# Latest

**URL:** https://discuss.elastic.co/latest.md?page=787

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 788

---

## [Uptime Alerts False Alarms on All Monitors](https://discuss.elastic.co/t/uptime-alerts-false-alarms-on-all-monitors/324822)

<div class="topic-metadata">

**Author:** [@WilAlcantara](https://discuss.elastic.co/u/WilAlcantara)\
**Replies:** 2\
**Last updated:** [February 10, 2023, 1:28pm UTC](https://discuss.elastic.co/t/uptime-alerts-false-alarms-on-all-monitors/324822 "2023-02-10T13:28:35Z")

</div>

Recently we experienced having a slew of alarms/notifications going to our slack channel without our instances actually going down. Uptime monitors also show they were up in the time we received the notifications. Is thi…

---

## [Remove plain text message in Logstash file input](https://discuss.elastic.co/t/remove-plain-text-message-in-logstash-file-input/325269)

<div class="topic-metadata">

**Author:** [@djrshn2346](https://discuss.elastic.co/u/djrshn2346)\
**Replies:** 1\
**Last updated:** [February 10, 2023, 1:24pm UTC](https://discuss.elastic.co/t/remove-plain-text-message-in-logstash-file-input/325269 "2023-02-10T13:24:17Z")

</div>

I am adding filter to remove a plain text as it causes error while JSON parsing. file { id =\> "my\_lt\_log" path =\> "/logs/logtransformer.log" type =\> "log" start\_position =\> "beginning" …

---

## [Heap memory full? new documents just disappeared!](https://discuss.elastic.co/t/heap-memory-full-new-documents-just-disappeared/325037)

<div class="topic-metadata">

**Author:** [@Pete\_Watcharawit1](https://discuss.elastic.co/u/Pete_Watcharawit1)\
**Replies:** 5\
**Last updated:** [February 10, 2023, 6:07am UTC](https://discuss.elastic.co/t/heap-memory-full-new-documents-just-disappeared/325037 "2023-02-10T06:07:59Z")

</div>

Hello, some of our new batch of documents disappeared lately and I tried checking the heap memory usage of the cluster of 2 nodes by running: curl -XGET 'http://\<address\>:9200/\_nodes/stats/jvm?pretty' Our cluster is usi…

---

## [View cost breakdown of Elasticsearch in Azure](https://discuss.elastic.co/t/view-cost-breakdown-of-elasticsearch-in-azure/325266)

<div class="topic-metadata">

**Author:** [@matthew\_gen](https://discuss.elastic.co/u/matthew_gen)\
**Replies:** 0\
**Last updated:** [February 10, 2023, 1:01pm UTC](https://discuss.elastic.co/t/view-cost-breakdown-of-elasticsearch-in-azure/325266 "2023-02-10T13:01:37Z")

</div>

Is there a way to extract the billing details of Elastic from the Elastic console (https://cloud.elastic.co/billing/usage) to the azure cost management page (Microsoft Azure)? I followed the links from the elastic cloud …

---

## [Logstash + Fortinet + Kibana](https://discuss.elastic.co/t/logstash-fortinet-kibana/323508)

<div class="topic-metadata">

**Author:** [@Cezary](https://discuss.elastic.co/u/Cezary)\
**Replies:** 10\
**Last updated:** [February 10, 2023, 12:57pm UTC](https://discuss.elastic.co/t/logstash-fortinet-kibana/323508 "2023-02-10T12:57:21Z")

</div>

Hello to All, I'm trying to create Kibana map using data from Fortinet syslog and Logstash. I was able to load geoip data to kibana, however geo.location field had to be created from Logstash because it was not created…

---

## [Elasticsearch, kibana y logstash y filebeat](https://discuss.elastic.co/t/elasticsearch-kibana-y-logstash-y-filebeat/325228)

<div class="topic-metadata">

**Author:** [@jomaguca](https://discuss.elastic.co/u/jomaguca)\
**Replies:** 1\
**Last updated:** [February 10, 2023, 12:46pm UTC](https://discuss.elastic.co/t/elasticsearch-kibana-y-logstash-y-filebeat/325228 "2023-02-10T12:46:06Z")

</div>

Hello everybody My name is José Manuel and I am testing this solution to be use in logs managment so I hope you can help to work with this. My idea is install this in a debian 11 and elasticsearch 8.6.1 with kibana 8.6…

---

## [Gelf Input plugin dropping messages](https://discuss.elastic.co/t/gelf-input-plugin-dropping-messages/325260)

<div class="topic-metadata">

**Author:** [@karlo95](https://discuss.elastic.co/u/karlo95)\
**Replies:** 0\
**Last updated:** [February 10, 2023, 12:08pm UTC](https://discuss.elastic.co/t/gelf-input-plugin-dropping-messages/325260 "2023-02-10T12:08:36Z")

</div>

Hello, I'm having problems with Gelf Input plugin dropping messages when listening on UDP. When a lot of messagess comes in same time, it seems like logstash plugin is dropping them randomly. E.g. when I restart quark…

---

## [Elastic-agent error ResourceExhausted desc = grpc: received message larger than max](https://discuss.elastic.co/t/elastic-agent-error-resourceexhausted-desc-grpc-received-message-larger-than-max/325256)

<div class="topic-metadata">

**Author:** [@fabien9402](https://discuss.elastic.co/u/fabien9402)\
**Replies:** 0\
**Last updated:** [February 10, 2023, 11:46am UTC](https://discuss.elastic.co/t/elastic-agent-error-resourceexhausted-desc-grpc-received-message-larger-than-max/325256 "2023-02-10T11:46:58Z")

</div>

We have an error in one of our elastic-agent. This returns the error below: 12:17:47.199 elastic\_agent.filebeat \[elastic\_agent.filebeat\]\[error\] elastic-agent-client got error: rpc error: code = ResourceExhausted desc =…

---

## [Adding Memcached integration turns agent unhealthy](https://discuss.elastic.co/t/adding-memcached-integration-turns-agent-unhealthy/325254)

<div class="topic-metadata">

**Author:** [@rrodrigues](https://discuss.elastic.co/u/rrodrigues)\
**Replies:** 0\
**Last updated:** [February 10, 2023, 11:39am UTC](https://discuss.elastic.co/t/adding-memcached-integration-turns-agent-unhealthy/325254 "2023-02-10T11:39:29Z")

</div>

When I add the Memcached Elastic Agent integration to a Fleet-managed agent it goes unhealthy. I believe this issue is similar to this one reported on Nginx/Kafka integration. Elastic Cloud/Elastic Agent: 8.6.1 Memcach…

---

## [GCSToElasticsearch Template](https://discuss.elastic.co/t/gcstoelasticsearch-template/323834)

<div class="topic-metadata">

**Author:** [@Roque\_Moyano](https://discuss.elastic.co/u/Roque_Moyano)\
**Replies:** 1\
**Last updated:** [February 10, 2023, 11:31am UTC](https://discuss.elastic.co/t/gcstoelasticsearch-template/323834 "2023-02-10T11:31:12Z")

</div>

Hi, I'm following this tutorial: Ingest data directly from Google Cloud Storage into Elastic using Google Dataflow | Elastic Blog but when the dataflow job is running I got this error: {"severity":"INFO","time":"2023/0…

---

## [Pass Multiple Fields in span term query](https://discuss.elastic.co/t/pass-multiple-fields-in-span-term-query/325213)

<div class="topic-metadata">

**Author:** [@Sahil5](https://discuss.elastic.co/u/Sahil5)\
**Replies:** 1\
**Last updated:** [February 10, 2023, 11:26am UTC](https://discuss.elastic.co/t/pass-multiple-fields-in-span-term-query/325213 "2023-02-10T11:26:25Z")

</div>

Hi Team, Can anyone please help how to pass multiple fields for searching in span\_term query? Example for span\_term query { "span\_term": { "field1": "value1" } } I want to pass something like this { "span\_term": { \[…

---

## [UNABLE TO CREATE THE VISUAL FOR MULTIPLE LOGS](https://discuss.elastic.co/t/unable-to-create-the-visual-for-multiple-logs/325245)

<div class="topic-metadata">

**Author:** [@Naveen3](https://discuss.elastic.co/u/Naveen3)\
**Replies:** 0\
**Last updated:** [February 10, 2023, 11:09am UTC](https://discuss.elastic.co/t/unable-to-create-the-visual-for-multiple-logs/325245 "2023-02-10T11:09:10Z")

</div>

How do I create the visual for the one value in two different logs? For the Example A is passed through L1. B is passed through L1. A is inducted from M1 L1 and M1 were in different logs for the same value. How do …

---

## [Fleet Server No Data Stream](https://discuss.elastic.co/t/fleet-server-no-data-stream/324753)

<div class="topic-metadata">

**Author:** [@NathanLau](https://discuss.elastic.co/u/NathanLau)\
**Replies:** 5\
**Last updated:** [February 10, 2023, 11:03am UTC](https://discuss.elastic.co/t/fleet-server-no-data-stream/324753 "2023-02-10T11:03:55Z")

</div>

Hi All , When installed Fleet server with quick start. the fleet server cannot receive any data themselves , same as system. install command : sudo ./elastic-agent install \\ --fleet-server-es=https://172.16.\*\*.\*\*:9…

---

## [Prometheus metricset - query vs. collector](https://discuss.elastic.co/t/prometheus-metricset-query-vs-collector/325140)

<div class="topic-metadata">

**Author:** [@Honken77](https://discuss.elastic.co/u/Honken77)\
**Replies:** 2\
**Last updated:** [February 10, 2023, 10:44am UTC](https://discuss.elastic.co/t/prometheus-metricset-query-vs-collector/325140 "2023-02-10T10:44:56Z")

</div>

Hi! At the moment I am collecting metrics from my OpenShift cluster with the collector metricset like so: metricbeat.modules: - module: prometheus period: 15s timeout: 15s hosts: \["https://prometheus-k8s.openshif…

---

## [Change StorageClass of an already running cluster](https://discuss.elastic.co/t/change-storageclass-of-an-already-running-cluster/325238)

<div class="topic-metadata">

**Author:** [@Maksym\_Postument](https://discuss.elastic.co/u/Maksym_Postument)\
**Replies:** 0\
**Last updated:** [February 10, 2023, 10:33am UTC](https://discuss.elastic.co/t/change-storageclass-of-an-already-running-cluster/325238 "2023-02-10T10:33:38Z")

</div>

Hello, i am trying to use suggested method here Change StorageClass of an already running cluster I changed nodeset name and storage class. And i see next elasticsearch-data-common-cluster-es-data-0 Bound …

---

## [Unable to install Kibana Development Enviroment](https://discuss.elastic.co/t/unable-to-install-kibana-development-enviroment/325214)

<div class="topic-metadata">

**Author:** [@Mufasa](https://discuss.elastic.co/u/Mufasa)\
**Replies:** 2\
**Last updated:** [February 10, 2023, 10:01am UTC](https://discuss.elastic.co/t/unable-to-install-kibana-development-enviroment/325214 "2023-02-10T10:01:38Z")

</div>

Hello Team, I am a beginner and almost tried all tutorials, blogs and gits to build my kibana development environment but unable to sort this mystery out. Can someone please help me out. Best

---

## [Installed ElasticSearch on linux, service is running but curl to elasticsearch url is failing](https://discuss.elastic.co/t/installed-elasticsearch-on-linux-service-is-running-but-curl-to-elasticsearch-url-is-failing/324937)

<div class="topic-metadata">

**Author:** [@Devanshu](https://discuss.elastic.co/u/Devanshu)\
**Replies:** 3\
**Last updated:** [February 10, 2023, 9:37am UTC](https://discuss.elastic.co/t/installed-elasticsearch-on-linux-service-is-running-but-curl-to-elasticsearch-url-is-failing/324937 "2023-02-10T09:37:55Z")

</div>

Installed Elasticsearch on linux, service is running but curl to elasticsearch url is failing. Getting below error curl: (52) Empty reply from server

---

## [Kibana cannot connect to the Elastic Package Registry, which provides Elastic Agent integrations](https://discuss.elastic.co/t/kibana-cannot-connect-to-the-elastic-package-registry-which-provides-elastic-agent-integrations/325233)

<div class="topic-metadata">

**Author:** [@zyaza](https://discuss.elastic.co/u/zyaza)\
**Replies:** 0\
**Last updated:** [February 10, 2023, 9:27am UTC](https://discuss.elastic.co/t/kibana-cannot-connect-to-the-elastic-package-registry-which-provides-elastic-agent-integrations/325233 "2023-02-10T09:27:28Z")

</div>

After installing elasticsearch, kibana and auditbeat i went to http://127.0.0.1:5601. I clicked on Discorver and this what the image I saw

---

## [Packetbeat TLS \[Client|Server\] hello Ciphers on one string](https://discuss.elastic.co/t/packetbeat-tls-client-server-hello-ciphers-on-one-string/325229)

<div class="topic-metadata">

**Author:** [@franpom](https://discuss.elastic.co/u/franpom)\
**Replies:** 0\
**Last updated:** [February 10, 2023, 9:06am UTC](https://discuss.elastic.co/t/packetbeat-tls-client-server-hello-ciphers-on-one-string/325229 "2023-02-10T09:06:32Z")

</div>

Hello, Would it be possible to integrate an additional field concerning the tls client support\_ciphers? This field currently is broken down for each cipher presented. The problem is that we lose the order of preferenc…

---

## [I use the SLM policy, and the start time of the snapshot is inconsistent with the scheduled time](https://discuss.elastic.co/t/i-use-the-slm-policy-and-the-start-time-of-the-snapshot-is-inconsistent-with-the-scheduled-time/325082)

<div class="topic-metadata">

**Author:** [@lijianzhi](https://discuss.elastic.co/u/lijianzhi)\
**Replies:** 8\
**Last updated:** [February 10, 2023, 8:59am UTC](https://discuss.elastic.co/t/i-use-the-slm-policy-and-the-start-time-of-the-snapshot-is-inconsistent-with-the-scheduled-time/325082 "2023-02-10T08:59:49Z")

</div>

I use slm policy to create a snapshot policy plan 0 0 \* \* \*?, The next plan is 12:00, but the actual start time of the snapshot is 11:59:59, one second ahead of schedule. Or 12:00:01, delay 1 second. There are three repl…

---

## [Split Alert Message in Elasticsearch Query type Alert](https://discuss.elastic.co/t/split-alert-message-in-elasticsearch-query-type-alert/325226)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 0\
**Last updated:** [February 10, 2023, 8:56am UTC](https://discuss.elastic.co/t/split-alert-message-in-elasticsearch-query-type-alert/325226 "2023-02-10T08:56:38Z")

</div>

Hi there, i want to ask about alerting message. i was created an alert using elasticsearch query to find some cert that close to it's expire date and i used server log connector. the alert is running as well, but the pr…

---

## [Elastic agent random shutdown/goes offline](https://discuss.elastic.co/t/elastic-agent-random-shutdown-goes-offline/325223)

<div class="topic-metadata">

**Author:** [@fontexD](https://discuss.elastic.co/u/fontexD)\
**Replies:** 0\
**Last updated:** [February 10, 2023, 8:27am UTC](https://discuss.elastic.co/t/elastic-agent-random-shutdown-goes-offline/325223 "2023-02-10T08:27:41Z")

</div>

Ive deployed a elk stack with elastic kibana and fleet server, all going smooth using self-gen self-created certs for transport all the way and my own ssl in front via ingress version 6.2.1 created with elk operator in…

---

## [Unable to install markdown & handlebars plugin in kibana](https://discuss.elastic.co/t/unable-to-install-markdown-handlebars-plugin-in-kibana/325218)

<div class="topic-metadata">

**Author:** [@ateethrigvedi](https://discuss.elastic.co/u/ateethrigvedi)\
**Replies:** 1\
**Last updated:** [February 10, 2023, 7:56am UTC](https://discuss.elastic.co/t/unable-to-install-markdown-handlebars-plugin-in-kibana/325218 "2023-02-10T07:56:02Z")

</div>

I have been trying to install sw-jung/kibana\_markdown\_doc\_view in windows. Command used: \*\*kibana-plugin install https://github.com/sw-jung/kibana\_markdown\_doc\_view/releases/download/v6.2.4/markdown\_doc\_view-6.2.4.zip\*…

---

## [Solace/Jagger integration with Elasticsearch](https://discuss.elastic.co/t/solace-jagger-integration-with-elasticsearch/325215)

<div class="topic-metadata">

**Author:** [@akhil](https://discuss.elastic.co/u/akhil)\
**Replies:** 1\
**Last updated:** [February 10, 2023, 7:43am UTC](https://discuss.elastic.co/t/solace-jagger-integration-with-elasticsearch/325215 "2023-02-10T07:43:55Z")

</div>

We are getting below exception while connecting elk through Jagger, please help us to fix the issue. HTTP Error: search services failed: elastic: Error 400 (Bad Request): all shards failed \[type=search\_phase\_execution\_e…

---

## [ILM deleted after run](https://discuss.elastic.co/t/ilm-deleted-after-run/325130)

<div class="topic-metadata">

**Author:** [@laurijssen](https://discuss.elastic.co/u/laurijssen)\
**Replies:** 2\
**Last updated:** [February 10, 2023, 7:42am UTC](https://discuss.elastic.co/t/ilm-deleted-after-run/325130 "2023-02-10T07:42:41Z")

</div>

I've created an ILM that deletes data after x days. PUT idx\*/\_settings { "index": { "lifecycle": { "name": "x-days-policy" } } } The data gets deleted only once and then the ILM is removed. GET idx/\_…

---

## [Kibana patches from 8.5.3 to 8.6.1](https://discuss.elastic.co/t/kibana-patches-from-8-5-3-to-8-6-1/324202)

<div class="topic-metadata">

**Author:** [@ArpitChoudhary](https://discuss.elastic.co/u/ArpitChoudhary)\
**Replies:** 26\
**Last updated:** [February 10, 2023, 7:15am UTC](https://discuss.elastic.co/t/kibana-patches-from-8-5-3-to-8-6-1/324202 "2023-02-10T07:15:12Z")

</div>

Hello guys, Need help while upgrading kibana patches from 8.5.3 to 8.6.1. not able to connect a node on browser. I update a node by apt update -y & apy upgrade -y, reboot it, try to make it out from the cluster but go…

---

## [Elasticsearch, Logstash, Kibana Scale-out Architecture](https://discuss.elastic.co/t/elasticsearch-logstash-kibana-scale-out-architecture/325206)

<div class="topic-metadata">

**Author:** [@haikal.azaim](https://discuss.elastic.co/u/haikal.azaim)\
**Replies:** 1\
**Last updated:** [February 10, 2023, 7:04am UTC](https://discuss.elastic.co/t/elasticsearch-logstash-kibana-scale-out-architecture/325206 "2023-02-10T07:04:54Z")

</div>

Hi Elastic Community, please need your advice. I have 2 logstash, 3 elasticsearch nodes, and 1 kibana for one office. I want to scale out the architecture, because there is new office with 300GB/day. My goal is to stick…

---

## [Grok filter request for json/custom pattern](https://discuss.elastic.co/t/grok-filter-request-for-json-custom-pattern/325135)

<div class="topic-metadata">

**Author:** [@a.emrekaraman](https://discuss.elastic.co/u/a.emrekaraman)\
**Replies:** 0\
**Last updated:** [February 9, 2023, 11:39am UTC](https://discuss.elastic.co/t/grok-filter-request-for-json-custom-pattern/325135 "2023-02-09T11:39:16Z")

</div>

Hi Team, I installed logstash and try to create right grok filter for my logs to parse it. How can I parse below logs ? ( timestamp seems as custom.%{TIMESTAMP\_ISO8601:timestamp}" doesnt work) 09-Feb-2023 09:52:49 tmp…

---

## [GROK Pattern creation](https://discuss.elastic.co/t/grok-pattern-creation/324605)

<div class="topic-metadata">

**Author:** [@anushka1203](https://discuss.elastic.co/u/anushka1203)\
**Replies:** 7\
**Last updated:** [February 10, 2023, 6:25am UTC](https://discuss.elastic.co/t/grok-pattern-creation/324605 "2023-02-10T06:25:33Z")

</div>

Hi all, Need help in creating grok pattern that works for both the following type of logs 01/25-05:17:51.314622 192.168.1.1:138 -\> 192.168.1.255:138 UDP TTL:64 TOS:0x0 ID:50222 IpLen:20 DgmLen:229 DF Len: 201 =+=+=+=+=…

---

## [Need help for RUM configuration for Angular 1.13](https://discuss.elastic.co/t/need-help-for-rum-configuration-for-angular-1-13/324535)

<div class="topic-metadata">

**Author:** [@Dixit](https://discuss.elastic.co/u/Dixit)\
**Replies:** 11\
**Last updated:** [February 10, 2023, 12:09am UTC](https://discuss.elastic.co/t/need-help-for-rum-configuration-for-angular-1-13/324535 "2023-02-10T00:09:33Z")

</div>

Hi @basepi & @lwintergerst , Need help on how to configure RUM for AngularJS 1.13 ? Thanks, Dixit

[Previous page](https://discuss.elastic.co/latest.md?page=786)

[Next page](https://discuss.elastic.co/latest.md?page=788)
