# Latest

**URL:** https://discuss.elastic.co/latest.md?page=761

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 762

---

## [Integration](https://discuss.elastic.co/t/integration/326744)

<div class="topic-metadata">

**Author:** [@bex](https://discuss.elastic.co/u/bex)\
**Replies:** 7\
**Last updated:** [March 3, 2023, 6:46am UTC](https://discuss.elastic.co/t/integration/326744 "2023-03-03T06:46:36Z")

</div>

I would like to clarify, what is the difference between "EndPoint Security" and "Elastic Defend" integrations? But there is only "Elastic Defend" in "integration" tab. But in "rules", it is asked to add "Endpoint securi…

---

## [How to create date bucket in dashboard](https://discuss.elastic.co/t/how-to-create-date-bucket-in-dashboard/326904)

<div class="topic-metadata">

**Author:** [@ikonrao](https://discuss.elastic.co/u/ikonrao)\
**Replies:** 0\
**Last updated:** [March 3, 2023, 4:56am UTC](https://discuss.elastic.co/t/how-to-create-date-bucket-in-dashboard/326904 "2023-03-03T04:56:07Z")

</div>

Hi, I have some records with date fields like Feb 27, 2023 Feb 25, 2023 Feb 11, 2023 Feb 4, 2023 Jan 26, 2023 Jan 18, 2023 Now while presenting these records in kibana dashboard , i need to show records from Jan …

---

## [But,how to hide add filter?](https://discuss.elastic.co/t/but-how-to-hide-add-filter/326549)

<div class="topic-metadata">

**Author:** [@quan\_w](https://discuss.elastic.co/u/quan_w)\
**Replies:** 2\
**Last updated:** [March 3, 2023, 4:42am UTC](https://discuss.elastic.co/t/but-how-to-hide-add-filter/326549 "2023-03-03T04:42:48Z")

</div>

Continuing the discussion from Show / Hide Global Filter Bar in Kibana:

---

## [Logstash close\_older in tail mode](https://discuss.elastic.co/t/logstash-close-older-in-tail-mode/326896)

<div class="topic-metadata">

**Author:** [@akassabi](https://discuss.elastic.co/u/akassabi)\
**Replies:** 7\
**Last updated:** [March 3, 2023, 4:26am UTC](https://discuss.elastic.co/t/logstash-close-older-in-tail-mode/326896 "2023-03-03T04:26:01Z")

</div>

Suppose we have an input file input.dat and we are reading it in Logstash in tail mode. We set close\_older to 10 minutes. My questions are: Is the close\_older setting deprecated? The docs say it is "retained for back…

---

## [Is @timestamp in kibana from filebeat or logstash?](https://discuss.elastic.co/t/is-timestamp-in-kibana-from-filebeat-or-logstash/326836)

<div class="topic-metadata">

**Author:** [@LongKang\_Fan](https://discuss.elastic.co/u/LongKang_Fan)\
**Replies:** 9\
**Last updated:** [March 3, 2023, 3:11am UTC](https://discuss.elastic.co/t/is-timestamp-in-kibana-from-filebeat-or-logstash/326836 "2023-03-03T03:11:22Z")

</div>

So the thing is I have filebeat that ship the log file to logstash then to the elasticsearch cluster. And I created the data view the get the messages on the discover page. I wonder where this @timestamp field comes from…

---

## [Add metric and Visualize from Visualize Library to User Experience Dasdboard](https://discuss.elastic.co/t/add-metric-and-visualize-from-visualize-library-to-user-experience-dasdboard/326898)

<div class="topic-metadata">

**Author:** [@hung.lengoc](https://discuss.elastic.co/u/hung.lengoc)\
**Replies:** 0\
**Last updated:** [March 3, 2023, 2:27am UTC](https://discuss.elastic.co/t/add-metric-and-visualize-from-visualize-library-to-user-experience-dasdboard/326898 "2023-03-03T02:27:05Z")

</div>

Hello team, I working with APM and RUM version 5.12.0. Now I want to add "user\_id" or "user\_name" information who is logged in to the app to "User Experience Dashboard". And can I add a "Visualize" from "Visualize Libr…

---

## [Logstash connection error](https://discuss.elastic.co/t/logstash-connection-error/326133)

<div class="topic-metadata">

**Author:** [@peinmercado](https://discuss.elastic.co/u/peinmercado)\
**Replies:** 1\
**Last updated:** [March 3, 2023, 1:27am UTC](https://discuss.elastic.co/t/logstash-connection-error/326133 "2023-03-03T01:27:32Z")

</div>

Hi all, I'm trying to setup log stash for my elasticsearch master region to backup region for our BCP, I will be using the in and out information of logstash however, I got an error \[2023-02-22T07:14:21,226\]\[ERROR\]\[l…

---

## [ECK Helm Charts](https://discuss.elastic.co/t/eck-helm-charts/326878)

<div class="topic-metadata">

**Author:** [@SeanPlacchetti](https://discuss.elastic.co/u/SeanPlacchetti)\
**Replies:** 2\
**Last updated:** [March 2, 2023, 11:28pm UTC](https://discuss.elastic.co/t/eck-helm-charts/326878 "2023-03-02T23:28:23Z")

</div>

I see there are now ECK Helm charts in the /deploy directory of the cloud-on-k8s repository maintained mostly by @Thibault\_Richard ... are these supported by Elastic? I know the old Helm charts are not, but are these?

---

## [Apply Log Threshold alert to specific hosts only](https://discuss.elastic.co/t/apply-log-threshold-alert-to-specific-hosts-only/326893)

<div class="topic-metadata">

**Author:** [@Rapture\_Buckley](https://discuss.elastic.co/u/Rapture_Buckley)\
**Replies:** 0\
**Last updated:** [March 2, 2023, 11:26pm UTC](https://discuss.elastic.co/t/apply-log-threshold-alert-to-specific-hosts-only/326893 "2023-03-02T23:26:47Z")

</div>

Hi, Currently I am ingesting log files from two radius servers. Setup of filebeat to ingest the logs is currently managed by Fleet - with the log file integration. The log files are passed through a pipeline and then …

---

## [Getting error when trying o update field value (it is a keyword)](https://discuss.elastic.co/t/getting-error-when-trying-o-update-field-value-it-is-a-keyword/326891)

<div class="topic-metadata">

**Author:** [@brunofl](https://discuss.elastic.co/u/brunofl)\
**Replies:** 0\
**Last updated:** [March 2, 2023, 10:36pm UTC](https://discuss.elastic.co/t/getting-error-when-trying-o-update-field-value-it-is-a-keyword/326891 "2023-03-02T22:36:06Z")

</div>

Trying to figure out this issue, the pmdata1.pm\_data\_source.hw\_alias is a text field that is also mapped as keyword pmdata1.pm\_data\_source.hw\_alias.key. I tried this query (\_update\_by\_query) using the field it worked (f…

---

## [How to enforce ordering within nested objects?](https://discuss.elastic.co/t/how-to-enforce-ordering-within-nested-objects/326889)

<div class="topic-metadata">

**Author:** [@pure](https://discuss.elastic.co/u/pure)\
**Replies:** 0\
**Last updated:** [March 2, 2023, 9:19pm UTC](https://discuss.elastic.co/t/how-to-enforce-ordering-within-nested-objects/326889 "2023-03-02T21:19:27Z")

</div>

I'm using elasticsearch as a Key-Value store, so that I can guarantee the query always return just 1 document. There is a nested field in the document schema, and I want to make sure multiple values within the nested obj…

---

## [Kubernetes - Inventory showing elastic agents instead of Host names](https://discuss.elastic.co/t/kubernetes-inventory-showing-elastic-agents-instead-of-host-names/323660)

<div class="topic-metadata">

**Author:** [@Pablo\_Halamaj](https://discuss.elastic.co/u/Pablo_Halamaj)\
**Replies:** 4\
**Last updated:** [March 2, 2023, 7:13pm UTC](https://discuss.elastic.co/t/kubernetes-inventory-showing-elastic-agents-instead-of-host-names/323660 "2023-03-02T19:13:07Z")

</div>

Hello, I set up Fleet and a bunch of agents running on a Kubernetes (K8S) cluster with the Kubernetes' integration. So far the log and metrics integration kind of work ( we see them on the DSs, the dashboards and the d…

---

## [How to control the timeout in journeys .ts](https://discuss.elastic.co/t/how-to-control-the-timeout-in-journeys-ts/326877)

<div class="topic-metadata">

**Author:** [@odelacruzc](https://discuss.elastic.co/u/odelacruzc)\
**Replies:** 3\
**Last updated:** [March 2, 2023, 7:07pm UTC](https://discuss.elastic.co/t/how-to-control-the-timeout-in-journeys-ts/326877 "2023-03-02T19:07:36Z")

</div>

hi, please how to control this timeout 30000 ms.

---

## [Kubernetes Node Condition NetworkUnavailable missing from metricbeat](https://discuss.elastic.co/t/kubernetes-node-condition-networkunavailable-missing-from-metricbeat/326789)

<div class="topic-metadata">

**Author:** [@kbujold\_wr](https://discuss.elastic.co/u/kbujold_wr)\
**Replies:** 4\
**Last updated:** [March 2, 2023, 6:52pm UTC](https://discuss.elastic.co/t/kubernetes-node-condition-networkunavailable-missing-from-metricbeat/326789 "2023-03-02T18:52:05Z")

</div>

The kubernetes Node Condition 'NetworkUnavailable' is missing from metricbeat. Can you please elaborate to why that is? Thank you, Kris

---

## [How to install elastic search fleet server on Kubernetes](https://discuss.elastic.co/t/how-to-install-elastic-search-fleet-server-on-kubernetes/326880)

<div class="topic-metadata">

**Author:** [@iojas](https://discuss.elastic.co/u/iojas)\
**Replies:** 0\
**Last updated:** [March 2, 2023, 6:03pm UTC](https://discuss.elastic.co/t/how-to-install-elastic-search-fleet-server-on-kubernetes/326880 "2023-03-02T18:03:56Z")

</div>

I think I have been going round and round with the whole setup. I am able to get the fleet connection working when working with ECK on cloud. Since it's a managed instance it comes prebuilt with fleet server installed. w…

---

## [Elastic APM log every 10 seconds?](https://discuss.elastic.co/t/elastic-apm-log-every-10-seconds/326870)

<div class="topic-metadata">

**Author:** [@pocketcolin](https://discuss.elastic.co/u/pocketcolin)\
**Replies:** 2\
**Last updated:** [March 2, 2023, 5:22pm UTC](https://discuss.elastic.co/t/elastic-apm-log-every-10-seconds/326870 "2023-03-02T17:22:00Z")

</div>

I've been slowly cleaning up my Elastic integration and fine tuning the logs I'm getting, but one thing I can't figure out is a log from APM that my integration is receiving every 10 seconds. Is it some sort of heartbeat…

---

## [Shift value in CSV condition](https://discuss.elastic.co/t/shift-value-in-csv-condition/326801)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 6\
**Last updated:** [March 2, 2023, 5:05pm UTC](https://discuss.elastic.co/t/shift-value-in-csv-condition/326801 "2023-03-02T17:05:29Z")

</div>

Hi How I can shift some fields with value in "if" condition for example: CLLI, SWREL for the output in one event? expected output: { "NDCFLXDA" =\> "0", "@version" =\> "1", "NDCFLXDC" =\> "0", "STATUS" =\> "K", "NM…

---

## [Kibana 7.x chart label font size](https://discuss.elastic.co/t/kibana-7-x-chart-label-font-size/325262)

<div class="topic-metadata">

**Author:** [@vincent2mots](https://discuss.elastic.co/u/vincent2mots)\
**Replies:** 2\
**Last updated:** [March 2, 2023, 4:38pm UTC](https://discuss.elastic.co/t/kibana-7-x-chart-label-font-size/325262 "2023-03-02T16:38:31Z")

</div>

Hi experts! I'm looking for a way to increase the font size of the labels in a Kibana chart, such as the pie (not into Lens). I found a css file "legacy\_light\_theme.css" in which I've been able to resize some font siz…

---

## [APM in kibana only shows my java application frontend](https://discuss.elastic.co/t/apm-in-kibana-only-shows-my-java-application-frontend/326875)

<div class="topic-metadata">

**Author:** [@irivas95](https://discuss.elastic.co/u/irivas95)\
**Replies:** 1\
**Last updated:** [March 2, 2023, 4:26pm UTC](https://discuss.elastic.co/t/apm-in-kibana-only-shows-my-java-application-frontend/326875 "2023-03-02T16:26:53Z")

</div>

Hi, I am using the following application,Deployed on a GKE cluster,opbeans-java the application as such is considered as the backend while the RUM part is considered as frontend. To get the RUM part I just added a jav…

---

## [Fleet Server seems to sent plain HTTP to Fleets Logstash Output](https://discuss.elastic.co/t/fleet-server-seems-to-sent-plain-http-to-fleets-logstash-output/324035)

<div class="topic-metadata">

**Author:** [@m-logs](https://discuss.elastic.co/u/m-logs)\
**Replies:** 14\
**Last updated:** [March 2, 2023, 4:13pm UTC](https://discuss.elastic.co/t/fleet-server-seems-to-sent-plain-http-to-fleets-logstash-output/324035 "2023-03-02T16:13:53Z")

</div>

Hello, I am currently trying to configure a logstash output for the fleet server. I followed the instruction from the documentation. First I set up a Elasticsearch output for the fleet server. That worked fine. After t…

---

## [Kubernetes integration does not work on Elasticsearch/Kibana ver. 8.6.2 (SSL issue)](https://discuss.elastic.co/t/kubernetes-integration-does-not-work-on-elasticsearch-kibana-ver-8-6-2-ssl-issue/326306)

<div class="topic-metadata">

**Author:** [@tgolubic](https://discuss.elastic.co/u/tgolubic)\
**Replies:** 15\
**Last updated:** [March 2, 2023, 3:57pm UTC](https://discuss.elastic.co/t/kubernetes-integration-does-not-work-on-elasticsearch-kibana-ver-8-6-2-ssl-issue/326306 "2023-03-02T15:57:47Z")

</div>

Hello team, I have a test environment set up that hosts a 3 node k8s cluster, Elasticsearch and Kibana. ELK is installed on a separate server. ELK works without problems and the integration with Kuberentes was done acco…

---

## [Pipeline on Logstash](https://discuss.elastic.co/t/pipeline-on-logstash/326249)

<div class="topic-metadata">

**Author:** [@psanggabuana](https://discuss.elastic.co/u/psanggabuana)\
**Replies:** 2\
**Last updated:** [March 2, 2023, 3:54pm UTC](https://discuss.elastic.co/t/pipeline-on-logstash/326249 "2023-03-02T15:54:33Z")

</div>

Hi all, I need some suggestions about the pipeline on Logstash. I have running the pipeline on Logstash, and suddenly I have an issue. The pipeline is configured that is automatically changed without restarting the se…

---

## [Custom TF-IDF implementation](https://discuss.elastic.co/t/custom-tf-idf-implementation/326872)

<div class="topic-metadata">

**Author:** [@Karel\_Haerens1](https://discuss.elastic.co/u/Karel_Haerens1)\
**Replies:** 0\
**Last updated:** [March 2, 2023, 3:32pm UTC](https://discuss.elastic.co/t/custom-tf-idf-implementation/326872 "2023-03-02T15:32:29Z")

</div>

I'm trying to implement a custom TF-IDF-like algorithm with scripted similarity, my current approach: The way term frequency is determined is custom, these values are precalculated and stored in the records as lists. as…

---

## [Help receiving logs in Logstash deployed in Heroku](https://discuss.elastic.co/t/help-receiving-logs-in-logstash-deployed-in-heroku/326795)

<div class="topic-metadata">

**Author:** [@lglt](https://discuss.elastic.co/u/lglt)\
**Replies:** 6\
**Last updated:** [March 2, 2023, 2:43pm UTC](https://discuss.elastic.co/t/help-receiving-logs-in-logstash-deployed-in-heroku/326795 "2023-03-02T14:43:22Z")

</div>

Hi! I just deployed my Logstash project in Heroku. My plan is use it to process and send the logs to my Elastic Cloud deploy (Kibana and Elasticsearch). Logstash is running successfully. These are the Logstash logs that…

---

## [WordPress plugin needed](https://discuss.elastic.co/t/wordpress-plugin-needed/326797)

<div class="topic-metadata">

**Author:** [@Peter\_Lipschutz](https://discuss.elastic.co/u/Peter_Lipschutz)\
**Replies:** 2\
**Last updated:** [March 2, 2023, 2:24pm UTC](https://discuss.elastic.co/t/wordpress-plugin-needed/326797 "2023-03-02T14:24:23Z")

</div>

We want to implement an elasticsearch database that we can access through our WordPress site. We want to create a separate db in elasticsearch. It will NOT be used to search the WP MySQL db. I need to figure out what plu…

---

## [How to use actual timestamp or createdtime in Table lens without interval](https://discuss.elastic.co/t/how-to-use-actual-timestamp-or-createdtime-in-table-lens-without-interval/326843)

<div class="topic-metadata">

**Author:** [@PappuSingh](https://discuss.elastic.co/u/PappuSingh)\
**Replies:** 2\
**Last updated:** [March 2, 2023, 2:02pm UTC](https://discuss.elastic.co/t/how-to-use-actual-timestamp-or-createdtime-in-table-lens-without-interval/326843 "2023-03-02T14:02:38Z")

</div>

Hi, How to show actual timestamp or createdTime on table lens which is available in the index. In the below snap highlighted column not showing the actual time which is available in the index, it is showing interval ti…

---

## [Max Number of data nodes per machines](https://discuss.elastic.co/t/max-number-of-data-nodes-per-machines/326788)

<div class="topic-metadata">

**Author:** [@avnere](https://discuss.elastic.co/u/avnere)\
**Replies:** 4\
**Last updated:** [March 2, 2023, 1:41pm UTC](https://discuss.elastic.co/t/max-number-of-data-nodes-per-machines/326788 "2023-03-02T13:41:13Z")

</div>

Hi, I want to install few data nodes on one machines. Each data node will get 32GB RAM. Is there any formula for getting the max number of nodes per machine CPU and RAM? Thanks

---

## [Ingest data from Firebase Firestore collection and subcollection to Elastic App Search engine](https://discuss.elastic.co/t/ingest-data-from-firebase-firestore-collection-and-subcollection-to-elastic-app-search-engine/326557)

<div class="topic-metadata">

**Author:** [@Rustin\_Spencer](https://discuss.elastic.co/u/Rustin_Spencer)\
**Replies:** 1\
**Last updated:** [March 2, 2023, 1:15pm UTC](https://discuss.elastic.co/t/ingest-data-from-firebase-firestore-collection-and-subcollection-to-elastic-app-search-engine/326557 "2023-03-02T13:15:08Z")

</div>

I'm using Firebase extension Elastic App Search, feeding my collection to the engine. Is it possible to ingest the whole collection and all subcollection inside it?

---

## [Logstash is processing old events](https://discuss.elastic.co/t/logstash-is-processing-old-events/326336)

<div class="topic-metadata">

**Author:** [@Nikhitha\_Karennagari](https://discuss.elastic.co/u/Nikhitha_Karennagari)\
**Replies:** 7\
**Last updated:** [March 2, 2023, 1:11pm UTC](https://discuss.elastic.co/t/logstash-is-processing-old-events/326336 "2023-03-02T13:11:57Z")

</div>

Getting continuous errors like below in logstash { "timestamp": "2023-02-10T14:04:33.661-08:00", "severity": "warning", "message": "Could not index event to Elasticsearch. {:status=\>404, :action=\>\['index', {:\_id=\>nil, :…

---

## [Create and Deploy custom ML models for NLP](https://discuss.elastic.co/t/create-and-deploy-custom-ml-models-for-nlp/326777)

<div class="topic-metadata">

**Author:** [@sebastianboelling](https://discuss.elastic.co/u/sebastianboelling)\
**Replies:** 3\
**Last updated:** [March 2, 2023, 12:57pm UTC](https://discuss.elastic.co/t/create-and-deploy-custom-ml-models-for-nlp/326777 "2023-03-02T12:57:22Z")

</div>

Hello, I've read the documentation on ML and deploying ML models Overview | Machine Learning in the Elastic Stack \[8.6\] | Elastic. Does anyone have examples of how to do the following: Create a custom ML model that f…

[Previous page](https://discuss.elastic.co/latest.md?page=760)

[Next page](https://discuss.elastic.co/latest.md?page=762)
