# Latest

**URL:** https://discuss.elastic.co/latest.md?page=768

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 769

---

## [Unable to enable Vnet or traffic filter for Elastic cloud](https://discuss.elastic.co/t/unable-to-enable-vnet-or-traffic-filter-for-elastic-cloud/325965)

<div class="topic-metadata">

**Author:** [@zameer712](https://discuss.elastic.co/u/zameer712)\
**Replies:** 4\
**Last updated:** [February 25, 2023, 4:14pm UTC](https://discuss.elastic.co/t/unable-to-enable-vnet-or-traffic-filter-for-elastic-cloud/325965 "2023-02-25T16:14:03Z")

</div>

Hi Team, Hope you are doing well & Safe. I have followed documentation to enabled our elastic cloud from public internet to azure networking boundaries as per the step granted as below documentation. But still we coul…

---

## [\[ML\] Custom function in anomaly detection job](https://discuss.elastic.co/t/ml-custom-function-in-anomaly-detection-job/326332)

<div class="topic-metadata">

**Author:** [@ylasri](https://discuss.elastic.co/u/ylasri)\
**Replies:** 6\
**Last updated:** [February 25, 2023, 12:58pm UTC](https://discuss.elastic.co/t/ml-custom-function-in-anomaly-detection-job/326332 "2023-02-25T12:58:38Z")

</div>

Dear community, I'm feeding documents directly from a source index to an ML anomaly job detection, using population analysis for a high cardinality use case (I don't want to feed aggregated data directly or using transf…

---

## [Kibana quick select value](https://discuss.elastic.co/t/kibana-quick-select-value/326490)

<div class="topic-metadata">

**Author:** [@not\_correct](https://discuss.elastic.co/u/not_correct)\
**Replies:** 2\
**Last updated:** [February 25, 2023, 9:39am UTC](https://discuss.elastic.co/t/kibana-quick-select-value/326490 "2023-02-25T09:39:52Z")

</div>

Hi, Is there a way to get a value from quick select (time range picker) in Kibana Lens , to be able to use this value into additional KQL filtering. My data is having two time fields. A user should be able to select/sl…

---

## [To view the index details using canvas dashboard](https://discuss.elastic.co/t/to-view-the-index-details-using-canvas-dashboard/325967)

<div class="topic-metadata">

**Author:** [@anushyaadam](https://discuss.elastic.co/u/anushyaadam)\
**Replies:** 2\
**Last updated:** [February 25, 2023, 8:44am UTC](https://discuss.elastic.co/t/to-view-the-index-details-using-canvas-dashboard/325967 "2023-02-25T08:44:57Z")

</div>

Hi Team, We are trying to create the canvas dashboard which will display the index details using the command "GET \_cat/indices". Could you please suggest any approach to proceed with this activity. Regards Anushya

---

## [Range with script fields](https://discuss.elastic.co/t/range-with-script-fields/326487)

<div class="topic-metadata">

**Author:** [@TECHNOID](https://discuss.elastic.co/u/TECHNOID)\
**Replies:** 0\
**Last updated:** [February 25, 2023, 7:41am UTC](https://discuss.elastic.co/t/range-with-script-fields/326487 "2023-02-25T07:41:50Z")

</div>

Hello, tell me if it's possible to filter aggregation by scriptfield range search result \[hits\] =\> Array ( ... \[hits\] =\> Array ( \[0\] =\> Array …

---

## [How load big data from database using Logstash in elasticsearch index?](https://discuss.elastic.co/t/how-load-big-data-from-database-using-logstash-in-elasticsearch-index/326489)

<div class="topic-metadata">

**Author:** [@boliwe](https://discuss.elastic.co/u/boliwe)\
**Replies:** 0\
**Last updated:** [February 25, 2023, 8:06am UTC](https://discuss.elastic.co/t/how-load-big-data-from-database-using-logstash-in-elasticsearch-index/326489 "2023-02-25T08:06:52Z")

</div>

I want to learn how to load big data from database to elasticsearch using logstash jdbc input plugin. I could not find my answer from other forums. I have 1billion data in databse. Logstash settings has 8 workers, 15000…

---

## [Querying data using script query with lang=expression for remainder operation](https://discuss.elastic.co/t/querying-data-using-script-query-with-lang-expression-for-remainder-operation/325895)

<div class="topic-metadata">

**Author:** [@Rachana\_Maniyar](https://discuss.elastic.co/u/Rachana_Maniyar)\
**Replies:** 16\
**Last updated:** [February 25, 2023, 7:20am UTC](https://discuss.elastic.co/t/querying-data-using-script-query-with-lang-expression-for-remainder-operation/325895 "2023-02-25T07:20:25Z")

</div>

hi Folks, We store a field of type "long" in elastic which has value of this nature = 9048716794795431 Need to retrieve these records based on modulus expression. So the query looks like this query: {'query': {'bool':…

---

## [Endpoint events dont contain process or file hash](https://discuss.elastic.co/t/endpoint-events-dont-contain-process-or-file-hash/324583)

<div class="topic-metadata">

**Author:** [@yak990](https://discuss.elastic.co/u/yak990)\
**Replies:** 2\
**Last updated:** [February 25, 2023, 1:51am UTC](https://discuss.elastic.co/t/endpoint-events-dont-contain-process-or-file-hash/324583 "2023-02-25T01:51:28Z")

</div>

I'm looking through a series of endpoint events, and do not see the hash of the process or file. The events are in endpoint.events.registry in this case. The hash is important, because its easy to cut and paste that in…

---

## [PDF/PNG Reporting chromium error](https://discuss.elastic.co/t/pdf-png-reporting-chromium-error/326121)

<div class="topic-metadata">

**Author:** [@furkano](https://discuss.elastic.co/u/furkano)\
**Replies:** 6\
**Last updated:** [February 24, 2023, 11:04pm UTC](https://discuss.elastic.co/t/pdf-png-reporting-chromium-error/326121 "2023-02-24T23:04:40Z")

</div>

Hi, I'm getting this error when i try to download some dashboards as PDF/PNG, I increased my timeout time and byte for reporting. By the way i've got platinium license

---

## [What is the difference between xpack.security.http.ssl.verification\_mode and xpack.http.ssl.verification\_mode](https://discuss.elastic.co/t/what-is-the-difference-between-xpack-security-http-ssl-verification-mode-and-xpack-http-ssl-verification-mode/326474)

<div class="topic-metadata">

**Author:** [@hiruni.insyncit.net](https://discuss.elastic.co/u/hiruni.insyncit.net)\
**Replies:** 0\
**Last updated:** [February 24, 2023, 9:39pm UTC](https://discuss.elastic.co/t/what-is-the-difference-between-xpack-security-http-ssl-verification-mode-and-xpack-http-ssl-verification-mode/326474 "2023-02-24T21:39:38Z")

</div>

I want to know what is the difference between xpack.security.http.ssl.verification\_mode: certificate and xpack.http.ssl.verification\_mode: certificate Also, can I use both setting at same time...? Thank you..! Hiruni

---

## [No Services data on APM Dashboard](https://discuss.elastic.co/t/no-services-data-on-apm-dashboard/326383)

<div class="topic-metadata">

**Author:** [@Matt\_Johnston](https://discuss.elastic.co/u/Matt_Johnston)\
**Replies:** 2\
**Last updated:** [February 24, 2023, 8:20pm UTC](https://discuss.elastic.co/t/no-services-data-on-apm-dashboard/326383 "2023-02-24T20:20:17Z")

</div>

I've set up two services on APM and I can see them in the APM dashboard as pictured below: The services are named my-sieve-app and panicbin-app. However, as you can see from the image, there is no data to display (e…

---

## [How to create many small separate indices](https://discuss.elastic.co/t/how-to-create-many-small-separate-indices/326459)

<div class="topic-metadata">

**Author:** [@tim28](https://discuss.elastic.co/u/tim28)\
**Replies:** 5\
**Last updated:** [February 24, 2023, 7:27pm UTC](https://discuss.elastic.co/t/how-to-create-many-small-separate-indices/326459 "2023-02-24T19:27:48Z")

</div>

Hi! I want to create many (~10k) indices each having a couple of hundred documents. I have read in other places that that's discouraged as it creates a shard per index which is a lot of overhead. However, I have the req…

---

## [Logstash.licensechecker.licensereader: elasticsearch: Name or service not known](https://discuss.elastic.co/t/logstash-licensechecker-licensereader-elasticsearch-name-or-service-not-known/326462)

<div class="topic-metadata">

**Author:** [@pocketcolin](https://discuss.elastic.co/u/pocketcolin)\
**Replies:** 2\
**Last updated:** [February 24, 2023, 6:53pm UTC](https://discuss.elastic.co/t/logstash-licensechecker-licensereader-elasticsearch-name-or-service-not-known/326462 "2023-02-24T18:53:33Z")

</div>

Apologies for all of the questions recently and huge thanks to everyone who has responded and helped me get this far. At this point I have logs being passed from a Render web server to a private service running Logstash …

---

## [Logstash is failing with file not found - 'cat JDK\_VERSION' when "LS\_JAVA\_HOME" is set](https://discuss.elastic.co/t/logstash-is-failing-with-file-not-found-cat-jdk-version-when-ls-java-home-is-set/326407)

<div class="topic-metadata">

**Author:** [@skumarp7](https://discuss.elastic.co/u/skumarp7)\
**Replies:** 1\
**Last updated:** [February 24, 2023, 5:23pm UTC](https://discuss.elastic.co/t/logstash-is-failing-with-file-not-found-cat-jdk-version-when-ls-java-home-is-set/326407 "2023-02-24T17:23:47Z")

</div>

Hi, Logstash RPM used: 8.6.1 We have built a docker image with the logstash rpm and running the container in our kubernetes cluster We are exporting LS\_JAVA\_HOME env in the container to the jdk already installed as a …

---

## [Add any 2 Index to form new index which will combined data and should not override any fields values](https://discuss.elastic.co/t/add-any-2-index-to-form-new-index-which-will-combined-data-and-should-not-override-any-fields-values/326173)

<div class="topic-metadata">

**Author:** [@Mangesh\_Mathe](https://discuss.elastic.co/u/Mangesh_Mathe)\
**Replies:** 3\
**Last updated:** [February 24, 2023, 5:09pm UTC](https://discuss.elastic.co/t/add-any-2-index-to-form-new-index-which-will-combined-data-and-should-not-override-any-fields-values/326173 "2023-02-24T17:09:46Z")

</div>

Hello All, I want to merge two Index with same structure , which will create 3rd Index without overriding field values. For example: index\_1: "businessUnits": "FR,JP,IE" index\_2: "businessUnits": "FR,GB,DE" If I m…

---

## [Filebeat still sending logs even if service is stopped](https://discuss.elastic.co/t/filebeat-still-sending-logs-even-if-service-is-stopped/326029)

<div class="topic-metadata">

**Author:** [@Azkiel19](https://discuss.elastic.co/u/Azkiel19)\
**Replies:** 1\
**Last updated:** [February 24, 2023, 4:43pm UTC](https://discuss.elastic.co/t/filebeat-still-sending-logs-even-if-service-is-stopped/326029 "2023-02-24T16:43:20Z")

</div>

Hi, I'm new to Filebeats and the ELK stack. To provide an overview, our setup uses: Filebeat -\> sends to Logstash -\> sends to Elastic Search I expected that once I turned off / stop the filebeat service from running …

---

## [Kibana server connection to browser multi-domains trusted certificates](https://discuss.elastic.co/t/kibana-server-connection-to-browser-multi-domains-trusted-certificates/326457)

<div class="topic-metadata">

**Author:** [@IamYipi](https://discuss.elastic.co/u/IamYipi)\
**Replies:** 0\
**Last updated:** [February 24, 2023, 4:22pm UTC](https://discuss.elastic.co/t/kibana-server-connection-to-browser-multi-domains-trusted-certificates/326457 "2023-02-24T16:22:53Z")

</div>

Hello, I'm trying to install in my kibana server two different certificates for two different domains where can connect to kibana. Example: Domain 1: example1.com Certificates: example.crt example.key example.ca …

---

## [Bug Report: Alert behaviour after deleting its rule](https://discuss.elastic.co/t/bug-report-alert-behaviour-after-deleting-its-rule/326416)

<div class="topic-metadata">

**Author:** [@Mistral](https://discuss.elastic.co/u/Mistral)\
**Replies:** 2\
**Last updated:** [February 24, 2023, 4:25pm UTC](https://discuss.elastic.co/t/bug-report-alert-behaviour-after-deleting-its-rule/326416 "2023-02-24T16:25:54Z")

</div>

Hi, would like to report a bug if this is the right place to do so. Environment : Elasticsearch & Kibana 8.6.1 Debian 11 Reproduction steps: Create a new alerting rule in Observability Trigger the alert to be active …

---

## [Logs are not coming for every half n hour](https://discuss.elastic.co/t/logs-are-not-coming-for-every-half-n-hour/326402)

<div class="topic-metadata">

**Author:** [@Haneesha](https://discuss.elastic.co/u/Haneesha)\
**Replies:** 1\
**Last updated:** [February 24, 2023, 4:16pm UTC](https://discuss.elastic.co/t/logs-are-not-coming-for-every-half-n-hour/326402 "2023-02-24T16:16:20Z")

</div>

Hi Team, Since today morning logs in kibana are coming and then going off . This is the third time in a single day. Could anyone please help.

---

## [Why does aggregation contain ID's that don't exist in the query results?](https://discuss.elastic.co/t/why-does-aggregation-contain-ids-that-dont-exist-in-the-query-results/326445)

<div class="topic-metadata">

**Author:** [@A\_K3](https://discuss.elastic.co/u/A_K3)\
**Replies:** 1\
**Last updated:** [February 24, 2023, 4:08pm UTC](https://discuss.elastic.co/t/why-does-aggregation-contain-ids-that-dont-exist-in-the-query-results/326445 "2023-02-24T16:08:10Z")

</div>

To gather data on how many documents have been prepared by some employee in a given time period, I have written this query: { "from": 0, "size": 0, "sort": \[\], "query": { "bool": { "must": \[ { …

---

## [Unable to see trace id or transaction info in logs](https://discuss.elastic.co/t/unable-to-see-trace-id-or-transaction-info-in-logs/326375)

<div class="topic-metadata">

**Author:** [@pocketcolin](https://discuss.elastic.co/u/pocketcolin)\
**Replies:** 6\
**Last updated:** [February 24, 2023, 4:01pm UTC](https://discuss.elastic.co/t/unable-to-see-trace-id-or-transaction-info-in-logs/326375 "2023-02-24T16:01:44Z")

</div>

I currently have a NodeJS server passing logs to a Logstash server with a TCP tunnel using a Winston transport. Logs make it through all the way to my Elastic Cloud hosted Elasticsearch and pretty much everything looks g…

---

## [Source maps are not being removed](https://discuss.elastic.co/t/source-maps-are-not-being-removed/325749)

<div class="topic-metadata">

**Author:** [@Casper\_Aangeenbrug](https://discuss.elastic.co/u/Casper_Aangeenbrug)\
**Replies:** 3\
**Last updated:** [February 24, 2023, 3:49pm UTC](https://discuss.elastic.co/t/source-maps-are-not-being-removed/325749 "2023-02-24T15:49:08Z")

</div>

ELK stack version: 8.5.2 Describe the bug I was testing the RUM agent and I realized that some of the source maps that I uploaded are incorrect. To mitigate this, I wrote a Python script that removes all source maps th…

---

## [Alert rules requiring endpoint integration 8.2.0 when 8.6.1 is installed already](https://discuss.elastic.co/t/alert-rules-requiring-endpoint-integration-8-2-0-when-8-6-1-is-installed-already/326219)

<div class="topic-metadata">

**Author:** [@Kelly\_Slavens](https://discuss.elastic.co/u/Kelly_Slavens)\
**Replies:** 2\
**Last updated:** [February 24, 2023, 3:31pm UTC](https://discuss.elastic.co/t/alert-rules-requiring-endpoint-integration-8-2-0-when-8-6-1-is-installed-already/326219 "2023-02-24T15:31:10Z")

</div>

We're seeing an issue in the Rules section. Several rules indicate they require the Endpoint Integration to be installed. Endpoint is installed and deployed on thousands of devices. The link provided points to version 8…

---

## [Different values using date histogram](https://discuss.elastic.co/t/different-values-using-date-histogram/326453)

<div class="topic-metadata">

**Author:** [@bcamboim](https://discuss.elastic.co/u/bcamboim)\
**Replies:** 0\
**Last updated:** [February 24, 2023, 3:15pm UTC](https://discuss.elastic.co/t/different-values-using-date-histogram/326453 "2023-02-24T15:15:26Z")

</div>

Hi everyone. I'am using the package @elastic/elasticsearch (^7.9.1) to do queries in my cluster. I have a dashboard showing the concurrent users using my videos platform. My query is: { query: { bool: { …

---

## [New "Elastic Defend" integration not recognized by rules (8.6.2)](https://discuss.elastic.co/t/new-elastic-defend-integration-not-recognized-by-rules-8-6-2/326436)

<div class="topic-metadata">

**Author:** [@syk](https://discuss.elastic.co/u/syk)\
**Replies:** 2\
**Last updated:** [February 24, 2023, 3:06pm UTC](https://discuss.elastic.co/t/new-elastic-defend-integration-not-recognized-by-rules-8-6-2/326436 "2023-02-24T15:06:57Z")

</div>

Hi, I'm not able to satisfy the dependency of the "Prebuilt Security Detection Rules" on a fresh installation (on premises) of Elastic and Kibana version 8.6.2: Rules demand "Endpoint Security" integration being instal…

---

## [Create a rule that alerts on out of hours](https://discuss.elastic.co/t/create-a-rule-that-alerts-on-out-of-hours/326351)

<div class="topic-metadata">

**Author:** [@Alex.W](https://discuss.elastic.co/u/Alex.W)\
**Replies:** 3\
**Last updated:** [February 24, 2023, 2:50pm UTC](https://discuss.elastic.co/t/create-a-rule-that-alerts-on-out-of-hours/326351 "2023-02-24T14:50:11Z")

</div>

Hello, I have just started using Elastic and am trying to create a rule that will alert for role assignment changes in AzureAD out of office hours. Using @timestamp appears to be the option but I cant seem to have it l…

---

## [How to get a series aggregation in Lens?](https://discuss.elastic.co/t/how-to-get-a-series-aggregation-in-lens/326438)

<div class="topic-metadata">

**Author:** [@Rick\_V](https://discuss.elastic.co/u/Rick_V)\
**Replies:** 0\
**Last updated:** [February 24, 2023, 1:00pm UTC](https://discuss.elastic.co/t/how-to-get-a-series-aggregation-in-lens/326438 "2023-02-24T13:00:31Z")

</div>

Hi, Currently i am using a TSVB visualization with a series aggregation like described in this post to visualize apm data, it shows the duration of a series of transactions. The aggregation first takes the average of t…

---

## [Migrate backups from S3 to GCP](https://discuss.elastic.co/t/migrate-backups-from-s3-to-gcp/326447)

<div class="topic-metadata">

**Author:** [@Pete1](https://discuss.elastic.co/u/Pete1)\
**Replies:** 3\
**Last updated:** [February 24, 2023, 2:28pm UTC](https://discuss.elastic.co/t/migrate-backups-from-s3-to-gcp/326447 "2023-02-24T14:28:54Z")

</div>

Hello, I want to copy all of my backups that have been made using the s3 plugin to Google Cloud Storage. I tried to copy them just like that, but it seems that this is not the way to do it. Is there a tool or is there so…

---

## [Ingest Pipeline with filebeat not working](https://discuss.elastic.co/t/ingest-pipeline-with-filebeat-not-working/326357)

<div class="topic-metadata">

**Author:** [@heisenberg93](https://discuss.elastic.co/u/heisenberg93)\
**Replies:** 4\
**Last updated:** [February 24, 2023, 2:28pm UTC](https://discuss.elastic.co/t/ingest-pipeline-with-filebeat-not-working/326357 "2023-02-24T14:28:07Z")

</div>

Hi, We have a few Linux hosts which monitor each other with Pacemaker. Here we would like to evaluate the pacemaker.log for this. With Filebeat the log arrives, but the message is not yet analyzable. Therefore I thought…

---

## [Unable to start elasticsearch 7.11.0](https://discuss.elastic.co/t/unable-to-start-elasticsearch-7-11-0/326342)

<div class="topic-metadata">

**Author:** [@anandgavai](https://discuss.elastic.co/u/anandgavai)\
**Replies:** 6\
**Last updated:** [February 24, 2023, 2:27pm UTC](https://discuss.elastic.co/t/unable-to-start-elasticsearch-7-11-0/326342 "2023-02-24T14:27:10Z")

</div>

Hi there, am getting an ElasticsearchUncaughtExceptionHandler error and not able to start elasticsearch. All I know was there was there was an abrupt shutdown of my server and since then am not able to start the elastic…

[Previous page](https://discuss.elastic.co/latest.md?page=767)

[Next page](https://discuss.elastic.co/latest.md?page=769)
