# Latest

**URL:** https://discuss.elastic.co/latest.md?page=775

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 776

---

## [Rising trends of data values to latest data in Heatmap visualisation](https://discuss.elastic.co/t/rising-trends-of-data-values-to-latest-data-in-heatmap-visualisation/326031)

<div class="topic-metadata">

**Author:** [@Sahil\_Sharma1](https://discuss.elastic.co/u/Sahil_Sharma1)\
**Replies:** 0\
**Last updated:** [February 21, 2023, 7:42am UTC](https://discuss.elastic.co/t/rising-trends-of-data-values-to-latest-data-in-heatmap-visualisation/326031 "2023-02-21T07:42:39Z")

</div>

Hi, We want to show rising trends of data values in selected date range. The logic is that we want to show attributes with consistent growing values sorted in descending order. Kindly suggest how can we achieve the sam…

---

## [Refresh schedule](https://discuss.elastic.co/t/refresh-schedule/325999)

<div class="topic-metadata">

**Author:** [@Apoorva\_Shandilya](https://discuss.elastic.co/u/Apoorva_Shandilya)\
**Replies:** 4\
**Last updated:** [February 21, 2023, 8:44am UTC](https://discuss.elastic.co/t/refresh-schedule/325999 "2023-02-21T08:44:24Z")

</div>

Hi all I am beginner here . Can we add information related to refresh schedule in dashboard . I want to see if a dashboard is updated today, I would like to have this date and time as an info in the dashboard it shou…

---

## [Sum of a field after terms aggregation](https://discuss.elastic.co/t/sum-of-a-field-after-terms-aggregation/325985)

<div class="topic-metadata">

**Author:** [@Miguel\_Azorin](https://discuss.elastic.co/u/Miguel_Azorin)\
**Replies:** 4\
**Last updated:** [February 21, 2023, 8:26am UTC](https://discuss.elastic.co/t/sum-of-a-field-after-terms-aggregation/325985 "2023-02-21T08:26:32Z")

</div>

Hi! Given docs as the ones in the example below: { "id" : "1", "numValue": 9.7 } { "id" : "1", "numValue": 9.7 } { "id" : "1", "numValue": 9.7 } { "id" : "2", "numValue": 7 } { "id" : "2", "numValue": 7 } { "id" : "3",…

---

## [Query on Logstash to Elasticsearch and third party](https://discuss.elastic.co/t/query-on-logstash-to-elasticsearch-and-third-party/325990)

<div class="topic-metadata">

**Author:** [@ianrobo](https://discuss.elastic.co/u/ianrobo)\
**Replies:** 3\
**Last updated:** [February 21, 2023, 7:36am UTC](https://discuss.elastic.co/t/query-on-logstash-to-elasticsearch-and-third-party/325990 "2023-02-21T07:36:39Z")

</div>

Hi, I have an isue which should be simple to resolve but can not. Basically we send all our log data to a beat on a server in the DMZ an then that forwards onto Elastic. However we now have a requirement to forward on…

---

## [Confirmation please](https://discuss.elastic.co/t/confirmation-please/325956)

<div class="topic-metadata">

**Author:** [@jomaguca](https://discuss.elastic.co/u/jomaguca)\
**Replies:** 2\
**Last updated:** [February 21, 2023, 6:56am UTC](https://discuss.elastic.co/t/confirmation-please/325956 "2023-02-21T06:56:41Z")

</div>

Hello again I have not still could connect filebeat to elasticsearch buy the error that is showed to me is that "the proxy needs autentification" so, Can anybody confirm to me that filebeat can not pass HTTP proxies? If…

---

## [Information on the elk suite](https://discuss.elastic.co/t/information-on-the-elk-suite/325978)

<div class="topic-metadata">

**Author:** [@Baudillon\_Remy](https://discuss.elastic.co/u/Baudillon_Remy)\
**Replies:** 3\
**Last updated:** [February 21, 2023, 6:36am UTC](https://discuss.elastic.co/t/information-on-the-elk-suite/325978 "2023-02-21T06:36:17Z")

</div>

Hello, I would like to set up an infrastructure with the ELK suite. It will be a distributed architecture. I would like to have some information about the configuration required. In your opinion, how much RAM / CPU /…

---

## [Ingest data directly from Google Cloud Storage into Elastic using Google](https://discuss.elastic.co/t/ingest-data-directly-from-google-cloud-storage-into-elastic-using-google/325769)

<div class="topic-metadata">

**Author:** [@YvorL](https://discuss.elastic.co/u/YvorL)\
**Replies:** 8\
**Last updated:** [February 21, 2023, 6:32am UTC](https://discuss.elastic.co/t/ingest-data-directly-from-google-cloud-storage-into-elastic-using-google/325769 "2023-02-21T06:32:49Z")

</div>

Hi, I was reading this article and read this line: Currently, CSV file format is supported and we’ll be adding support for JSON soon. I know that it doesn't mean "the next day" but after 17 months, I checked and sti…

---

## [How to collect log of NVR Hikvision (all camera's log) to Elastic?](https://discuss.elastic.co/t/how-to-collect-log-of-nvr-hikvision-all-cameras-log-to-elastic/326018)

<div class="topic-metadata">

**Author:** [@Anh\_Nguyen](https://discuss.elastic.co/u/Anh_Nguyen)\
**Replies:** 4\
**Last updated:** [February 21, 2023, 6:28am UTC](https://discuss.elastic.co/t/how-to-collect-log-of-nvr-hikvision-all-cameras-log-to-elastic/326018 "2023-02-21T06:28:18Z")

</div>

Hello everyone, I want to collect all logs (all type logs) of the cameras to my SIEM system. I have a NVR and it have function "Logs Server Configuration" but it always failed. ( UDP port use to collect logs on the linux…

---

## [How di I map Timestamp to event Timestamp from filebeat thru logstash](https://discuss.elastic.co/t/how-di-i-map-timestamp-to-event-timestamp-from-filebeat-thru-logstash/325577)

<div class="topic-metadata">

**Author:** [@jkingstone](https://discuss.elastic.co/u/jkingstone)\
**Replies:** 9\
**Last updated:** [February 21, 2023, 6:23am UTC](https://discuss.elastic.co/t/how-di-i-map-timestamp-to-event-timestamp-from-filebeat-thru-logstash/325577 "2023-02-21T06:23:25Z")

</div>

Hi, I want to change the @timestamp to the timestamp out of event.original or message. I don't know what I do wrong. right now the @timestamp is the time where the filebeat logfile ist importet thru logstash into elast…

---

## [Esrally benchmark takes longer time to run while the report service time doesn't change](https://discuss.elastic.co/t/esrally-benchmark-takes-longer-time-to-run-while-the-report-service-time-doesnt-change/324597)

<div class="topic-metadata">

**Author:** [@fatcloud](https://discuss.elastic.co/u/fatcloud)\
**Replies:** 9\
**Last updated:** [February 21, 2023, 5:34am UTC](https://discuss.elastic.co/t/esrally-benchmark-takes-longer-time-to-run-while-the-report-service-time-doesnt-change/324597 "2023-02-21T05:34:52Z")

</div>

Hi, I'm trying to run some test to see how the number of index affect the elasticsearch cluster performance. I tested from 1k indices to 8k indices, and ran some random requests against those indices. One weird thing …

---

## [Kubernetes integration on ECK Kibana Fleet policy sample](https://discuss.elastic.co/t/kubernetes-integration-on-eck-kibana-fleet-policy-sample/326024)

<div class="topic-metadata">

**Author:** [@Brian\_Brockel](https://discuss.elastic.co/u/Brian_Brockel)\
**Replies:** 0\
**Last updated:** [February 21, 2023, 5:08am UTC](https://discuss.elastic.co/t/kubernetes-integration-on-eck-kibana-fleet-policy-sample/326024 "2023-02-21T05:08:41Z")

</div>

Looking to deploy ECK from kubernetes manifest configuring a Kubernetes integration through a fleet agent policy defined in Kibana manifest yaml. Any well defined templates that could help me understand where I went wro…

---

## [How to start and end transaction in python aws lambda function , also how to add labels between transaction](https://discuss.elastic.co/t/how-to-start-and-end-transaction-in-python-aws-lambda-function-also-how-to-add-labels-between-transaction/324320)

<div class="topic-metadata">

**Author:** [@Pratiksha\_Nagoshe](https://discuss.elastic.co/u/Pratiksha_Nagoshe)\
**Replies:** 16\
**Last updated:** [February 21, 2023, 4:21am UTC](https://discuss.elastic.co/t/how-to-start-and-end-transaction-in-python-aws-lambda-function-also-how-to-add-labels-between-transaction/324320 "2023-02-21T04:21:16Z")

</div>

If you are asking about a problem you are experiencing, please use the following template, as it will help us help you. If you have a different problem, please delete all of this text :slight\_smile: TIP 1: select at lea…

---

## [Ingesting Delinea Audit/event Logs into Elasticsearch](https://discuss.elastic.co/t/ingesting-delinea-audit-event-logs-into-elasticsearch/325870)

<div class="topic-metadata">

**Author:** [@tthiry](https://discuss.elastic.co/u/tthiry)\
**Replies:** 4\
**Last updated:** [February 21, 2023, 1:58am UTC](https://discuss.elastic.co/t/ingesting-delinea-audit-event-logs-into-elasticsearch/325870 "2023-02-21T01:58:11Z")

</div>

Hello, I am wondering if anyone has tried ingesting Delinea Secret Server logs into Elasticsearch. I'm not quite sure where to start. We are using the cloud version of both Elastic and Delinea. Any helpful hints would …

---

## [Fleet-server can not running, "only 1 fleet-server input can be defined accessing config" occur in the log files](https://discuss.elastic.co/t/fleet-server-can-not-running-only-1-fleet-server-input-can-be-defined-accessing-config-occur-in-the-log-files/325951)

<div class="topic-metadata">

**Author:** [@hds1989824](https://discuss.elastic.co/u/hds1989824)\
**Replies:** 2\
**Last updated:** [February 21, 2023, 1:56am UTC](https://discuss.elastic.co/t/fleet-server-can-not-running-only-1-fleet-server-input-can-be-defined-accessing-config-occur-in-the-log-files/325951 "2023-02-21T01:56:10Z")

</div>

first, my elk server version is 7.17.7,and deploy by docker ,such as logstach,kibana,elasticsearch,server ip is 10.30.25.223 。port forward has added to the firewall (sonicwall), 10.30.25.223: 5601，10.30.25.223:920…

---

## [Nginx access log using grok filter](https://discuss.elastic.co/t/nginx-access-log-using-grok-filter/324877)

<div class="topic-metadata">

**Author:** [@yc99](https://discuss.elastic.co/u/yc99)\
**Replies:** 1\
**Last updated:** [February 21, 2023, 12:36am UTC](https://discuss.elastic.co/t/nginx-access-log-using-grok-filter/324877 "2023-02-21T00:36:14Z")

</div>

My nginx access log format as below, there certain access log without the "$request\_time" "$http\_x\_forwarded\_for" $http\_host ' field, therefore, for certain access log, the grok filter not working, is there anyway to a…

---

## [Filebeat azure module multiple eventhubs in self managed elastic version 8.6.1](https://discuss.elastic.co/t/filebeat-azure-module-multiple-eventhubs-in-self-managed-elastic-version-8-6-1/325455)

<div class="topic-metadata">

**Author:** [@Dov\_Zelinger](https://discuss.elastic.co/u/Dov_Zelinger)\
**Replies:** 1\
**Last updated:** [February 20, 2023, 10:19pm UTC](https://discuss.elastic.co/t/filebeat-azure-module-multiple-eventhubs-in-self-managed-elastic-version-8-6-1/325455 "2023-02-20T22:19:30Z")

</div>

Hi, As written in the below link, the issue was resolved. multiple-event-hubs Unfortunately, the issue still exists. When configuring multiple platformlogs as can be seen below, only one of them gets active and that …

---

## [High Vulnerabilities found in Elasticsearch docker image v7.17.9](https://discuss.elastic.co/t/high-vulnerabilities-found-in-elasticsearch-docker-image-v7-17-9/325976)

<div class="topic-metadata">

**Author:** [@hexer338](https://discuss.elastic.co/u/hexer338)\
**Replies:** 2\
**Last updated:** [February 20, 2023, 8:58pm UTC](https://discuss.elastic.co/t/high-vulnerabilities-found-in-elasticsearch-docker-image-v7-17-9/325976 "2023-02-20T20:58:46Z")

</div>

Hi Elastic Team, We used aquasec's trivy scan(Trivy) to do vuln. scan on elasticsearch docker image: docker.elastic.co/elasticsearch/elasticsearch:7.17.9 We found 4 HIGH severity vulnerabilities below: CVE-2023-0286 …

---

## [Using Arithmetic in pipeline.yml Processor](https://discuss.elastic.co/t/using-arithmetic-in-pipeline-yml-processor/325725)

<div class="topic-metadata">

**Author:** [@fbaer](https://discuss.elastic.co/u/fbaer)\
**Replies:** 3\
**Last updated:** [February 20, 2023, 6:11pm UTC](https://discuss.elastic.co/t/using-arithmetic-in-pipeline-yml-processor/325725 "2023-02-20T18:11:52Z")

</div>

Hello, I'm appointed to update or rewriting an old ELK project. In the old version we used Logstash and its corresponding 'filebeat.cfg' file. I was rebuilding an IngestPipeline in a 'pipeline.yml'. In Losgtash we had f…

---

## [Elasticsearch data nodes - disk usage optimisation](https://discuss.elastic.co/t/elasticsearch-data-nodes-disk-usage-optimisation/325544)

<div class="topic-metadata">

**Author:** [@chethan\_m](https://discuss.elastic.co/u/chethan_m)\
**Replies:** 5\
**Last updated:** [February 20, 2023, 5:36pm UTC](https://discuss.elastic.co/t/elasticsearch-data-nodes-disk-usage-optimisation/325544 "2023-02-20T17:36:15Z")

</div>

I have an elasticsearch deployed on kubenetes/aws platform. I'm observing that Disk Free Space is not equal in the data nodes. I have 4 data nodes out of which, Two data nodes have around 1 TB free disk space One …

---

## [Matching ip address](https://discuss.elastic.co/t/matching-ip-address/325992)

<div class="topic-metadata">

**Author:** [@Lalii](https://discuss.elastic.co/u/Lalii)\
**Replies:** 4\
**Last updated:** [February 20, 2023, 4:55pm UTC](https://discuss.elastic.co/t/matching-ip-address/325992 "2023-02-20T16:55:01Z")

</div>

Hello everyone, I'm trying to do a condition on IP regex. Trying to match every IPs if \[destination.XXX\] =~ /^\\d{1,3}\\.\\d{1,3}\\.\\d{1,3}\\.\\d{1,3}$/ { mutate { ... } } I tried the solution from that post but doesnt wor…

---

## [Kibana 8.6.2-1 cannot create APM indices on ElasticSearch 8.6.2-1](https://discuss.elastic.co/t/kibana-8-6-2-1-cannot-create-apm-indices-on-elasticsearch-8-6-2-1/325877)

<div class="topic-metadata">

**Author:** [@Christopher\_Cheng](https://discuss.elastic.co/u/Christopher_Cheng)\
**Replies:** 1\
**Last updated:** [February 20, 2023, 4:40pm UTC](https://discuss.elastic.co/t/kibana-8-6-2-1-cannot-create-apm-indices-on-elasticsearch-8-6-2-1/325877 "2023-02-20T16:40:48Z")

</div>

I have installed a fresh CentOS 7, Elasticsearch 8.6.2-1, Kibana 8.6.2-1, APM 8.6.2-1 After I logged in to Kibana with the user "elastic" (superuser), I went to "Observability" \> "APM" \> "Services" \> "Settings" \> "Indi…

---

## [Issues enabling Logstash logs integration for ELK stack](https://discuss.elastic.co/t/issues-enabling-logstash-logs-integration-for-elk-stack/325993)

<div class="topic-metadata">

**Author:** [@Joshua\_Sheathelm](https://discuss.elastic.co/u/Joshua_Sheathelm)\
**Replies:** 0\
**Last updated:** [February 20, 2023, 4:13pm UTC](https://discuss.elastic.co/t/issues-enabling-logstash-logs-integration-for-elk-stack/325993 "2023-02-20T16:13:23Z")

</div>

I am currently configuring an ELK stack with three separate hosts for each service (Elastic search on one host, Logstash on another, and Kibana on the last) I have verified that Elasticsearch and Kibana are accessible fr…

---

## [Visualization of parts of URL](https://discuss.elastic.co/t/visualization-of-parts-of-url/324769)

<div class="topic-metadata">

**Author:** [@khteh](https://discuss.elastic.co/u/khteh)\
**Replies:** 1\
**Last updated:** [February 20, 2023, 4:09pm UTC](https://discuss.elastic.co/t/visualization-of-parts-of-url/324769 "2023-02-20T16:09:57Z")

</div>

I am using ECK. I have created request PATHs visualization in Kibana. One of the URL has the format of /products/product-brand/\<brand\>. How can I create a visualization on parts of the URL like \<brand\>?

---

## [Java APM : Public API + JDBC Driver](https://discuss.elastic.co/t/java-apm-public-api-jdbc-driver/325960)

<div class="topic-metadata">

**Author:** [@jlannoy](https://discuss.elastic.co/u/jlannoy)\
**Replies:** 4\
**Last updated:** [February 20, 2023, 4:05pm UTC](https://discuss.elastic.co/t/java-apm-public-api-jdbc-driver/325960 "2023-02-20T16:05:18Z")

</div>

Hello. I'm trying to set up APM agent for a Java application. The application is using an Undertow server with HTTP handlers (that means, without the Servlet part of Undertow), which is not supported out of the box. I u…

---

## [Not an int hash when using Murmur3](https://discuss.elastic.co/t/not-an-int-hash-when-using-murmur3/324902)

<div class="topic-metadata">

**Author:** [@divadpoc](https://discuss.elastic.co/u/divadpoc)\
**Replies:** 3\
**Last updated:** [February 20, 2023, 3:09pm UTC](https://discuss.elastic.co/t/not-an-int-hash-when-using-murmur3/324902 "2023-02-20T15:09:12Z")

</div>

I've tried the Fingerprint filter plugin w/ the MURMUR3 method. If set to MURMUR3 or MURMUR3\_128 the non-cryptographic MurmurHash function (either the 32-bit or 128-bit implementation, respectively) will be used. So …

---

## [Stuck on LAB login Kibana user](https://discuss.elastic.co/t/stuck-on-lab-login-kibana-user/325828)

<div class="topic-metadata">

**Author:** [@Linsra](https://discuss.elastic.co/u/Linsra)\
**Replies:** 1\
**Last updated:** [February 20, 2023, 1:18pm UTC](https://discuss.elastic.co/t/stuck-on-lab-login-kibana-user/325828 "2023-02-20T13:18:05Z")

</div>

Course: Building Great Search Experiences Version: E-Q07Q71 Question: Hi, I'm not able to login into Kibana in my Lab environment. The elastic user and password is not accepted. Is it possible to reset this password? …

---

## [Kibana UI Change](https://discuss.elastic.co/t/kibana-ui-change/325938)

<div class="topic-metadata">

**Author:** [@Ajay\_Kotnala](https://discuss.elastic.co/u/Ajay_Kotnala)\
**Replies:** 3\
**Last updated:** [February 20, 2023, 1:00pm UTC](https://discuss.elastic.co/t/kibana-ui-change/325938 "2023-02-20T13:00:54Z")

</div>

Is there a way to remove the option toggle dialog with the details option in Kibana UI. Need to rollback to older layout.

---

## [How to Access Field that made by Scripted field](https://discuss.elastic.co/t/how-to-access-field-that-made-by-scripted-field/324610)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 0\
**Last updated:** [February 3, 2023, 8:02am UTC](https://discuss.elastic.co/t/how-to-access-field-that-made-by-scripted-field/324610 "2023-02-03T08:02:43Z")

</div>

Hi everyone, i've been made scripted field like this: From the script, it generates field named expire\_days with number data type and I have also created an alert that points to this index. The problem is if i wan…

---

## [Details of Elasticserver receiving logs](https://discuss.elastic.co/t/details-of-elasticserver-receiving-logs/325969)

<div class="topic-metadata">

**Author:** [@Kosala\_Randika\_Paran](https://discuss.elastic.co/u/Kosala_Randika_Paran)\
**Replies:** 1\
**Last updated:** [February 20, 2023, 12:45pm UTC](https://discuss.elastic.co/t/details-of-elasticserver-receiving-logs/325969 "2023-02-20T12:45:13Z")

</div>

Hi flocks, We have a fresh ELK stack and now I am trying to create a details dashboard for ES receiving logs daily, weekly and monthly, so we do not have much indexes but default ones. since I am new to this subject is …

---

## [Aliases API : error deleting index](https://discuss.elastic.co/t/aliases-api-error-deleting-index/325265)

<div class="topic-metadata">

**Author:** [@quentin.renoux](https://discuss.elastic.co/u/quentin.renoux)\
**Replies:** 2\
**Last updated:** [February 20, 2023, 12:36pm UTC](https://discuss.elastic.co/t/aliases-api-error-deleting-index/325265 "2023-02-20T12:36:06Z")

</div>

Hi everyone, TL;DR : the \_aliases API throw error trying to remove index saying it doesn't exist but it does. I'm using the aliases API to swap two indices behind an alias in a single atomic operation. I'm following th…

[Previous page](https://discuss.elastic.co/latest.md?page=774)

[Next page](https://discuss.elastic.co/latest.md?page=776)
