# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=273

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 274

---

## [Kibana data table visualization repeating the fields](https://discuss.elastic.co/t/kibana-data-table-visualization-repeating-the-fields/347110)

<div class="topic-metadata">

**Author:** [@laale1](https://discuss.elastic.co/u/laale1)\
**Replies:** 1\
**Last updated:** [November 14, 2023, 10:58pm UTC](https://discuss.elastic.co/t/kibana-data-table-visualization-repeating-the-fields/347110 "2023-11-14T22:58:18Z")

</div>

Hello community I'm trying to create data table visualization, but I have an issue of fields are repeating it self when ever new value comes in here is a screen shot of my data table I want to make it like this da…

---

## [Compare 2 run of elastic synthetic monitor runs](https://discuss.elastic.co/t/compare-2-run-of-elastic-synthetic-monitor-runs/345134)

<div class="topic-metadata">

**Author:** [@senyam08](https://discuss.elastic.co/u/senyam08)\
**Replies:** 2\
**Last updated:** [November 14, 2023, 10:08pm UTC](https://discuss.elastic.co/t/compare-2-run-of-elastic-synthetic-monitor-runs/345134 "2023-11-14T22:08:43Z")

</div>

Can we use elastic synthetics to compare 2 different runs and get the difference in performance with waterfall chart to get insight into root cause for load time increase? We got load time trend to identify whether page…

---

## [When will the patch be available for CVE-2023-38552/39331/39332/44487 upgrading nodejs \>= 18.18.2](https://discuss.elastic.co/t/when-will-the-patch-be-available-for-cve-2023-38552-39331-39332-44487-upgrading-nodejs-18-18-2/346356)

<div class="topic-metadata">

**Author:** [@stanislasm](https://discuss.elastic.co/u/stanislasm)\
**Replies:** 8\
**Last updated:** [November 14, 2023, 9:58pm UTC](https://discuss.elastic.co/t/when-will-the-patch-be-available-for-cve-2023-38552-39331-39332-44487-upgrading-nodejs-18-18-2/346356 "2023-11-14T21:58:24Z")

</div>

Hello, When will the fix for CVE-2023-38552/39331/39332/44487 upgrading nodejs \>= 18.18.2 be available in the Kibana 8.10.x version? Thanks

---

## [False positive report](https://discuss.elastic.co/t/false-positive-report/347155)

<div class="topic-metadata">

**Author:** [@armada](https://discuss.elastic.co/u/armada)\
**Replies:** 2\
**Last updated:** [November 14, 2023, 7:46pm UTC](https://discuss.elastic.co/t/false-positive-report/347155 "2023-11-14T19:46:13Z")

</div>

Hi, we followed your advice and forwarded a false positive report to fp\_reports@elastic.co but have not received any response. Pls advise: As a result of this nonsense, Lurkit terminated our service contract and suffere…

---

## [Detection rules: include Kibana visualization in email](https://discuss.elastic.co/t/detection-rules-include-kibana-visualization-in-email/347159)

<div class="topic-metadata">

**Author:** [@cdelgado](https://discuss.elastic.co/u/cdelgado)\
**Replies:** 0\
**Last updated:** [November 14, 2023, 7:20pm UTC](https://discuss.elastic.co/t/detection-rules-include-kibana-visualization-in-email/347159 "2023-11-14T19:20:52Z")

</div>

Hi all, Is there any way to include Kibana visualizations (i.e., from Visualize Library) in the Email action of a Detection Rule? I am looking for different available options to include more complex forms of data on a …

---

## [Default index template](https://discuss.elastic.co/t/default-index-template/347158)

<div class="topic-metadata">

**Author:** [@Milad\_Heydariaan](https://discuss.elastic.co/u/Milad_Heydariaan)\
**Replies:** 0\
**Last updated:** [November 14, 2023, 7:15pm UTC](https://discuss.elastic.co/t/default-index-template/347158 "2023-11-14T19:15:41Z")

</div>

With legacy templates, we used to have a "default template" (with \* pattern and order -10) which sets a few index settings including threshold for slowlogs, number of shard, and number of replicas. Then users could creat…

---

## [Unassigned shards -- and two shards rebalancing](https://discuss.elastic.co/t/unassigned-shards-and-two-shards-rebalancing/346555)

<div class="topic-metadata">

**Author:** [@Russell\_Fulton](https://discuss.elastic.co/u/Russell_Fulton)\
**Replies:** 6\
**Last updated:** [November 14, 2023, 7:00pm UTC](https://discuss.elastic.co/t/unassigned-shards-and-two-shards-rebalancing/346555 "2023-11-14T19:00:24Z")

</div>

My cluster has been stuck in Yellow for a couple of days. There are two shards that are being rebalanced (and have been for days ???) and this is appears to be causing the cluster to refuse to allocate replicas of prima…

---

## [Elasticsearch improvements from version 7.9 to 8.10](https://discuss.elastic.co/t/elasticsearch-improvements-from-version-7-9-to-8-10/347026)

<div class="topic-metadata">

**Author:** [@michele\_crudele](https://discuss.elastic.co/u/michele_crudele)\
**Replies:** 3\
**Last updated:** [November 14, 2023, 6:48pm UTC](https://discuss.elastic.co/t/elasticsearch-improvements-from-version-7-9-to-8-10/347026 "2023-11-14T18:48:28Z")

</div>

Is there a list somewhere of the Elasticsearch significant improvements from 7.9 version to 8.7

---

## [Failed execution of ESQL query and high cpu load](https://discuss.elastic.co/t/failed-execution-of-esql-query-and-high-cpu-load/346992)

<div class="topic-metadata">

**Author:** [@Stefan\_Sabolowitsch](https://discuss.elastic.co/u/Stefan_Sabolowitsch)\
**Replies:** 15\
**Last updated:** [November 14, 2023, 4:04pm UTC](https://discuss.elastic.co/t/failed-execution-of-esql-query-and-high-cpu-load/346992 "2023-11-14T16:04:54Z")

</div>

Hi There, I have a one node cluster here for testing. Hardware Spec: 16 Core // 148GB // 6 SAS 15K Raid0 Everything is running smoothly except for Elastic Security. As soon as i perform an action here, i get Kibana …

---

## [Cannot create datastream under new index template](https://discuss.elastic.co/t/cannot-create-datastream-under-new-index-template/347126)

<div class="topic-metadata">

**Author:** [@Casper\_Thrane](https://discuss.elastic.co/u/Casper_Thrane)\
**Replies:** 5\
**Last updated:** [November 14, 2023, 3:17pm UTC](https://discuss.elastic.co/t/cannot-create-datastream-under-new-index-template/347126 "2023-11-14T15:17:49Z")

</div>

Hi I am using logstash running Kubernetes under ECK. I am ingesting both logs (filebeat) and metrics (metricbeat). Now i want ingest data from heartbeat. I get the following error: \[2023-11-14T13:22:23,598\]\[INFO \]\[logs…

---

## [Restart the Logstash 8.8 configuration without restarting it](https://discuss.elastic.co/t/restart-the-logstash-8-8-configuration-without-restarting-it/347095)

<div class="topic-metadata">

**Author:** [@Manal\_A](https://discuss.elastic.co/u/Manal_A)\
**Replies:** 2\
**Last updated:** [November 14, 2023, 2:34pm UTC](https://discuss.elastic.co/t/restart-the-logstash-8-8-configuration-without-restarting-it/347095 "2023-11-14T14:34:07Z")

</div>

Hello, Is there a way to reload the Logstash 8.8 configuration without restarting it? Thank you

---

## [Using transforms and ingest pipelines on data that changes over time](https://discuss.elastic.co/t/using-transforms-and-ingest-pipelines-on-data-that-changes-over-time/347101)

<div class="topic-metadata">

**Author:** [@pulsy](https://discuss.elastic.co/u/pulsy)\
**Replies:** 5\
**Last updated:** [November 14, 2023, 1:55pm UTC](https://discuss.elastic.co/t/using-transforms-and-ingest-pipelines-on-data-that-changes-over-time/347101 "2023-11-14T13:55:36Z")

</div>

I'm thinking about using elastic transforms together with ingest pipelines to basically create views of mongodb collections that are spread over multiple database servers, so we can efficiently sort and filter by referen…

---

## [Logstash Multiple Output Atomicity](https://discuss.elastic.co/t/logstash-multiple-output-atomicity/347100)

<div class="topic-metadata">

**Author:** [@mile3880](https://discuss.elastic.co/u/mile3880)\
**Replies:** 1\
**Last updated:** [November 14, 2023, 1:14pm UTC](https://discuss.elastic.co/t/logstash-multiple-output-atomicity/347100 "2023-11-14T13:14:48Z")

</div>

Does Logstash guarantee atomicity of multiple output options? For Example, if I set 2 different outputs to Elasticsearch A and B, and when connection to Elasticsearch A is temporarily unstable, can Logstash stop sending…

---

## [Non-existent secret key: elastic-internal-pre-stop](https://discuss.elastic.co/t/non-existent-secret-key-elastic-internal-pre-stop/347122)

<div class="topic-metadata">

**Author:** [@ElSamhaa](https://discuss.elastic.co/u/ElSamhaa)\
**Replies:** 0\
**Last updated:** [November 14, 2023, 12:57pm UTC](https://discuss.elastic.co/t/non-existent-secret-key-elastic-internal-pre-stop/347122 "2023-11-14T12:57:36Z")

</div>

Can someone take a look at this pls? Non-existent secret key: elastic-internal-pre-stop · Issue #7315 · elastic/cloud-on-k8s · GitHub

---

## [No crea nuevo indice](https://discuss.elastic.co/t/no-crea-nuevo-indice/347040)

<div class="topic-metadata">

**Author:** [@marotaal](https://discuss.elastic.co/u/marotaal)\
**Replies:** 3\
**Last updated:** [November 14, 2023, 12:29pm UTC](https://discuss.elastic.co/t/no-crea-nuevo-indice/347040 "2023-11-14T12:29:56Z")

</div>

Hola. Tengo un único nodo elastic donde almaceno los logs para luego tratarlos. Hace unos días me quede sin espacio en el disco duro. He liberado espacio y reiniciado el nodo. Pero no se crean los nuevos índices (que…

---

## [Does anyone use connection pooling in ElasticSearch8.5? How to use it?](https://discuss.elastic.co/t/does-anyone-use-connection-pooling-in-elasticsearch8-5-how-to-use-it/346974)

<div class="topic-metadata">

**Author:** [@maoqingjue](https://discuss.elastic.co/u/maoqingjue)\
**Replies:** 16\
**Last updated:** [November 14, 2023, 11:09am UTC](https://discuss.elastic.co/t/does-anyone-use-connection-pooling-in-elasticsearch8-5-how-to-use-it/346974 "2023-11-14T11:09:13Z")

</div>

Does anyone use connection pooling in Elasticsearch8.5? How to use it?

---

## [Sending AWS Cloud Watch Logs to Elasticsearch](https://discuss.elastic.co/t/sending-aws-cloud-watch-logs-to-elasticsearch/346459)

<div class="topic-metadata">

**Author:** [@laale1](https://discuss.elastic.co/u/laale1)\
**Replies:** 5\
**Last updated:** [November 14, 2023, 11:01am UTC](https://discuss.elastic.co/t/sending-aws-cloud-watch-logs-to-elasticsearch/346459 "2023-11-14T11:01:37Z")

</div>

Hello community. I want to send AWS Cloud Watch logs to my local Elasticsearch cluster? I have seen AWS integrations but my question is how I'm going to connect those integrations on my AWS Cloud Watch?

---

## [Server requirement for every node role](https://discuss.elastic.co/t/server-requirement-for-every-node-role/347075)

<div class="topic-metadata">

**Author:** [@psanggabuana](https://discuss.elastic.co/u/psanggabuana)\
**Replies:** 3\
**Last updated:** [November 14, 2023, 10:20am UTC](https://discuss.elastic.co/t/server-requirement-for-every-node-role/347075 "2023-11-14T10:20:29Z")

</div>

Hi all, I need information about master, data, inget, and coordination server requirements. Anyone can share with me about CPU and Memory needs of each role node? CPU RAM Master Data Coordinatin…

---

## [One day, the dashboards and graphs were using disappeared](https://discuss.elastic.co/t/one-day-the-dashboards-and-graphs-were-using-disappeared/346976)

<div class="topic-metadata">

**Author:** [@Cusis\_Eel](https://discuss.elastic.co/u/Cusis_Eel)\
**Replies:** 7\
**Last updated:** [November 14, 2023, 9:47am UTC](https://discuss.elastic.co/t/one-day-the-dashboards-and-graphs-were-using-disappeared/346976 "2023-11-14T09:47:07Z")

</div>

One day, I changed the value of 'xpack.security.enabled' from 'true' to 'false' in my Kibana+Elasticsearch environment. I had no problems using it after that, but when I logged into Kibana a few days later, all my dashbo…

---

## [Elastic Defend - Is default logging on the endpoint enough?](https://discuss.elastic.co/t/elastic-defend-is-default-logging-on-the-endpoint-enough/346296)

<div class="topic-metadata">

**Author:** [@h49nakxs](https://discuss.elastic.co/u/h49nakxs)\
**Replies:** 2\
**Last updated:** [November 14, 2023, 9:27am UTC](https://discuss.elastic.co/t/elastic-defend-is-default-logging-on-the-endpoint-enough/346296 "2023-11-14T09:27:54Z")

</div>

Hello, If I use "Elastic Defend" integration, will all the Elastic Security detection rules get enough information to be triggered or do I need to enhance the logging on the endpoints (for example with Sysmon on Windows…

---

## [No span and transaction for Dubbo example](https://discuss.elastic.co/t/no-span-and-transaction-for-dubbo-example/347094)

<div class="topic-metadata">

**Author:** [@bixiyan](https://discuss.elastic.co/u/bixiyan)\
**Replies:** 0\
**Last updated:** [November 14, 2023, 9:12am UTC](https://discuss.elastic.co/t/no-span-and-transaction-for-dubbo-example/347094 "2023-11-14T09:12:30Z")

</div>

Hi team: I am doing a poc on elastic apm using dubbo. Kibana version: 7.16.3 Elasticsearch: 7.16.3 apm-server:v7.16.3 I have create a dubbo provider and consumer. Consumer run every second to call provider. Now I c…

---

## [Field and Value missmatch Paolo Alto OS11 paring Logstash \> Elastic \> Kibana](https://discuss.elastic.co/t/field-and-value-missmatch-paolo-alto-os11-paring-logstash-elastic-kibana/346969)

<div class="topic-metadata">

**Author:** [@Trung\_Nguyen](https://discuss.elastic.co/u/Trung_Nguyen)\
**Replies:** 5\
**Last updated:** [November 14, 2023, 8:30am UTC](https://discuss.elastic.co/t/field-and-value-missmatch-paolo-alto-os11-paring-logstash-elastic-kibana/346969 "2023-11-14T08:30:59Z")

</div>

Hi, i'm a new logstash and trying to parsing log from my firewall PAN\_OS 11 but the field and value dose not match, such as field "NAT Destination IP" get value from the "Rule Name" Thanks a lot for any hlep Trung

---

## [Logstash and since db permission](https://discuss.elastic.co/t/logstash-and-since-db-permission/346934)

<div class="topic-metadata">

**Author:** [@ranjini](https://discuss.elastic.co/u/ranjini)\
**Replies:** 2\
**Last updated:** [November 14, 2023, 7:15am UTC](https://discuss.elastic.co/t/logstash-and-since-db-permission/346934 "2023-11-14T07:15:56Z")

</div>

Logstash runs as a container.logstash version 8.11.0 Logstash input looks like the below input { file { path =\> "/common/logs/parser-server-tasks-application/app.log" start\_position =\> "beginning" sincedb…

---

## [Is Logstash Free use?](https://discuss.elastic.co/t/is-logstash-free-use/347078)

<div class="topic-metadata">

**Author:** [@inbeom\_cho](https://discuss.elastic.co/u/inbeom_cho)\
**Replies:** 1\
**Last updated:** [November 14, 2023, 6:10am UTC](https://discuss.elastic.co/t/is-logstash-free-use/347078 "2023-11-14T06:10:55Z")

</div>

Hi forum, when i use only logstash 8.8 version, that is free? Or If i want free, must use logstash oss?

---

## [Logstash: SNMP Poll Input - skipping "error: no such.."](https://discuss.elastic.co/t/logstash-snmp-poll-input-skipping-error-no-such/347051)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 2\
**Last updated:** [November 13, 2023, 10:59pm UTC](https://discuss.elastic.co/t/logstash-snmp-poll-input-skipping-error-no-such/347051 "2023-11-13T22:59:49Z")

</div>

Hello, I am using SNMP poll input for logstash. Using SNMP V3, I have a wide range of network devices to monitor which means many oids that are specific by vendor. I want to know if there is a way to skip oids in whic…

---

## [Detection rule: Email CSV file as action](https://discuss.elastic.co/t/detection-rule-email-csv-file-as-action/347065)

<div class="topic-metadata">

**Author:** [@cdelgado](https://discuss.elastic.co/u/cdelgado)\
**Replies:** 0\
**Last updated:** [November 13, 2023, 10:12pm UTC](https://discuss.elastic.co/t/detection-rule-email-csv-file-as-action/347065 "2023-11-13T22:12:19Z")

</div>

Hello, When configuring Detection Rules, is there a way to send a CSV file as part of the Email action (when the rule triggers)? I am aware Mustache and Markdown syntax is supported for the email body, but I was wonderi…

---

## [Can't delete or recover .kibana\_security\_session\_1 index](https://discuss.elastic.co/t/cant-delete-or-recover-kibana-security-session-1-index/347035)

<div class="topic-metadata">

**Author:** [@RRGTHWAR](https://discuss.elastic.co/u/RRGTHWAR)\
**Replies:** 2\
**Last updated:** [November 13, 2023, 9:26pm UTC](https://discuss.elastic.co/t/cant-delete-or-recover-kibana-security-session-1-index/347035 "2023-11-13T21:26:44Z")

</div>

My storage team badly botched an upgrade, and as a result the .kibana\_security\_session\_1 index in my ECK cluster was corrupted. I don't have any backups of it to restore, and I can't delete it because the superuser privi…

---

## [QueryPhaseCollector invokes lucene score() twice on every doc when min\_score is used](https://discuss.elastic.co/t/queryphasecollector-invokes-lucene-score-twice-on-every-doc-when-min-score-is-used/347062)

<div class="topic-metadata">

**Author:** [@Mike\_McMahon](https://discuss.elastic.co/u/Mike_McMahon)\
**Replies:** 0\
**Last updated:** [November 13, 2023, 8:56pm UTC](https://discuss.elastic.co/t/queryphasecollector-invokes-lucene-score-twice-on-every-doc-when-min-score-is-used/347062 "2023-11-13T20:56:42Z")

</div>

Elastic 8.10 introduced a major change QueryPhaseCollector (see https://github.com/elastic/elasticsearch/pull/97410) in how lucene queries are executed. I have observed that now, when using min\_score, each document gets …

---

## [Kibana server is not ready yet](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet/346809)

<div class="topic-metadata">

**Author:** [@maycoonferreira](https://discuss.elastic.co/u/maycoonferreira)\
**Replies:** 17\
**Last updated:** [November 13, 2023, 6:54pm UTC](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet/346809 "2023-11-13T18:54:52Z")

</div>

Kibana server is not ready yet

---

## [Elasticsearch 8.10.2 synonyms not working when synonyms\_path is used](https://discuss.elastic.co/t/elasticsearch-8-10-2-synonyms-not-working-when-synonyms-path-is-used/346745)

<div class="topic-metadata">

**Author:** [@smritibhandari91](https://discuss.elastic.co/u/smritibhandari91)\
**Replies:** 1\
**Last updated:** [November 13, 2023, 6:35pm UTC](https://discuss.elastic.co/t/elasticsearch-8-10-2-synonyms-not-working-when-synonyms-path-is-used/346745 "2023-11-13T18:35:24Z")

</div>

We successfully deployed Elasticsearch 8.10.2 using the ECK operator. However, we encountered an issue when trying to access the synonyms\_path during the index creation process. Error: The problem is that the index crea…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=272)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=274)
