# Latest

**URL:** https://discuss.elastic.co/latest.md?page=766

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 767

---

## [Manual Alias vs ILM read performance](https://discuss.elastic.co/t/manual-alias-vs-ilm-read-performance/326627)

<div class="topic-metadata">

**Author:** [@Chirag\_Poddar](https://discuss.elastic.co/u/Chirag_Poddar)\
**Replies:** 1\
**Last updated:** [February 27, 2023, 8:31pm UTC](https://discuss.elastic.co/t/manual-alias-vs-ilm-read-performance/326627 "2023-02-27T20:31:06Z")

</div>

I want to know about read performance between the following 2 Creating monthly indices on my own and pointing them to an alias Creating monthly indices using ILM Will they have any difference in search performance for…

---

## [Kibana API output](https://discuss.elastic.co/t/kibana-api-output/325776)

<div class="topic-metadata">

**Author:** [@branden.heifner](https://discuss.elastic.co/u/branden.heifner)\
**Replies:** 2\
**Last updated:** [February 27, 2023, 8:16pm UTC](https://discuss.elastic.co/t/kibana-api-output/325776 "2023-02-27T20:16:36Z")

</div>

Hello everyone, I am using the Kibana API to output the list of agent for auditing purposes. Is there a built-in way to output the list of agents in CSV format instead of JSON? Below is the current API call I am using. …

---

## [Using ILM for huge size of indexes](https://discuss.elastic.co/t/using-ilm-for-huge-size-of-indexes/326496)

<div class="topic-metadata">

**Author:** [@Chirag\_Poddar](https://discuss.elastic.co/u/Chirag_Poddar)\
**Replies:** 16\
**Last updated:** [February 27, 2023, 8:11pm UTC](https://discuss.elastic.co/t/using-ilm-for-huge-size-of-indexes/326496 "2023-02-27T20:11:22Z")

</div>

Use case: We have a few indexes which have huge amounts of data and they are growing. We need to figure out a way to optimize the search time. We are thinking of using ILM to manage the indexes. But there are a few roadb…

---

## [Kibana Dashboard - Pie chart from two dependent fields](https://discuss.elastic.co/t/kibana-dashboard-pie-chart-from-two-dependent-fields/326625)

<div class="topic-metadata">

**Author:** [@rvadiga](https://discuss.elastic.co/u/rvadiga)\
**Replies:** 0\
**Last updated:** [February 27, 2023, 6:55pm UTC](https://discuss.elastic.co/t/kibana-dashboard-pie-chart-from-two-dependent-fields/326625 "2023-02-27T18:55:18Z")

</div>

Hi Team, I am newbie to Elasticsearch, but trying to make hand dirty. Trying to develop a pie chart in Kibana dashboard. Want to know how we can link two fields for generating a pie chart. Sample problem statement: W…

---

## [After parsing in logstash got error](https://discuss.elastic.co/t/after-parsing-in-logstash-got-error/326560)

<div class="topic-metadata">

**Author:** [@neeldey](https://discuss.elastic.co/u/neeldey)\
**Replies:** 1\
**Last updated:** [February 27, 2023, 5:09pm UTC](https://discuss.elastic.co/t/after-parsing-in-logstash-got-error/326560 "2023-02-27T17:09:49Z")

</div>

Hi all, i getting error, while to start logstash. logstash log is as bellow. \[2023-02-27T15:18:50,526\]\[FATAL\]\[org.logstash.Logstash \] Logstash stopped processing because of an error: (SystemExit) exit org.jruby.ex…

---

## [Correct parsing Syslog message to json](https://discuss.elastic.co/t/correct-parsing-syslog-message-to-json/326564)

<div class="topic-metadata">

**Author:** [@poky](https://discuss.elastic.co/u/poky)\
**Replies:** 1\
**Last updated:** [February 27, 2023, 5:07pm UTC](https://discuss.elastic.co/t/correct-parsing-syslog-message-to-json/326564 "2023-02-27T17:07:34Z")

</div>

Hi Folks! I'm trying to parse the following message from mcafee proxy syslog inside my logstash pipeline: \<30\>Feb 24 9:33:45 mwg-n3 mwg-n3: x-message="{"DateTime":"2023-02-22 14:03:44.927","MWG\_Source":"mwg-n3.foo.de",…

---

## [About Kibana's "Color mapping" in 8.X](https://discuss.elastic.co/t/about-kibanas-color-mapping-in-8-x/326607)

<div class="topic-metadata">

**Author:** [@Juanma](https://discuss.elastic.co/u/Juanma)\
**Replies:** 1\
**Last updated:** [February 27, 2023, 5:04pm UTC](https://discuss.elastic.co/t/about-kibanas-color-mapping-in-8-x/326607 "2023-02-27T17:04:25Z")

</div>

Hi! I was looking throught my kibana 7.17 advanced options, and I've notice that "color mapping" is deprecated and removed from 8.0... Is it deprecated/removed in favor of any other thing that gives the same functional…

---

## [Synonym graph token filter backed by Elastic index](https://discuss.elastic.co/t/synonym-graph-token-filter-backed-by-elastic-index/326616)

<div class="topic-metadata">

**Author:** [@jnioche](https://discuss.elastic.co/u/jnioche)\
**Replies:** 0\
**Last updated:** [February 27, 2023, 4:35pm UTC](https://discuss.elastic.co/t/synonym-graph-token-filter-backed-by-elastic-index/326616 "2023-02-27T16:35:20Z")

</div>

Hi, I want to use the synonym graph token filter but ideally have the data stored in an Elasticsearch index so that it can be easily updated and modified. My understanding of the code is that it reads the data from a f…

---

## [Start elasticsearch that used to be in a cluster as a single-node or in a different cluster](https://discuss.elastic.co/t/start-elasticsearch-that-used-to-be-in-a-cluster-as-a-single-node-or-in-a-different-cluster/326568)

<div class="topic-metadata">

**Author:** [@lduvnjak](https://discuss.elastic.co/u/lduvnjak)\
**Replies:** 8\
**Last updated:** [February 27, 2023, 4:22pm UTC](https://discuss.elastic.co/t/start-elasticsearch-that-used-to-be-in-a-cluster-as-a-single-node-or-in-a-different-cluster/326568 "2023-02-27T16:22:24Z")

</div>

Hey Everyone, Due to some stuff that happened, I have an Elasticsearch node with a lot of data, that isn't up to date with the cluster. What I need to do is somehow start this node as a separate cluster, without it nee…

---

## [How to develop the Security Dashboard](https://discuss.elastic.co/t/how-to-develop-the-security-dashboard/326483)

<div class="topic-metadata">

**Author:** [@red-dragon](https://discuss.elastic.co/u/red-dragon)\
**Replies:** 1\
**Last updated:** [February 27, 2023, 4:14pm UTC](https://discuss.elastic.co/t/how-to-develop-the-security-dashboard/326483 "2023-02-27T16:14:19Z")

</div>

I wanted to review the security panel codes and develop them But I don't know in which part the codes of the security part are located

---

## [How to ignore 404 error in dependencies?](https://discuss.elastic.co/t/how-to-ignore-404-error-in-dependencies/325465)

<div class="topic-metadata">

**Author:** [@leandro.silva](https://discuss.elastic.co/u/leandro.silva)\
**Replies:** 4\
**Last updated:** [February 27, 2023, 3:57pm UTC](https://discuss.elastic.co/t/how-to-ignore-404-error-in-dependencies/325465 "2023-02-27T15:57:39Z")

</div>

Hi! We are using elastic apm in a micro-service environment and we have some 404 response from internal APIs that are totally acceptable, like verifying if a resource exists, but those are reported as erros in the Depen…

---

## [Agent for Endpoint is shown as unhealthy](https://discuss.elastic.co/t/agent-for-endpoint-is-shown-as-unhealthy/326485)

<div class="topic-metadata">

**Author:** [@Cosmic\_Season](https://discuss.elastic.co/u/Cosmic_Season)\
**Replies:** 1\
**Last updated:** [February 27, 2023, 3:41pm UTC](https://discuss.elastic.co/t/agent-for-endpoint-is-shown-as-unhealthy/326485 "2023-02-27T15:41:15Z")

</div>

I am unable to understand the issue. I tried to uninstall and install multiple times but the agent still shows as "Unhealthy". The agent is installed on windows and I am unable to open the file from GUI as it says "acce…

---

## [Using metricbeat in a CRC Instalation of Openshift](https://discuss.elastic.co/t/using-metricbeat-in-a-crc-instalation-of-openshift/326346)

<div class="topic-metadata">

**Author:** [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Replies:** 1\
**Last updated:** [February 27, 2023, 3:22pm UTC](https://discuss.elastic.co/t/using-metricbeat-in-a-crc-instalation-of-openshift/326346 "2023-02-27T15:22:56Z")

</div>

Hi Im having problems with the instalation of metricbeat using the manifest in the documentation https://raw.githubusercontent.com/elastic/beats/7.17/deploy/kubernetes/metricbeat-kubernetes.yaml this path doesnt exist …

---

## [Filebeat log not in elastic when matching parser](https://discuss.elastic.co/t/filebeat-log-not-in-elastic-when-matching-parser/326609)

<div class="topic-metadata">

**Author:** [@NL-kk](https://discuss.elastic.co/u/NL-kk)\
**Replies:** 0\
**Last updated:** [February 27, 2023, 3:16pm UTC](https://discuss.elastic.co/t/filebeat-log-not-in-elastic-when-matching-parser/326609 "2023-02-27T15:16:24Z")

</div>

I just setup a multiline parser because of the multiline error logs of nginx. Before the logs were visible in kibana as seperate log enteries, now they are not visible at all. The single line logs are being logged corr…

---

## [Monitoring of the private locations/Heartbeats](https://discuss.elastic.co/t/monitoring-of-the-private-locations-heartbeats/326601)

<div class="topic-metadata">

**Author:** [@Savva\_Morozov](https://discuss.elastic.co/u/Savva_Morozov)\
**Replies:** 1\
**Last updated:** [February 27, 2023, 3:03pm UTC](https://discuss.elastic.co/t/monitoring-of-the-private-locations-heartbeats/326601 "2023-02-27T15:03:09Z")

</div>

Hello! Are there any recommendations on how to monitor health of the private locations created with Elastic Agents and Heartbeats? For example, I would like to know that all the private locatons/Heartbeats are healthy an…

---

## [Create "Flop 10" with 0 values](https://discuss.elastic.co/t/create-flop-10-with-0-values/326572)

<div class="topic-metadata">

**Author:** [@StadtGE](https://discuss.elastic.co/u/StadtGE)\
**Replies:** 3\
**Last updated:** [February 27, 2023, 2:50pm UTC](https://discuss.elastic.co/t/create-flop-10-with-0-values/326572 "2023-02-27T14:50:52Z")

</div>

Hi, I hope you can help me. I want to create a visualisation (bar, metric, bucket etc.) for flop 10. It works, but I want show 0 values, areas that have not been selected. I have added {"min\_doc\_count":0} for the JSON …

---

## [Elastic Agent Google Workspace module retrieves repeated events](https://discuss.elastic.co/t/elastic-agent-google-workspace-module-retrieves-repeated-events/323516)

<div class="topic-metadata">

**Author:** [@German\_Bravo](https://discuss.elastic.co/u/German_Bravo)\
**Replies:** 8\
**Last updated:** [February 27, 2023, 2:46pm UTC](https://discuss.elastic.co/t/elastic-agent-google-workspace-module-retrieves-repeated-events/323516 "2023-02-27T14:46:12Z")

</div>

Hi im using Elastic Agent version 8.6 installed on one host, applying a policy with Google Workspace module enabled retrieving all type of events from our Google Workspace tenant. It works perfectly as alert rules give …

---

## [Elastic enrich data based on two matching fields](https://discuss.elastic.co/t/elastic-enrich-data-based-on-two-matching-fields/325561)

<div class="topic-metadata">

**Author:** [@maggo](https://discuss.elastic.co/u/maggo)\
**Replies:** 8\
**Last updated:** [February 27, 2023, 2:35pm UTC](https://discuss.elastic.co/t/elastic-enrich-data-based-on-two-matching-fields/325561 "2023-02-27T14:35:42Z")

</div>

Hello guys, i'm pretty new to ELK and want to implement a vulnerability enrichment for incoming osquery data. I have one index with vulnerability data with fields like: "affected\_product": "chrome" "affected\_version":…

---

## [Trusting remote clusters' CA](https://discuss.elastic.co/t/trusting-remote-clusters-ca/326465)

<div class="topic-metadata">

**Author:** [@YvorL](https://discuss.elastic.co/u/YvorL)\
**Replies:** 3\
**Last updated:** [February 27, 2023, 2:33pm UTC](https://discuss.elastic.co/t/trusting-remote-clusters-ca/326465 "2023-02-27T14:33:53Z")

</div>

Hi, I have two scenarios and would like a solution for both. I created a new cluster (8.6.X) with the self-generated certificates and enrolling new nodes. After that, I want to create a separate cluster, but I'd like …

---

## [Ingest issue during re-indexing/cloning?](https://discuss.elastic.co/t/ingest-issue-during-re-indexing-cloning/326466)

<div class="topic-metadata">

**Author:** [@GenSSC](https://discuss.elastic.co/u/GenSSC)\
**Replies:** 5\
**Last updated:** [February 27, 2023, 2:17pm UTC](https://discuss.elastic.co/t/ingest-issue-during-re-indexing-cloning/326466 "2023-02-27T14:17:29Z")

</div>

Hello ! I need to re-index multiple indices prior to an update of our stack. In order to test the reindexing process, I am cloning an index. However, the index needs to be read-only. My question is...what if data is in…

---

## [Elastic Search query](https://discuss.elastic.co/t/elastic-search-query/326430)

<div class="topic-metadata">

**Author:** [@ashish.akm](https://discuss.elastic.co/u/ashish.akm)\
**Replies:** 3\
**Last updated:** [February 27, 2023, 1:39pm UTC](https://discuss.elastic.co/t/elastic-search-query/326430 "2023-02-27T13:39:06Z")

</div>

how to create one query with match sort by newer report date and martch\_phrase sort by newer report and combine both result

---

## [Only one of the data nodes has a significantly higher cpu usage than other data nodes](https://discuss.elastic.co/t/only-one-of-the-data-nodes-has-a-significantly-higher-cpu-usage-than-other-data-nodes/326589)

<div class="topic-metadata">

**Author:** [@wangxr1985](https://discuss.elastic.co/u/wangxr1985)\
**Replies:** 0\
**Last updated:** [February 27, 2023, 1:07pm UTC](https://discuss.elastic.co/t/only-one-of-the-data-nodes-has-a-significantly-higher-cpu-usage-than-other-data-nodes/326589 "2023-02-27T13:07:23Z")

</div>

ES version: elasticsearch-5.6.3-1.noarch OS version: CentOS Linux release 7.6.1810 (Core) Linux version 3.10.0-1160.31.1.el7.x86\_64 (mockbuild@kbuilder.bsys.centos.org) (gcc version 4.8.5 20150623 (Red Hat 4.8.5-44) (…

---

## [Elastic security time zone issue](https://discuss.elastic.co/t/elastic-security-time-zone-issue/325915)

<div class="topic-metadata">

**Author:** [@frank\_rib](https://discuss.elastic.co/u/frank_rib)\
**Replies:** 4\
**Last updated:** [February 27, 2023, 12:43pm UTC](https://discuss.elastic.co/t/elastic-security-time-zone-issue/325915 "2023-02-27T12:43:34Z")

</div>

Hello Community, I have an issue with the TIMEZONE in the SECURITY – ALERTS section, the logs are received in UTC+1 in Discovery and in UTC+3 in SECURITY – ALERTS. Knowning that the timezone configured at the kibana i…

---

## [Two Node Cluster Failover did not work](https://discuss.elastic.co/t/two-node-cluster-failover-did-not-work/326583)

<div class="topic-metadata">

**Author:** [@sven\_begis](https://discuss.elastic.co/u/sven_begis)\
**Replies:** 2\
**Last updated:** [February 27, 2023, 12:32pm UTC](https://discuss.elastic.co/t/two-node-cluster-failover-did-not-work/326583 "2023-02-27T12:32:26Z")

</div>

Two Node Cluster Failover did not work Hello, I'm trying to set up a two node cluster. VST-ELA01 -- RAM = 8 GB -- CPU = 8 -- HD = 100 GB -- OS = Ubuntu 22.04 LTS VST-ELA02 -- RAM = 8 GB -- CPU = 8 -- HD = 1…

---

## [How to Ingest MultiLine Json file into ElasticSearch using Logstash Pipeline](https://discuss.elastic.co/t/how-to-ingest-multiline-json-file-into-elasticsearch-using-logstash-pipeline/326580)

<div class="topic-metadata">

**Author:** [@prabhakar\_kamath](https://discuss.elastic.co/u/prabhakar_kamath)\
**Replies:** 0\
**Last updated:** [February 27, 2023, 12:15pm UTC](https://discuss.elastic.co/t/how-to-ingest-multiline-json-file-into-elasticsearch-using-logstash-pipeline/326580 "2023-02-27T12:15:29Z")

</div>

I have a json file similar to following: { "Key1": "value1", "Key2": "value2" ....... } I want to ingest it as it is into logstash, The Keys should be fields and values should be values to the field, value can be a…

---

## [Kibana error connecting to package registry getaddrinfo EAI error](https://discuss.elastic.co/t/kibana-error-connecting-to-package-registry-getaddrinfo-eai-error/326579)

<div class="topic-metadata">

**Author:** [@Timo\_Anzalone](https://discuss.elastic.co/u/Timo_Anzalone)\
**Replies:** 0\
**Last updated:** [February 27, 2023, 12:14pm UTC](https://discuss.elastic.co/t/kibana-error-connecting-to-package-registry-getaddrinfo-eai-error/326579 "2023-02-27T12:14:15Z")

</div>

2023-02-27T12:01:09.365155555Z \[2023-02-27T12:01:09.364+00:00\]\[ERROR\]\[plugins.fleet\] Failed to fetch latest version of endpoint from registry: Error connecting to package registry: request to https://epr.elastic.co/searc…

---

## [Elasticsearch Engineer Lab 7.3: Index lifecycle management query](https://discuss.elastic.co/t/elasticsearch-engineer-lab-7-3-index-lifecycle-management-query/326512)

<div class="topic-metadata">

**Author:** [@Bryce\_Fernandes](https://discuss.elastic.co/u/Bryce_Fernandes)\
**Replies:** 1\
**Last updated:** [February 27, 2023, 12:12pm UTC](https://discuss.elastic.co/t/elasticsearch-engineer-lab-7-3-index-lifecycle-management-query/326512 "2023-02-27T12:12:51Z")

</div>

Course: Elasticsearch Engineer Lab 7.3: Index lifecycle management Version: 8.1 Question: Query regarding rollover duration Below is the lab question: the index is in the hot phase for 2 minutes when the index rolls…

---

## [Get sum of record count for inner bucket key in two level term aggregation](https://discuss.elastic.co/t/get-sum-of-record-count-for-inner-bucket-key-in-two-level-term-aggregation/326575)

<div class="topic-metadata">

**Author:** [@Baekjun-Kim](https://discuss.elastic.co/u/Baekjun-Kim)\
**Replies:** 0\
**Last updated:** [February 27, 2023, 12:01pm UTC](https://discuss.elastic.co/t/get-sum-of-record-count-for-inner-bucket-key-in-two-level-term-aggregation/326575 "2023-02-27T12:01:45Z")

</div>

I have records with two keyword type field user\_id: String that identifies individual user, result: String such as "success", "failure" or "pending" etc. These are what I want to do: Get record count for each result…

---

## [Compare two indexes based on more than two fields](https://discuss.elastic.co/t/compare-two-indexes-based-on-more-than-two-fields/325464)

<div class="topic-metadata">

**Author:** [@Prashant\_Pandey1](https://discuss.elastic.co/u/Prashant_Pandey1)\
**Replies:** 3\
**Last updated:** [February 27, 2023, 11:56am UTC](https://discuss.elastic.co/t/compare-two-indexes-based-on-more-than-two-fields/325464 "2023-02-27T11:56:24Z")

</div>

I have two Indexes. I want to get the list of matched and unmatched data based on field(s). I had tried to use Preview transform Api , but it's showing data only up to 100 records. Please let me know ,is there any oth…

---

## [\[ERROR\]\[elasticsearch-service\] Unable to retrieve version information from Elasticsearch nodes](https://discuss.elastic.co/t/error-elasticsearch-service-unable-to-retrieve-version-information-from-elasticsearch-nodes/325827)

<div class="topic-metadata">

**Author:** [@Mausam\_Singh](https://discuss.elastic.co/u/Mausam_Singh)\
**Replies:** 5\
**Last updated:** [February 27, 2023, 11:49am UTC](https://discuss.elastic.co/t/error-elasticsearch-service-unable-to-retrieve-version-information-from-elasticsearch-nodes/325827 "2023-02-27T11:49:21Z")

</div>

Hi Team, I have locally installed elasticsearch and kibana on Mac OS. it was working fine from last 1.5 months . However I am getting below error (while starting kibana) from last week: Below is elasticsearch detail : …

[Previous page](https://discuss.elastic.co/latest.md?page=765)

[Next page](https://discuss.elastic.co/latest.md?page=767)
