# \#none

**URL:** https://discuss.elastic.co/tag/none.md

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

---

## [Notes on Using These Forums](https://discuss.elastic.co/t/notes-on-using-these-forums/118)

<div class="topic-metadata">

**Author:** [@Leslie\_Hawthorn](https://discuss.elastic.co/u/Leslie_Hawthorn)\
**Replies:** 0\
**Last updated:** [May 4, 2015, 3:24pm UTC](https://discuss.elastic.co/t/notes-on-using-these-forums/118 "2015-05-04T15:24:11Z")

</div>

Welcome to Elastic's Discussion Forums! We're glad you're here. :smile: You can use these forums to ask questions about any of Elastic's products, share tips and tricks you've learned with your fellow users and keep up …

---

## [Elasticsearch does not remove shards on closing due to locking issues](https://discuss.elastic.co/t/elasticsearch-does-not-remove-shards-on-closing-due-to-locking-issues/361321)

<div class="topic-metadata">

**Author:** [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Replies:** 4\
**Last updated:** [October 3, 2026, 2:50pm UTC](https://discuss.elastic.co/t/elasticsearch-does-not-remove-shards-on-closing-due-to-locking-issues/361321 "2026-10-03T14:50:23Z")

</div>

Hey, we have an issue with out 7.18.18 cluster. It seems that closing a shard is throwing issues. This happens with several data nodes, so it's not a single glitch. This has never happened with out previous 7.12 version…

---

## [Elasticsearch Sometimes Returns Incomplete Search Results From My Website Even Though the Documents Are Indexed](https://discuss.elastic.co/t/elasticsearch-sometimes-returns-incomplete-search-results-from-my-website-even-though-the-documents-are-indexed/390803)

<div class="topic-metadata">

**Author:** [@joeroot](https://discuss.elastic.co/u/joeroot)\
**Replies:** 1\
**Last updated:** [October 2, 2026, 9:33am UTC](https://discuss.elastic.co/t/elasticsearch-sometimes-returns-incomplete-search-results-from-my-website-even-though-the-documents-are-indexed/390803 "2026-10-02T09:33:10Z")

</div>

Hi All, I am having an issue with Elasticsearch on my website where search requests sometimes return incomplete results even though the relevant documents are already present in the Elasticsearch index. The website uses…

---

## [Elasticsearch Netflow Top-N dashboard showing data in bytes instead of MB.GB etc](https://discuss.elastic.co/t/elasticsearch-netflow-top-n-dashboard-showing-data-in-bytes-instead-of-mb-gb-etc/390772)

<div class="topic-metadata">

**Author:** [@ahsan0331](https://discuss.elastic.co/u/ahsan0331)\
**Replies:** 2\
**Last updated:** [October 2, 2026, 7:59am UTC](https://discuss.elastic.co/t/elasticsearch-netflow-top-n-dashboard-showing-data-in-bytes-instead-of-mb-gb-etc/390772 "2026-10-02T07:59:56Z")

</div>

Hi i have upgraded "or so to speak" from filebeat netflow module to elastic netflow fleet based. And while i see its dashboards are somewhat good compared to the filebeat ones. but one dashboard that i used a lot in fil…

---

## [Kibana Alert Email - URL broken in SMTP email notifications](https://discuss.elastic.co/t/kibana-alert-email-url-broken-in-smtp-email-notifications/390797)

<div class="topic-metadata">

**Author:** [@Omar2](https://discuss.elastic.co/u/Omar2)\
**Replies:** 2\
**Last updated:** [October 2, 2026, 7:56am UTC](https://discuss.elastic.co/t/kibana-alert-email-url-broken-in-smtp-email-notifications/390797 "2026-10-02T07:56:01Z")

</div>

Hello, I'm experiencing an issue with Kibana alert emails sent through an SMTP connector. Kibana version: 9.4.3 Alert message: La règle Kibana {{rule.name}} s'est déclenchée: Nombre d'erreurs : {{context.value}} …

---

## [Downsampling non-dimension labels to last value is misleading](https://discuss.elastic.co/t/downsampling-non-dimension-labels-to-last-value-is-misleading/390779)

<div class="topic-metadata">

**Author:** [@pmcc](https://discuss.elastic.co/u/pmcc)\
**Replies:** 0\
**Last updated:** [September 30, 2026, 11:36am UTC](https://discuss.elastic.co/t/downsampling-non-dimension-labels-to-last-value-is-misleading/390779 "2026-09-30T11:36:22Z")

</div>

I'm upgrading from v7 to 9.5 - lots of great new features! For my application, TSDS look ideal, and downsampling will be a major improvement. There appears to be one flaw with downsampling for my use cases. Keyword fiel…

---

## [Support for metrics for kafka consumer group using new Consumer Rebalance Protocol](https://discuss.elastic.co/t/support-for-metrics-for-kafka-consumer-group-using-new-consumer-rebalance-protocol/390766)

<div class="topic-metadata">

**Author:** [@rakesh.iitism95](https://discuss.elastic.co/u/rakesh.iitism95)\
**Replies:** 0\
**Last updated:** [September 29, 2026, 8:29pm UTC](https://discuss.elastic.co/t/support-for-metrics-for-kafka-consumer-group-using-new-consumer-rebalance-protocol/390766 "2026-09-29T20:29:36Z")

</div>

We are currently using elastic agent to collect kafka consumer group metric. After a consumer group was configured to use the new consumer rebalance protocol available in Kafka 4.0 , the agent was not collecting the metr…

---

## [GC occurred in the Elasticsearch cluster](https://discuss.elastic.co/t/gc-occurred-in-the-elasticsearch-cluster/390606)

<div class="topic-metadata">

**Author:** [@Siva\_Karan](https://discuss.elastic.co/u/Siva_Karan)\
**Replies:** 1\
**Last updated:** [September 28, 2026, 12:00pm UTC](https://discuss.elastic.co/t/gc-occurred-in-the-elasticsearch-cluster/390606 "2026-09-28T12:00:23Z")

</div>

Hi Team, \[2026-09-22T22:20:13,448\]\[WARN \]\[o.e.m.j.JvmGcMonitorService\] \[node2\] \[gc\]\[435482\] overhead, spent \[4s\] collecting in the last \[4.6s\]. we are faced the GC issue with low heap usage and also we are unable to ac…

---

## [Elasticsearch monitoring tool - A chrome extension](https://discuss.elastic.co/t/elasticsearch-monitoring-tool-a-chrome-extension/388969)

<div class="topic-metadata">

**Author:** [@Musab\_Dogan](https://discuss.elastic.co/u/Musab_Dogan)\
**Replies:** 18\
**Last updated:** [September 28, 2026, 7:29am UTC](https://discuss.elastic.co/t/elasticsearch-monitoring-tool-a-chrome-extension/388969 "2026-09-28T07:29:15Z")

</div>

Hey guys, I've been debugging Elasticsearch clusters for years, and I got tired of jumping between \_cat APIs, and terminal tabs just to check cluster health. So I built a lightweight Chrome extension that surfaces the m…

---

## [Capture Elasticsearch diagnostics](https://discuss.elastic.co/t/capture-elasticsearch-diagnostics/390628)

<div class="topic-metadata">

**Author:** [@smm](https://discuss.elastic.co/u/smm)\
**Replies:** 2\
**Last updated:** [September 28, 2026, 7:19am UTC](https://discuss.elastic.co/t/capture-elasticsearch-diagnostics/390628 "2026-09-28T07:19:28Z")

</div>

Hi there, very soon I am going to purchase elastic licence. In a prior company I had also elastic licences and was used to use the Elasticsearch diagnostics script by the support to collect cluster health parameters. M…

---

## [Logstash at Tenant end or server end?](https://discuss.elastic.co/t/logstash-at-tenant-end-or-server-end/390608)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 1\
**Last updated:** [September 25, 2026, 10:59pm UTC](https://discuss.elastic.co/t/logstash-at-tenant-end-or-server-end/390608 "2026-09-25T22:59:52Z")

</div>

I’m trying to design an architecture where multiple tenants ingest their logs into Elastic. My understanding is that if the requirement is primarily log collection, I can use Elastic Agent, and if additional enrichment,…

---

## [Sharing my rule update experience on Elastic Security Serverless](https://discuss.elastic.co/t/sharing-my-rule-update-experience-on-elastic-security-serverless/389853)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 13\
**Last updated:** [September 25, 2026, 12:27pm UTC](https://discuss.elastic.co/t/sharing-my-rule-update-experience-on-elastic-security-serverless/389853 "2026-09-25T12:27:47Z")

</div>

Hello, Just sharing my experience updating Elastic prebuilt Security rules after being away for about 1.5 months. When I logged back in, I had roughly 1,200 rule updates waiting. That is fine in itself - I clicked Upda…

---

## [Elastic defend (Automatic Response Action Isnt Working )](https://discuss.elastic.co/t/elastic-defend-automatic-response-action-isnt-working/390597)

<div class="topic-metadata">

**Author:** [@jatin3101](https://discuss.elastic.co/u/jatin3101)\
**Replies:** 1\
**Last updated:** [September 25, 2026, 9:17am UTC](https://discuss.elastic.co/t/elastic-defend-automatic-response-action-isnt-working/390597 "2026-09-25T09:17:29Z")

</div>

Hi , i came across this problem that my response action arent working & somehad the same issue but their was solved and i dont undertsand how detection rule- firewall disabled issue- want to run a script for enablin…

---

## [Integration with omega-scan](https://discuss.elastic.co/t/integration-with-omega-scan/390677)

<div class="topic-metadata">

**Author:** [@wessorh](https://discuss.elastic.co/u/wessorh)\
**Replies:** 0\
**Last updated:** [September 25, 2026, 8:07am UTC](https://discuss.elastic.co/t/integration-with-omega-scan/390677 "2026-09-25T08:07:24Z")

</div>

I'm interested in testing a opensource sample scanner called omega-scan and am looking for documentation on what capabilities there are for calling 3rd party file scanners. A pointer would be greatly appreciated.

---

## [Why is the operator run as a statefulset?](https://discuss.elastic.co/t/why-is-the-operator-run-as-a-statefulset/390605)

<div class="topic-metadata">

**Author:** [@Frederic\_PEGE](https://discuss.elastic.co/u/Frederic_PEGE)\
**Replies:** 0\
**Last updated:** [September 23, 2026, 11:37am UTC](https://discuss.elastic.co/t/why-is-the-operator-run-as-a-statefulset/390605 "2026-09-23T11:37:14Z")

</div>

Hi, Why is the operator run as a STS ? I'm talking about the ES cluster, but the actual operator ?

---

## [RFC: Disable automatic refresh in event analyzer](https://discuss.elastic.co/t/rfc-disable-automatic-refresh-in-event-analyzer/390600)

<div class="topic-metadata">

**Author:** [@michael-a](https://discuss.elastic.co/u/michael-a)\
**Replies:** 0\
**Last updated:** [September 23, 2026, 8:35am UTC](https://discuss.elastic.co/t/rfc-disable-automatic-refresh-in-event-analyzer/390600 "2026-09-23T08:35:03Z")

</div>

When analyzing events from detections/alerts with automatic refresh, the analyze view automatically refresh too which isn't necessarily what one wants. Therefore it would be better if the automatic refresh either would t…

---

## [Integration-level Outputs](https://discuss.elastic.co/t/integration-level-outputs/390582)

<div class="topic-metadata">

**Author:** [@jameswiggins](https://discuss.elastic.co/u/jameswiggins)\
**Replies:** 3\
**Last updated:** [September 22, 2026, 8:17pm UTC](https://discuss.elastic.co/t/integration-level-outputs/390582 "2026-09-22T20:17:35Z")

</div>

I'm trying to determine how to configure integration-level outputs: Set integration-level outputs | Elastic Docs I followed the instructions for configuring, but do not see the option. Can someone share a screenshot of…

---

## [Kibana 9 - Detail pane is a bad replacement for Expandable row for my use cases](https://discuss.elastic.co/t/kibana-9-detail-pane-is-a-bad-replacement-for-expandable-row-for-my-use-cases/390555)

<div class="topic-metadata">

**Author:** [@poifir](https://discuss.elastic.co/u/poifir)\
**Replies:** 0\
**Last updated:** [September 21, 2026, 12:00pm UTC](https://discuss.elastic.co/t/kibana-9-detail-pane-is-a-bad-replacement-for-expandable-row-for-my-use-cases/390555 "2026-09-21T12:00:16Z")

</div>

In Kibana 8 we continued to use the "old" UI that offered to expand each row individually to show it's detail values. This works good as the full width of the windows is also available to the detailed attributes and so …

---

## [Kibana 9 - Detail dialog also shows "Truncated string" as configured for the overview](https://discuss.elastic.co/t/kibana-9-detail-dialog-also-shows-truncated-string-as-configured-for-the-overview/390551)

<div class="topic-metadata">

**Author:** [@poifir](https://discuss.elastic.co/u/poifir)\
**Replies:** 0\
**Last updated:** [September 21, 2026, 11:49am UTC](https://discuss.elastic.co/t/kibana-9-detail-dialog-also-shows-truncated-string-as-configured-for-the-overview/390551 "2026-09-21T11:49:22Z")

</div>

In the new Kibana 9 UI it's possible to customize the column visualization with "Edit data view field". This allows to e.g. enable to truncate a field to the first x characters so it only needs a reasonable size i…

---

## [Are you getting 403's when downloading? Please read here first](https://discuss.elastic.co/t/are-you-getting-403s-when-downloading-please-read-here-first/307340)

<div class="topic-metadata">

**Author:** [@carly.richmond](https://discuss.elastic.co/u/carly.richmond)\
**Replies:** 627\
**Last updated:** [September 21, 2026, 9:28am UTC](https://discuss.elastic.co/t/are-you-getting-403s-when-downloading-please-read-here-first/307340 "2026-09-21T09:28:18Z")

</div>

To save multiple topics on this, please copy and paste the below and we will follow it up with our geoip service provider (Google). Alternatively if you cannot post this information, please copy and paste the above into …

---

## [Kibana Dark Theme Now Blue?](https://discuss.elastic.co/t/kibana-dark-theme-now-blue/377919)

<div class="topic-metadata">

**Author:** [@MakoWish](https://discuss.elastic.co/u/MakoWish)\
**Replies:** 4\
**Last updated:** [September 21, 2026, 9:26am UTC](https://discuss.elastic.co/t/kibana-dark-theme-now-blue/377919 "2026-09-21T09:26:32Z")

</div>

In Kibana versions up to 8.18.1, the dark theme was black, just as with almost all other software I have used that offers a dark theme. I just upgraded my company's DEV cluster, as well as my home cluster, to 9.0.1, and …

---

## [java.nio.file.NoSuchFileException: /usr/share/elasticsearch/data/\_state/\_pu2t.cfs](https://discuss.elastic.co/t/java-nio-file-nosuchfileexception-usr-share-elasticsearch-data-state-pu2t-cfs/390250)

<div class="topic-metadata">

**Author:** [@TheJ](https://discuss.elastic.co/u/TheJ)\
**Replies:** 15\
**Last updated:** [September 19, 2026, 6:07pm UTC](https://discuss.elastic.co/t/java-nio-file-nosuchfileexception-usr-share-elasticsearch-data-state-pu2t-cfs/390250 "2026-09-19T18:07:12Z")

</div>

Hi, I have a problem with one of my elasticsearch node. For some reason node was shutdown due to some error. When I look into the log, I get the error java.nio.file.NoSuchFileException: /usr/share/elasticsearch/data/\_st…

---

## [Kibana error](https://discuss.elastic.co/t/kibana-error/390521)

<div class="topic-metadata">

**Author:** [@vanhung0709](https://discuss.elastic.co/u/vanhung0709)\
**Replies:** 1\
**Last updated:** [September 18, 2026, 4:17am UTC](https://discuss.elastic.co/t/kibana-error/390521 "2026-09-18T04:17:51Z")

</div>

I have set up elasticsearch and kibana. All steps have been done. Although i can curl es from kibana pod, kibana doesn’t put request to create index .kibana. When searching logs in pod kibana, it loop curl get nodes, but…

---

## [POSTFIX Ingest and the future of Logstash](https://discuss.elastic.co/t/postfix-ingest-and-the-future-of-logstash/390279)

<div class="topic-metadata">

**Author:** [@RalphDibney](https://discuss.elastic.co/u/RalphDibney)\
**Replies:** 6\
**Last updated:** [September 16, 2026, 12:40pm UTC](https://discuss.elastic.co/t/postfix-ingest-and-the-future-of-logstash/390279 "2026-09-16T12:40:22Z")

</div>

We have a mail gateway based on Postfix, and we want to get these logs into Elastic. For our product, our MSP that helps us with it has a logstash based integration that is also merges the mutliline log of postfix to on…

---

## [External Inference using google vertex ai and gemini-3.6-flash error](https://discuss.elastic.co/t/external-inference-using-google-vertex-ai-and-gemini-3-6-flash-error/390296)

<div class="topic-metadata">

**Author:** [@tallakh](https://discuss.elastic.co/u/tallakh)\
**Replies:** 2\
**Last updated:** [September 11, 2026, 7:13am UTC](https://discuss.elastic.co/t/external-inference-using-google-vertex-ai-and-gemini-3-6-flash-error/390296 "2026-09-11T07:13:06Z")

</div>

Hi! I'm trying to set up an external inference using our Google vertex ai account and the model gemini-3.6-flash. The inference creation works, but trying to use it as a chat-completion fails with an error: Error: Rec…

---

## [Found not migrated detection alerts](https://discuss.elastic.co/t/found-not-migrated-detection-alerts/385044)

<div class="topic-metadata">

**Author:** [@CD9820](https://discuss.elastic.co/u/CD9820)\
**Replies:** 2\
**Last updated:** [September 10, 2026, 6:57pm UTC](https://discuss.elastic.co/t/found-not-migrated-detection-alerts/385044 "2026-09-10T18:57:35Z")

</div>

Hello we are planning our upgrade from 8.19.x to 9.2.x The upgrade assistant contains a warning for Kibana: "Found not migrated detection alerts" I have tried to migrate but this does not work (example with .reindexed…

---

## [DNS Activity Data from Elastic Defend](https://discuss.elastic.co/t/dns-activity-data-from-elastic-defend/390171)

<div class="topic-metadata">

**Author:** [@RalphDibney](https://discuss.elastic.co/u/RalphDibney)\
**Replies:** 7\
**Last updated:** [September 10, 2026, 8:58am UTC](https://discuss.elastic.co/t/dns-activity-data-from-elastic-defend/390171 "2026-09-10T08:58:51Z")

</div>

Hey Elastic Community, after realizing that our Elastic Defend DNS data collected in our Windows machines has some data missing, we found some threads here in the community about it: Missing DNS requests on Windows mac…

---

## [HA-Cluster: Simple design on prem, self managed](https://discuss.elastic.co/t/ha-cluster-simple-design-on-prem-self-managed/390177)

<div class="topic-metadata">

**Author:** [@smm](https://discuss.elastic.co/u/smm)\
**Replies:** 12\
**Last updated:** [September 9, 2026, 5:33pm UTC](https://discuss.elastic.co/t/ha-cluster-simple-design-on-prem-self-managed/390177 "2026-09-09T17:33:34Z")

</div>

Hi there, I am looking for a simple HA-design for a logging use case, on prem & self managed. Would this be a good design? NODE-1 master, data, ingest, kibana, logstash, redis NODE-2 master, data, ingest, kibana, log…

---

## [Can Elastic Defend Event Collection interfere with software installation?](https://discuss.elastic.co/t/can-elastic-defend-event-collection-interfere-with-software-installation/389935)

<div class="topic-metadata">

**Author:** [@marrc.rousseau](https://discuss.elastic.co/u/marrc.rousseau)\
**Replies:** 5\
**Last updated:** [September 9, 2026, 4:43pm UTC](https://discuss.elastic.co/t/can-elastic-defend-event-collection-interfere-with-software-installation/389935 "2026-09-09T16:43:35Z")

</div>

Hello, I have a Windows server on which Elastic Defend is enabled, but only the Event Collection component is active. Nothing else is enabled — no malware protection, no ransomware protection, etc... The sole purpose i…

---

## [Elastic Agent 9.3.7 CPU spikes](https://discuss.elastic.co/t/elastic-agent-9-3-7-cpu-spikes/390264)

<div class="topic-metadata">

**Author:** [@etrevino-lumificyber](https://discuss.elastic.co/u/etrevino-lumificyber)\
**Replies:** 1\
**Last updated:** [September 9, 2026, 1:36am UTC](https://discuss.elastic.co/t/elastic-agent-9-3-7-cpu-spikes/390264 "2026-09-09T01:36:06Z")

</div>

I mostly see the spiking when apps are being opened or occasionally while they are being used. I tested using standard apps like Outlook, Excel, Word, Chrome. Doing a search in Chrome for example caused a spike from 7% t…

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=1)
