# Latest

**URL:** https://discuss.elastic.co/latest.md?page=754

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 755

---

## [Meta data not written to logstash output file](https://discuss.elastic.co/t/meta-data-not-written-to-logstash-output-file/327366)

<div class="topic-metadata">

**Author:** [@eeijlar](https://discuss.elastic.co/u/eeijlar)\
**Replies:** 0\
**Last updated:** [March 9, 2023, 2:02pm UTC](https://discuss.elastic.co/t/meta-data-not-written-to-logstash-output-file/327366 "2023-03-09T14:02:14Z")

</div>

I am using the following logstash pipeline: - pipeline.id: export-process pipeline.workers: 4 config.string: | input { elasticsearch { hosts =\> "http://elastic:80/elasticsearch/…

---

## [The chart shows a time beyond what's actually in data](https://discuss.elastic.co/t/the-chart-shows-a-time-beyond-whats-actually-in-data/327292)

<div class="topic-metadata">

**Author:** [@SamuelSMendes](https://discuss.elastic.co/u/SamuelSMendes)\
**Replies:** 1\
**Last updated:** [March 9, 2023, 1:57pm UTC](https://discuss.elastic.co/t/the-chart-shows-a-time-beyond-whats-actually-in-data/327292 "2023-03-09T13:57:54Z")

</div>

So I'm making this chart to pick up some data cross time but the chart shows data that doesn't exist yet. In a time that is yet to come: Latest timestamp in preview: The chart: How can I make so the chart will fol…

---

## [Kibana Lens - Cannot cutomize timestamp on several months, weeks or years](https://discuss.elastic.co/t/kibana-lens-cannot-cutomize-timestamp-on-several-months-weeks-or-years/327156)

<div class="topic-metadata">

**Author:** [@xchess64](https://discuss.elastic.co/u/xchess64)\
**Replies:** 1\
**Last updated:** [March 9, 2023, 1:31pm UTC](https://discuss.elastic.co/t/kibana-lens-cannot-cutomize-timestamp-on-several-months-weeks-or-years/327156 "2023-03-09T13:31:15Z")

</div>

I am creating a Lens Visualization on Kibana 7.17 When I try to customize my timestamp to aggregate data on several days, I can do it easily However, when I try to aggregate my data on several weeks, months or years…

---

## [Issue with removing tag](https://discuss.elastic.co/t/issue-with-removing-tag/327193)

<div class="topic-metadata">

**Author:** [@Harika](https://discuss.elastic.co/u/Harika)\
**Replies:** 1\
**Last updated:** [March 9, 2023, 1:27pm UTC](https://discuss.elastic.co/t/issue-with-removing-tag/327193 "2023-03-09T13:27:03Z")

</div>

we are having the \<system-out\>\<!\[CDATA\[\]\]\>\</system-out\> tag in our XML File. Due to this tag it could not index and throwing the below Error: "error"=\>{"type"=\>"illegal\_argument\_exception", "reason"=\>"can't merge a non …

---

## [Not able to send add logstash output in Elastic Agent setup](https://discuss.elastic.co/t/not-able-to-send-add-logstash-output-in-elastic-agent-setup/326726)

<div class="topic-metadata">

**Author:** [@sanju1323](https://discuss.elastic.co/u/sanju1323)\
**Replies:** 7\
**Last updated:** [March 9, 2023, 12:46pm UTC](https://discuss.elastic.co/t/not-able-to-send-add-logstash-output-in-elastic-agent-setup/326726 "2023-03-09T12:46:44Z")

</div>

I have created Fleet output as Logstash but while assigning the output to the agent, I'm getting only Elasticsearch output (default). But I want to send the data from Elastic Agent to Logstash. I have followed this link…

---

## [Cannot confirm deprecation log on K8S deployment or docker](https://discuss.elastic.co/t/cannot-confirm-deprecation-log-on-k8s-deployment-or-docker/327356)

<div class="topic-metadata">

**Author:** [@shimpeko](https://discuss.elastic.co/u/shimpeko)\
**Replies:** 0\
**Last updated:** [March 9, 2023, 12:30pm UTC](https://discuss.elastic.co/t/cannot-confirm-deprecation-log-on-k8s-deployment-or-docker/327356 "2023-03-09T12:30:58Z")

</div>

Hello, I'm operating Elasticsearch 7.17.9 on K8S using the ECK. I'm trying to review the deprecation log which is documented here Logging | Elasticsearch Guide \[7.17\] | Elastic as I'm planning to upgrade our Elasticsea…

---

## [Convert Keyword to object data type](https://discuss.elastic.co/t/convert-keyword-to-object-data-type/327355)

<div class="topic-metadata">

**Author:** [@Gaurav\_kr](https://discuss.elastic.co/u/Gaurav_kr)\
**Replies:** 0\
**Last updated:** [March 9, 2023, 12:23pm UTC](https://discuss.elastic.co/t/convert-keyword-to-object-data-type/327355 "2023-03-09T12:23:34Z")

</div>

Hi Team I want to convert a keyword data type field to object data type, i know we can do by editing the data stream but as i am using a ingest pipeline which is creating a the field in keyword data type so wanted to kno…

---

## [How to load CSV data to already created and existing Index in Kibana?](https://discuss.elastic.co/t/how-to-load-csv-data-to-already-created-and-existing-index-in-kibana/326979)

<div class="topic-metadata">

**Author:** [@hitnalli\_praveen](https://discuss.elastic.co/u/hitnalli_praveen)\
**Replies:** 8\
**Last updated:** [March 9, 2023, 11:55am UTC](https://discuss.elastic.co/t/how-to-load-csv-data-to-already-created-and-existing-index-in-kibana/326979 "2023-03-09T11:55:07Z")

</div>

I've a unique requirement and trying few new things. My main objective is to display scanned data from Tenable Nessus (showing total count of scanned vulnerabilities - Critical, High and Medium) on to Kibana Dashboard af…

---

## [Filebeat for AWS Cloudwatch does not support timestamps with milliseconds](https://discuss.elastic.co/t/filebeat-for-aws-cloudwatch-does-not-support-timestamps-with-milliseconds/327338)

<div class="topic-metadata">

**Author:** [@Tomas\_Mocek](https://discuss.elastic.co/u/Tomas_Mocek)\
**Replies:** 0\
**Last updated:** [March 9, 2023, 8:59am UTC](https://discuss.elastic.co/t/filebeat-for-aws-cloudwatch-does-not-support-timestamps-with-milliseconds/327338 "2023-03-09T08:59:08Z")

</div>

Hi, we are using AWS Filebeat CloudWatch input, and everything works as expected, however, the logs are fetched without milliseconds precision. I believe this is caused because of this code, which cuts milliseconds ret…

---

## [Get top 10 data for each group](https://discuss.elastic.co/t/get-top-10-data-for-each-group/327349)

<div class="topic-metadata">

**Author:** [@Shishir\_Kumar2](https://discuss.elastic.co/u/Shishir_Kumar2)\
**Replies:** 0\
**Last updated:** [March 9, 2023, 11:25am UTC](https://discuss.elastic.co/t/get-top-10-data-for-each-group/327349 "2023-03-09T11:25:39Z")

</div>

Requirement is to get top 10 data for each group. I created below index and tried using few combination of aggregation query but it does not get desired result. Index Definition PUT /poc\_agg { "settings": { "numb…

---

## [Vega kibana tooltip](https://discuss.elastic.co/t/vega-kibana-tooltip/327093)

<div class="topic-metadata">

**Author:** [@Farah\_Bhr](https://discuss.elastic.co/u/Farah_Bhr)\
**Replies:** 2\
**Last updated:** [March 9, 2023, 11:12am UTC](https://discuss.elastic.co/t/vega-kibana-tooltip/327093 "2023-03-09T11:12:05Z")

</div>

Hello everyone, I want to adjust kibana vega tooltip, make it smaller and modify its fontsize, its position, etc Meaning that I want to modify the styling of the vega Kibana tooltip from this to something like this …

---

## [Logstash stopped processing logs after enabling minimal security](https://discuss.elastic.co/t/logstash-stopped-processing-logs-after-enabling-minimal-security/327232)

<div class="topic-metadata">

**Author:** [@A.Hani](https://discuss.elastic.co/u/A.Hani)\
**Replies:** 4\
**Last updated:** [March 9, 2023, 11:02am UTC](https://discuss.elastic.co/t/logstash-stopped-processing-logs-after-enabling-minimal-security/327232 "2023-03-09T11:02:25Z")

</div>

I was wondering what should be configured on logstash side after enabling basic on Elasticsearch node? I set x.pack.security.enabled to true on elasticsearch.yml, generated passwords for the cluster users, added the ki…

---

## [Very high CPU usage on some projects](https://discuss.elastic.co/t/very-high-cpu-usage-on-some-projects/326177)

<div class="topic-metadata">

**Author:** [@leandro.silva](https://discuss.elastic.co/u/leandro.silva)\
**Replies:** 2\
**Last updated:** [March 9, 2023, 10:40am UTC](https://discuss.elastic.co/t/very-high-cpu-usage-on-some-projects/326177 "2023-03-09T10:40:02Z")

</div>

I installed elastic apm on some projects, a front in PHP and some APIs. The front doen not use any database directly only through the APIs and the CPU went crazy for all front instances. We revert the version, which in t…

---

## [Configuration issues - Filebeat for shipping messages from a Kafka topic to Elasticsearch](https://discuss.elastic.co/t/configuration-issues-filebeat-for-shipping-messages-from-a-kafka-topic-to-elasticsearch/327315)

<div class="topic-metadata">

**Author:** [@dvoracek-martin](https://discuss.elastic.co/u/dvoracek-martin)\
**Replies:** 0\
**Last updated:** [March 9, 2023, 1:04am UTC](https://discuss.elastic.co/t/configuration-issues-filebeat-for-shipping-messages-from-a-kafka-topic-to-elasticsearch/327315 "2023-03-09T01:04:01Z")

</div>

Hi! I'd like to have Filebeat set up the way that it would consume messages from Kafka topic and then send them to Elasticsearch. Is there a way, how to set it all up in docker-compose? I could register Logstash as a Kaf…

---

## [Metricbeat not sending data or Elasticsearch not recieving (?)](https://discuss.elastic.co/t/metricbeat-not-sending-data-or-elasticsearch-not-recieving/326863)

<div class="topic-metadata">

**Author:** [@enigmatic](https://discuss.elastic.co/u/enigmatic)\
**Replies:** 12\
**Last updated:** [March 9, 2023, 9:06am UTC](https://discuss.elastic.co/t/metricbeat-not-sending-data-or-elasticsearch-not-recieving/326863 "2023-03-09T09:06:34Z")

</div>

Hi Guys, hope you can help me out in the following. i'm using: Elasticseearch 8.4.3 metricbeat 8.4.3 kubernetes / AWS EKS I've deployed metricbeat in a kubernetes cluster. it gathering all sort of data and i also wa…

---

## [Elasticsearch Setup Custom Index and Write Issue](https://discuss.elastic.co/t/elasticsearch-setup-custom-index-and-write-issue/327332)

<div class="topic-metadata">

**Author:** [@elk-siwm](https://discuss.elastic.co/u/elk-siwm)\
**Replies:** 0\
**Last updated:** [March 9, 2023, 8:28am UTC](https://discuss.elastic.co/t/elasticsearch-setup-custom-index-and-write-issue/327332 "2023-03-09T08:28:45Z")

</div>

Elasticsearch get logs via filebeats shipper default settings. All custom index settings were configured on /etc/filebeats/filebeats.yml file. This is my configuration file: output.elasticsearch: # Array of hosts to c…

---

## [Sorting by ranges in old (not Lens) visualizations](https://discuss.elastic.co/t/sorting-by-ranges-in-old-not-lens-visualizations/327176)

<div class="topic-metadata">

**Author:** [@InesCM](https://discuss.elastic.co/u/InesCM)\
**Replies:** 2\
**Last updated:** [March 9, 2023, 8:12am UTC](https://discuss.elastic.co/t/sorting-by-ranges-in-old-not-lens-visualizations/327176 "2023-03-09T08:12:11Z")

</div>

Hi! I have a set of old visualizations in Kibana, built not in Lens but in the Legacy visualization tool. They are donut charts split in slices by some custom defined numerical ranges. The problem is that when I built …

---

## [Request body is required Error encountered while performing reindexing task](https://discuss.elastic.co/t/request-body-is-required-error-encountered-while-performing-reindexing-task/327327)

<div class="topic-metadata">

**Author:** [@Chandan1](https://discuss.elastic.co/u/Chandan1)\
**Replies:** 4\
**Last updated:** [March 9, 2023, 7:58am UTC](https://discuss.elastic.co/t/request-body-is-required-error-encountered-while-performing-reindexing-task/327327 "2023-03-09T07:58:37Z")

</div>

Hello, I am trying to reindex the index with reindex api by providing a proper request body with the Source and Destination Index details and still iam receiving Request body is required Error. Please find below Reques…

---

## [Split a field value in a Visualization](https://discuss.elastic.co/t/split-a-field-value-in-a-visualization/327303)

<div class="topic-metadata">

**Author:** [@Jonathan\_Fernandez](https://discuss.elastic.co/u/Jonathan_Fernandez)\
**Replies:** 3\
**Last updated:** [March 9, 2023, 7:37am UTC](https://discuss.elastic.co/t/split-a-field-value-in-a-visualization/327303 "2023-03-09T07:37:53Z")

</div>

Hi everyone, Currently I am trying to split the value of a field (an email) by the '@' in an "Aggregation Based - Data Table" visualization at Kibana, so the expected output for an email field with value name@domain.com …

---

## [Monitoring Metricbeat On Kibana](https://discuss.elastic.co/t/monitoring-metricbeat-on-kibana/327244)

<div class="topic-metadata">

**Author:** [@Tw1cUser](https://discuss.elastic.co/u/Tw1cUser)\
**Replies:** 5\
**Last updated:** [March 9, 2023, 6:15am UTC](https://discuss.elastic.co/t/monitoring-metricbeat-on-kibana/327244 "2023-03-09T06:15:15Z")

</div>

Hi all, I use windows server 2019 to monitor my laptop's data system, but after I do the .\\metricbeat setup, after Index setup finished. Loading dashboards (Kibana must be running and reachable) Loaded dashboards I chec…

---

## [\[plugin-development\] java.security.AccessControlException](https://discuss.elastic.co/t/plugin-development-java-security-accesscontrolexception/327326)

<div class="topic-metadata">

**Author:** [@Jinnrry](https://discuss.elastic.co/u/Jinnrry)\
**Replies:** 0\
**Last updated:** [March 9, 2023, 7:10am UTC](https://discuss.elastic.co/t/plugin-development-java-security-accesscontrolexception/327326 "2023-03-09T07:10:37Z")

</div>

Vesion: Elasticsearch 8.6.2 (My plugin is working on Elasticsearch7.6.0 ) I am developing a plugin to let ES filter through Redis data. So I import Jedis package in my code. But when ES starts, I get this error. Her…

---

## [Поисковая строка](https://discuss.elastic.co/t/topic/327325)

<div class="topic-metadata">

**Author:** [@beoatch](https://discuss.elastic.co/u/beoatch)\
**Replies:** 0\
**Last updated:** [March 9, 2023, 7:03am UTC](https://discuss.elastic.co/t/topic/327325 "2023-03-09T07:03:07Z")

</div>

Добрый день! Нужна помощь... Ситуация такая - есть большое количество учетных записей, формирующихся из имени и фамилии. Учетки формируются по нескольким сценариям, условно так : Анна Абрикосова - A.Abrikosova Михаил Б…

---

## [Cannot use https on elasticsearch server](https://discuss.elastic.co/t/cannot-use-https-on-elasticsearch-server/327148)

<div class="topic-metadata">

**Author:** [@dityudha](https://discuss.elastic.co/u/dityudha)\
**Replies:** 1\
**Last updated:** [March 9, 2023, 6:53am UTC](https://discuss.elastic.co/t/cannot-use-https-on-elasticsearch-server/327148 "2023-03-09T06:53:53Z")

</div>

Hello there, Right now i'm configuring elastic security with https based on article: I'm getting trouble after generate http.p12 certificate. Error like this: elastic server already up, but still not secured el…

---

## [\[esrally\] what cause difference of latency and service time?, what is proper way of custom parameter](https://discuss.elastic.co/t/esrally-what-cause-difference-of-latency-and-service-time-what-is-proper-way-of-custom-parameter/327317)

<div class="topic-metadata">

**Author:** [@dan\_kim](https://discuss.elastic.co/u/dan_kim)\
**Replies:** 4\
**Last updated:** [March 9, 2023, 6:15am UTC](https://discuss.elastic.co/t/esrally-what-cause-difference-of-latency-and-service-time-what-is-proper-way-of-custom-parameter/327317 "2023-03-09T06:15:47Z")

</div>

Hello. i just saw strange stuff when im trying to do single shard test. here is my metric it's error rate is 0.01% and its service time looks reasonable to service, but latency is really bad. the question is what ca…

---

## [Elastic Operator 2.6.1 Failing Reconciliation with "Invalid Settings" Error on ES 8.6.2 in AKS but not specifying what setting is invalid](https://discuss.elastic.co/t/elastic-operator-2-6-1-failing-reconciliation-with-invalid-settings-error-on-es-8-6-2-in-aks-but-not-specifying-what-setting-is-invalid/327285)

<div class="topic-metadata">

**Author:** [@Thomas\_Kuisel](https://discuss.elastic.co/u/Thomas_Kuisel)\
**Replies:** 1\
**Last updated:** [March 9, 2023, 5:44am UTC](https://discuss.elastic.co/t/elastic-operator-2-6-1-failing-reconciliation-with-invalid-settings-error-on-es-8-6-2-in-aks-but-not-specifying-what-setting-is-invalid/327285 "2023-03-09T05:44:19Z")

</div>

Hi - We are trying to upgrade our elastic operator to 2.6.1 from 1.9, and subsequently our elastic cluster deployed in K8s and managed by the operator from 7.17 to 8.6.2. Upgrading the operator to 2.6.1 intially posed n…

---

## [Logstash compliance with RFC5425 and RFC5426](https://discuss.elastic.co/t/logstash-compliance-with-rfc5425-and-rfc5426/327243)

<div class="topic-metadata">

**Author:** [@Nikhitha\_Karennagari](https://discuss.elastic.co/u/Nikhitha_Karennagari)\
**Replies:** 2\
**Last updated:** [March 9, 2023, 3:13am UTC](https://discuss.elastic.co/t/logstash-compliance-with-rfc5425-and-rfc5426/327243 "2023-03-09T03:13:49Z")

</div>

From the official logstash docs , the syslog output plugin of logstash supports any of RFC5424, RFC3164 formats only. Syslog output plugin | Logstash Reference \[8.6\] | Elastic Does logstash syslog output plugin comply w…

---

## [Shards Rebalancing Issue Version 7](https://discuss.elastic.co/t/shards-rebalancing-issue-version-7/327107)

<div class="topic-metadata">

**Author:** [@chateesh](https://discuss.elastic.co/u/chateesh)\
**Replies:** 3\
**Last updated:** [March 8, 2023, 10:57pm UTC](https://discuss.elastic.co/t/shards-rebalancing-issue-version-7/327107 "2023-03-08T22:57:05Z")

</div>

ES version 7, Shards are not equally distributing, one data node has more shards, rest of the two data nodes are less number of shards and low disk used. Replication set to "1" on all indices Please let me know if any …

---

## [Enrollment in Fleet works but agent don't receive its configuration](https://discuss.elastic.co/t/enrollment-in-fleet-works-but-agent-dont-receive-its-configuration/325636)

<div class="topic-metadata">

**Author:** [@litronics](https://discuss.elastic.co/u/litronics)\
**Replies:** 2\
**Last updated:** [March 8, 2023, 9:13pm UTC](https://discuss.elastic.co/t/enrollment-in-fleet-works-but-agent-dont-receive-its-configuration/325636 "2023-03-08T21:13:29Z")

</div>

:frowning: am running a fresh docker based instance of elasticsearch, kibana and fleet-server (all in separate containers). Now I am starting a fresh elastic-agent container which enrolls in fleet just fine but don't re…

---

## [Scripted fields versus scripts in discovery objects](https://discuss.elastic.co/t/scripted-fields-versus-scripts-in-discovery-objects/326802)

<div class="topic-metadata">

**Author:** [@gyannea](https://discuss.elastic.co/u/gyannea)\
**Replies:** 9\
**Last updated:** [March 8, 2023, 7:02pm UTC](https://discuss.elastic.co/t/scripted-fields-versus-scripts-in-discovery-objects/326802 "2023-03-08T19:02:42Z")

</div>

In Kibana I have found two ways to create an additional field based upon what is in the documents. Use scripted fields in the index patterns. Since I want to convert a parameter that is in seconds to hours the script i…

---

## [Getting stuck on load geoip database file while installing Elasticsearch 8.6.2](https://discuss.elastic.co/t/getting-stuck-on-load-geoip-database-file-while-installing-elasticsearch-8-6-2/327289)

<div class="topic-metadata">

**Author:** [@Alfred\_C](https://discuss.elastic.co/u/Alfred_C)\
**Replies:** 2\
**Last updated:** [March 8, 2023, 6:21pm UTC](https://discuss.elastic.co/t/getting-stuck-on-load-geoip-database-file-while-installing-elasticsearch-8-6-2/327289 "2023-03-08T18:21:11Z")

</div>

Hi, I just tried to install Elasticsearch 8.6.2, however it was stuck when run elasticsearch.bat details as show at the screenshot

[Previous page](https://discuss.elastic.co/latest.md?page=753)

[Next page](https://discuss.elastic.co/latest.md?page=755)
