new line character in transit because all of the logs come in as a single document. (If I leave the pipeline runnin…

---

## [Kibana Dashboard Filter - Based on Columns](https://discuss.elastic.co/t/kibana-dashboard-filter-based-on-columns/327695)

<div class="topic-metadata">

**Author:** [@Raj4](https://discuss.elastic.co/u/Raj4)\
**Replies:** 1\
**Last updated:** [April 11, 2023, 6:59pm UTC](https://discuss.elastic.co/t/kibana-dashboard-filter-based-on-columns/327695 "2023-04-11T18:59:35Z")

</div>

Hi, Please advise to achieve the below requirement Data Fields and Sample Values I want to have only one Bar chart which should top 3 person name based upon the selected filter. The Dashboard filter should have the…

---

## [How to send error message to Elastic APM and show the error in Kibana tab](https://discuss.elastic.co/t/how-to-send-error-message-to-elastic-apm-and-show-the-error-in-kibana-tab/329183)

<div class="topic-metadata">

**Author:** [@JasonREC](https://discuss.elastic.co/u/JasonREC)\
**Replies:** 8\
**Last updated:** [April 11, 2023, 6:31pm UTC](https://discuss.elastic.co/t/how-to-send-error-message-to-elastic-apm-and-show-the-error-in-kibana-tab/329183 "2023-04-11T18:31:58Z")

</div>

I followed the set up of this page I am using the template.yml to set up my lambda function and Elastic APM ... Resources: yourLambdaFunction: Type: AWS::Serverless::Function Properties: ... Envi…

---

## [Breakdown metric by formula result](https://discuss.elastic.co/t/breakdown-metric-by-formula-result/328954)

<div class="topic-metadata">

**Author:** [@Nithin\_Ramesh](https://discuss.elastic.co/u/Nithin_Ramesh)\
**Replies:** 2\
**Last updated:** [April 11, 2023, 5:59pm UTC](https://discuss.elastic.co/t/breakdown-metric-by-formula-result/328954 "2023-04-11T17:59:00Z")

</div>

Hey, I am trying to visualize some data, but I have a feeling that I may be trying to do something that is impossible in Kibana currently. I have data that logs each event in a shipment process that consists of moving 1…

---

## [Is Elasticsearch paid?](https://discuss.elastic.co/t/is-elasticsearch-paid/329759)

<div class="topic-metadata">

**Author:** [@adzik](https://discuss.elastic.co/u/adzik)\
**Replies:** 6\
**Last updated:** [April 11, 2023, 5:52pm UTC](https://discuss.elastic.co/t/is-elasticsearch-paid/329759 "2023-04-11T17:52:54Z")

</div>

Hello, I have an ecommerce app and I would like to utilize Elasticsearch to search my products by customers. Do I need to buy a license in this case? I just want to make sure

---

## [Showing percentage](https://discuss.elastic.co/t/showing-percentage/328604)

<div class="topic-metadata">

**Author:** [@demarco-ion](https://discuss.elastic.co/u/demarco-ion)\
**Replies:** 2\
**Last updated:** [April 11, 2023, 5:43pm UTC](https://discuss.elastic.co/t/showing-percentage/328604 "2023-04-11T17:43:18Z")

</div>

Hi, I am trying to show a percentage value on Kibana, but let me specify better the problem. Basically I have two integer fields in two different indexes which are related to each other, the first one is computed on the…

---

## [Elasicsearch index error: org.elasticsearch.core.Tuple.v2()" is null](https://discuss.elastic.co/t/elasicsearch-index-error-org-elasticsearch-core-tuple-v2-is-null/329763)

<div class="topic-metadata">

**Author:** [@vanwoes](https://discuss.elastic.co/u/vanwoes)\
**Replies:** 0\
**Last updated:** [April 11, 2023, 4:06pm UTC](https://discuss.elastic.co/t/elasicsearch-index-error-org-elasticsearch-core-tuple-v2-is-null/329763 "2023-04-11T16:06:53Z")

</div>

Hi there, We have recently moved from a single node to multi node cluster and I have set up an ILM to move from hot, warm to cold. I keep seeing data moving from cold to warm despite it being marked as complete. I'm co…

---

## [Error: system/socket dataset setup failed](https://discuss.elastic.co/t/error-system-socket-dataset-setup-failed/329761)

<div class="topic-metadata">

**Author:** [@med\_dp](https://discuss.elastic.co/u/med_dp)\
**Replies:** 0\
**Last updated:** [April 11, 2023, 3:33pm UTC](https://discuss.elastic.co/t/error-system-socket-dataset-setup-failed/329761 "2023-04-11T15:33:29Z")

</div>

Hello all I have this issus with auditeat, any help please Apr 11 01:08:47 wnl03 auditbeat\[13640\]: 2023-04-11T01:08:47.574+0200 ERROR instance/beat.go:989 Exiting: 1 error: system/socket dataset se…

---

## [Logstash error](https://discuss.elastic.co/t/logstash-error/329706)

<div class="topic-metadata">

**Author:** [@sks](https://discuss.elastic.co/u/sks)\
**Replies:** 1\
**Last updated:** [April 11, 2023, 3:16pm UTC](https://discuss.elastic.co/t/logstash-error/329706 "2023-04-11T15:16:08Z")

</div>

Dear sir ; i want to send a json log file from my local pc to Elasticsearch my sample json file is { "people" : \[ { "firstName": "Joe", "lastName": "Jackson", "gender": "male", "age": 28, "number": "7349282382" …

---

## [Grok filter isn't working but working in kibana grok debugger](https://discuss.elastic.co/t/grok-filter-isnt-working-but-working-in-kibana-grok-debugger/329755)

<div class="topic-metadata">

**Author:** [@ira-zaya](https://discuss.elastic.co/u/ira-zaya)\
**Replies:** 0\
**Last updated:** [April 11, 2023, 2:44pm UTC](https://discuss.elastic.co/t/grok-filter-isnt-working-but-working-in-kibana-grok-debugger/329755 "2023-04-11T14:44:21Z")

</div>

Hi. I have the following logstash configuration: filter { if "platform1" in \[tags\] { grok { match =\> { "message" =\> \['%{TIMESTAMP\_ISO8601:timestamp}? ?\\\[?L?:? ?%{LOGLEVEL:logLevel}?\\\]…

---

## [How to give access to few documents in a field on a role?](https://discuss.elastic.co/t/how-to-give-access-to-few-documents-in-a-field-on-a-role/329534)

<div class="topic-metadata">

**Author:** [@stramzik](https://discuss.elastic.co/u/stramzik)\
**Replies:** 4\
**Last updated:** [April 11, 2023, 1:52pm UTC](https://discuss.elastic.co/t/how-to-give-access-to-few-documents-in-a-field-on-a-role/329534 "2023-04-11T13:52:50Z")

</div>

Hi, Lets say I have an index with following documents {"Country": "India", "sample":1 , "Data":"hi" } {"Country": "India", "sample": 2, "Data":"hello" } {"Country": "India", "sample": 3, "Data":"how" } {"Country": "B…

---

## [What contributes to APM Failure rate?](https://discuss.elastic.co/t/what-contributes-to-apm-failure-rate/329165)

<div class="topic-metadata">

**Author:** [@Ivan\_Hosea](https://discuss.elastic.co/u/Ivan_Hosea)\
**Replies:** 5\
**Last updated:** [April 11, 2023, 1:30pm UTC](https://discuss.elastic.co/t/what-contributes-to-apm-failure-rate/329165 "2023-04-11T13:30:57Z")

</div>

Hi, I would like to ask what is the failure rate in APM services stands for? I have read the documentation that suggest that the it is based on event.outcome / the status code / and the errors if there are no status cod…

[Previous page](https://discuss.elastic.co/latest.md?page=714)

[Next page](https://discuss.elastic.co/latest.md?page=716)
