# Latest

**URL:** https://discuss.elastic.co/latest.md?page=776

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 777

---

## [Interruptions of Metricbeat Metrics in Kibana](https://discuss.elastic.co/t/interruptions-of-metricbeat-metrics-in-kibana/325580)

<div class="topic-metadata">

**Author:** [@Swathi12](https://discuss.elastic.co/u/Swathi12)\
**Replies:** 0\
**Last updated:** [February 15, 2023, 9:56am UTC](https://discuss.elastic.co/t/interruptions-of-metricbeat-metrics-in-kibana/325580 "2023-02-15T09:56:58Z")

</div>

Hi team, i am working for several months on metricbeat in k8s i installed on 3 azure kubernetes cluster metricbeat and i saw it not showing the metrics correctly or with some interruptions each cluster has between 3 …

---

## [Kibana fleet management: failed to decrypt attribute ssl](https://discuss.elastic.co/t/kibana-fleet-management-failed-to-decrypt-attribute-ssl/324881)

<div class="topic-metadata">

**Author:** [@Jesse\_Geens](https://discuss.elastic.co/u/Jesse_Geens)\
**Replies:** 0\
**Last updated:** [February 7, 2023, 10:06am UTC](https://discuss.elastic.co/t/kibana-fleet-management-failed-to-decrypt-attribute-ssl/324881 "2023-02-07T10:06:42Z")

</div>

Hello, I am trying to configure my elastic fleet such that elastic agents connect to a logstash instance, secured with SSL. I set up the SSL for logstash, and was now trying to configure the agents. To make sure that th…

---

## [How to Install APM Server in Legacy mode without Elastic APM Integration](https://discuss.elastic.co/t/how-to-install-apm-server-in-legacy-mode-without-elastic-apm-integration/325724)

<div class="topic-metadata">

**Author:** [@Mikele](https://discuss.elastic.co/u/Mikele)\
**Replies:** 2\
**Last updated:** [February 20, 2023, 11:50am UTC](https://discuss.elastic.co/t/how-to-install-apm-server-in-legacy-mode-without-elastic-apm-integration/325724 "2023-02-20T11:50:05Z")

</div>

I would like to install APM Server in old way so in Legacy. I have few problems with this installation. Could someone explain me two cases: Is it possible to install APM in Legacy mode without this step? Step 2: Set…

---

## [How to use request.ssl in Filebeat httpjson Input](https://discuss.elastic.co/t/how-to-use-request-ssl-in-filebeat-httpjson-input/325966)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 0\
**Last updated:** [February 20, 2023, 11:35am UTC](https://discuss.elastic.co/t/how-to-use-request-ssl-in-filebeat-httpjson-input/325966 "2023-02-20T11:35:50Z")

</div>

Hi there, i want to know how using request.ssl in Filebeat input on httpjson type. So, here's an overview of the config I made: filebeat.inputs: - type: httpjson config\_version: 2 request.url: https://192.168.0.217:…

---

## [Kibana UI Not Accessible](https://discuss.elastic.co/t/kibana-ui-not-accessible/325904)

<div class="topic-metadata">

**Author:** [@altif](https://discuss.elastic.co/u/altif)\
**Replies:** 2\
**Last updated:** [February 20, 2023, 11:12am UTC](https://discuss.elastic.co/t/kibana-ui-not-accessible/325904 "2023-02-20T11:12:24Z")

</div>

Greetings, I'm a Kibana novice who recently imported saved-objects via the Kibana UI. However, upon importing the saved-objects JSON file, I encountered an error as illustrated in the attached screenshot. Whenever I…

---

## [Mapper\_parsing\_exception](https://discuss.elastic.co/t/mapper-parsing-exception/325962)

<div class="topic-metadata">

**Author:** [@Roshan\_M\_Thomas](https://discuss.elastic.co/u/Roshan_M_Thomas)\
**Replies:** 0\
**Last updated:** [February 20, 2023, 11:04am UTC](https://discuss.elastic.co/t/mapper-parsing-exception/325962 "2023-02-20T11:04:53Z")

</div>

Hi , getting this error in elastic 7.8.1 and 8.0.0 while inserting mapping using PUT method. Please help us to resolve it. { "error": { "root\_cause": \[ { "type": "mapper\_parsing\_exception", "reason": "Root mapping …

---

## [Elasticsearch creates empty directories in /tmp, can I delete these empty directories](https://discuss.elastic.co/t/elasticsearch-creates-empty-directories-in-tmp-can-i-delete-these-empty-directories/325887)

<div class="topic-metadata">

**Author:** [@eranga\_bandara](https://discuss.elastic.co/u/eranga_bandara)\
**Replies:** 2\
**Last updated:** [February 20, 2023, 8:59am UTC](https://discuss.elastic.co/t/elasticsearch-creates-empty-directories-in-tmp-can-i-delete-these-empty-directories/325887 "2023-02-20T08:59:47Z")

</div>

Elasticsearch creates directories inside /tmp. These directories used to execute native code by jna and libffi. Most of the time these directories are empty and have the name like elasticsearch.KNoHBn19. more info here. …

---

## [How to store Key value pairs and visualize in Kibana?](https://discuss.elastic.co/t/how-to-store-key-value-pairs-and-visualize-in-kibana/325888)

<div class="topic-metadata">

**Author:** [@stramzik](https://discuss.elastic.co/u/stramzik)\
**Replies:** 1\
**Last updated:** [February 20, 2023, 10:14am UTC](https://discuss.elastic.co/t/how-to-store-key-value-pairs-and-visualize-in-kibana/325888 "2023-02-20T10:14:12Z")

</div>

Hi, I am trying to store key value pairs into Elasticsearch and visualize in Kibana. I am new to Elastic so sorry if the question is dumb. So here's my data { "mappings": { "properties": { "Topics": {"type…

---

## [How to check the index size on daily basis using python scripts?](https://discuss.elastic.co/t/how-to-check-the-index-size-on-daily-basis-using-python-scripts/325377)

<div class="topic-metadata">

**Author:** [@jisha](https://discuss.elastic.co/u/jisha)\
**Replies:** 1\
**Last updated:** [February 20, 2023, 9:48am UTC](https://discuss.elastic.co/t/how-to-check-the-index-size-on-daily-basis-using-python-scripts/325377 "2023-02-20T09:48:01Z")

</div>

Hi, Does anyone know how to check the index size on daily basis using python scripts?

---

## [Need help to create active directory alerts in Kibana](https://discuss.elastic.co/t/need-help-to-create-active-directory-alerts-in-kibana/325102)

<div class="topic-metadata">

**Author:** [@abhi\_tcs](https://discuss.elastic.co/u/abhi_tcs)\
**Replies:** 0\
**Last updated:** [February 9, 2023, 7:27am UTC](https://discuss.elastic.co/t/need-help-to-create-active-directory-alerts-in-kibana/325102 "2023-02-09T07:27:11Z")

</div>

Hello All, I am new to ELK stack. I need to create Active Directory related alerts in Kibana for below test cases. Can someone help me. Account lockout Account Disable Regards, AB

---

## [When Downloading CSV, one variable value's is getting in two different column because of comma](https://discuss.elastic.co/t/when-downloading-csv-one-variable-values-is-getting-in-two-different-column-because-of-comma/324984)

<div class="topic-metadata">

**Author:** [@Arshukla](https://discuss.elastic.co/u/Arshukla)\
**Replies:** 5\
**Last updated:** [February 20, 2023, 9:25am UTC](https://discuss.elastic.co/t/when-downloading-csv-one-variable-values-is-getting-in-two-different-column-because-of-comma/324984 "2023-02-20T09:25:07Z")

</div>

When Downloading CSV from Tabular format, each variable is getting separated with Comma (,). Due to this variable which are numerical values (for e.g., 2,946) are also getting in different columns. As shown in below ima…

---

## [Unable to get real time logs for Elastic-Github Integration](https://discuss.elastic.co/t/unable-to-get-real-time-logs-for-elastic-github-integration/324993)

<div class="topic-metadata">

**Author:** [@Pallavi\_Kshirsagar](https://discuss.elastic.co/u/Pallavi_Kshirsagar)\
**Replies:** 0\
**Last updated:** [February 8, 2023, 10:09am UTC](https://discuss.elastic.co/t/unable-to-get-real-time-logs-for-elastic-github-integration/324993 "2023-02-08T10:09:39Z")

</div>

I've performed Github integration using elastic agent, where I'm running the agent on an EC2 instance. When I go to Discover the logs I see that logs aren't pulled in real time and I get to see too old logs until a certa…

---

## [Two data folder present](https://discuss.elastic.co/t/two-data-folder-present/325834)

<div class="topic-metadata">

**Author:** [@dev\_sab](https://discuss.elastic.co/u/dev_sab)\
**Replies:** 2\
**Last updated:** [February 20, 2023, 8:59am UTC](https://discuss.elastic.co/t/two-data-folder-present/325834 "2023-02-20T08:59:00Z")

</div>

Hello All, I am having the scenario two data folder present. I have accidently changed the path.data in elasticsearch.yml file. So, Two data folder present, one with old data and another with new data. I need to merge …

---

## [How to find a missing word in elastic search query](https://discuss.elastic.co/t/how-to-find-a-missing-word-in-elastic-search-query/325351)

<div class="topic-metadata">

**Author:** [@Jude\_Jerome](https://discuss.elastic.co/u/Jude_Jerome)\
**Replies:** 7\
**Last updated:** [February 20, 2023, 7:06am UTC](https://discuss.elastic.co/t/how-to-find-a-missing-word-in-elastic-search-query/325351 "2023-02-20T07:06:39Z")

</div>

Hello Team, I have a 100 + applications which sending logs daily. I want to filter out the application which does not have a specific word. For example if a application log does not have success keyword then i need to f…

---

## [Logstash masking logs syntax](https://discuss.elastic.co/t/logstash-masking-logs-syntax/325699)

<div class="topic-metadata">

**Author:** [@furkano](https://discuss.elastic.co/u/furkano)\
**Replies:** 3\
**Last updated:** [February 20, 2023, 5:32am UTC](https://discuss.elastic.co/t/logstash-masking-logs-syntax/325699 "2023-02-20T05:32:58Z")

</div>

Hi, I want to mask some logs in spesific fields, for example if end point ends with api or token i want to remove userKey messages from field ResponseMessage But not whole field that i want to remove or mask, only the …

---

## [Проблема с парсингом логов в Logstash](https://discuss.elastic.co/t/logstash/325927)

<div class="topic-metadata">

**Author:** [@Bender1](https://discuss.elastic.co/u/Bender1)\
**Replies:** 0\
**Last updated:** [February 20, 2023, 3:39am UTC](https://discuss.elastic.co/t/logstash/325927 "2023-02-20T03:39:47Z")

</div>

Пришла в голову идея добывать и хранить логи с большого зоопарка сетевого оборудования с помощью ELK. Все шло отлично, пока не добрался до фильтров. Вот пример моих логов: 23-Nov-2008 03:53:27 :%STP-W-PORTSTATUS: e1: …

---

## [Elasticsearch error all shards failed on single node](https://discuss.elastic.co/t/elasticsearch-error-all-shards-failed-on-single-node/325812)

<div class="topic-metadata">

**Author:** [@yc99](https://discuss.elastic.co/u/yc99)\
**Replies:** 6\
**Last updated:** [February 20, 2023, 3:19am UTC](https://discuss.elastic.co/t/elasticsearch-error-all-shards-failed-on-single-node/325812 "2023-02-20T03:19:13Z")

</div>

Caused by: org.elasticsearch.action.NoShardAvailableActionException: \[ip-13-35-23-200.ap-1.compute.internal\]\[13.35.23.200:9300\]\[indices:data/read/search\[phase/query\]\] \[2023-02-17T08:14:15,934\]\[WARN \]\[r.suppressed …

---

## [Beginner’s Crash Course to Elastic Stack - Part 4: Aggregations | Issues with data](https://discuss.elastic.co/t/beginner-s-crash-course-to-elastic-stack-part-4-aggregations-issues-with-data/325902)

<div class="topic-metadata">

**Author:** [@pathaniaamn](https://discuss.elastic.co/u/pathaniaamn)\
**Replies:** 4\
**Last updated:** [February 20, 2023, 3:13am UTC](https://discuss.elastic.co/t/beginner-s-crash-course-to-elastic-stack-part-4-aggregations-issues-with-data/325902 "2023-02-20T03:13:24Z")

</div>

After importing the data.csv file and running the STEP 1: Create a new index(ecommerce\_data) with the following mapping., I am getting an error: { "error": { "root\_cause": \[ { "type": "resource\_already\_exists\_except…

---

## [Make a span becomes transaction](https://discuss.elastic.co/t/make-a-span-becomes-transaction/325711)

<div class="topic-metadata">

**Author:** [@Ivan\_Hosea](https://discuss.elastic.co/u/Ivan_Hosea)\
**Replies:** 4\
**Last updated:** [February 20, 2023, 3:04am UTC](https://discuss.elastic.co/t/make-a-span-becomes-transaction/325711 "2023-02-20T03:04:10Z")

</div>

APM Agent language and version: 1.36 Description of the problem including expected versus actual behavior. Please include screenshots (if relevant): I tried to trace a method using this: Core configuration options | A…

---

## [Watcher search on multiple terms and action depending on conditional result](https://discuss.elastic.co/t/watcher-search-on-multiple-terms-and-action-depending-on-conditional-result/325868)

<div class="topic-metadata">

**Author:** [@mape](https://discuss.elastic.co/u/mape)\
**Replies:** 0\
**Last updated:** [February 17, 2023, 9:11pm UTC](https://discuss.elastic.co/t/watcher-search-on-multiple-terms-and-action-depending-on-conditional-result/325868 "2023-02-17T21:11:03Z")

</div>

Hi. What I am trying to achieve is: Use a search query to find all events where field status code = 400 OR 401 OR 403, AND field servicegroup is one of 6 options AND if the count of events is \> 300 if it occurs on any …

---

## [Elasticsearch data node out of memory](https://discuss.elastic.co/t/elasticsearch-data-node-out-of-memory/325866)

<div class="topic-metadata">

**Author:** [@sssamant](https://discuss.elastic.co/u/sssamant)\
**Replies:** 6\
**Last updated:** [February 20, 2023, 2:26am UTC](https://discuss.elastic.co/t/elasticsearch-data-node-out-of-memory/325866 "2023-02-20T02:26:02Z")

</div>

Hello everyone, We are having out of memory issue for the elasticsearch data nodes? Can you please help me out to find the issue. Here is log from elasticsearch cluster. \[2023-02-17 10:02:47,551\]\[WARN \]\[netty.channel.…

---

## [Parsing Exception when using Bucket\_sort with org.elasticsearch.test.framework:8.6.2](https://discuss.elastic.co/t/parsing-exception-when-using-bucket-sort-with-org-elasticsearch-test-framework-8-6-2/325893)

<div class="topic-metadata">

**Author:** [@Neoministein](https://discuss.elastic.co/u/Neoministein)\
**Replies:** 0\
**Last updated:** [February 18, 2023, 5:00pm UTC](https://discuss.elastic.co/t/parsing-exception-when-using-bucket-sort-with-org-elasticsearch-test-framework-8-6-2/325893 "2023-02-18T17:00:39Z")

</div>

I am using org.elasticsearch.test.framework for Integration testing parts of my codebase. I am currently using the Elasticsearch Java API Client 8.7.0-SNAPSHOT to use the new BulkIngester. I've therefore bumped the ver…

---

## [Is there a recommendation on the number of Indices that can be created using ILM](https://discuss.elastic.co/t/is-there-a-recommendation-on-the-number-of-indices-that-can-be-created-using-ilm/325716)

<div class="topic-metadata">

**Author:** [@siddhartha\_c](https://discuss.elastic.co/u/siddhartha_c)\
**Replies:** 9\
**Last updated:** [February 20, 2023, 2:13am UTC](https://discuss.elastic.co/t/is-there-a-recommendation-on-the-number-of-indices-that-can-be-created-using-ilm/325716 "2023-02-20T02:13:19Z")

</div>

Hi Team, I am quite new to Elasticsearch. We are migrating Data from a Licensed Product to Elastic. But the amount of data is huge, its about 100 TB/month. And we have to index data for 10 years. So effectively 1 Pet…

---

## [Kibana not found in custom definitions using Istio](https://discuss.elastic.co/t/kibana-not-found-in-custom-definitions-using-istio/325925)

<div class="topic-metadata">

**Author:** [@Fran\_D](https://discuss.elastic.co/u/Fran_D)\
**Replies:** 0\
**Last updated:** [February 20, 2023, 12:19am UTC](https://discuss.elastic.co/t/kibana-not-found-in-custom-definitions-using-istio/325925 "2023-02-20T00:19:57Z")

</div>

The deployment of the elastic operator is working fine, following the steps of this guide: https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-service-mesh-istio.html After deploying the Kibana, anything is starti…

---

## [Installed Lateral movement detection package but couldn't find the package under ML preconfigured jobs](https://discuss.elastic.co/t/installed-lateral-movement-detection-package-but-couldnt-find-the-package-under-ml-preconfigured-jobs/325809)

<div class="topic-metadata">

**Author:** [@deepthi.manam](https://discuss.elastic.co/u/deepthi.manam)\
**Replies:** 2\
**Last updated:** [February 20, 2023, 1:31am UTC](https://discuss.elastic.co/t/installed-lateral-movement-detection-package-but-couldnt-find-the-package-under-ml-preconfigured-jobs/325809 "2023-02-20T01:31:40Z")

</div>

I have installed lateral movement detection package under Integrations but haven't created any policies. I couldn't find Lateral movement detection under ML preconfigured jobs while creating a job. Does this require a i…

---

## [Does Elastic Cloud service support SDK to access its APIs](https://discuss.elastic.co/t/does-elastic-cloud-service-support-sdk-to-access-its-apis/325719)

<div class="topic-metadata">

**Author:** [@vaibhav\_b](https://discuss.elastic.co/u/vaibhav_b)\
**Replies:** 1\
**Last updated:** [February 20, 2023, 1:15am UTC](https://discuss.elastic.co/t/does-elastic-cloud-service-support-sdk-to-access-its-apis/325719 "2023-02-20T01:15:49Z")

</div>

I have question related to SDK support to provision Elasticsearch service on elastic cloud. I am going through the documentation where I am seeing, "how can I consume the API", here I am not seeing anything mentioned r…

---

## [Easy way to monitor ElasticSearch](https://discuss.elastic.co/t/easy-way-to-monitor-elasticsearch/324404)

<div class="topic-metadata">

**Author:** [@frankmehlhop.com](https://discuss.elastic.co/u/frankmehlhop.com)\
**Replies:** 3\
**Last updated:** [February 20, 2023, 1:08am UTC](https://discuss.elastic.co/t/easy-way-to-monitor-elasticsearch/324404 "2023-02-20T01:08:15Z")

</div>

I want a easy way to monitor Elasticsearch. What I found is Metricbeat. But it seems to be very extensive. For my purpose it is enough to see green, yellow, red and it would be nice to have if the administrator gets a …

---

## [Kubectl can not create elastic podse](https://discuss.elastic.co/t/kubectl-can-not-create-elastic-podse/325917)

<div class="topic-metadata">

**Author:** [@suminlim](https://discuss.elastic.co/u/suminlim)\
**Replies:** 0\
**Last updated:** [February 19, 2023, 4:23pm UTC](https://discuss.elastic.co/t/kubectl-can-not-create-elastic-podse/325917 "2023-02-19T16:23:03Z")

</div>

root@~# kubectl get elasticsearch NAME HEALTH NODES VERSION PHASE AGE quickstart 50s root@~# kubectl get pods --selector='elasticsearch.k8s.elastic.co/cluster-name=…

---

## [Unassigned Shards - issue](https://discuss.elastic.co/t/unassigned-shards-issue/325692)

<div class="topic-metadata">

**Author:** [@azuramazda](https://discuss.elastic.co/u/azuramazda)\
**Replies:** 1\
**Last updated:** [February 19, 2023, 9:00pm UTC](https://discuss.elastic.co/t/unassigned-shards-issue/325692 "2023-02-19T21:00:59Z")

</div>

I am facing an issue with ES where it shows 174 shards are unassigned. and allocate\_explanation is :"cannot allocate because all found copies of the shard are there stale or corrupt". This issue is arising since yesterd…

---

## [Systemctl reload elasticsearch.service or systemctl restart elasticsearch.service](https://discuss.elastic.co/t/systemctl-reload-elasticsearch-service-or-systemctl-restart-elasticsearch-service/325703)

<div class="topic-metadata">

**Author:** [@firdaussaad](https://discuss.elastic.co/u/firdaussaad)\
**Replies:** 1\
**Last updated:** [February 19, 2023, 8:59pm UTC](https://discuss.elastic.co/t/systemctl-reload-elasticsearch-service-or-systemctl-restart-elasticsearch-service/325703 "2023-02-19T20:59:33Z")

</div>

Hi all, I am currently working on a bash script. Whenever i make changes to elasticsearch.yml file, should i perform systemctl reload elascticsearch.service or systemctl restart elasticsearch.service? Any difference be…

[Previous page](https://discuss.elastic.co/latest.md?page=775)

[Next page](https://discuss.elastic.co/latest.md?page=777)
