# Latest

**URL:** https://discuss.elastic.co/latest.md?page=753

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 754

---

## [ELK Vulnerability Detection](https://discuss.elastic.co/t/elk-vulnerability-detection/327261)

<div class="topic-metadata">

**Author:** [@cyberintellect](https://discuss.elastic.co/u/cyberintellect)\
**Replies:** 2\
**Last updated:** [March 10, 2023, 6:01am UTC](https://discuss.elastic.co/t/elk-vulnerability-detection/327261 "2023-03-10T06:01:03Z")

</div>

Hi guys, I was wondering if the function exists or is being looked at to implement vulnerability detections via the agent like with Wazuh Vulnerability Detection module. I searched the forum but I'm not seeing, might b…

---

## [No Service Found in APM DATA](https://discuss.elastic.co/t/no-service-found-in-apm-data/326325)

<div class="topic-metadata">

**Author:** [@Sam\_1995](https://discuss.elastic.co/u/Sam_1995)\
**Replies:** 4\
**Last updated:** [March 10, 2023, 5:52am UTC](https://discuss.elastic.co/t/no-service-found-in-apm-data/326325 "2023-03-10T05:52:59Z")

</div>

No Service Found in APM DATA in Kibana even though data is present in apm\* index and could application apm data received in apm-server logs Kibana version: 7.17.9 Elasticsearch version: 7.17.9 APM Server version: 7…

---

## [How to filter the buckets that have more than N documents using ElasticSearch DSL in python?](https://discuss.elastic.co/t/how-to-filter-the-buckets-that-have-more-than-n-documents-using-elasticsearch-dsl-in-python/327412)

<div class="topic-metadata">

**Author:** [@Ashar\_Ahmad](https://discuss.elastic.co/u/Ashar_Ahmad)\
**Replies:** 0\
**Last updated:** [March 10, 2023, 4:41am UTC](https://discuss.elastic.co/t/how-to-filter-the-buckets-that-have-more-than-n-documents-using-elasticsearch-dsl-in-python/327412 "2023-03-10T04:41:09Z")

</div>

I have an index in Elasticsearch that contains information of a user in each document, along with the facebook posts they have made (in a denormalized manner). Each document contains: User\_ID | User\_Name | Post\_Text | P…

---

## [Cannot add new CA to keystore](https://discuss.elastic.co/t/cannot-add-new-ca-to-keystore/326767)

<div class="topic-metadata">

**Author:** [@alrubaa](https://discuss.elastic.co/u/alrubaa)\
**Replies:** 3\
**Last updated:** [March 10, 2023, 12:37am UTC](https://discuss.elastic.co/t/cannot-add-new-ca-to-keystore/326767 "2023-03-10T00:37:10Z")

</div>

Hi All, I have an ELasticsearch cluster of 12 nodes running 8.2 and the certificates have expired, just crossed 3 years which I did not realise. I have been trying to follow the instructions on Update security certifica…

---

## [Creating Endpoint Exception for one endpoint](https://discuss.elastic.co/t/creating-endpoint-exception-for-one-endpoint/326593)

<div class="topic-metadata">

**Author:** [@slash24](https://discuss.elastic.co/u/slash24)\
**Replies:** 1\
**Last updated:** [March 9, 2023, 11:41pm UTC](https://discuss.elastic.co/t/creating-endpoint-exception-for-one-endpoint/326593 "2023-03-09T23:41:43Z")

</div>

How do I create an Endpoint Exception that only apply to one specfic host? I have alot of servers in one Fleet policy and would like to excluse w3wp.exe. This however a dangerous blindspot so of course i want to limit th…

---

## [Importing rules with detection\_rules CLI](https://discuss.elastic.co/t/importing-rules-with-detection-rules-cli/327190)

<div class="topic-metadata">

**Author:** [@Fredrick](https://discuss.elastic.co/u/Fredrick)\
**Replies:** 1\
**Last updated:** [March 9, 2023, 10:35pm UTC](https://discuss.elastic.co/t/importing-rules-with-detection-rules-cli/327190 "2023-03-09T22:35:55Z")

</div>

Hello! I've been recently importing rules with detection\_rules - detection-rules/CLI.md at main · elastic/detection-rules · GitHub. My usecase is to convert our custom Kibana rules into toml files so we can manage our c…

---

## [Prometheus collector query defined once, applied everywhere](https://discuss.elastic.co/t/prometheus-collector-query-defined-once-applied-everywhere/327400)

<div class="topic-metadata">

**Author:** [@jeanfabrice](https://discuss.elastic.co/u/jeanfabrice)\
**Replies:** 0\
**Last updated:** [March 9, 2023, 10:33pm UTC](https://discuss.elastic.co/t/prometheus-collector-query-defined-once-applied-everywhere/327400 "2023-03-09T22:33:31Z")

</div>

Hi, I'm using Metricbeat 8.6.2 and I'm trying to collect Prometheus metrics using the official Prom snmp exporter. This particular exporter requires passing a URL query string to configure the snmp endpoint to collect t…

---

## [Endpoint service not honoring proxy environment variables](https://discuss.elastic.co/t/endpoint-service-not-honoring-proxy-environment-variables/327234)

<div class="topic-metadata">

**Author:** [@indyg](https://discuss.elastic.co/u/indyg)\
**Replies:** 2\
**Last updated:** [March 9, 2023, 10:26pm UTC](https://discuss.elastic.co/t/endpoint-service-not-honoring-proxy-environment-variables/327234 "2023-03-09T22:26:13Z")

</div>

We're testing out deploying Defend to our fleet but are running into an issue where the endpoint service isn't honoring the HTTP\_PROXY or HTTPS\_PROXY environment variables, which for us is needed to push documents into E…

---

## [Custom Query detection Rule is not runnig on my elk](https://discuss.elastic.co/t/custom-query-detection-rule-is-not-runnig-on-my-elk/327256)

<div class="topic-metadata">

**Author:** [@Sajith](https://discuss.elastic.co/u/Sajith)\
**Replies:** 2\
**Last updated:** [March 9, 2023, 10:20pm UTC](https://discuss.elastic.co/t/custom-query-detection-rule-is-not-runnig-on-my-elk/327256 "2023-03-09T22:20:54Z")

</div>

I created a custom detection rule which is just a query for failed logins (event.code : "4625") I have pointed it to the index pattern and I can see the output on preview results as well. After enabling the rule there …

---

## [Unassigned.reason CLUSTER\_RECOVERED](https://discuss.elastic.co/t/unassigned-reason-cluster-recovered/327370)

<div class="topic-metadata">

**Author:** [@frankmehlhop.com](https://discuss.elastic.co/u/frankmehlhop.com)\
**Replies:** 1\
**Last updated:** [March 9, 2023, 8:05pm UTC](https://discuss.elastic.co/t/unassigned-reason-cluster-recovered/327370 "2023-03-09T20:05:34Z")

</div>

My health status is only yellow instead of green. { "cluster\_name" : "elasticsearch", "status" : "yellow", "timed\_out" : false, "number\_of\_nodes" : 1, "number\_of\_data\_nodes" : 1, "active\_primary\_shards" : 22…

---

## [Does this mean my "\_id" field is taking up GB of RAM?](https://discuss.elastic.co/t/does-this-mean-my-id-field-is-taking-up-gb-of-ram/327128)

<div class="topic-metadata">

**Author:** [@linkerc](https://discuss.elastic.co/u/linkerc)\
**Replies:** 3\
**Last updated:** [March 9, 2023, 6:39pm UTC](https://discuss.elastic.co/t/does-this-mean-my-id-field-is-taking-up-gb-of-ram/327128 "2023-03-09T18:39:27Z")

</div>

\[fielddata\] New used memory 13315258923 \[12.4gb\] for data of \[\_id\] would be larger than configured breaker: 13314398617 \[12.3gb\], breaking I'm getting the above warning and wondering why. Does it mean my "\_id" field (t…

---

## [How to stop ECK Operator changes to elastic cluster at k8s](https://discuss.elastic.co/t/how-to-stop-eck-operator-changes-to-elastic-cluster-at-k8s/327358)

<div class="topic-metadata">

**Author:** [@prabhakar\_talari](https://discuss.elastic.co/u/prabhakar_talari)\
**Replies:** 0\
**Last updated:** [March 9, 2023, 12:31pm UTC](https://discuss.elastic.co/t/how-to-stop-eck-operator-changes-to-elastic-cluster-at-k8s/327358 "2023-03-09T12:31:58Z")

</div>

Hi Team, I am running ECK 1.4.1 & elastic 7.16.3 version at OnPrem K8s, Some times when i want to add more data nodes to cluster i will do the changes in elastic yam file and deployit then operator will push the changes…

---

## [\[HELP! ! \] About ILM (IndexLifecycleManagement) of ElasticSearch](https://discuss.elastic.co/t/help-about-ilm-indexlifecyclemanagement-of-elasticsearch/326813)

<div class="topic-metadata">

**Author:** [@YUUTA.INOUE-JPN](https://discuss.elastic.co/u/YUUTA.INOUE-JPN)\
**Replies:** 10\
**Last updated:** [March 9, 2023, 4:38pm UTC](https://discuss.elastic.co/t/help-about-ilm-indexlifecyclemanagement-of-elasticsearch/326813 "2023-03-09T16:38:56Z")

</div>

Hello from Japan I have a question for you dear engineers I'm using Elasticsearch 7.6.2 and want to remove the accumulated indexes The created ILM policy rolls over at 50GB/30 days, and I created an ILM policy that de…

---

## [Watches not writing to wacher history](https://discuss.elastic.co/t/watches-not-writing-to-wacher-history/327364)

<div class="topic-metadata">

**Author:** [@Sagi\_Bensimon](https://discuss.elastic.co/u/Sagi_Bensimon)\
**Replies:** 3\
**Last updated:** [March 9, 2023, 5:38pm UTC](https://discuss.elastic.co/t/watches-not-writing-to-wacher-history/327364 "2023-03-09T17:38:23Z")

</div>

.watcher-history indices aren't being created and are also missing. There aren't any errors and action.auto\_create\_index isn't set anywhere.

---

## [\[synthetics\] errors with private location with synthetics browser monitors](https://discuss.elastic.co/t/synthetics-errors-with-private-location-with-synthetics-browser-monitors/327094)

<div class="topic-metadata">

**Author:** [@irivas95](https://discuss.elastic.co/u/irivas95)\
**Replies:** 1\
**Last updated:** [March 9, 2023, 5:14pm UTC](https://discuss.elastic.co/t/synthetics-errors-with-private-location-with-synthetics-browser-monitors/327094 "2023-03-09T17:14:13Z")

</div>

Hi, I am trying to create a monitor using a private location. I am following this procedure however, when I set up the monitor with the private location from the uptime page in kibana, I get the following error: io:jo…

---

## [Elastic-agent updates](https://discuss.elastic.co/t/elastic-agent-updates/327382)

<div class="topic-metadata">

**Author:** [@stobbe](https://discuss.elastic.co/u/stobbe)\
**Replies:** 0\
**Last updated:** [March 9, 2023, 5:00pm UTC](https://discuss.elastic.co/t/elastic-agent-updates/327382 "2023-03-09T17:00:14Z")

</div>

Hello, If I understand correctly, if you update an agent to a new version, the software (binaries) have to be downloaded from a repository. The extra "plugins" are available from kibana Simple question, why not use Ki…

---

## [ECE does not officially support Debian 11?](https://discuss.elastic.co/t/ece-does-not-officially-support-debian-11/327368)

<div class="topic-metadata">

**Author:** [@UPPERCASE](https://discuss.elastic.co/u/UPPERCASE)\
**Replies:** 1\
**Last updated:** [March 9, 2023, 4:37pm UTC](https://discuss.elastic.co/t/ece-does-not-officially-support-debian-11/327368 "2023-03-09T16:37:04Z")

</div>

According to the official documentation, Debian 11 is not supported. Could this be that this is because Debian 11 uses cgroups version 2? Which is not supported for ECE, probably also why RHEL9 is not listed. But you …

---

## [Statuscode-404-error-not-found-message-not-found](https://discuss.elastic.co/t/statuscode-404-error-not-found-message-not-found/327359)

<div class="topic-metadata">

**Author:** [@thomas4](https://discuss.elastic.co/u/thomas4)\
**Replies:** 1\
**Last updated:** [March 9, 2023, 4:13pm UTC](https://discuss.elastic.co/t/statuscode-404-error-not-found-message-not-found/327359 "2023-03-09T16:13:29Z")

</div>

Hi all, I created a space and when i try to login to it i get the message above, but if i sign in with the super user account and then sign out, and sign in with my new space account it works. Any help would be grateful. …

---

## [Disappearing Documents on Batch Upload with Enrich Policy](https://discuss.elastic.co/t/disappearing-documents-on-batch-upload-with-enrich-policy/327377)

<div class="topic-metadata">

**Author:** [@cj\_hillbrand](https://discuss.elastic.co/u/cj_hillbrand)\
**Replies:** 0\
**Last updated:** [March 9, 2023, 4:12pm UTC](https://discuss.elastic.co/t/disappearing-documents-on-batch-upload-with-enrich-policy/327377 "2023-03-09T16:12:39Z")

</div>

Hey folks, My team and I are evaluating some interesting behavior when our system attempts to batch upload documents to our Elasticsearch store. We are noticing that occasionally a collection of documents that we expect…

---

## [Static variables in Kibana discovery script](https://discuss.elastic.co/t/static-variables-in-kibana-discovery-script/327125)

<div class="topic-metadata">

**Author:** [@gyannea](https://discuss.elastic.co/u/gyannea)\
**Replies:** 6\
**Last updated:** [March 9, 2023, 3:41pm UTC](https://discuss.elastic.co/t/static-variables-in-kibana-discovery-script/327125 "2023-03-09T15:41:23Z")

</div>

What should be something very simple. I want to create a new field for a Kibana discovery and dashboard that simply counts the received document. So each document will have an index 0, 1, 2, ..., n. However, I do not se…

---

## [Not able to parse geojson data in logstash](https://discuss.elastic.co/t/not-able-to-parse-geojson-data-in-logstash/325247)

<div class="topic-metadata">

**Author:** [@aaryan](https://discuss.elastic.co/u/aaryan)\
**Replies:** 1\
**Last updated:** [March 9, 2023, 3:35pm UTC](https://discuss.elastic.co/t/not-able-to-parse-geojson-data-in-logstash/325247 "2023-03-09T15:35:45Z")

</div>

This is the config I am using. input { file { path =\> "D:/Softwares/ELK/data/geojson/features.geojson" start\_position =\> "beginning" sincedb\_path =\> "D:/Softwares/ELK/data/cache/geojsontry.txt" codec =\> mult…

---

## [Integration Elastic Dashboard to Power BI Visualization](https://discuss.elastic.co/t/integration-elastic-dashboard-to-power-bi-visualization/327018)

<div class="topic-metadata">

**Author:** [@aisyaharifin](https://discuss.elastic.co/u/aisyaharifin)\
**Replies:** 6\
**Last updated:** [March 9, 2023, 3:29pm UTC](https://discuss.elastic.co/t/integration-elastic-dashboard-to-power-bi-visualization/327018 "2023-03-09T15:29:07Z")

</div>

Hi, I would like to ask is there any way I could integrate my Elastic Dashboard to Power BI? I have a situation to export my Elastic Uptime Availability Dashboard to Power BI. Is there any way I could just drop the…

---

## [\[ES 8.6.1 & 8.6.2\] Fleet's "Custom Logs" integration stops sending logs with "failed to publish events: temporary bulk send failure" message](https://discuss.elastic.co/t/es-8-6-1-8-6-2-fleets-custom-logs-integration-stops-sending-logs-with-failed-to-publish-events-temporary-bulk-send-failure-message/327293)

<div class="topic-metadata">

**Author:** [@BorisNaguet](https://discuss.elastic.co/u/BorisNaguet)\
**Replies:** 0\
**Last updated:** [March 8, 2023, 5:08pm UTC](https://discuss.elastic.co/t/es-8-6-1-8-6-2-fleets-custom-logs-integration-stops-sending-logs-with-failed-to-publish-events-temporary-bulk-send-failure-message/327293 "2023-03-08T17:08:35Z")

</div>

Hello, I'm new to Elastic, so it's possible that I configured something wrong... Also, please be precise on where/how to find things if you ask for more info. Base installationI installed a fresh Elastic recently: 8…

---

## ["Unable to completely restore the URL" when viewing results from osquery in discover](https://discuss.elastic.co/t/unable-to-completely-restore-the-url-when-viewing-results-from-osquery-in-discover/327231)

<div class="topic-metadata">

**Author:** [@nemhods](https://discuss.elastic.co/u/nemhods)\
**Replies:** 1\
**Last updated:** [March 9, 2023, 3:07pm UTC](https://discuss.elastic.co/t/unable-to-completely-restore-the-url-when-viewing-results-from-osquery-in-discover/327231 "2023-03-09T15:07:37Z")

</div>

Hey, When investigating the results from osquery, I want to use the "View in Discover" button: It leads me to discover, but applies no filters and shows an error popup with the message "Unable to completely restore …

---

## [Logstash log file location](https://discuss.elastic.co/t/logstash-log-file-location/327307)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 2\
**Last updated:** [March 9, 2023, 2:57pm UTC](https://discuss.elastic.co/t/logstash-log-file-location/327307 "2023-03-09T14:57:19Z")

</div>

I am running logstash as daemon via systemd I get my log in to my special log dir /log/logstash/logstash-plain.log but I also get that in /var/log/message. I want to stop them and I read that it is control by log4j2 fi…

---

## [Format a Scripted Date Field](https://discuss.elastic.co/t/format-a-scripted-date-field/327309)

<div class="topic-metadata">

**Author:** [@ashryver1995](https://discuss.elastic.co/u/ashryver1995)\
**Replies:** 1\
**Last updated:** [March 9, 2023, 2:55pm UTC](https://discuss.elastic.co/t/format-a-scripted-date-field/327309 "2023-03-09T14:55:54Z")

</div>

Hi, I have a scripted field using painless that is referencing from an existing field in my index. Below is the code snippet: if(doc\['market'\].value == 'SAMPLE'){ if (doc\['date field\].size()==0){ return ''…

---

## [Index sorting with two order values in the same field](https://discuss.elastic.co/t/index-sorting-with-two-order-values-in-the-same-field/327333)

<div class="topic-metadata">

**Author:** [@joaoantao](https://discuss.elastic.co/u/joaoantao)\
**Replies:** 0\
**Last updated:** [March 9, 2023, 8:33am UTC](https://discuss.elastic.co/t/index-sorting-with-two-order-values-in-the-same-field/327333 "2023-03-09T08:33:53Z")

</div>

I am trying to improve queries in one index with ~ 125 million documents and 3 shards. Most of the queries hitting this index have a sort order for a given field with values ascending and descending. Currently the index…

---

## [Adding watcher condition](https://discuss.elastic.co/t/adding-watcher-condition/326763)

<div class="topic-metadata">

**Author:** [@alextg](https://discuss.elastic.co/u/alextg)\
**Replies:** 6\
**Last updated:** [March 9, 2023, 2:23pm UTC](https://discuss.elastic.co/t/adding-watcher-condition/326763 "2023-03-09T14:23:10Z")

</div>

Hello, I'm looking to add a new condition to my working watcher. Currently, it alerts when the index doesn't received logs in the last 10 minutes (see below). The functionality I'm trying to add is to alert when the ind…

---

## [Group input values in Bar Chart Aggregation](https://discuss.elastic.co/t/group-input-values-in-bar-chart-aggregation/327306)

<div class="topic-metadata">

**Author:** [@Miriam99](https://discuss.elastic.co/u/Miriam99)\
**Replies:** 1\
**Last updated:** [March 9, 2023, 2:22pm UTC](https://discuss.elastic.co/t/group-input-values-in-bar-chart-aggregation/327306 "2023-03-09T14:22:37Z")

</div>

If I have documents where value.keyword = A1, value.keyword = A2 ... A3, B1, B2, B3 How would I get all of the A values to group together and B values to group together instead of having 6 separate bars on my graph? Th…

---

## [Stackoverflow error on logstash when using es\_bulk codec](https://discuss.elastic.co/t/stackoverflow-error-on-logstash-when-using-es-bulk-codec/327337)

<div class="topic-metadata">

**Author:** [@eeijlar](https://discuss.elastic.co/u/eeijlar)\
**Replies:** 1\
**Last updated:** [March 9, 2023, 2:17pm UTC](https://discuss.elastic.co/t/stackoverflow-error-on-logstash-when-using-es-bulk-codec/327337 "2023-03-09T14:17:45Z")

</div>

Using the following pipeline with logstash: - pipeline.id: export-process pipeline.workers: 4 config.string: | input { elasticsearch { hosts =\> "http://elastic:80/elasticsearch/…

[Previous page](https://discuss.elastic.co/latest.md?page=752)

[Next page](https://discuss.elastic.co/latest.md?page=754)
