# Latest

**URL:** https://discuss.elastic.co/latest.md?page=751

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 752

---

## [Osquery Manager integration: Settings page stuck updating](https://discuss.elastic.co/t/osquery-manager-integration-settings-page-stuck-updating/327508)

<div class="topic-metadata">

**Author:** [@ceekay](https://discuss.elastic.co/u/ceekay)\
**Replies:** 0\
**Last updated:** [March 12, 2023, 11:15pm UTC](https://discuss.elastic.co/t/osquery-manager-integration-settings-page-stuck-updating/327508 "2023-03-12T23:15:57Z")

</div>

Hi there, I have an air-gapped install using the Elastic Docker image for the integration registry. The Docker container is running on that same node as Kibana. This is all fine and integration installs and such are wor…

---

## [Filebeat custom module](https://discuss.elastic.co/t/filebeat-custom-module/327509)

<div class="topic-metadata">

**Author:** [@stefws](https://discuss.elastic.co/u/stefws)\
**Replies:** 0\
**Last updated:** [March 12, 2023, 11:49pm UTC](https://discuss.elastic.co/t/filebeat-custom-module/327509 "2023-03-12T23:49:26Z")

</div>

Not finding the doc of modules sufficient to make me a custom module. Would it be possible to convert a filebeat.inputs section to a filebeat.config.modules configuration? Eg. having working filestream like this: - t…

---

## [Error: Kibana server is not ready yet](https://discuss.elastic.co/t/error-kibana-server-is-not-ready-yet/327488)

<div class="topic-metadata">

**Author:** [@Matt\_Johnston](https://discuss.elastic.co/u/Matt_Johnston)\
**Replies:** 18\
**Last updated:** [March 12, 2023, 11:29pm UTC](https://discuss.elastic.co/t/error-kibana-server-is-not-ready-yet/327488 "2023-03-12T23:29:39Z")

</div>

Hello. I'm running Elasticsearch and Kibana via docker containers, whose images I'm building from the Dockerfiles from this repository: GitHub - elastic/dockerfiles: Dockerfiles for the official Elastic Stack images. Whe…

---

## [Filebeat vs elastic putput](https://discuss.elastic.co/t/filebeat-vs-elastic-putput/327506)

<div class="topic-metadata">

**Author:** [@stefws](https://discuss.elastic.co/u/stefws)\
**Replies:** 10\
**Last updated:** [March 12, 2023, 9:47pm UTC](https://discuss.elastic.co/t/filebeat-vs-elastic-putput/327506 "2023-03-12T21:47:10Z")

</div>

Hi Need a wall to play against here TIA :slight\_smile: What am I missing out on, I wonder, when trying to launch filebeat.service. I'm see these errors: ==\> /var/log/filebeat/filebeat-20230312.ndjson \<== {"log.level":…

---

## [Visualizations not working in dashboard](https://discuss.elastic.co/t/visualizations-not-working-in-dashboard/327505)

<div class="topic-metadata">

**Author:** [@Sara\_YB](https://discuss.elastic.co/u/Sara_YB)\
**Replies:** 0\
**Last updated:** [March 12, 2023, 5:12pm UTC](https://discuss.elastic.co/t/visualizations-not-working-in-dashboard/327505 "2023-03-12T17:12:27Z")

</div>

I already upgraded to Elastic 8.6, and repalced beats by Elastic Agent. The problem is that because of some visualizations built in using filebeat, they stopped showing data after the replacement. So, is there any work…

---

## [False alert about certificate expiry](https://discuss.elastic.co/t/false-alert-about-certificate-expiry/327504)

<div class="topic-metadata">

**Author:** [@Sara\_YB](https://discuss.elastic.co/u/Sara_YB)\
**Replies:** 0\
**Last updated:** [March 12, 2023, 5:05pm UTC](https://discuss.elastic.co/t/false-alert-about-certificate-expiry/327504 "2023-03-12T17:05:05Z")

</div>

The certificate is up to date; however, it is not updated in Kibana as indicated in the below screenshot: This caused sending fslse alerts. I need your help to solve this issue as it is happening with this certifica…

---

## [Simple question about timestamp in logs](https://discuss.elastic.co/t/simple-question-about-timestamp-in-logs/327485)

<div class="topic-metadata">

**Author:** [@Mark\_S](https://discuss.elastic.co/u/Mark_S)\
**Replies:** 3\
**Last updated:** [March 12, 2023, 4:31pm UTC](https://discuss.elastic.co/t/simple-question-about-timestamp-in-logs/327485 "2023-03-12T16:31:42Z")

</div>

When I create an index and use Logstash to send logfiles, I use the option start\_position =\> "beginning". However when viewing "discover" mode in kibana, I only see the logs after the index was created. Shouldn't there …

---

## [ILM doesn't rollover](https://discuss.elastic.co/t/ilm-doesnt-rollover/327497)

<div class="topic-metadata">

**Author:** [@m3bgwad](https://discuss.elastic.co/u/m3bgwad)\
**Replies:** 1\
**Last updated:** [March 12, 2023, 4:46pm UTC](https://discuss.elastic.co/t/ilm-doesnt-rollover/327497 "2023-03-12T16:46:56Z")

</div>

Hello all, can any one help me to get the ILM wrong, I created ILM for support the retention period so everything is well but the new rollover indices doesn't store any data (the docs count is 0), I need to move the da…

---

## [Generate image out of kibana](https://discuss.elastic.co/t/generate-image-out-of-kibana/326914)

<div class="topic-metadata">

**Author:** [@mayer](https://discuss.elastic.co/u/mayer)\
**Replies:** 4\
**Last updated:** [March 12, 2023, 3:29pm UTC](https://discuss.elastic.co/t/generate-image-out-of-kibana/326914 "2023-03-12T15:29:22Z")

</div>

Dear All, We are running ELK latest version with authentication available on Intranet but not accessible from Internet. We want to make some images public available but we do not want to give access to ELK directly for …

---

## [Help with http certs in elasticsearch](https://discuss.elastic.co/t/help-with-http-certs-in-elasticsearch/327371)

<div class="topic-metadata">

**Author:** [@Mary2022](https://discuss.elastic.co/u/Mary2022)\
**Replies:** 5\
**Last updated:** [March 12, 2023, 1:11pm UTC](https://discuss.elastic.co/t/help-with-http-certs-in-elasticsearch/327371 "2023-03-12T13:11:19Z")

</div>

I used elasticsearch-certutil with my companies CA.jks to create http certificates for my node but I am at the last step to send the output zip file to the path I give I get the following error: Exception in thread "mai…

---

## [Grok (or any alternative) to search for keywords in logs](https://discuss.elastic.co/t/grok-or-any-alternative-to-search-for-keywords-in-logs/327351)

<div class="topic-metadata">

**Author:** [@Mark\_S](https://discuss.elastic.co/u/Mark_S)\
**Replies:** 14\
**Last updated:** [March 12, 2023, 12:34pm UTC](https://discuss.elastic.co/t/grok-or-any-alternative-to-search-for-keywords-in-logs/327351 "2023-03-12T12:34:26Z")

</div>

Hello, Is it possible to create keywords in logstash, by searching for them in the message? The logs are formatted in the following way, however they are not always in the same place - they could be embedded in other m…

---

## [Curator 8 not showing all indexes](https://discuss.elastic.co/t/curator-8-not-showing-all-indexes/327381)

<div class="topic-metadata">

**Author:** [@alon\_carmelly](https://discuss.elastic.co/u/alon_carmelly)\
**Replies:** 2\
**Last updated:** [March 12, 2023, 12:17pm UTC](https://discuss.elastic.co/t/curator-8-not-showing-all-indexes/327381 "2023-03-12T12:17:07Z")

</div>

I am usining : pip install -U elasticsearch-curator to get version 8 ran: curator --dry-run --config ./curator.yml ./delete\_log\_files\_curator.yml action file :slight\_smile: actions: 1: action: delete\_indices …

---

## [Canvas: timefilter being ignored](https://discuss.elastic.co/t/canvas-timefilter-being-ignored/327376)

<div class="topic-metadata">

**Author:** [@JeroenK](https://discuss.elastic.co/u/JeroenK)\
**Replies:** 2\
**Last updated:** [March 12, 2023, 9:28am UTC](https://discuss.elastic.co/t/canvas-timefilter-being-ignored/327376 "2023-03-12T09:28:26Z")

</div>

Ok, this used to work somewhere in release 8.5 or before (I did not get around posting this for some months, at that moment I fixed the issue with a workaround, but I'm still puzzled about it) timefilter column="timesta…

---

## [How to filter buckets based on the comparison of two sub-aggregation metrics in ElasticSearch (python)?](https://discuss.elastic.co/t/how-to-filter-buckets-based-on-the-comparison-of-two-sub-aggregation-metrics-in-elasticsearch-python/327498)

<div class="topic-metadata">

**Author:** [@Ashar\_Ahmad](https://discuss.elastic.co/u/Ashar_Ahmad)\
**Replies:** 0\
**Last updated:** [March 12, 2023, 8:59am UTC](https://discuss.elastic.co/t/how-to-filter-buckets-based-on-the-comparison-of-two-sub-aggregation-metrics-in-elasticsearch-python/327498 "2023-03-12T08:59:20Z")

</div>

My index has documents with the following fields: user\_id, user\_name, post\_text, post\_sentiment where post\_sentiment is of type double, and represents the sentiment of the post. A post\_sentiment greater than 0 indicates …

---

## [Unbale to view logs but indices available](https://discuss.elastic.co/t/unbale-to-view-logs-but-indices-available/327496)

<div class="topic-metadata">

**Author:** [@Prabhakar\_D](https://discuss.elastic.co/u/Prabhakar_D)\
**Replies:** 6\
**Last updated:** [March 12, 2023, 8:20am UTC](https://discuss.elastic.co/t/unbale-to-view-logs-but-indices-available/327496 "2023-03-12T08:20:08Z")

</div>

Hi, ELK uable to view logs for specific period but indices available. Someone please suggest how to recover the indices which is already rolledup as per lifecycle

---

## [Scripted fields: text field returns null](https://discuss.elastic.co/t/scripted-fields-text-field-returns-null/327178)

<div class="topic-metadata">

**Author:** [@RonGros](https://discuss.elastic.co/u/RonGros)\
**Replies:** 5\
**Last updated:** [March 12, 2023, 6:54am UTC](https://discuss.elastic.co/t/scripted-fields-text-field-returns-null/327178 "2023-03-12T06:54:03Z")

</div>

Hi, I have an index with a lot of fields. I am trying to create a scripted field that will do some string manipulation on another field, but when I try to access it - I keep getting null What I've noticed is that if I t…

---

## [Logstash Keeps Restarting](https://discuss.elastic.co/t/logstash-keeps-restarting/327494)

<div class="topic-metadata">

**Author:** [@kirkofthefleet](https://discuss.elastic.co/u/kirkofthefleet)\
**Replies:** 1\
**Last updated:** [March 12, 2023, 3:06am UTC](https://discuss.elastic.co/t/logstash-keeps-restarting/327494 "2023-03-12T03:06:51Z")

</div>

Hello! Please forgive any "syntax errors" as I am a complete newb to all of the elastic stack. I am working on getting elasticstack working for my small IT business. I have a few servers that I am interested in monitor…

---

## [What AWS config file settings are honored?](https://discuss.elastic.co/t/what-aws-config-file-settings-are-honored/327490)

<div class="topic-metadata">

**Author:** [@marcoderama](https://discuss.elastic.co/u/marcoderama)\
**Replies:** 0\
**Last updated:** [March 11, 2023, 9:39pm UTC](https://discuss.elastic.co/t/what-aws-config-file-settings-are-honored/327490 "2023-03-11T21:39:24Z")

</div>

\[Elastic noob warning!\] Fundamentally, I'm trying to figure out how to automatically update temporary credentials for the Elastic AWS integration. I'm trying to configure my AWS Elastic Agent integration to use a shar…

---

## [Waiting for all shards copies to be active](https://discuss.elastic.co/t/waiting-for-all-shards-copies-to-be-active/327360)

<div class="topic-metadata">

**Author:** [@Gaurav\_kr](https://discuss.elastic.co/u/Gaurav_kr)\
**Replies:** 1\
**Last updated:** [March 11, 2023, 4:33pm UTC](https://discuss.elastic.co/t/waiting-for-all-shards-copies-to-be-active/327360 "2023-03-11T16:33:36Z")

</div>

Hi Team, I am using basic license version 8.0.0 of ELK, which is setup using docker. We are using ILM for hot, warm and cold phase but after completing the hot phase it is waiting in warm phase with an action "Waiting …

---

## [Kibana Vega: simple text-label](https://discuss.elastic.co/t/kibana-vega-simple-text-label/327489)

<div class="topic-metadata">

**Author:** [@joerg55](https://discuss.elastic.co/u/joerg55)\
**Replies:** 0\
**Last updated:** [March 11, 2023, 7:05pm UTC](https://discuss.elastic.co/t/kibana-vega-simple-text-label/327489 "2023-03-11T19:05:11Z")

</div>

Hi community, I need a simple text in vertical orientation. I found this: https://vega.github.io/vega/docs/marks/text/ but I'm not very familiar with vega and this example is not to understand by me. Can somebody give…

---

## [Error filebeat - Trying to retrieve too many docvalue\_fields](https://discuss.elastic.co/t/error-filebeat-trying-to-retrieve-too-many-docvalue-fields/327394)

<div class="topic-metadata">

**Author:** [@Maria\_Gabriela\_Perez](https://discuss.elastic.co/u/Maria_Gabriela_Perez)\
**Replies:** 1\
**Last updated:** [March 11, 2023, 4:30pm UTC](https://discuss.elastic.co/t/error-filebeat-trying-to-retrieve-too-many-docvalue-fields/327394 "2023-03-11T16:30:01Z")

</div>

\[illegal\_argument\_exception\] Trying to retrieve too many docvalue\_fields. Must be less than or equal to: \[200\] but was \[208\]. This limit can be set by changing the \[index.max\_docvalue\_fields\_search\] index level setting.

---

## [How to detect and avoid UDP input loss](https://discuss.elastic.co/t/how-to-detect-and-avoid-udp-input-loss/327483)

<div class="topic-metadata">

**Author:** [@YvesZhi](https://discuss.elastic.co/u/YvesZhi)\
**Replies:** 1\
**Last updated:** [March 11, 2023, 3:22pm UTC](https://discuss.elastic.co/t/how-to-detect-and-avoid-udp-input-loss/327483 "2023-03-11T15:22:26Z")

</div>

I'm using Envoy, which is kind of similar to Nginx, as the gateway of my micro-services backend. Since it's micro-service, there are five Envoys. All of envoys are deployed by Docker and their logs are sent to my Logsta…

---

## [How Translog Work on elastic](https://discuss.elastic.co/t/how-translog-work-on-elastic/325880)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 6\
**Last updated:** [March 11, 2023, 10:35am UTC](https://discuss.elastic.co/t/how-translog-work-on-elastic/325880 "2023-03-11T10:35:29Z")

</div>

Hi everyone, I have a question about translog. So here is the situation: I have one index with 1 primary and 1 replica shard and continuously ingesting data. If i read documentation, it says that primary and replica sh…

---

## [How to cut off the part of syslog](https://discuss.elastic.co/t/how-to-cut-off-the-part-of-syslog/327242)

<div class="topic-metadata">

**Author:** [@YvesZhi](https://discuss.elastic.co/u/YvesZhi)\
**Replies:** 2\
**Last updated:** [March 11, 2023, 6:25am UTC](https://discuss.elastic.co/t/how-to-cut-off-the-part-of-syslog/327242 "2023-03-11T06:25:51Z")

</div>

I've some micro services, which are deployed with Docker. They send their logs to my Logstash with the log driver syslog. Here is the config of my Logstash: input { syslog { port =\> 9771 type =\> "syslog" } }…

---

## [Insert multiple fields in nested array](https://discuss.elastic.co/t/insert-multiple-fields-in-nested-array/327415)

<div class="topic-metadata">

**Author:** [@Claudio\_Ract\_Costa](https://discuss.elastic.co/u/Claudio_Ract_Costa)\
**Replies:** 2\
**Last updated:** [March 11, 2023, 1:21am UTC](https://discuss.elastic.co/t/insert-multiple-fields-in-nested-array/327415 "2023-03-11T01:21:59Z")

</div>

Hi Guys I have the following input as example: generator { count =\> 1 lines =\> \[ '{ "RATING\_GROUP": "7,843,13", "CONSUMO": "328994,29715,13948" }' \] codec =\> json } Which filter can I use in Logstash to obtain a outp…

---

## [Elastic Agent USB Locking Feature](https://discuss.elastic.co/t/elastic-agent-usb-locking-feature/327323)

<div class="topic-metadata">

**Author:** [@ali.sharjeel](https://discuss.elastic.co/u/ali.sharjeel)\
**Replies:** 3\
**Last updated:** [March 10, 2023, 11:43pm UTC](https://discuss.elastic.co/t/elastic-agent-usb-locking-feature/327323 "2023-03-10T23:43:53Z")

</div>

Is there any feature like we have in antivirus to lock usb devices from plugging in Elastic Agent?

---

## [Elastic Security Rules Analytics](https://discuss.elastic.co/t/elastic-security-rules-analytics/326890)

<div class="topic-metadata">

**Author:** [@Alexander\_A](https://discuss.elastic.co/u/Alexander_A)\
**Replies:** 2\
**Last updated:** [March 10, 2023, 9:38pm UTC](https://discuss.elastic.co/t/elastic-security-rules-analytics/326890 "2023-03-10T21:38:13Z")

</div>

Is there a way to get how much time it gets to execute all security rules. In "Stack Management" -\> "Rules and Connectors" analytics available per each rule but summary analytics seems to be missing. For example all rule…

---

## [How to make a time series of discrete events](https://discuss.elastic.co/t/how-to-make-a-time-series-of-discrete-events/327367)

<div class="topic-metadata">

**Author:** [@gyannea](https://discuss.elastic.co/u/gyannea)\
**Replies:** 4\
**Last updated:** [March 10, 2023, 9:15pm UTC](https://discuss.elastic.co/t/how-to-make-a-time-series-of-discrete-events/327367 "2023-03-10T21:15:44Z")

</div>

It seems I can only make time series (including with TSBV) of numerical values. What I have are gateways that send a finite set of event types. What I would like to do is plot in a time series which type event was sent.…

---

## [Slow indexing speed, possibly related to filebeat misconfiguration](https://discuss.elastic.co/t/slow-indexing-speed-possibly-related-to-filebeat-misconfiguration/327283)

<div class="topic-metadata">

**Author:** [@alexandrpaliy](https://discuss.elastic.co/u/alexandrpaliy)\
**Replies:** 4\
**Last updated:** [March 10, 2023, 9:05pm UTC](https://discuss.elastic.co/t/slow-indexing-speed-possibly-related-to-filebeat-misconfiguration/327283 "2023-03-10T21:05:38Z")

</div>

I have actually no idea which tag/subforum to use, because I have an issue with a general filebeat -\> logstash -\> elasticsearch pipelinem and I am not entirely sure, is this issue related to ES indexing performance, or i…

---

## [Going from data nodes to hot and warm nodes](https://discuss.elastic.co/t/going-from-data-nodes-to-hot-and-warm-nodes/327311)

<div class="topic-metadata">

**Author:** [@reswob](https://discuss.elastic.co/u/reswob)\
**Replies:** 1\
**Last updated:** [March 10, 2023, 8:36pm UTC](https://discuss.elastic.co/t/going-from-data-nodes-to-hot-and-warm-nodes/327311 "2023-03-10T20:36:01Z")

</div>

Lab Environment: 3 Master and 2 Data nodes. Just sent some data to cluster without building custom templates or ILM policies or mappings. I added 2 more Data nodes and made the first two Hot and the new 2 Warm nodes p…

[Previous page](https://discuss.elastic.co/latest.md?page=750)

[Next page](https://discuss.elastic.co/latest.md?page=752)
