# Latest

**URL:** https://discuss.elastic.co/latest.md?page=724

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 725

---

## [Embedding iframe dashboards -auto login](https://discuss.elastic.co/t/embedding-iframe-dashboards-auto-login/329159)

<div class="topic-metadata">

**Author:** [@Sandeep\_Raju](https://discuss.elastic.co/u/Sandeep_Raju)\
**Replies:** 1\
**Last updated:** [April 3, 2023, 9:03am UTC](https://discuss.elastic.co/t/embedding-iframe-dashboards-auto-login/329159 "2023-04-03T09:03:05Z")

</div>

I want to embed my iframe dashboard links in another application. But when i embed them , it is asking for login. I cannot add login & password in my iframe link. How can i configure auto login for dashboards when it …

---

## [【Please share info】Plugins and OSS for implementing alert functions in kibana (elasticsearch) version 7 series](https://discuss.elastic.co/t/please-share-info-plugins-and-oss-for-implementing-alert-functions-in-kibana-elasticsearch-version-7-series/329182)

<div class="topic-metadata">

**Author:** [@YUUTA.INOUE-JPN](https://discuss.elastic.co/u/YUUTA.INOUE-JPN)\
**Replies:** 0\
**Last updated:** [April 3, 2023, 8:51am UTC](https://discuss.elastic.co/t/please-share-info-plugins-and-oss-for-implementing-alert-functions-in-kibana-elasticsearch-version-7-series/329182 "2023-04-03T08:51:53Z")

</div>

Good evening from japan Dear Elastic Engineers, I am always grateful for your help In Elasticsearch/Kibana version 7 series, I would like to create a mechanism to send an alert email when a specific log is received by…

---

## [Fleet-Server Certificate issue](https://discuss.elastic.co/t/fleet-server-certificate-issue/328635)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 6\
**Last updated:** [April 3, 2023, 8:51am UTC](https://discuss.elastic.co/t/fleet-server-certificate-issue/328635 "2023-04-03T08:51:22Z")

</div>

Hi Community, xpack.security.enabled: true xpack.security.enrollment.enabled: true # Enable encryption for HTTP API client connections, such as Kibana, Logstash, and Agents xpack.security.http.ssl.enabled: true xpack.se…

---

## [Kibana does not work with https on Docker Swarm cluster](https://discuss.elastic.co/t/kibana-does-not-work-with-https-on-docker-swarm-cluster/329179)

<div class="topic-metadata">

**Author:** [@mrkitt](https://discuss.elastic.co/u/mrkitt)\
**Replies:** 0\
**Last updated:** [April 3, 2023, 8:48am UTC](https://discuss.elastic.co/t/kibana-does-not-work-with-https-on-docker-swarm-cluster/329179 "2023-04-03T08:48:11Z")

</div>

I have a Docker Swarm cluster which consists of one manager and two virtual machines inside as workers. I have successfully deployed Elasticsearch with basic security and https and connected it with Kibana. However, I w…

---

## [Elastic Dissect](https://discuss.elastic.co/t/elastic-dissect/329117)

<div class="topic-metadata">

**Author:** [@oleksiiorel](https://discuss.elastic.co/u/oleksiiorel)\
**Replies:** 5\
**Last updated:** [April 3, 2023, 8:25am UTC](https://discuss.elastic.co/t/elastic-dissect/329117 "2023-04-03T08:25:13Z")

</div>

Hi everyone :slight\_smile: How to split a single cell with a different number of strings in CVS file into separate cells (fields). Assign the names of the fields from the string itself. If I manually write the names of…

---

## [Query template that will append to existing query for further filtering out results](https://discuss.elastic.co/t/query-template-that-will-append-to-existing-query-for-further-filtering-out-results/329151)

<div class="topic-metadata">

**Author:** [@Java2avaj](https://discuss.elastic.co/u/Java2avaj)\
**Replies:** 3\
**Last updated:** [April 3, 2023, 8:23am UTC](https://discuss.elastic.co/t/query-template-that-will-append-to-existing-query-for-further-filtering-out-results/329151 "2023-04-03T08:23:02Z")

</div>

We have an existing "person" index that has "status" field in it. We have several (around 6) existing queries for retrieving person document with different parameters and logic. However, we have a new requirement that o…

---

## [Removing \\ from raw input log data](https://discuss.elastic.co/t/removing-from-raw-input-log-data/329062)

<div class="topic-metadata">

**Author:** [@Merdesz](https://discuss.elastic.co/u/Merdesz)\
**Replies:** 2\
**Last updated:** [April 3, 2023, 8:17am UTC](https://discuss.elastic.co/t/removing-from-raw-input-log-data/329062 "2023-04-03T08:17:59Z")

</div>

I have a device sending in logs which have "" before every string caracter and I would like to remove them or rewrite them to a simple ". So this " --\> " to this. Logs: srcintfrole="undefined" dstip=255.255.255.255 dst…

---

## ["timestamp.us" field in Elastic APM Delay](https://discuss.elastic.co/t/timestamp-us-field-in-elastic-apm-delay/329053)

<div class="topic-metadata">

**Author:** [@Namita\_Jaokar](https://discuss.elastic.co/u/Namita_Jaokar)\
**Replies:** 3\
**Last updated:** [April 3, 2023, 8:10am UTC](https://discuss.elastic.co/t/timestamp-us-field-in-elastic-apm-delay/329053 "2023-04-03T08:10:54Z")

</div>

Hi , I am Using Elasticsearch version 8.6.2 with Elastic APM java Agent. While parallelly running 3 to 4 scenarios of my application, it seems the stop-time time of my application does not match the timestamp.us of the…

---

## [Call External API through Kibana](https://discuss.elastic.co/t/call-external-api-through-kibana/329169)

<div class="topic-metadata">

**Author:** [@ANUBHAV\_GUPTA](https://discuss.elastic.co/u/ANUBHAV_GUPTA)\
**Replies:** 0\
**Last updated:** [April 3, 2023, 7:24am UTC](https://discuss.elastic.co/t/call-external-api-through-kibana/329169 "2023-04-03T07:24:49Z")

</div>

Can we do something like this in Kibana:- Suppose I am querying an index with a particular document whose value is in some other format(let's say jumbled) and what I need to do is to convert it into some other format(m…

---

## [Elasticsearch Watcher Capabilities](https://discuss.elastic.co/t/elasticsearch-watcher-capabilities/329167)

<div class="topic-metadata">

**Author:** [@umityayla](https://discuss.elastic.co/u/umityayla)\
**Replies:** 0\
**Last updated:** [April 3, 2023, 7:12am UTC](https://discuss.elastic.co/t/elasticsearch-watcher-capabilities/329167 "2023-04-03T07:12:32Z")

</div>

Hello, We plan to implement such a watcher that will regex a field in the documents that are found and pass it to the clients. What I mean is; Let's assume there are 2 documents like below; { "\_type": "\_doc", "\_id…

---

## [About Elastalert errors](https://discuss.elastic.co/t/about-elastalert-errors/329138)

<div class="topic-metadata">

**Author:** [@YUUTA.INOUE-JPN](https://discuss.elastic.co/u/YUUTA.INOUE-JPN)\
**Replies:** 1\
**Last updated:** [April 3, 2023, 5:57am UTC](https://discuss.elastic.co/t/about-elastalert-errors/329138 "2023-04-03T05:57:31Z")

</div>

We would like to use elasrticsearch and kibana to achieve the ability to email administrators about unusual events. We're using elastalert2 for this purpose but the filter is in error. We have spent a lot of time on th…

---

## [Logstash and mongodb connection error](https://discuss.elastic.co/t/logstash-and-mongodb-connection-error/329153)

<div class="topic-metadata">

**Author:** [@jskang](https://discuss.elastic.co/u/jskang)\
**Replies:** 0\
**Last updated:** [April 3, 2023, 5:50am UTC](https://discuss.elastic.co/t/logstash-and-mongodb-connection-error/329153 "2023-04-03T05:50:34Z")

</div>

input{ jdbc{ jdbc\_driver\_library =\> "/home/admin/lg-862/lgstash-core/lib/jars/mongojdbc4.8.jar" jdbc\_driver\_class =\> "Java::com.wisecoders.dbschema.mongodb.JdbcDriver" jdbc\_connection\_string =\> "mongodb://XXXXXX:XXXX…

---

## [Kibana bar chart aggr query doc\_count](https://discuss.elastic.co/t/kibana-bar-chart-aggr-query-doc-count/329149)

<div class="topic-metadata">

**Author:** [@math1](https://discuss.elastic.co/u/math1)\
**Replies:** 4\
**Last updated:** [April 3, 2023, 5:44am UTC](https://discuss.elastic.co/t/kibana-bar-chart-aggr-query-doc-count/329149 "2023-04-03T05:44:38Z")

</div>

I want to draw the query statement below as a bar chart in Kibana. GET food\_info/\_search { "size": 0, "aggs": { "country": { "terms": { "field": "food.countryCode" }, "aggs": { …

---

## [Can't match string to format date](https://discuss.elastic.co/t/cant-match-string-to-format-date/329132)

<div class="topic-metadata">

**Author:** [@german](https://discuss.elastic.co/u/german)\
**Replies:** 4\
**Last updated:** [April 3, 2023, 3:30am UTC](https://discuss.elastic.co/t/cant-match-string-to-format-date/329132 "2023-04-03T03:30:23Z")

</div>

Hi everybody, I have a problem while I try to convert a string variable to timestamp. I'm using date module without successful result. Format date is dd/MM/yyyy hh:mm:ss.SSSSSS and originally the variable newDate is: …

---

## [Synthetics monitors are not working on Elastic Agent (Complete)](https://discuss.elastic.co/t/synthetics-monitors-are-not-working-on-elastic-agent-complete/328978)

<div class="topic-metadata">

**Author:** [@chrispangg](https://discuss.elastic.co/u/chrispangg)\
**Replies:** 1\
**Last updated:** [April 3, 2023, 12:31am UTC](https://discuss.elastic.co/t/synthetics-monitors-are-not-working-on-elastic-agent-complete/328978 "2023-04-03T00:31:15Z")

</div>

The Elastic Agent is running within a container, just like the rest of the stack, in my local environment. Tried this across different versions (on 8.7 now) and they all come back with the same error. Elastic Agent - Do…

---

## [Help with using Grok to parse these three log formats](https://discuss.elastic.co/t/help-with-using-grok-to-parse-these-three-log-formats/329107)

<div class="topic-metadata">

**Author:** [@roman-tasi](https://discuss.elastic.co/u/roman-tasi)\
**Replies:** 8\
**Last updated:** [April 2, 2023, 10:37pm UTC](https://discuss.elastic.co/t/help-with-using-grok-to-parse-these-three-log-formats/329107 "2023-04-02T22:37:55Z")

</div>

Hi I am experienced with Dissect but not Grok. I think I need to use Grok here because the log format varies between the logs, so dissect will only work on one format, not all three: Case 1: 2023-03-31 00:01:24,366 INF…

---

## [Users and Groups export](https://discuss.elastic.co/t/users-and-groups-export/329133)

<div class="topic-metadata">

**Author:** [@mruthyu](https://discuss.elastic.co/u/mruthyu)\
**Replies:** 0\
**Last updated:** [April 2, 2023, 6:47pm UTC](https://discuss.elastic.co/t/users-and-groups-export/329133 "2023-04-02T18:47:26Z")

</div>

Is it possible to export and import users and groups from Kibana, so that these can be managed in multiple life cycle environments? or the user and role related apis needs to be used?

---

## [Enhanced data table slow response in comparison to kibana discover search?](https://discuss.elastic.co/t/enhanced-data-table-slow-response-in-comparison-to-kibana-discover-search/329047)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 3\
**Last updated:** [April 2, 2023, 4:49pm UTC](https://discuss.elastic.co/t/enhanced-data-table-slow-response-in-comparison-to-kibana-discover-search/329047 "2023-04-02T16:49:55Z")

</div>

Hello @fbaligand , Can you please let me understand why enhanced table/document table provides data slow or sometime hangs when filtered for huge data. Example 1 month data fetch,document count 20 million(here the data…

---

## [Getting Peak day and corresponding count based on last 30 days data](https://discuss.elastic.co/t/getting-peak-day-and-corresponding-count-based-on-last-30-days-data/329126)

<div class="topic-metadata">

**Author:** [@Yadhav](https://discuss.elastic.co/u/Yadhav)\
**Replies:** 0\
**Last updated:** [April 2, 2023, 3:05pm UTC](https://discuss.elastic.co/t/getting-peak-day-and-corresponding-count-based-on-last-30-days-data/329126 "2023-04-02T15:05:49Z")

</div>

Hi, I have requirement to get max of count value along with its date in last 7 days time frame. Below is my kibana visualization setting. Here I need to get max of count value along with its date. Seeing forward to…

---

## [Upstream prematurely closed connection while connecting to Kibana](https://discuss.elastic.co/t/upstream-prematurely-closed-connection-while-connecting-to-kibana/329056)

<div class="topic-metadata">

**Author:** [@Ravi\_Prakash1](https://discuss.elastic.co/u/Ravi_Prakash1)\
**Replies:** 1\
**Last updated:** [April 2, 2023, 2:26pm UTC](https://discuss.elastic.co/t/upstream-prematurely-closed-connection-while-connecting-to-kibana/329056 "2023-04-02T14:26:03Z")

</div>

Hello , Need some help with issue which we are facing while connecting to Kibana via Nginx using proxy\_pass. We are using ECK operator on Openshift ( Elasticsearch (ECK) Operator 2.6.2 provided by Elastic ) . While d…

---

## [Timestamp search between two fields](https://discuss.elastic.co/t/timestamp-search-between-two-fields/329048)

<div class="topic-metadata">

**Author:** [@Farah\_Bhr](https://discuss.elastic.co/u/Farah_Bhr)\
**Replies:** 4\
**Last updated:** [April 2, 2023, 11:32am UTC](https://discuss.elastic.co/t/timestamp-search-between-two-fields/329048 "2023-04-02T11:32:53Z")

</div>

In my use case, I created two fields for the values of start\_time and end\_time based on some indicators in the log lines with kibana discover , I want to search for all the log lines that their timestamp is between thes…

---

## [Watchers are not working after elasticsearch migration 7.16.1 to 8.5.1](https://discuss.elastic.co/t/watchers-are-not-working-after-elasticsearch-migration-7-16-1-to-8-5-1/328733)

<div class="topic-metadata">

**Author:** [@mkaymak](https://discuss.elastic.co/u/mkaymak)\
**Replies:** 1\
**Last updated:** [April 2, 2023, 2:57am UTC](https://discuss.elastic.co/t/watchers-are-not-working-after-elasticsearch-migration-7-16-1-to-8-5-1/328733 "2023-04-02T02:57:59Z")

</div>

After migrating Elasticsearch version 7.16.1 to 8.5.1 The watchers which basically find the error logs and send them to our messaging channel started to not working. When I simulate my watcher the error message is: "…

---

## [How to add my network logs of my applications to elastic/observability](https://discuss.elastic.co/t/how-to-add-my-network-logs-of-my-applications-to-elastic-observability/327704)

<div class="topic-metadata">

**Author:** [@schavaku](https://discuss.elastic.co/u/schavaku)\
**Replies:** 12\
**Last updated:** [April 2, 2023, 2:12am UTC](https://discuss.elastic.co/t/how-to-add-my-network-logs-of-my-applications-to-elastic-observability/327704 "2023-04-02T02:12:34Z")

</div>

I would like to access my logs and create a dashboard in Elasticsearch/observability. Please let me know how to integrate the application logs from the network. I would like to know the steps.

---

## [Elastic Filter](https://discuss.elastic.co/t/elastic-filter/329104)

<div class="topic-metadata">

**Author:** [@oleksiiorel](https://discuss.elastic.co/u/oleksiiorel)\
**Replies:** 8\
**Last updated:** [April 1, 2023, 4:57pm UTC](https://discuss.elastic.co/t/elastic-filter/329104 "2023-04-01T16:57:52Z")

</div>

I import a csv file via logstash "filter cvs" into Elasticsearch. One of the cells in a table (CVS file) contains several strings example: (categoty, subcategory, sub\_subcategory). I would like to split these strings int…

---

## [Today Avg value vs Moving AVG (14 days) value to trigger an alert based on DSL query](https://discuss.elastic.co/t/today-avg-value-vs-moving-avg-14-days-value-to-trigger-an-alert-based-on-dsl-query/328527)

<div class="topic-metadata">

**Author:** [@cpu](https://discuss.elastic.co/u/cpu)\
**Replies:** 9\
**Last updated:** [April 1, 2023, 9:38am UTC](https://discuss.elastic.co/t/today-avg-value-vs-moving-avg-14-days-value-to-trigger-an-alert-based-on-dsl-query/328527 "2023-04-01T09:38:23Z")

</div>

Hi All, I'm trying to setup an alert (in Stack Management --\> Rules and Connectors -- Rules) to track when the "today" AVG value on a field is lower than the moving AVG (14 days) value for the same field. This check sh…

---

## [Master not discovered yet, this node has not previously joined a bootstrapped](https://discuss.elastic.co/t/master-not-discovered-yet-this-node-has-not-previously-joined-a-bootstrapped/329093)

<div class="topic-metadata">

**Author:** [@williamsun](https://discuss.elastic.co/u/williamsun)\
**Replies:** 1\
**Last updated:** [April 1, 2023, 6:20am UTC](https://discuss.elastic.co/t/master-not-discovered-yet-this-node-has-not-previously-joined-a-bootstrapped/329093 "2023-04-01T06:20:37Z")

</div>

My issue is related to the last post. Master not discovered yet, this node has not previously joined a bootstrapped ====== I installed Elasticsearch 8.7.0 on AWS EKS 1.23 with three master Pods, three Data Pods and tw…

---

## [Elastic Defend - impact on application](https://discuss.elastic.co/t/elastic-defend-impact-on-application/328880)

<div class="topic-metadata">

**Author:** [@GKre](https://discuss.elastic.co/u/GKre)\
**Replies:** 1\
**Last updated:** [April 1, 2023, 4:48am UTC](https://discuss.elastic.co/t/elastic-defend-impact-on-application/328880 "2023-04-01T04:48:50Z")

</div>

Hello, i deployed Elastic Defend Integration on my endpoints and also on my two DC's. One of the DC's is hosting go1984 - a video surveilance application i use since many years. Soon after the Integration had been dep…

---

## [How can I join or paste array elements as of a one element?](https://discuss.elastic.co/t/how-can-i-join-or-paste-array-elements-as-of-a-one-element/329089)

<div class="topic-metadata">

**Author:** [@german](https://discuss.elastic.co/u/german)\
**Replies:** 2\
**Last updated:** [April 1, 2023, 3:08am UTC](https://discuss.elastic.co/t/how-can-i-join-or-paste-array-elements-as-of-a-one-element/329089 "2023-04-01T03:08:19Z")

</div>

Hi everybody, First of all, thanks for your time. I have a question regarding to Logstash. I would like to join some array elements as of a specific element. The log that I am processing, the first six fields have the …

---

## [Data stream rollover & writing documents at pre-rollover date](https://discuss.elastic.co/t/data-stream-rollover-writing-documents-at-pre-rollover-date/329086)

<div class="topic-metadata">

**Author:** [@nouknouk](https://discuss.elastic.co/u/nouknouk)\
**Replies:** 2\
**Last updated:** [April 1, 2023, 12:14am UTC](https://discuss.elastic.co/t/data-stream-rollover-writing-documents-at-pre-rollover-date/329086 "2023-04-01T00:14:58Z")

</div>

Hi, I brand new to the concept of data streams, and I'm trying to understand the concepts & limits behind them. So sorry in advance if my question is a dumb one. Let's say: I configure a data stream "foo" with rollo…

---

## [How to link to entries triggering a rule](https://discuss.elastic.co/t/how-to-link-to-entries-triggering-a-rule/327334)

<div class="topic-metadata">

**Author:** [@blindahl](https://discuss.elastic.co/u/blindahl)\
**Replies:** 6\
**Last updated:** [March 31, 2023, 9:19pm UTC](https://discuss.elastic.co/t/how-to-link-to-entries-triggering-a-rule/327334 "2023-03-31T21:19:26Z")

</div>

We have setup some Rules and Alerts that should trigger if we get error in our logs. In the mail that is sent when a rule is triggered it feels natural to include a link to Discover view with some filters setup and with …

[Previous page](https://discuss.elastic.co/latest.md?page=723)

[Next page](https://discuss.elastic.co/latest.md?page=725)
