# Latest

**URL:** https://discuss.elastic.co/latest.md?page=756

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 757

---

## [About elasticsearch and kibana snapshot and backup feature](https://discuss.elastic.co/t/about-elasticsearch-and-kibana-snapshot-and-backup-feature/327198)

<div class="topic-metadata">

**Author:** [@Rakesh\_Bare1](https://discuss.elastic.co/u/Rakesh_Bare1)\
**Replies:** 6\
**Last updated:** [March 8, 2023, 7:41am UTC](https://discuss.elastic.co/t/about-elasticsearch-and-kibana-snapshot-and-backup-feature/327198 "2023-03-08T07:41:10Z")

</div>

hey, i am used elasticsearch is cluster. i want to take snapshot of my es. i have create snapshot directory and mention in elasticsearch.yml in path.repo. after that elasticsearch docker not running. i have check logs …

---

## [Metricbeat VM Can't Connect To Elasticsearch On Different Device](https://discuss.elastic.co/t/metricbeat-vm-cant-connect-to-elasticsearch-on-different-device/326722)

<div class="topic-metadata">

**Author:** [@Tw1cUser](https://discuss.elastic.co/u/Tw1cUser)\
**Replies:** 44\
**Last updated:** [March 8, 2023, 12:47am UTC](https://discuss.elastic.co/t/metricbeat-vm-cant-connect-to-elasticsearch-on-different-device/326722 "2023-03-08T00:47:22Z")

</div>

Hello i'm new on ELK, Metricbeat on my VM can't connect to my laptop for monitoring the system on VM, i already following the instruction from many source but still can't connect from Metricbeat VM to my laptop for monit…

---

## [TLS Certificate Roll - Enterprise Search Readiness probe failed - Failed to connect to Elasticsearch backend. (HTTPS/TLS)](https://discuss.elastic.co/t/tls-certificate-roll-enterprise-search-readiness-probe-failed-failed-to-connect-to-elasticsearch-backend-https-tls/327026)

<div class="topic-metadata">

**Author:** [@Glenn\_Sampson](https://discuss.elastic.co/u/Glenn_Sampson)\
**Replies:** 0\
**Last updated:** [March 6, 2023, 5:05am UTC](https://discuss.elastic.co/t/tls-certificate-roll-enterprise-search-readiness-probe-failed-failed-to-connect-to-elasticsearch-backend-https-tls/327026 "2023-03-06T05:05:43Z")

</div>

When rolling our CA certificates on our azure k8s clusters I noticed that our Elasticsearch is not using HTTPS/TLS. So I have attempted to updated the yamls and apply however my enterprise search is no longer working an…

---

## [What is the deciding factor for the number of coordinating only node in a cluster and how to route the requests?](https://discuss.elastic.co/t/what-is-the-deciding-factor-for-the-number-of-coordinating-only-node-in-a-cluster-and-how-to-route-the-requests/326842)

<div class="topic-metadata">

**Author:** [@pruthvi](https://discuss.elastic.co/u/pruthvi)\
**Replies:** 1\
**Last updated:** [March 8, 2023, 12:54am UTC](https://discuss.elastic.co/t/what-is-the-deciding-factor-for-the-number-of-coordinating-only-node-in-a-cluster-and-how-to-route-the-requests/326842 "2023-03-08T00:54:28Z")

</div>

Hi, I have a requirement to index 100TB of data per month in ES with ILM. No. dedicated master nodes – 3 nodes. Total no. of hot nodes - 66 nodes. Total no. of warm nodes - 216 nodes. Above calculations are based on…

---

## [Create new field value is incorrect](https://discuss.elastic.co/t/create-new-field-value-is-incorrect/326912)

<div class="topic-metadata">

**Author:** [@ikonrao](https://discuss.elastic.co/u/ikonrao)\
**Replies:** 1\
**Last updated:** [March 7, 2023, 10:54pm UTC](https://discuss.elastic.co/t/create-new-field-value-is-incorrect/326912 "2023-03-07T22:54:34Z")

</div>

Hi, I have a field which has value in seconds. I need to view it in hours. I used create new field and used script to convert it into hours. What i have observed is it is not able to take decimal values. For example, …

---

## [Logstash writer permissions](https://discuss.elastic.co/t/logstash-writer-permissions/327099)

<div class="topic-metadata">

**Author:** [@jfs1](https://discuss.elastic.co/u/jfs1)\
**Replies:** 0\
**Last updated:** [March 6, 2023, 3:45pm UTC](https://discuss.elastic.co/t/logstash-writer-permissions/327099 "2023-03-06T15:45:03Z")

</div>

On a new on-premises 8.6 logstash+elasticsearch deployment, I have the following error when configuring my "logstash\_writer" role as explained in Secure your connection to Elasticsearch | Logstash Reference \[8.6\] | Elast…

---

## [ElasticSearch and Kibana Migration](https://discuss.elastic.co/t/elasticsearch-and-kibana-migration/327146)

<div class="topic-metadata">

**Author:** [@Ramesh\_Ramachandran](https://discuss.elastic.co/u/Ramesh_Ramachandran)\
**Replies:** 1\
**Last updated:** [March 7, 2023, 10:25pm UTC](https://discuss.elastic.co/t/elasticsearch-and-kibana-migration/327146 "2023-03-07T22:25:37Z")

</div>

Hi Team, We are in the process of migrating Elasticsearch and Kibana from 8.2.2 to 8.5.3. We have deployed ES and Kibana in AKS with helm chart deployment. On migrating we are facing the below issue. \[2023-03-07T05:17…

---

## [Error in installing kibana](https://discuss.elastic.co/t/error-in-installing-kibana/327092)

<div class="topic-metadata">

**Author:** [@Ahmed\_Khaled](https://discuss.elastic.co/u/Ahmed_Khaled)\
**Replies:** 3\
**Last updated:** [March 7, 2023, 10:23pm UTC](https://discuss.elastic.co/t/error-in-installing-kibana/327092 "2023-03-07T22:23:51Z")

</div>

hello team, I am a beginner in using elastic stack and I have a problem (Kibana server is not ready) how I can fix it please????

---

## [Map Alert Rules to Kibana Widgets](https://discuss.elastic.co/t/map-alert-rules-to-kibana-widgets/327127)

<div class="topic-metadata">

**Author:** [@jsoule6](https://discuss.elastic.co/u/jsoule6)\
**Replies:** 0\
**Last updated:** [March 7, 2023, 12:28am UTC](https://discuss.elastic.co/t/map-alert-rules-to-kibana-widgets/327127 "2023-03-07T00:28:02Z")

</div>

Hello, We are looking to use Kibana dashboard capability to provide monitoring capability for our customer. We are going to be create alert rules based on numerous custom conditions and would like to map the rules to wi…

---

## [Number of Zones for Zone awared Shard allocation](https://discuss.elastic.co/t/number-of-zones-for-zone-awared-shard-allocation/327169)

<div class="topic-metadata">

**Author:** [@Mani2](https://discuss.elastic.co/u/Mani2)\
**Replies:** 1\
**Last updated:** [March 7, 2023, 10:20pm UTC](https://discuss.elastic.co/t/number-of-zones-for-zone-awared-shard-allocation/327169 "2023-03-07T22:20:37Z")

</div>

Hello, What can be the criteria of deciding the maximum number of zones within a data centre. For ex, If I have 30 Racks in a Data Centre, and if I have Primary and Secondary shards are 1,2 so minimum zones require will…

---

## [Getting authentication failure when logging into kibana](https://discuss.elastic.co/t/getting-authentication-failure-when-logging-into-kibana/327222)

<div class="topic-metadata">

**Author:** [@Russell\_Fulton](https://discuss.elastic.co/u/Russell_Fulton)\
**Replies:** 1\
**Last updated:** [March 7, 2023, 10:06pm UTC](https://discuss.elastic.co/t/getting-authentication-failure-when-logging-into-kibana/327222 "2023-03-07T22:06:42Z")

</div>

I am trying to log into kibana as the elastic user to do some maintenance but the login fails -- server shows: Authentication of \[elastic\] was terminated by realm \[reserved\] - failed to authenticate user \[elastic\] I ca…

---

## [Why does this SIMPLE Kibana script not work?](https://discuss.elastic.co/t/why-does-this-simple-kibana-script-not-work/327228)

<div class="topic-metadata">

**Author:** [@gyannea](https://discuss.elastic.co/u/gyannea)\
**Replies:** 1\
**Last updated:** [March 7, 2023, 9:46pm UTC](https://discuss.elastic.co/t/why-does-this-simple-kibana-script-not-work/327228 "2023-03-07T21:46:00Z")

</div>

Following right from the documentation: hubEvent.rssi is a String like '-98 dBm' I want to return a number def rssi = doc\['hubEvent.rssi.keyword'\].value; if (rssi != null) { int lastdBIndex = rssi.lastIndexOf('d…

---

## [Configuracion del Node.Roles \[master\]](https://discuss.elastic.co/t/configuracion-del-node-roles-master/327098)

<div class="topic-metadata">

**Author:** [@LeonardoCord](https://discuss.elastic.co/u/LeonardoCord)\
**Replies:** 5\
**Last updated:** [March 7, 2023, 9:33pm UTC](https://discuss.elastic.co/t/configuracion-del-node-roles-master/327098 "2023-03-07T21:33:11Z")

</div>

Buenas Estoy tratando de configurar el Node.Roles \[master\] debido a que es una configuracion obsoleta en la version que tengo 7.17.6 y he configurado mi .YML pero a la hora de correrlo mi elastic no arranca.

---

## [Importing multiple large csv and json files into a single index](https://discuss.elastic.co/t/importing-multiple-large-csv-and-json-files-into-a-single-index/326738)

<div class="topic-metadata">

**Author:** [@mansi\_raval](https://discuss.elastic.co/u/mansi_raval)\
**Replies:** 10\
**Last updated:** [March 7, 2023, 9:29pm UTC](https://discuss.elastic.co/t/importing-multiple-large-csv-and-json-files-into-a-single-index/326738 "2023-03-07T21:29:17Z")

</div>

I have an folder containing data (20 GB) and this folder contains 26 subfolders that are sorted city-wise. Each of these subfolder contain many more subfolders comprising of csv and json files (The data that is stored in…

---

## [Disk size and performance optimization for Elasticsearch cluster](https://discuss.elastic.co/t/disk-size-and-performance-optimization-for-elasticsearch-cluster/327071)

<div class="topic-metadata">

**Author:** [@yago82](https://discuss.elastic.co/u/yago82)\
**Replies:** 1\
**Last updated:** [March 7, 2023, 9:20pm UTC](https://discuss.elastic.co/t/disk-size-and-performance-optimization-for-elasticsearch-cluster/327071 "2023-03-07T21:20:48Z")

</div>

Hi everyone, I'm currently running an Elasticsearch cluster with 6 nodes, and (for every node) the disk usage is around 5.5 TB out of a total disk size of 20 TB. I don't anticipate a significant increase in data storag…

---

## [Logs definition](https://discuss.elastic.co/t/logs-definition/327211)

<div class="topic-metadata">

**Author:** [@Stefan7](https://discuss.elastic.co/u/Stefan7)\
**Replies:** 4\
**Last updated:** [March 7, 2023, 8:01pm UTC](https://discuss.elastic.co/t/logs-definition/327211 "2023-03-07T20:01:45Z")

</div>

Greetings, Can someone please direct me to a location where I can find a definition of logs? Here's a preliminary list that I am trying to clarify: 'logs-elastic\_agent' 'metrics-elastic\_agent.elastic\_agent ' 'logs-e…

---

## [Elasticsearch monitor with metricbeat](https://discuss.elastic.co/t/elasticsearch-monitor-with-metricbeat/327223)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 4\
**Last updated:** [March 7, 2023, 7:26pm UTC](https://discuss.elastic.co/t/elasticsearch-monitor-with-metricbeat/327223 "2023-03-07T19:26:47Z")

</div>

I am so crazy confuse on this setup. can't seems to make it work. this is my test setup that I am trying and getting more confuse every min. here is my configuration. monitor cluster:: elkdev11 monitoring cluster: …

---

## [Extracting year in short format from the log file name](https://discuss.elastic.co/t/extracting-year-in-short-format-from-the-log-file-name/327172)

<div class="topic-metadata">

**Author:** [@lupsya](https://discuss.elastic.co/u/lupsya)\
**Replies:** 1\
**Last updated:** [March 7, 2023, 5:38pm UTC](https://discuss.elastic.co/t/extracting-year-in-short-format-from-the-log-file-name/327172 "2023-03-07T17:38:01Z")

</div>

Hello, I am extracting Year, Month, and Day from the following testing log name and converting it to timestamp later. log20230225.log I am using the following grok filter: log%{YEAR:year}%{MONTHNUM:month}%{MONTHDAY:d…

---

## [Difference between Timestamp and @timestamp in kibana logs](https://discuss.elastic.co/t/difference-between-timestamp-and-timestamp-in-kibana-logs/327203)

<div class="topic-metadata">

**Author:** [@Amani188](https://discuss.elastic.co/u/Amani188)\
**Replies:** 3\
**Last updated:** [March 7, 2023, 4:33pm UTC](https://discuss.elastic.co/t/difference-between-timestamp-and-timestamp-in-kibana-logs/327203 "2023-03-07T16:33:17Z")

</div>

Hi everyone, I noticed that there is a difference of time between Timestamp and @timestamp generated with logstash . Is there a way to synchronise the value of @timestamp to be equal to Timestamp on kibana logs? Thank …

---

## [Elasticsearch Cloud API Authentication](https://discuss.elastic.co/t/elasticsearch-cloud-api-authentication/327161)

<div class="topic-metadata">

**Author:** [@Mark\_Rodman](https://discuss.elastic.co/u/Mark_Rodman)\
**Replies:** 1\
**Last updated:** [March 7, 2023, 4:28pm UTC](https://discuss.elastic.co/t/elasticsearch-cloud-api-authentication/327161 "2023-03-07T16:28:31Z")

</div>

Hi, I'm trying to figure how to authenticate REST API use against our Elasticsearch cloud instance. I understand how to use the cloud id etc when using a client library in a language such as Python however in my use ca…

---

## [Issue with RecyclerBytesStreamOutput](https://discuss.elastic.co/t/issue-with-recyclerbytesstreamoutput/325996)

<div class="topic-metadata">

**Author:** [@aurelien.guillaume](https://discuss.elastic.co/u/aurelien.guillaume)\
**Replies:** 3\
**Last updated:** [March 7, 2023, 4:03pm UTC](https://discuss.elastic.co/t/issue-with-recyclerbytesstreamoutput/325996 "2023-03-07T16:03:26Z")

</div>

Hi, I'm new in the usage of Elasticsearch (integrated into a security onion appliance) I'm working to get a huge query (2.5M logs), and I'm stuck with this error message { "error": { "root\_cause": \[ { …

---

## [How to Access Kibana time range (timepicker) in a painless script](https://discuss.elastic.co/t/how-to-access-kibana-time-range-timepicker-in-a-painless-script/326871)

<div class="topic-metadata">

**Author:** [@gyannea](https://discuss.elastic.co/u/gyannea)\
**Replies:** 2\
**Last updated:** [March 7, 2023, 3:50pm UTC](https://discuss.elastic.co/t/how-to-access-kibana-time-range-timepicker-in-a-painless-script/326871 "2023-03-07T15:50:55Z")

</div>

When making a search for documents that have a time stamp the user can specify a time range over which the search will be done. It looks like this in the search request: { "range": { "date"…

---

## [ES query to trigger n no. of email/webhook based on document hits](https://discuss.elastic.co/t/es-query-to-trigger-n-no-of-email-webhook-based-on-document-hits/326910)

<div class="topic-metadata">

**Author:** [@Amulya\_Nanda](https://discuss.elastic.co/u/Amulya_Nanda)\
**Replies:** 12\
**Last updated:** [March 7, 2023, 3:46pm UTC](https://discuss.elastic.co/t/es-query-to-trigger-n-no-of-email-webhook-based-on-document-hits/326910 "2023-03-07T15:46:24Z")

</div>

We are using this below code to trigger email/webhook actions once the threshold is met. But we are getting n no.of hits in one single email. Example our threshold has met with10 documents. So 10 emails/webhook has to …

---

## [Help needed for scripting for runtime fields](https://discuss.elastic.co/t/help-needed-for-scripting-for-runtime-fields/326001)

<div class="topic-metadata">

**Author:** [@jreyes25](https://discuss.elastic.co/u/jreyes25)\
**Replies:** 26\
**Last updated:** [March 7, 2023, 3:35pm UTC](https://discuss.elastic.co/t/help-needed-for-scripting-for-runtime-fields/326001 "2023-03-07T15:35:29Z")

</div>

Hello everyone, I am completely new to Elastic and scripting in general. I was told to install ElasticStack on our network for monitoring purposes. I now have both Elasticsearch and Kibana installed. I am currently try…

---

## [Markdown link to a secondary dashboard is not time persistent](https://discuss.elastic.co/t/markdown-link-to-a-secondary-dashboard-is-not-time-persistent/326980)

<div class="topic-metadata">

**Author:** [@Shreesh\_Narayanan](https://discuss.elastic.co/u/Shreesh_Narayanan)\
**Replies:** 4\
**Last updated:** [March 7, 2023, 3:31pm UTC](https://discuss.elastic.co/t/markdown-link-to-a-secondary-dashboard-is-not-time-persistent/326980 "2023-03-07T15:31:00Z")

</div>

Hi Folks, I have a primary dashboard that uses a markdown visualization that links to a secondary dashboard , while the page opens just fine. The time values from the primary dashboard are not carried over to the second…

---

## [Filebeat: failed to parse field \[user\_agent.version\] of type \[date\]](https://discuss.elastic.co/t/filebeat-failed-to-parse-field-user-agent-version-of-type-date/327124)

<div class="topic-metadata">

**Author:** [@mevan](https://discuss.elastic.co/u/mevan)\
**Replies:** 12\
**Last updated:** [March 7, 2023, 2:43pm UTC](https://discuss.elastic.co/t/filebeat-failed-to-parse-field-user-agent-version-of-type-date/327124 "2023-03-07T14:43:29Z")

</div>

This begins as a filebeat issue but I think it's now a matter of elasticsearch index. I'm seeing repeated messages like this in our logging. I can see this is related to the nginx module but I'm unsure how to go about f…

---

## [Timestamp under data stream](https://discuss.elastic.co/t/timestamp-under-data-stream/327192)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 0\
**Last updated:** [March 7, 2023, 2:32pm UTC](https://discuss.elastic.co/t/timestamp-under-data-stream/327192 "2023-03-07T14:32:57Z")

</div>

Hi I'm facing the case with timestamp under data stream When I put the data do data stream template I can find these data under the different time shifted 1hour ahead. the same data was put to index and looks as e…

---

## [Kibana - one visualization should not be affected by user click on another](https://discuss.elastic.co/t/kibana-one-visualization-should-not-be-affected-by-user-click-on-another/327123)

<div class="topic-metadata">

**Author:** [@richfish](https://discuss.elastic.co/u/richfish)\
**Replies:** 1\
**Last updated:** [March 7, 2023, 2:30pm UTC](https://discuss.elastic.co/t/kibana-one-visualization-should-not-be-affected-by-user-click-on-another/327123 "2023-03-07T14:30:11Z")

</div>

I have a dashboard with 4 pie charts, a data table and a search. When the user clicks on a slice on one of the pies, I want the data table and the search to reflect what they clicked. But I don't want the other 3 pie cha…

---

## [Building beats with oss lisence](https://discuss.elastic.co/t/building-beats-with-oss-lisence/327187)

<div class="topic-metadata">

**Author:** [@Udemy\_Guy](https://discuss.elastic.co/u/Udemy_Guy)\
**Replies:** 0\
**Last updated:** [March 7, 2023, 2:13pm UTC](https://discuss.elastic.co/t/building-beats-with-oss-lisence/327187 "2023-03-07T14:13:09Z")

</div>

We are trying to rebuild beats with oss licensing, anyone can guide? We used "mage build" but looks like it does not build it as oss.

---

## [Is there a way to remove or hide the black "Elastic" bar with the "Search Elastic" box from Kibana 7.x?](https://discuss.elastic.co/t/is-there-a-way-to-remove-or-hide-the-black-elastic-bar-with-the-search-elastic-box-from-kibana-7-x/327017)

<div class="topic-metadata">

**Author:** [@quan\_w](https://discuss.elastic.co/u/quan_w)\
**Replies:** 1\
**Last updated:** [March 7, 2023, 1:57pm UTC](https://discuss.elastic.co/t/is-there-a-way-to-remove-or-hide-the-black-elastic-bar-with-the-search-elastic-box-from-kibana-7-x/327017 "2023-03-07T13:57:42Z")

</div>

how to remove or hide the black "Elastic" bar in the header ?

[Previous page](https://discuss.elastic.co/latest.md?page=755)

[Next page](https://discuss.elastic.co/latest.md?page=757)
