# Latest

**URL:** https://discuss.elastic.co/latest.md?page=738

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 739

---

## [Threat intelligence](https://discuss.elastic.co/t/threat-intelligence/328211)

<div class="topic-metadata">

**Author:** [@ermilan2309](https://discuss.elastic.co/u/ermilan2309)\
**Replies:** 7\
**Last updated:** [March 22, 2023, 9:30pm UTC](https://discuss.elastic.co/t/threat-intelligence/328211 "2023-03-22T21:30:33Z")

</div>

Hello, I would like to integrate threat intelligence with wazuh. How can I do that. what are the ways to archive this ? I have deployed the hive , cortex and MISP for threat intelligence but do not know how to integra…

---

## [Remove Specific Field matching pattern](https://discuss.elastic.co/t/remove-specific-field-matching-pattern/328260)

<div class="topic-metadata">

**Author:** [@rubhamra](https://discuss.elastic.co/u/rubhamra)\
**Replies:** 4\
**Last updated:** [March 22, 2023, 8:55pm UTC](https://discuss.elastic.co/t/remove-specific-field-matching-pattern/328260 "2023-03-22T20:55:44Z")

</div>

Hello I am trying to remove specific fields in logstash before it goes to elasticssearch, I tried below config. with drop option. if "\[response\]\[body\]\[entries\]\[values\]" == '^n1D.\*' { drop { } } I have a…

---

## [It is not possible to install Multi-tenancy in kibana](https://discuss.elastic.co/t/it-is-not-possible-to-install-multi-tenancy-in-kibana/328274)

<div class="topic-metadata">

**Author:** [@Marco\_Batista\_12](https://discuss.elastic.co/u/Marco_Batista_12)\
**Replies:** 1\
**Last updated:** [March 22, 2023, 8:50pm UTC](https://discuss.elastic.co/t/it-is-not-possible-to-install-multi-tenancy-in-kibana/328274 "2023-03-22T20:50:21Z")

</div>

There is no possibility or plugin for the latest version to install Multi-tenancy.

---

## [Speed question between v5 and 7 and 8](https://discuss.elastic.co/t/speed-question-between-v5-and-7-and-8/328291)

<div class="topic-metadata">

**Author:** [@Ahmed\_Alsamarrai](https://discuss.elastic.co/u/Ahmed_Alsamarrai)\
**Replies:** 0\
**Last updated:** [March 22, 2023, 7:56pm UTC](https://discuss.elastic.co/t/speed-question-between-v5-and-7-and-8/328291 "2023-03-22T19:56:37Z")

</div>

Hi, We are facing a situation which we would like to resolve. We have a server running Elastic version 5.6 (on Docker). We wanted to upgrade and tried 7.17, on the same network, on a machine which is identical and also…

---

## [Unable to PUT \_index\_template which was captured from GET \_index\_template](https://discuss.elastic.co/t/unable-to-put-index-template-which-was-captured-from-get-index-template/328221)

<div class="topic-metadata">

**Author:** [@eeijlar](https://discuss.elastic.co/u/eeijlar)\
**Replies:** 4\
**Last updated:** [March 22, 2023, 7:14pm UTC](https://discuss.elastic.co/t/unable-to-put-index-template-which-was-captured-from-get-index-template/328221 "2023-03-22T19:14:32Z")

</div>

I am getting an index template as follows: curl -X GET http://localhost:9200/\_index\_template/filebeat\* \> /var/tmp/filebeat-template.json Now I want to PUT the same template into another elastic instance: curl http://…

---

## [Snapshots and malicious deletion of backups](https://discuss.elastic.co/t/snapshots-and-malicious-deletion-of-backups/328191)

<div class="topic-metadata">

**Author:** [@jgimenez](https://discuss.elastic.co/u/jgimenez)\
**Replies:** 2\
**Last updated:** [March 22, 2023, 7:07pm UTC](https://discuss.elastic.co/t/snapshots-and-malicious-deletion-of-backups/328191 "2023-03-22T19:07:10Z")

</div>

Hi there, I'm evaluating the options to protect against malicious deletion of backups. The recommendation is usually to keep some of the backups in offline storage and give the backup process the minimum permission poss…

---

## [{"statusCode":503,"error":"Service Unavailable","message":"License is not available."}](https://discuss.elastic.co/t/statuscode-503-error-service-unavailable-message-license-is-not-available/326340)

<div class="topic-metadata">

**Author:** [@nvelumani](https://discuss.elastic.co/u/nvelumani)\
**Replies:** 5\
**Last updated:** [March 22, 2023, 6:43pm UTC](https://discuss.elastic.co/t/statuscode-503-error-service-unavailable-message-license-is-not-available/326340 "2023-03-22T18:43:59Z")

</div>

Hello Team, I have installed elastic version 8.5.2 on three node cluster, it runs good. when I take down down node 2 (master -2), cluster is up and running with other two nodes. when I take down down node 3 (master -3…

---

## [Error when starting Elasticsearch single node](https://discuss.elastic.co/t/error-when-starting-elasticsearch-single-node/328207)

<div class="topic-metadata">

**Author:** [@abctha1234](https://discuss.elastic.co/u/abctha1234)\
**Replies:** 2\
**Last updated:** [March 22, 2023, 5:17pm UTC](https://discuss.elastic.co/t/error-when-starting-elasticsearch-single-node/328207 "2023-03-22T17:17:20Z")

</div>

My docker-compose.yaml elasticsearch: container\_name: elasticsearch image: docker.elastic.co/elasticsearch/elasticsearch:8.6.2 volumes: - elasticsearch\_data:/usr/share/elasticsearch/data - cert…

---

## [HTTP Request details](https://discuss.elastic.co/t/http-request-details/327884)

<div class="topic-metadata">

**Author:** [@Scott\_Chapman1](https://discuss.elastic.co/u/Scott_Chapman1)\
**Replies:** 8\
**Last updated:** [March 22, 2023, 5:05pm UTC](https://discuss.elastic.co/t/http-request-details/327884 "2023-03-22T17:05:54Z")

</div>

I'm doing a new deployment, and playing around with the java APM agent. We are using Apache HTTPClient (supported version), and I can see that I can spans created for requests, but I don't see things like what the URL is…

---

## [Elasticsearch endpoint giving http 504 error](https://discuss.elastic.co/t/elasticsearch-endpoint-giving-http-504-error/328276)

<div class="topic-metadata">

**Author:** [@Raman\_Sawhney](https://discuss.elastic.co/u/Raman_Sawhney)\
**Replies:** 1\
**Last updated:** [March 22, 2023, 4:58pm UTC](https://discuss.elastic.co/t/elasticsearch-endpoint-giving-http-504-error/328276 "2023-03-22T16:58:16Z")

</div>

Hello Team, I am trying to install Elasticsearch on Kubernetes (1.24) version using the Elasticsearch(8.5.1) helm charts. I was able to install the charts and pods are in running status but when i tried to access the e…

---

## [Convert unix timestamp to epoch\_second and assign to @timestamp](https://discuss.elastic.co/t/convert-unix-timestamp-to-epoch-second-and-assign-to-timestamp/328133)

<div class="topic-metadata">

**Author:** [@nika](https://discuss.elastic.co/u/nika)\
**Replies:** 1\
**Last updated:** [March 22, 2023, 4:54pm UTC](https://discuss.elastic.co/t/convert-unix-timestamp-to-epoch-second-and-assign-to-timestamp/328133 "2023-03-22T16:54:11Z")

</div>

I'm sorry if this is covered elsewhere, but I have been having trouble getting this to work. I have a field in a log being sent to elasticsearch from filebeat. The log is ndjson formatted. The field is called time and…

---

## [DSL query in Kibana Rules does not work the same as from Dev Tools](https://discuss.elastic.co/t/dsl-query-in-kibana-rules-does-not-work-the-same-as-from-dev-tools/327577)

<div class="topic-metadata">

**Author:** [@mohsin106](https://discuss.elastic.co/u/mohsin106)\
**Replies:** 9\
**Last updated:** [March 22, 2023, 4:30pm UTC](https://discuss.elastic.co/t/dsl-query-in-kibana-rules-does-not-work-the-same-as-from-dev-tools/327577 "2023-03-22T16:30:12Z")

</div>

Hello, I'm using Elastic 7.17.6 and I have an alert rule set up which is using the below DSL query to search for the data: { "size": 0, "query": { "bool": { "must": \[ { "match": { "empty": "true" …

---

## [ES persistent outages](https://discuss.elastic.co/t/es-persistent-outages/327395)

<div class="topic-metadata">

**Author:** [@orthecreedence](https://discuss.elastic.co/u/orthecreedence)\
**Replies:** 5\
**Last updated:** [March 22, 2023, 4:22pm UTC](https://discuss.elastic.co/t/es-persistent-outages/327395 "2023-03-22T16:22:35Z")

</div>

Hello. We recently upgraded to ES 7.17.9 (8.x is on the radar, but we have a lot of reindexing to do before then) and are having a lot of problems. We're using a fairly stock configuration on EC2. Our setup consists of …

---

## [Internal\_networks setting for netflow integration](https://discuss.elastic.co/t/internal-networks-setting-for-netflow-integration/327586)

<div class="topic-metadata">

**Author:** [@Andres\_Altamirano](https://discuss.elastic.co/u/Andres_Altamirano)\
**Replies:** 1\
**Last updated:** [March 22, 2023, 9:09am UTC](https://discuss.elastic.co/t/internal-networks-setting-for-netflow-integration/327586 "2023-03-22T09:09:36Z")

</div>

Hi, I'm trying to replace filebeat netflow module with elastic integration "netflow" that is deployed on a policy running on a few servers. Flows are indexed properly, but there is no way to set the internal\_networks p…

---

## [Cisco AnyConnect VPN Integration](https://discuss.elastic.co/t/cisco-anyconnect-vpn-integration/327942)

<div class="topic-metadata">

**Author:** [@MDimsey](https://discuss.elastic.co/u/MDimsey)\
**Replies:** 2\
**Last updated:** [March 22, 2023, 4:03pm UTC](https://discuss.elastic.co/t/cisco-anyconnect-vpn-integration/327942 "2023-03-22T16:03:33Z")

</div>

Hello, My organization is looking to use the Elastic Agent as a replacement for running dedicated winlogbeat.exe agents on hosts. However, through winlogbeat we were able to collect logs from Cisco AnyConnect Security M…

---

## [Why I get after Client.Indices.Create() a second and unassigned index?](https://discuss.elastic.co/t/why-i-get-after-client-indices-create-a-second-and-unassigned-index/328264)

<div class="topic-metadata">

**Author:** [@frankmehlhop.com](https://discuss.elastic.co/u/frankmehlhop.com)\
**Replies:** 2\
**Last updated:** [March 22, 2023, 3:34pm UTC](https://discuss.elastic.co/t/why-i-get-after-client-indices-create-a-second-and-unassigned-index/328264 "2023-03-22T15:34:12Z")

</div>

I create a index on Elasticsearch with the C# code below. But instead of creating one assigned index I find a second unassigned index with the same name. I don't want and need this second (unassigned) index. My elasticse…

---

## [TSVB "Your query attempted to fetch too much data." when interval is changed](https://discuss.elastic.co/t/tsvb-your-query-attempted-to-fetch-too-much-data-when-interval-is-changed/328195)

<div class="topic-metadata">

**Author:** [@Joshua\_Boyd](https://discuss.elastic.co/u/Joshua_Boyd)\
**Replies:** 4\
**Last updated:** [March 22, 2023, 3:40pm UTC](https://discuss.elastic.co/t/tsvb-your-query-attempted-to-fetch-too-much-data-when-interval-is-changed/328195 "2023-03-22T15:40:09Z")

</div>

Fails with 1m interval For 30day interval or greater it works fine, but i I want to group by month I set the advance setting from 2000 to 10000 based on another thread, but no luck Any ideas?

---

## [Counter rate from log entries](https://discuss.elastic.co/t/counter-rate-from-log-entries/328148)

<div class="topic-metadata">

**Author:** [@andreycha](https://discuss.elastic.co/u/andreycha)\
**Replies:** 6\
**Last updated:** [March 22, 2023, 3:31pm UTC](https://discuss.elastic.co/t/counter-rate-from-log-entries/328148 "2023-03-22T15:31:24Z")

</div>

Hi, I'm trying to cheaply get some numeric data out of our logs. There an event that we log every time it happens and I'd like to see the rate at which it happens. I've added a lens with a filter for that log message an…

---

## [Datastream with upsert](https://discuss.elastic.co/t/datastream-with-upsert/328266)

<div class="topic-metadata">

**Author:** [@djkprojects](https://discuss.elastic.co/u/djkprojects)\
**Replies:** 1\
**Last updated:** [March 22, 2023, 3:28pm UTC](https://discuss.elastic.co/t/datastream-with-upsert/328266 "2023-03-22T15:28:45Z")

</div>

Hello, We are pulling data from MS SQL database into Elastic via Logstash which is working fine however some records get updated and so we want to update the existing entries in Elastic accordingly. The data is stored …

---

## [Data compression and retention](https://discuss.elastic.co/t/data-compression-and-retention/328252)

<div class="topic-metadata">

**Author:** [@krzychohoho](https://discuss.elastic.co/u/krzychohoho)\
**Replies:** 3\
**Last updated:** [March 22, 2023, 2:40pm UTC](https://discuss.elastic.co/t/data-compression-and-retention/328252 "2023-03-22T14:40:24Z")

</div>

Hi, I have a task in which i need to store data in elastic cluster. Altogether i have 12TB of disk space available. These are the requirments: 90 days of data retention One replica shard per one primary shard 100GB of…

---

## [Elastic-agent with Misp integration policy no data received while no errors comes up](https://discuss.elastic.co/t/elastic-agent-with-misp-integration-policy-no-data-received-while-no-errors-comes-up/328183)

<div class="topic-metadata">

**Author:** [@Nicolas\_Pellletier](https://discuss.elastic.co/u/Nicolas_Pellletier)\
**Replies:** 8\
**Last updated:** [March 22, 2023, 2:37pm UTC](https://discuss.elastic.co/t/elastic-agent-with-misp-integration-policy-no-data-received-while-no-errors-comes-up/328183 "2023-03-22T14:37:58Z")

</div>

Hello, I've got a standalone elastic-agent deployed on localhost where my MISP instance is running. I'm trying to integrate MISP IOC's to Elastic in order to use the dashboard. I don't understand why i don't receive a…

---

## [Bug: No Misp event data send to Kibana when Threat intel module used](https://discuss.elastic.co/t/bug-no-misp-event-data-send-to-kibana-when-threat-intel-module-used/327979)

<div class="topic-metadata">

**Author:** [@Nicolas\_Pelletier](https://discuss.elastic.co/u/Nicolas_Pelletier)\
**Replies:** 5\
**Last updated:** [March 22, 2023, 2:24pm UTC](https://discuss.elastic.co/t/bug-no-misp-event-data-send-to-kibana-when-threat-intel-module-used/327979 "2023-03-22T14:24:03Z")

</div>

Hello, I'm trying to integrate IOCs from MISP to Elastic stack (ELK) using the Filebeat Threat intel module. I'm receiving event in Analytics Discover panel of Kibana with filebeat-\* toggle on: (see below image) B…

---

## [Increase doc\_count even if record is same in date\_histogram on Array field](https://discuss.elastic.co/t/increase-doc-count-even-if-record-is-same-in-date-histogram-on-array-field/328257)

<div class="topic-metadata">

**Author:** [@AbhimanyuSharma](https://discuss.elastic.co/u/AbhimanyuSharma)\
**Replies:** 0\
**Last updated:** [March 22, 2023, 2:16pm UTC](https://discuss.elastic.co/t/increase-doc-count-even-if-record-is-same-in-date-histogram-on-array-field/328257 "2023-03-22T14:16:41Z")

</div>

I have an object / array field which contains date-time. This field contains every second of the duration between start and end time of some event. I am doing this because I want to see the running events on each second.…

---

## [Error loading Monitor Management](https://discuss.elastic.co/t/error-loading-monitor-management/326104)

<div class="topic-metadata">

**Author:** [@Juan\_Pablo\_Carvajal](https://discuss.elastic.co/u/Juan_Pablo_Carvajal)\
**Replies:** 11\
**Last updated:** [March 22, 2023, 2:02pm UTC](https://discuss.elastic.co/t/error-loading-monitor-management/326104 "2023-03-22T14:02:32Z")

</div>

Hello! I am currently deploying synthetic monitoring for a few applications. But when trying to enable Monitor Management, I get the following message: Error loading Monitor Management Monitor Management settings coul…

---

## [Intermittent outbound connection issue to elastic cloud from azure app service](https://discuss.elastic.co/t/intermittent-outbound-connection-issue-to-elastic-cloud-from-azure-app-service/328181)

<div class="topic-metadata">

**Author:** [@chiragsharp](https://discuss.elastic.co/u/chiragsharp)\
**Replies:** 4\
**Last updated:** [March 22, 2023, 1:36pm UTC](https://discuss.elastic.co/t/intermittent-outbound-connection-issue-to-elastic-cloud-from-azure-app-service/328181 "2023-03-22T13:36:47Z")

</div>

Hello Folks, I have a Virto Commerce deployed in azure app service. From app service intermittently, I am getting below error for connection to elastic cloud. Invalid NEST response built from a unsuccessful () low leve…

---

## [Error talk to server](https://discuss.elastic.co/t/error-talk-to-server/328160)

<div class="topic-metadata">

**Author:** [@rachit](https://discuss.elastic.co/u/rachit)\
**Replies:** 11\
**Last updated:** [March 22, 2023, 1:00pm UTC](https://discuss.elastic.co/t/error-talk-to-server/328160 "2023-03-22T13:00:09Z")

</div>

Hi Team, I'm facing error while connecting apm to Elasticsearch. apm-server test output elasticsearch: http://localhost:9200... parse url... OK connection... parse host... OK dns lookup... OK addresses: 127.0.0.1…

---

## [Elastic shards are not storing data equally](https://discuss.elastic.co/t/elastic-shards-are-not-storing-data-equally/328235)

<div class="topic-metadata">

**Author:** [@Chanaka\_Liyanarachch](https://discuss.elastic.co/u/Chanaka_Liyanarachch)\
**Replies:** 1\
**Last updated:** [March 22, 2023, 12:39pm UTC](https://discuss.elastic.co/t/elastic-shards-are-not-storing-data-equally/328235 "2023-03-22T12:39:54Z")

</div>

elastic shards are not storing data equally,

---

## [Error al ejecutar docker compose](https://discuss.elastic.co/t/error-al-ejecutar-docker-compose/328239)

<div class="topic-metadata">

**Author:** [@karlosmartos](https://discuss.elastic.co/u/karlosmartos)\
**Replies:** 1\
**Last updated:** [March 22, 2023, 12:37pm UTC](https://discuss.elastic.co/t/error-al-ejecutar-docker-compose/328239 "2023-03-22T12:37:18Z")

</div>

ERROR: \[1\] bootstrap checks failed. You must address the points described in the following \[1\] lines before starting Elasticsearch.

---

## [Filebeat with multiple log path should direct to different Index and Should follow ILM,ILM policy and rollover already defined in elastic](https://discuss.elastic.co/t/filebeat-with-multiple-log-path-should-direct-to-different-index-and-should-follow-ilm-ilm-policy-and-rollover-already-defined-in-elastic/328236)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 0\
**Last updated:** [March 22, 2023, 11:17am UTC](https://discuss.elastic.co/t/filebeat-with-multiple-log-path-should-direct-to-different-index-and-should-follow-ilm-ilm-policy-and-rollover-already-defined-in-elastic/328236 "2023-03-22T11:17:03Z")

</div>

Hello All, I've a requirement wherein I would like to have single filebeat.yml and this will have different log paths and will direct the data to respective diffrent index according to path. Now this filebeat.yml would…

---

## [APM on Azure Functions](https://discuss.elastic.co/t/apm-on-azure-functions/327947)

<div class="topic-metadata">

**Author:** [@PedroBrasilBorges](https://discuss.elastic.co/u/PedroBrasilBorges)\
**Replies:** 4\
**Last updated:** [March 22, 2023, 11:45am UTC](https://discuss.elastic.co/t/apm-on-azure-functions/327947 "2023-03-22T11:45:48Z")

</div>

Hello, On the recent update, v1.20.0, it was added support for the Azure Functions though the new nuget package, but I'm having some doubts, and I don't know if it's not supported or if I'm doing something wrong. I saw…

[Previous page](https://discuss.elastic.co/latest.md?page=737)

[Next page](https://discuss.elastic.co/latest.md?page=739)
