# Latest

**URL:** https://discuss.elastic.co/latest.md?page=780

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 781

---

## [Fail to add second fleet server with error missing enrollment api key](https://discuss.elastic.co/t/fail-to-add-second-fleet-server-with-error-missing-enrollment-api-key/325698)

<div class="topic-metadata">

**Author:** [@lusynda](https://discuss.elastic.co/u/lusynda)\
**Replies:** 0\
**Last updated:** [February 16, 2023, 7:41am UTC](https://discuss.elastic.co/t/fail-to-add-second-fleet-server-with-error-missing-enrollment-api-key/325698 "2023-02-16T07:41:15Z")

</div>

Hi all, I have a weird case that i dont know how to fix. I've already setup a fleet server successfully and already enrolling agent to that fleet. But now i want to add another fleet server to the cluster to ensure hig…

---

## [Elastic decay function not working on nested field](https://discuss.elastic.co/t/elastic-decay-function-not-working-on-nested-field/324517)

<div class="topic-metadata">

**Author:** [@AthanatiusC](https://discuss.elastic.co/u/AthanatiusC)\
**Replies:** 2\
**Last updated:** [February 16, 2023, 6:58am UTC](https://discuss.elastic.co/t/elastic-decay-function-not-working-on-nested-field/324517 "2023-02-16T06:58:19Z")

</div>

I have the following configuration: mapping put geo\_test { "mappings":{ "properties":{ "name":{ "type":"text" }, "location":{ "type":"nested", "properties":{ "n…

---

## [Elasticsearch cluster automatically adds transient settings...How do I remove this?](https://discuss.elastic.co/t/elasticsearch-cluster-automatically-adds-transient-settings-how-do-i-remove-this/325353)

<div class="topic-metadata">

**Author:** [@prabhash\_mohanty](https://discuss.elastic.co/u/prabhash_mohanty)\
**Replies:** 4\
**Last updated:** [February 16, 2023, 6:27am UTC](https://discuss.elastic.co/t/elasticsearch-cluster-automatically-adds-transient-settings-how-do-i-remove-this/325353 "2023-02-16T06:27:29Z")

</div>

I have 2 nodes in the cluster log-es-default-0 and log-es-default-1. log-es-default-0 - master node log-es-default-1 - data node I tried running the below command but it still adds it. PUT /\_cluster/settings?pretty {…

---

## [ELK for Jasper](https://discuss.elastic.co/t/elk-for-jasper/325579)

<div class="topic-metadata">

**Author:** [@ELK\_USR1](https://discuss.elastic.co/u/ELK_USR1)\
**Replies:** 2\
**Last updated:** [February 16, 2023, 6:18am UTC](https://discuss.elastic.co/t/elk-for-jasper/325579 "2023-02-16T06:18:11Z")

</div>

I need elk on Jasper application. Can someone guide me to configure.

---

## [Index is not moving to warm phase](https://discuss.elastic.co/t/index-is-not-moving-to-warm-phase/325677)

<div class="topic-metadata">

**Author:** [@rahul\_sirugudi](https://discuss.elastic.co/u/rahul_sirugudi)\
**Replies:** 1\
**Last updated:** [February 16, 2023, 5:56am UTC](https://discuss.elastic.co/t/index-is-not-moving-to-warm-phase/325677 "2023-02-16T05:56:09Z")

</div>

I have an index, i have implemented ILM on that. I am not seeing index is not moving to warm phase after reaching out 8 days old. There are no errors to. { "emailer-lifecycle-policy" : { "version" : 1, "modifi…

---

## [One rsyslog port vs multiple syslog ports](https://discuss.elastic.co/t/one-rsyslog-port-vs-multiple-syslog-ports/325668)

<div class="topic-metadata">

**Author:** [@Tiharqa](https://discuss.elastic.co/u/Tiharqa)\
**Replies:** 0\
**Last updated:** [February 16, 2023, 12:24am UTC](https://discuss.elastic.co/t/one-rsyslog-port-vs-multiple-syslog-ports/325668 "2023-02-16T00:24:56Z")

</div>

Trying to decide if I can direct all syslog data from cisco and vmware and f5 to a centralized location running elastic agent as syslog and if elastic supports having multiple integration used would that be ideal set…

---

## [When i use snmp . why value in key:value is missing](https://discuss.elastic.co/t/when-i-use-snmp-why-value-in-key-value-is-missing/325684)

<div class="topic-metadata">

**Author:** [@sirichai\_phungsuntho](https://discuss.elastic.co/u/sirichai_phungsuntho)\
**Replies:** 0\
**Last updated:** [February 16, 2023, 4:37am UTC](https://discuss.elastic.co/t/when-i-use-snmp-why-value-in-key-value-is-missing/325684 "2023-02-16T04:37:06Z")

</div>

When i use input snmp and selct more than 10 columns in function tables i will receive missing value like this how can i fix it?

---

## [Logstash Kafka consumer count](https://discuss.elastic.co/t/logstash-kafka-consumer-count/325671)

<div class="topic-metadata">

**Author:** [@rsk0](https://discuss.elastic.co/u/rsk0)\
**Replies:** 1\
**Last updated:** [February 16, 2023, 5:47am UTC](https://discuss.elastic.co/t/logstash-kafka-consumer-count/325671 "2023-02-16T05:47:58Z")

</div>

According to the Logstash guide: "How many partitions should I use per topic?" At least the number of Logstash nodes multiplied by consumer threads per node. Better yet, use a multiple of the above number. Increasing…

---

## [Restart elastic agent from fleet server in kibana](https://discuss.elastic.co/t/restart-elastic-agent-from-fleet-server-in-kibana/325097)

<div class="topic-metadata">

**Author:** [@bex](https://discuss.elastic.co/u/bex)\
**Replies:** 1\
**Last updated:** [February 16, 2023, 4:56am UTC](https://discuss.elastic.co/t/restart-elastic-agent-from-fleet-server-in-kibana/325097 "2023-02-16T04:56:11Z")

</div>

Is it possible to restart the elastic agent (which is on the fleet server) from kibana? There is only an option to update, is there a way to restart elastic agents remotely? In case you have so many elastic agents, it …

---

## [Kibana not displaying logs after implementing XPack Security in Elasticsearch 7.16](https://discuss.elastic.co/t/kibana-not-displaying-logs-after-implementing-xpack-security-in-elasticsearch-7-16/325552)

<div class="topic-metadata">

**Author:** [@b2njam1n](https://discuss.elastic.co/u/b2njam1n)\
**Replies:** 2\
**Last updated:** [February 16, 2023, 2:39am UTC](https://discuss.elastic.co/t/kibana-not-displaying-logs-after-implementing-xpack-security-in-elasticsearch-7-16/325552 "2023-02-16T02:39:45Z")

</div>

Hello everyone, I recently set up an Elasticsearch version 7.16 cluster on a RHEL7.9 with Kibana and two Filebeat servers: a Hardware Log Server and an OS Log Server. Everything was working well until I implemented XPac…

---

## [Missing setting option "response.include\_body\_max\_bytes" in "Add Elastic Synthetics integration" UI](https://discuss.elastic.co/t/missing-setting-option-response-include-body-max-bytes-in-add-elastic-synthetics-integration-ui/325444)

<div class="topic-metadata">

**Author:** [@billhong-just](https://discuss.elastic.co/u/billhong-just)\
**Replies:** 1\
**Last updated:** [February 16, 2023, 1:24am UTC](https://discuss.elastic.co/t/missing-setting-option-response-include-body-max-bytes-in-add-elastic-synthetics-integration-ui/325444 "2023-02-16T01:24:03Z")

</div>

Description In Kibana v8.5.3's dashboard, I can't find the setting option response.include\_body\_max\_bytes to control the maximum size of the stored body contents. Is this a bug or is it by design? :thinking: Refer…

---

## [Multiple Logstash Containers](https://discuss.elastic.co/t/multiple-logstash-containers/325319)

<div class="topic-metadata">

**Author:** [@Vaibhav\_Saxena1](https://discuss.elastic.co/u/Vaibhav_Saxena1)\
**Replies:** 0\
**Last updated:** [February 11, 2023, 5:32pm UTC](https://discuss.elastic.co/t/multiple-logstash-containers/325319 "2023-02-11T17:32:58Z")

</div>

Hello, We have following containers setup on our environment: 1- logstash ( Stomp) 2- logstash ( Filebeat) port: 5044 3- Kibana 4- Elasticsearch But by mistake i created the logstash(filebeat) to read only one "lo…

---

## [Default Elasticsearch ECK Installation stuck on "readiness probe failed"](https://discuss.elastic.co/t/default-elasticsearch-eck-installation-stuck-on-readiness-probe-failed/323553)

<div class="topic-metadata">

**Author:** [@Melvin\_Suter](https://discuss.elastic.co/u/Melvin_Suter)\
**Replies:** 1\
**Last updated:** [February 15, 2023, 9:47pm UTC](https://discuss.elastic.co/t/default-elasticsearch-eck-installation-stuck-on-readiness-probe-failed/323553 "2023-02-15T21:47:48Z")

</div>

Hi there I need help. I'm at the end of my knowledge and I can't get elasticsearch to work on my kubernetes cluster. My kubernetes version: v1.24.8+rke2r1 I installed ECK without any issues. (Kibana for instance works…

---

## [Filebeat multiline ignores last line](https://discuss.elastic.co/t/filebeat-multiline-ignores-last-line/325654)

<div class="topic-metadata">

**Author:** [@mariana17](https://discuss.elastic.co/u/mariana17)\
**Replies:** 3\
**Last updated:** [February 15, 2023, 9:47pm UTC](https://discuss.elastic.co/t/filebeat-multiline-ignores-last-line/325654 "2023-02-15T21:47:40Z")

</div>

What I want to do is read these records, each of them is inside braces, so I use multilines in filebeat to be able to read them together, however, the last line "\]}" is not read by filebeat, so the record is unfinished a…

---

## [Best practices for internal corporate site search](https://discuss.elastic.co/t/best-practices-for-internal-corporate-site-search/325532)

<div class="topic-metadata">

**Author:** [@Buntu\_Dev](https://discuss.elastic.co/u/Buntu_Dev)\
**Replies:** 1\
**Last updated:** [February 15, 2023, 9:44pm UTC](https://discuss.elastic.co/t/best-practices-for-internal-corporate-site-search/325532 "2023-02-15T21:44:48Z")

</div>

I'm looking for best practices to tag the existing webpages which consist internal web apps and employee resources (internal forms, static content, policy documents) to help index into ES and make them available for site…

---

## [Couldn't open localhost:9200 for elasticsearch version 8.2.3](https://discuss.elastic.co/t/couldnt-open-localhost-9200-for-elasticsearch-version-8-2-3/325534)

<div class="topic-metadata">

**Author:** [@Sivapriya-Sugumar](https://discuss.elastic.co/u/Sivapriya-Sugumar)\
**Replies:** 1\
**Last updated:** [February 15, 2023, 9:44pm UTC](https://discuss.elastic.co/t/couldnt-open-localhost-9200-for-elasticsearch-version-8-2-3/325534 "2023-02-15T21:44:15Z")

</div>

This page isn’t working localhost didn’t send any data. ERR\_EMPTY\_RESPONSE getting this batch file is running but couldn't open localhost:9200 in elasticsaerch 8.2.3

---

## [Kibana alerts](https://discuss.elastic.co/t/kibana-alerts/325570)

<div class="topic-metadata">

**Author:** [@MahithaSarala](https://discuss.elastic.co/u/MahithaSarala)\
**Replies:** 1\
**Last updated:** [February 15, 2023, 9:41pm UTC](https://discuss.elastic.co/t/kibana-alerts/325570 "2023-02-15T21:41:00Z")

</div>

Hi team, I have installed elastisearch and kibana 8.5.1 throgh helm on cluster, now i tried to configure the alerts on kibana. So inside kibana pod kibana.yaml, In the kibana.yml configuration file, add the xpack.encryp…

---

## [Why data save to master cluster?](https://discuss.elastic.co/t/why-data-save-to-master-cluster/325576)

<div class="topic-metadata">

**Author:** [@fered](https://discuss.elastic.co/u/fered)\
**Replies:** 1\
**Last updated:** [February 15, 2023, 9:33pm UTC](https://discuss.elastic.co/t/why-data-save-to-master-cluster/325576 "2023-02-15T21:33:24Z")

</div>

I have a cluster that it have 3 master and 4 data node(2 hot , 1 warm , 1 cold). so i configure ILM for this cluster , but I dont know why index(primery & replica) save in master node ?

---

## [Swiftype stopped crawling all of a sudden - sitemap and robot files apparently are not reachable](https://discuss.elastic.co/t/swiftype-stopped-crawling-all-of-a-sudden-sitemap-and-robot-files-apparently-are-not-reachable/325606)

<div class="topic-metadata">

**Author:** [@James-S](https://discuss.elastic.co/u/James-S)\
**Replies:** 0\
**Last updated:** [February 15, 2023, 12:13pm UTC](https://discuss.elastic.co/t/swiftype-stopped-crawling-all-of-a-sudden-sitemap-and-robot-files-apparently-are-not-reachable/325606 "2023-02-15T12:13:59Z")

</div>

Hello! I've been using Swiftype on my websites for a while, and it's been working fine until 1 month ago or so. All of a sudden, my websites stopped being crawled, meaning new content is not showing up on my search any…

---

## [Getting 403 code while connecting to elastic](https://discuss.elastic.co/t/getting-403-code-while-connecting-to-elastic/325615)

<div class="topic-metadata">

**Author:** [@fvtarnovskiy](https://discuss.elastic.co/u/fvtarnovskiy)\
**Replies:** 1\
**Last updated:** [February 15, 2023, 9:32pm UTC](https://discuss.elastic.co/t/getting-403-code-while-connecting-to-elastic/325615 "2023-02-15T21:32:05Z")

</div>

Hello! We are a cloud provider from Uzbekistan pro-data.tech (https://pro-data.tech/). Please help in solving the problem - when trying to access Elastic, we get an error code 403 from all our addresses (95.47.127.0/24…

---

## [Logstash pipeline index question](https://discuss.elastic.co/t/logstash-pipeline-index-question/325273)

<div class="topic-metadata">

**Author:** [@MKirby](https://discuss.elastic.co/u/MKirby)\
**Replies:** 12\
**Last updated:** [February 15, 2023, 9:28pm UTC](https://discuss.elastic.co/t/logstash-pipeline-index-question/325273 "2023-02-15T21:28:45Z")

</div>

AS many of you know and have been following, my syslog collectors keep stopping due to running out of shards. I have made some improvements and they now run for about 3 weeks before I have to "close" the index. Better …

---

## [Kibana does not recognize the @timestamp field as a time filter](https://discuss.elastic.co/t/kibana-does-not-recognize-the-timestamp-field-as-a-time-filter/325404)

<div class="topic-metadata">

**Author:** [@Alvik173](https://discuss.elastic.co/u/Alvik173)\
**Replies:** 4\
**Last updated:** [February 15, 2023, 9:27pm UTC](https://discuss.elastic.co/t/kibana-does-not-recognize-the-timestamp-field-as-a-time-filter/325404 "2023-02-15T21:27:07Z")

</div>

Kibana (7.17.8) does not seem to recognize the @timestamp field in my index as a time field. The symptoms are as follows. In Discover, the "Show dates" box on the top right is missing The time series chart above the D…

---

## [Logstash rename json fields](https://discuss.elastic.co/t/logstash-rename-json-fields/325399)

<div class="topic-metadata">

**Author:** [@yilmazbuhar](https://discuss.elastic.co/u/yilmazbuhar)\
**Replies:** 6\
**Last updated:** [February 15, 2023, 9:24pm UTC](https://discuss.elastic.co/t/logstash-rename-json-fields/325399 "2023-02-15T21:24:05Z")

</div>

Hi community, We have a json log as below { "Timestamp": "2023-02-09T17:41:54.5320239+03:00", "Level": "", "MessageTemplate": "", "Properties": { "responsetime": 4758, "SourceContext": "", "Username…

---

## [Kibana server is not ready yet](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet/325665)

<div class="topic-metadata">

**Author:** [@tagba](https://discuss.elastic.co/u/tagba)\
**Replies:** 0\
**Last updated:** [February 15, 2023, 9:07pm UTC](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet/325665 "2023-02-15T21:07:06Z")

</div>

Hi All, Please am new to Dsiem. I have just clone it from github and running it on ubuntu, below is the error am getting. "Kibana server is not ready yet" see the logs below, can I get help with this please {"type":"…

---

## [【Logstash】The output configuration of logstash cannot connect to the elasticsearch](https://discuss.elastic.co/t/logstash-the-output-configuration-of-logstash-cannot-connect-to-the-elasticsearch/325523)

<div class="topic-metadata">

**Author:** [@Roy176](https://discuss.elastic.co/u/Roy176)\
**Replies:** 3\
**Last updated:** [February 15, 2023, 8:47pm UTC](https://discuss.elastic.co/t/logstash-the-output-configuration-of-logstash-cannot-connect-to-the-elasticsearch/325523 "2023-02-15T20:47:53Z")

</div>

I build a single-node of elasticsearch on GCP and a logstash on the local side. I want to connect the output configuration of logstash to elasticsearch. Info: Elasticsearch、Kibana、Logstash: 8.6.1. I set up an extenal …

---

## [Scoring based on percentage of category](https://discuss.elastic.co/t/scoring-based-on-percentage-of-category/325661)

<div class="topic-metadata">

**Author:** [@sprath](https://discuss.elastic.co/u/sprath)\
**Replies:** 1\
**Last updated:** [February 15, 2023, 8:33pm UTC](https://discuss.elastic.co/t/scoring-based-on-percentage-of-category/325661 "2023-02-15T20:33:59Z")

</div>

I'm not quite sure where to get started with this query. I'm using the opensearch quickstart data to try to explain. The documents have the following fields for example: { ... "customer\_first\_name": …

---

## [Simple aggregation counting distinct values that has turned out to be difficult](https://discuss.elastic.co/t/simple-aggregation-counting-distinct-values-that-has-turned-out-to-be-difficult/325659)

<div class="topic-metadata">

**Author:** [@Adam\_Burr](https://discuss.elastic.co/u/Adam_Burr)\
**Replies:** 0\
**Last updated:** [February 15, 2023, 8:26pm UTC](https://discuss.elastic.co/t/simple-aggregation-counting-distinct-values-that-has-turned-out-to-be-difficult/325659 "2023-02-15T20:26:30Z")

</div>

I have a very simple index and I am trying to produce what I thought would be a simple aggregation, but I am finding it difficult to get working. I would be very grateful for any help the community can give. My "sales"…

---

## [Computation of total in Reindex API status response](https://discuss.elastic.co/t/computation-of-total-in-reindex-api-status-response/325658)

<div class="topic-metadata">

**Author:** [@fifthist](https://discuss.elastic.co/u/fifthist)\
**Replies:** 0\
**Last updated:** [February 15, 2023, 8:23pm UTC](https://discuss.elastic.co/t/computation-of-total-in-reindex-api-status-response/325658 "2023-02-15T20:23:53Z")

</div>

I call Reindex API by creating a Task (wait\_for\_completion=false). I then use \_tasks API to get the details of the task once it is completed. Part of the task response is the response of the Reindex API with created, upd…

---

## [Elastic Helm Charts are not working integrated OOTB in version 8.5.1](https://discuss.elastic.co/t/elastic-helm-charts-are-not-working-integrated-ootb-in-version-8-5-1/325642)

<div class="topic-metadata">

**Author:** [@Enrique\_Carbonell](https://discuss.elastic.co/u/Enrique_Carbonell)\
**Replies:** 3\
**Last updated:** [February 15, 2023, 6:29pm UTC](https://discuss.elastic.co/t/elastic-helm-charts-are-not-working-integrated-ootb-in-version-8-5-1/325642 "2023-02-15T18:29:19Z")

</div>

Kibana version: 8.5.1 Elasticsearch version: 8.5.1 APM Server version: 8.5.1 OpenTelementry Java Agent: 1.22.1 We are using the official Helm Chart to deploy the Elastic Stack on Kubernetes with the following compone…

---

## [Metric to count number of queries per day/month](https://discuss.elastic.co/t/metric-to-count-number-of-queries-per-day-month/325076)

<div class="topic-metadata">

**Author:** [@Milad\_Heydariaan](https://discuss.elastic.co/u/Milad_Heydariaan)\
**Replies:** 4\
**Last updated:** [February 15, 2023, 6:23pm UTC](https://discuss.elastic.co/t/metric-to-count-number-of-queries-per-day-month/325076 "2023-02-15T18:23:00Z")

</div>

Hi, I'm trying to collect the number of queries that users send to Elasticsearch to understand how many queries per day/month are submitted to our clusters. I've tried using the following metrics mentioned in Nodes sta…

[Previous page](https://discuss.elastic.co/latest.md?page=779)

[Next page](https://discuss.elastic.co/latest.md?page=781)
