# Latest

**URL:** https://discuss.elastic.co/latest.md?page=772

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 773

---

## ["Error: fleet-server failed: context canceled" error when trying to "Install Fleet Server to a centralized host"](https://discuss.elastic.co/t/error-fleet-server-failed-context-canceled-error-when-trying-to-install-fleet-server-to-a-centralized-host/326112)

<div class="topic-metadata">

**Author:** [@Matt\_Johnston](https://discuss.elastic.co/u/Matt_Johnston)\
**Replies:** 4\
**Last updated:** [February 22, 2023, 9:30pm UTC](https://discuss.elastic.co/t/error-fleet-server-failed-context-canceled-error-when-trying-to-install-fleet-server-to-a-centralized-host/326112 "2023-02-22T21:30:09Z")

</div>

I am trying to "Add a Fleet Server" but am getting an error when I try to install the Elastic Agent. After running the following command as instructed: curl -L -O https://artifacts.elastic.co/downloads/beats/elastic…

---

## [Elasticsearch Crashing OOM](https://discuss.elastic.co/t/elasticsearch-crashing-oom/326210)

<div class="topic-metadata">

**Author:** [@mbrimmer83](https://discuss.elastic.co/u/mbrimmer83)\
**Replies:** 8\
**Last updated:** [February 22, 2023, 9:29pm UTC](https://discuss.elastic.co/t/elasticsearch-crashing-oom/326210 "2023-02-22T21:29:20Z")

</div>

My local Enterprise Search development environment keeps crashing while indexing documents. My docker compose version: '3' services: setup: image: docker.elastic.co/elasticsearch/elasticsearch:8.6.1 volumes:…

---

## [ES custom ILM policy with cumulative index or disk size](https://discuss.elastic.co/t/es-custom-ilm-policy-with-cumulative-index-or-disk-size/326135)

<div class="topic-metadata">

**Author:** [@blueren](https://discuss.elastic.co/u/blueren)\
**Replies:** 3\
**Last updated:** [February 22, 2023, 9:25pm UTC](https://discuss.elastic.co/t/es-custom-ilm-policy-with-cumulative-index-or-disk-size/326135 "2023-02-22T21:25:47Z")

</div>

We're trying to implement an ILM policy for moving indices between hot -\> warm -\> cold in out on-premise server. What we have is this: SSD for storing hot indices HDD for storing warm indices \> 7d NAS for storing cold…

---

## [Kibana upgrade from 7.16.1 to 7.17.8 using docker compose](https://discuss.elastic.co/t/kibana-upgrade-from-7-16-1-to-7-17-8-using-docker-compose/325609)

<div class="topic-metadata">

**Author:** [@Irshu786](https://discuss.elastic.co/u/Irshu786)\
**Replies:** 7\
**Last updated:** [February 22, 2023, 9:25pm UTC](https://discuss.elastic.co/t/kibana-upgrade-from-7-16-1-to-7-17-8-using-docker-compose/325609 "2023-02-22T21:25:20Z")

</div>

What is the procedure to perform kibana upgrade with zero downtime.

---

## [Deploying elastic agent container in kubernetes: error retrieving resource lock](https://discuss.elastic.co/t/deploying-elastic-agent-container-in-kubernetes-error-retrieving-resource-lock/326227)

<div class="topic-metadata">

**Author:** [@jmyns](https://discuss.elastic.co/u/jmyns)\
**Replies:** 0\
**Last updated:** [February 22, 2023, 9:22pm UTC](https://discuss.elastic.co/t/deploying-elastic-agent-container-in-kubernetes-error-retrieving-resource-lock/326227 "2023-02-22T21:22:24Z")

</div>

When I deploy an elastic agent image I see this repeated error in the container logs. error retrieving resource lock default/elastic-agent-cluster-leader: leases.coordination.k8s.io "elastic-agent-cluster-leader" is for…

---

## [Load different formats of data under the same index name](https://discuss.elastic.co/t/load-different-formats-of-data-under-the-same-index-name/326131)

<div class="topic-metadata">

**Author:** [@Raj4](https://discuss.elastic.co/u/Raj4)\
**Replies:** 1\
**Last updated:** [February 22, 2023, 9:16pm UTC](https://discuss.elastic.co/t/load-different-formats-of-data-under-the-same-index-name/326131 "2023-02-22T21:16:08Z")

</div>

Hello All, Is it possible to load different formats of data (from different sources) under the same index name in Elasticsearch? If yes, how can we do and what are the pros and cons. Please advise

---

## [Cannot use ElasticSearch IP Address as Node URI (does not trust server certificate)](https://discuss.elastic.co/t/cannot-use-elasticsearch-ip-address-as-node-uri-does-not-trust-server-certificate/326155)

<div class="topic-metadata">

**Author:** [@lemesios10](https://discuss.elastic.co/u/lemesios10)\
**Replies:** 0\
**Last updated:** [February 22, 2023, 10:16am UTC](https://discuss.elastic.co/t/cannot-use-elasticsearch-ip-address-as-node-uri-does-not-trust-server-certificate/326155 "2023-02-22T10:16:18Z")

</div>

Hello all. This is my first post here, so please bear with me! Current setup: -Elasticsearch & Kibana hosted on an ubuntu server with docker (therefore the Elastics API URI is something like xxx.xxx.xxx.xxx:9200 for El…

---

## [Slow transform performance](https://discuss.elastic.co/t/slow-transform-performance/326195)

<div class="topic-metadata">

**Author:** [@ijsco](https://discuss.elastic.co/u/ijsco)\
**Replies:** 0\
**Last updated:** [February 22, 2023, 3:38pm UTC](https://discuss.elastic.co/t/slow-transform-performance/326195 "2023-02-22T15:38:27Z")

</div>

I'm currently running multiple transforms on the same source index. The source index is an ILM with a lifecycle policy, which shrinks the data after 30 days. These are my transform stats for one of my transforms: { "…

---

## [Kibana shows old/expired Cluster's certificates even though I have updated them](https://discuss.elastic.co/t/kibana-shows-old-expired-clusters-certificates-even-though-i-have-updated-them/326120)

<div class="topic-metadata">

**Author:** [@raespinoza](https://discuss.elastic.co/u/raespinoza)\
**Replies:** 4\
**Last updated:** [February 22, 2023, 9:09pm UTC](https://discuss.elastic.co/t/kibana-shows-old-expired-clusters-certificates-even-though-i-have-updated-them/326120 "2023-02-22T21:09:01Z")

</div>

Hi all, I have updated our cluster's certificates that are about to expire. I followed the steps suggested by the official docs and completed the task with success.....at least that's what I thought. I generated all ne…

---

## [Anomaly Detection Assistance](https://discuss.elastic.co/t/anomaly-detection-assistance/326004)

<div class="topic-metadata">

**Author:** [@tr78](https://discuss.elastic.co/u/tr78)\
**Replies:** 6\
**Last updated:** [February 22, 2023, 8:50pm UTC](https://discuss.elastic.co/t/anomaly-detection-assistance/326004 "2023-02-22T20:50:37Z")

</div>

Kibana version: 8.6.1 (ECK) Elasticsearch version: 8.6.1 (ECK) APM Server version: Fleet 8.6.1 (ECK) APM Agent language and version: Browser version: Chrome 110.0.5481.104 Original install method (e.g. download …

---

## [Create time series index from non-time series index](https://discuss.elastic.co/t/create-time-series-index-from-non-time-series-index/326221)

<div class="topic-metadata">

**Author:** [@butchkelley](https://discuss.elastic.co/u/butchkelley)\
**Replies:** 1\
**Last updated:** [February 22, 2023, 8:25pm UTC](https://discuss.elastic.co/t/create-time-series-index-from-non-time-series-index/326221 "2023-02-22T20:25:08Z")

</div>

Hello, I have a non-time series index that is updated on occasion however the data is typically very static. I would like to create a time series index from this data so I can track when it changes. I thought I could …

---

## [How to improve Kibana Dashboard loading Performance](https://discuss.elastic.co/t/how-to-improve-kibana-dashboard-loading-performance/325545)

<div class="topic-metadata">

**Author:** [@ysattvik](https://discuss.elastic.co/u/ysattvik)\
**Replies:** 1\
**Last updated:** [February 22, 2023, 5:59pm UTC](https://discuss.elastic.co/t/how-to-improve-kibana-dashboard-loading-performance/325545 "2023-02-22T17:59:15Z")

</div>

Hi Team, I am using Kibana 8.5.0 And I am using single cluster, single node and index size is also not so big, it is some kb but still while loading the Dashboard, it is taking more than 10 seconds of time. \*\*Is there …

---

## [Elasticsearch monitoring with metricbeat not working as expected](https://discuss.elastic.co/t/elasticsearch-monitoring-with-metricbeat-not-working-as-expected/326088)

<div class="topic-metadata">

**Author:** [@ramdas](https://discuss.elastic.co/u/ramdas)\
**Replies:** 3\
**Last updated:** [February 22, 2023, 5:57pm UTC](https://discuss.elastic.co/t/elasticsearch-monitoring-with-metricbeat-not-working-as-expected/326088 "2023-02-22T17:57:29Z")

</div>

Hi, i am using metricbeat for elasticsearch monitoring and the monitoring indexes are created with pattern like .ds-.monitoring-es-8-mb-\* and i can see data is also coming in. however when i go to stack monitoring it sa…

---

## [Unable to restart Kibana after configuring CSV max size](https://discuss.elastic.co/t/unable-to-restart-kibana-after-configuring-csv-max-size/325494)

<div class="topic-metadata">

**Author:** [@maskrider1111](https://discuss.elastic.co/u/maskrider1111)\
**Replies:** 1\
**Last updated:** [February 22, 2023, 5:49pm UTC](https://discuss.elastic.co/t/unable-to-restart-kibana-after-configuring-csv-max-size/325494 "2023-02-22T17:49:52Z")

</div>

Hey guys, My Kibana failed to restart after i changed the CSV setting "maxSizeBytes" in kibana.yml. Its working well if i reverted back the settings. Please advise

---

## [Logstash logs filling up disk. How to configure log4j?](https://discuss.elastic.co/t/logstash-logs-filling-up-disk-how-to-configure-log4j/326207)

<div class="topic-metadata">

**Author:** [@Thijsvdp](https://discuss.elastic.co/u/Thijsvdp)\
**Replies:** 0\
**Last updated:** [February 22, 2023, 5:29pm UTC](https://discuss.elastic.co/t/logstash-logs-filling-up-disk-how-to-configure-log4j/326207 "2023-02-22T17:29:13Z")

</div>

Hi all, We are currently facing an issue where Logstash fills up disk space on some of the nodes on our K8s cluster by outputting entire events to stdout. I am aware that I can change the loglevel of Logstash as a whole…

---

## [Trouble with my ILM](https://discuss.elastic.co/t/trouble-with-my-ilm/326051)

<div class="topic-metadata">

**Author:** [@ccaillet](https://discuss.elastic.co/u/ccaillet)\
**Replies:** 4\
**Last updated:** [February 22, 2023, 3:50pm UTC](https://discuss.elastic.co/t/trouble-with-my-ilm/326051 "2023-02-22T15:50:04Z")

</div>

Hi all, I've the following paramters on my ILM : "policy": { "phases": { "hot": { "min\_age": "0ms", "actions": { "rollover": { "max\_primary\_shard\_size": "12gb…

---

## [Very big time gap when use wildcard field on one word search](https://discuss.elastic.co/t/very-big-time-gap-when-use-wildcard-field-on-one-word-search/325947)

<div class="topic-metadata">

**Author:** [@913043599](https://discuss.elastic.co/u/913043599)\
**Replies:** 3\
**Last updated:** [February 22, 2023, 3:48pm UTC](https://discuss.elastic.co/t/very-big-time-gap-when-use-wildcard-field-on-one-word-search/325947 "2023-02-22T15:48:19Z")

</div>

Hi, When I used the new field type - wildcard field - for some queries, I found that different query inputs had a significant time difference, even though the input length was always one character: You can see ther…

---

## [Error Events with "\>"](https://discuss.elastic.co/t/error-events-with/326192)

<div class="topic-metadata">

**Author:** [@akrog79](https://discuss.elastic.co/u/akrog79)\
**Replies:** 1\
**Last updated:** [February 22, 2023, 3:43pm UTC](https://discuss.elastic.co/t/error-events-with/326192 "2023-02-22T15:43:21Z")

</div>

Hello people! I have a trouble with the ingestion of a anomaly events in fortigate. The raw event is: \<185\>logver=702032456 timestamp=1676305141 devname="FG200-E" devid="FG200ETK189243" vd="root" date=2023-02-13 time=…

---

## [Custom integration](https://discuss.elastic.co/t/custom-integration/324819)

<div class="topic-metadata">

**Author:** [@adrien\_moreau](https://discuss.elastic.co/u/adrien_moreau)\
**Replies:** 2\
**Last updated:** [February 22, 2023, 3:30pm UTC](https://discuss.elastic.co/t/custom-integration/324819 "2023-02-22T15:30:04Z")

</div>

Hi, I would like to build my own custom elastic integration for a self managed elk. I read documentation here: https://www.elastic.co/guide/en/integrations-developer I would like to know if the only way to use that in…

---

## [Dashboard creation with a query](https://discuss.elastic.co/t/dashboard-creation-with-a-query/326064)

<div class="topic-metadata">

**Author:** [@Haneesha](https://discuss.elastic.co/u/Haneesha)\
**Replies:** 7\
**Last updated:** [February 22, 2023, 3:07pm UTC](https://discuss.elastic.co/t/dashboard-creation-with-a-query/326064 "2023-02-22T15:07:27Z")

</div>

Hi Team, Could you please let me know how to create a dashboard using a query. I have a query, i am supposed to create a dashboard. Query: select type\_cd,status\_cd, count(row\_id) from siebel.s\_loy\_txn where TXN\_DT \>=…

---

## [Question about KEMP LoadManager](https://discuss.elastic.co/t/question-about-kemp-loadmanager/326188)

<div class="topic-metadata">

**Author:** [@MKirby](https://discuss.elastic.co/u/MKirby)\
**Replies:** 1\
**Last updated:** [February 22, 2023, 3:02pm UTC](https://discuss.elastic.co/t/question-about-kemp-loadmanager/326188 "2023-02-22T15:02:27Z")

</div>

In my home lab i am testing the collection of syslog from a Kemp LoadManager. Has anyone every worked with this product to ingest or have the syslogs captured? I was able to find the folowing page and have gone throug…

---

## [Joins across heterogenous documents in an index](https://discuss.elastic.co/t/joins-across-heterogenous-documents-in-an-index/325536)

<div class="topic-metadata">

**Author:** [@kembhootha](https://discuss.elastic.co/u/kembhootha)\
**Replies:** 1\
**Last updated:** [February 22, 2023, 2:58pm UTC](https://discuss.elastic.co/t/joins-across-heterogenous-documents-in-an-index/325536 "2023-02-22T14:58:35Z")

</div>

Newbie to ES. I have heterogenous documents being thrown into the same index in ES . Some example documents ( 8 typical documents that would be in the index ) {"actor\_id":1, "actor\_name":"Adam Sandler"} {"actor\_id":2,…

---

## [Unable to send logs using Filebeat to Logstash](https://discuss.elastic.co/t/unable-to-send-logs-using-filebeat-to-logstash/326114)

<div class="topic-metadata">

**Author:** [@Chris\_W1](https://discuss.elastic.co/u/Chris_W1)\
**Replies:** 11\
**Last updated:** [February 22, 2023, 2:57pm UTC](https://discuss.elastic.co/t/unable-to-send-logs-using-filebeat-to-logstash/326114 "2023-02-22T14:57:53Z")

</div>

Hi Team, I am trying to send logs in .json file on one of my server to Logstash using Filebeat. Below are the configs I did on the Filebeat & Logstash but I am not able to send it successfully. Your suggestions and help…

---

## [Implement elastic agent to collect postgresql log](https://discuss.elastic.co/t/implement-elastic-agent-to-collect-postgresql-log/326189)

<div class="topic-metadata">

**Author:** [@bagafoot](https://discuss.elastic.co/u/bagafoot)\
**Replies:** 0\
**Last updated:** [February 22, 2023, 2:47pm UTC](https://discuss.elastic.co/t/implement-elastic-agent-to-collect-postgresql-log/326189 "2023-02-22T14:47:50Z")

</div>

Hello all, I recently install elastic agent in postgresql server, I follow steps that in integration scope "add postgresql" in kibana user interface, download the yaml file and copy to postgresql server agent home dir …

---

## [How to maintain the JSON sequence in the response from Elasctic, currently ordering is getting changed](https://discuss.elastic.co/t/how-to-maintain-the-json-sequence-in-the-response-from-elasctic-currently-ordering-is-getting-changed/326168)

<div class="topic-metadata">

**Author:** [@Shraddha29](https://discuss.elastic.co/u/Shraddha29)\
**Replies:** 1\
**Last updated:** [February 22, 2023, 2:08pm UTC](https://discuss.elastic.co/t/how-to-maintain-the-json-sequence-in-the-response-from-elasctic-currently-ordering-is-getting-changed/326168 "2023-02-22T14:08:33Z")

</div>

How to maintain the JSON sequence in the response from Elastic, currently ordering is getting changed to what was inserted.

---

## [Kibana email alert](https://discuss.elastic.co/t/kibana-email-alert/326147)

<div class="topic-metadata">

**Author:** [@Sharmila\_Natarajan](https://discuss.elastic.co/u/Sharmila_Natarajan)\
**Replies:** 1\
**Last updated:** [February 22, 2023, 1:56pm UTC](https://discuss.elastic.co/t/kibana-email-alert/326147 "2023-02-22T13:56:25Z")

</div>

Hi, We are using ELK setup on Kubernetes with a basic license version (8.5.3 - ECK TEMPLATE INSTALLATION), our requirement is to send email alerts based on some logs from the index (eg. if number of test environments ar…

---

## [Transporterror 429 for search & bulk operations](https://discuss.elastic.co/t/transporterror-429-for-search-bulk-operations/326180)

<div class="topic-metadata">

**Author:** [@abhaygc](https://discuss.elastic.co/u/abhaygc)\
**Replies:** 4\
**Last updated:** [February 22, 2023, 1:55pm UTC](https://discuss.elastic.co/t/transporterror-429-for-search-bulk-operations/326180 "2023-02-22T13:55:02Z")

</div>

I am getting elasticsearch.exceptions.TransportError: TransportError(429, '429 Too Many Requests for my "\_search" & "\_bulk" operations. My cluster health is green. I have monitored threadpool write & search queues. Nu…

---

## [App Search Fundamentals](https://discuss.elastic.co/t/app-search-fundamentals/325631)

<div class="topic-metadata">

**Author:** [@lonpm2](https://discuss.elastic.co/u/lonpm2)\
**Replies:** 1\
**Last updated:** [February 22, 2023, 1:30pm UTC](https://discuss.elastic.co/t/app-search-fundamentals/325631 "2023-02-22T13:30:33Z")

</div>

Course: Version: Question: In the App Search Fundamentals guidance, following the curation guidance it asks me to return to the engine menu and look at the resulting suggestion. Click on the eye to open it... Howev…

---

## [Stuck on Observability Lab 2.2](https://discuss.elastic.co/t/stuck-on-observability-lab-2-2/325767)

<div class="topic-metadata">

**Author:** [@katie.ainscough](https://discuss.elastic.co/u/katie.ainscough)\
**Replies:** 1\
**Last updated:** [February 22, 2023, 1:20pm UTC](https://discuss.elastic.co/t/stuck-on-observability-lab-2-2/325767 "2023-02-22T13:20:06Z")

</div>

Course: Elastic Observability Version: 7.9.2 Question: Petclinic-client isn't displaying on Kibana, Discover, Metricbeat-\* Index? Have repeated the lab multiple times to check for errors I made and I still cant get th…

---

## [Rabbitmq output plugin with 'x-delayed-message' exchange](https://discuss.elastic.co/t/rabbitmq-output-plugin-with-x-delayed-message-exchange/326182)

<div class="topic-metadata">

**Author:** [@yilmazbuhar](https://discuss.elastic.co/u/yilmazbuhar)\
**Replies:** 0\
**Last updated:** [February 22, 2023, 1:04pm UTC](https://discuss.elastic.co/t/rabbitmq-output-plugin-with-x-delayed-message-exchange/326182 "2023-02-22T13:04:07Z")

</div>

Hi all, Can i send a message to "x-delayed-message" exchange with logstash. When i try this, getting error like this output { rabbitmq { # This setting must be a \["fanout", "direct", "topic", "x-consistent-…

[Previous page](https://discuss.elastic.co/latest.md?page=771)

[Next page](https://discuss.elastic.co/latest.md?page=773)
