# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=341

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 342

---

## [How to update service account which is used to create snapshot](https://discuss.elastic.co/t/how-to-update-service-account-which-is-used-to-create-snapshot/337128)

<div class="topic-metadata">

**Author:** [@Aysh14](https://discuss.elastic.co/u/Aysh14)\
**Replies:** 5\
**Last updated:** [July 14, 2023, 3:38am UTC](https://discuss.elastic.co/t/how-to-update-service-account-which-is-used-to-create-snapshot/337128 "2023-07-14T03:38:16Z")

</div>

How to update service account which is used to create snapshot. I created repository from Kibana to snapshot the Elastic search indices. The snapshot location is GCS bucket. However, the repository is not getting verifie…

---

## [Snapshotter setup](https://discuss.elastic.co/t/snapshotter-setup/338365)

<div class="topic-metadata">

**Author:** [@Aysh14](https://discuss.elastic.co/u/Aysh14)\
**Replies:** 0\
**Last updated:** [July 14, 2023, 3:33am UTC](https://discuss.elastic.co/t/snapshotter-setup/338365 "2023-07-14T03:33:39Z")

</div>

Can I setup a new repository to take snapshots today onwards without having to restart the data and master nodes on the Elastic Search cluster ? I am currently using ES 7.16 . The old snapshots are not available and ther…

---

## [Error loading execution history for alert rules](https://discuss.elastic.co/t/error-loading-execution-history-for-alert-rules/329774)

<div class="topic-metadata">

**Author:** [@Landorks](https://discuss.elastic.co/u/Landorks)\
**Replies:** 2\
**Last updated:** [July 13, 2023, 7:47pm UTC](https://discuss.elastic.co/t/error-loading-execution-history-for-alert-rules/329774 "2023-07-13T19:47:34Z")

</div>

Hi, I get the following error in Kibana (8.4.3) when trying to view an alert. It appears that this is causing alerts not to fire at all. Everything was working fine about a week ago. I've already tried creating a new al…

---

## [Charts are not properly embeding in the dash board](https://discuss.elastic.co/t/charts-are-not-properly-embeding-in-the-dash-board/338261)

<div class="topic-metadata">

**Author:** [@Kumar\_Abhinav](https://discuss.elastic.co/u/Kumar_Abhinav)\
**Replies:** 2\
**Last updated:** [July 13, 2023, 7:39pm UTC](https://discuss.elastic.co/t/charts-are-not-properly-embeding-in-the-dash-board/338261 "2023-07-13T19:39:14Z")

</div>

Hi, I have edited a field name with a Custom Label and edited the Format to Title Case. While it is showing well in the visualization i.e. (With Changes) when I import the visual into the dashboard it goes back to its d…

---

## [Kibana savej object giving error on import: migrating from 7.9.1 to 8.7.1 version full elk stack](https://discuss.elastic.co/t/kibana-savej-object-giving-error-on-import-migrating-from-7-9-1-to-8-7-1-version-full-elk-stack/338220)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 8\
**Last updated:** [July 13, 2023, 6:35pm UTC](https://discuss.elastic.co/t/kibana-savej-object-giving-error-on-import-migrating-from-7-9-1-to-8-7-1-version-full-elk-stack/338220 "2023-07-13T18:35:47Z")

</div>

Hello All, I'm migrating my full elk stack stack from 7.9.1 to 8.7.1 and facing issues while importing saved object in 8.7.1,below is the error in second image: How do I save saved object and download -shown below 1st …

---

## [Elasticsearch creating different indices with identical data](https://discuss.elastic.co/t/elasticsearch-creating-different-indices-with-identical-data/338352)

<div class="topic-metadata">

**Author:** [@mfisher](https://discuss.elastic.co/u/mfisher)\
**Replies:** 5\
**Last updated:** [July 13, 2023, 6:30pm UTC](https://discuss.elastic.co/t/elasticsearch-creating-different-indices-with-identical-data/338352 "2023-07-13T18:30:00Z")

</div>

I recently moved from ELK stack 7.X to 8.8.2. I'm using my old Logstash pipline confs. For some reason Elasticsearch/Kibana is showing each individual index but each index as the same data. I don't think its a datavie…

---

## [Best Practice For Private Locations (Synthetics)](https://discuss.elastic.co/t/best-practice-for-private-locations-synthetics/337318)

<div class="topic-metadata">

**Author:** [@ameindel](https://discuss.elastic.co/u/ameindel)\
**Replies:** 2\
**Last updated:** [July 13, 2023, 6:01pm UTC](https://discuss.elastic.co/t/best-practice-for-private-locations-synthetics/337318 "2023-07-13T18:01:00Z")

</div>

Hello, Elastic! I had a couple questions for you regarding best practices for utilizing Private Locations with Synthetics. I'll explain the two scenarios: 1 - We currently have two Elastic Stacks (dev and prod). The '…

---

## [Record Who Closes Alert](https://discuss.elastic.co/t/record-who-closes-alert/338254)

<div class="topic-metadata">

**Author:** [@SomeRobot](https://discuss.elastic.co/u/SomeRobot)\
**Replies:** 1\
**Last updated:** [July 13, 2023, 4:29pm UTC](https://discuss.elastic.co/t/record-who-closes-alert/338254 "2023-07-13T16:29:24Z")

</div>

Is there a way to record which user has 'closed' an alert in Elastic Security? I read through the audit log documentation, and it doesn't reference this specific topic. Is there any way to log this?

---

## [Scripted field was used to show traffic light image up or down in index pattern 7.9.1 kibana,8.8.2 dont support,wht is alternative to implement?](https://discuss.elastic.co/t/scripted-field-was-used-to-show-traffic-light-image-up-or-down-in-index-pattern-7-9-1-kibana-8-8-2-dont-support-wht-is-alternative-to-implement/338345)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 1\
**Last updated:** [July 13, 2023, 3:35pm UTC](https://discuss.elastic.co/t/scripted-field-was-used-to-show-traffic-light-image-up-or-down-in-index-pattern-7-9-1-kibana-8-8-2-dont-support-wht-is-alternative-to-implement/338345 "2023-07-13T15:35:08Z")

</div>

In kinbana 7.9.1 I used to use scripted fields in index pattern option ,now going forward its not supported in future version.We want this feature of tarffic light image show green or red. Its recommended to use run tim…

---

## [Filebeat Syslog no listening port](https://discuss.elastic.co/t/filebeat-syslog-no-listening-port/336969)

<div class="topic-metadata">

**Author:** [@mc.gyver.reboot](https://discuss.elastic.co/u/mc.gyver.reboot)\
**Replies:** 15\
**Last updated:** [July 13, 2023, 2:35pm UTC](https://discuss.elastic.co/t/filebeat-syslog-no-listening-port/336969 "2023-07-13T14:35:45Z")

</div>

Good morning, Configuration: Ubuntu version 22 Filebeat version 8.8.1 Aucun message d'erreur au lancement de Filebeat After hours of searching and testing, I can't find why Filebeat isn't listening on the ports I te…

---

## [Anomaly Detection Rule Won't Send Email](https://discuss.elastic.co/t/anomaly-detection-rule-wont-send-email/338244)

<div class="topic-metadata">

**Author:** [@McJava1967](https://discuss.elastic.co/u/McJava1967)\
**Replies:** 6\
**Last updated:** [July 13, 2023, 2:02pm UTC](https://discuss.elastic.co/t/anomaly-detection-rule-wont-send-email/338244 "2023-07-13T14:02:45Z")

</div>

Hi all. I'm evaluating Anomaly alerting using a locally hosted Platinum trial. In short, the anomaly detection Job itself is working. I can see anomalies in the results. And I have set up a Rule with a Connector. I…

---

## [Elasticsearch Cluster Health watch Watcher](https://discuss.elastic.co/t/elasticsearch-cluster-health-watch-watcher/338321)

<div class="topic-metadata">

**Author:** [@Shalinicts](https://discuss.elastic.co/u/Shalinicts)\
**Replies:** 8\
**Last updated:** [July 13, 2023, 1:36pm UTC](https://discuss.elastic.co/t/elasticsearch-cluster-health-watch-watcher/338321 "2023-07-13T13:36:55Z")

</div>

Hi Team, I am trying to create a watcher for cluster health check (Clluster is 3 master and 5 data node ) as per Elastic documentation In the input section it is referred to provide host as host:localhost "input" :…

---

## [ECE & Watcher: Trouble sending API key to ECE](https://discuss.elastic.co/t/ece-watcher-trouble-sending-api-key-to-ece/300980)

<div class="topic-metadata">

**Author:** [@Apprentice](https://discuss.elastic.co/u/Apprentice)\
**Replies:** 1\
**Last updated:** [July 13, 2023, 1:05pm UTC](https://discuss.elastic.co/t/ece-watcher-trouble-sending-api-key-to-ece/300980 "2023-07-13T13:05:45Z")

</div>

I am trying to create a Watcher using information from the ECE API as input. However I am having trouble getting authenticated. This is the Input for the watcher: "input": { "http" : { "request" : { "s…

---

## [Problem to add new date field in filter logstash](https://discuss.elastic.co/t/problem-to-add-new-date-field-in-filter-logstash/338107)

<div class="topic-metadata">

**Author:** [@shayn](https://discuss.elastic.co/u/shayn)\
**Replies:** 3\
**Last updated:** [July 13, 2023, 12:27pm UTC](https://discuss.elastic.co/t/problem-to-add-new-date-field-in-filter-logstash/338107 "2023-07-13T12:27:22Z")

</div>

i have date field called case\_start\_time in format of date and time . i am trying to add new field called case\_day which will cut the date without the time from case\_start\_time . case\_start\_time: 09/07/23 23:54:26 ca…

---

## [Logstash forwarding connection refused](https://discuss.elastic.co/t/logstash-forwarding-connection-refused/338293)

<div class="topic-metadata">

**Author:** [@willsy](https://discuss.elastic.co/u/willsy)\
**Replies:** 2\
**Last updated:** [July 13, 2023, 11:29am UTC](https://discuss.elastic.co/t/logstash-forwarding-connection-refused/338293 "2023-07-13T11:29:53Z")

</div>

Hello, I am trying to forward logs to any other location for the moment however i have the following error when trying to forward any data what so ever. I have a netcat listener on the opposite end and can see the incom…

---

## [Controlled rotation of elasticsearch data nodes while enabling the shard allocation awareness](https://discuss.elastic.co/t/controlled-rotation-of-elasticsearch-data-nodes-while-enabling-the-shard-allocation-awareness/338269)

<div class="topic-metadata">

**Author:** [@veerachenna](https://discuss.elastic.co/u/veerachenna)\
**Replies:** 7\
**Last updated:** [July 13, 2023, 10:44am UTC](https://discuss.elastic.co/t/controlled-rotation-of-elasticsearch-data-nodes-while-enabling-the-shard-allocation-awareness/338269 "2023-07-13T10:44:16Z")

</div>

Hi All, We are trying to enable the shard allocation awareness on the elasticsearch cluster on "zone" attribute while rotating the data nodes one after the other. We wanted to achieve this in more controlled manner. Ini…

---

## [Logstash pipeline Http output plugin error "\[HTTP Output Failure\] Encountered non-2xx HTTP code 400"](https://discuss.elastic.co/t/logstash-pipeline-http-output-plugin-error-http-output-failure-encountered-non-2xx-http-code-400/338116)

<div class="topic-metadata">

**Author:** [@PodarcisMuralis](https://discuss.elastic.co/u/PodarcisMuralis)\
**Replies:** 1\
**Last updated:** [July 13, 2023, 9:55am UTC](https://discuss.elastic.co/t/logstash-pipeline-http-output-plugin-error-http-output-failure-encountered-non-2xx-http-code-400/338116 "2023-07-13T09:55:29Z")

</div>

Hi all, I have a logstash output http plugin: output { if \[@metadata\]\[index\_to\_delete\] == "first\_index" or \[@metadata\]\[index\_to\_delete\] == "second\_index" { http { id =\> "http\_index\_delete" …

---

## [How to support complex filters in nested aggregation?](https://discuss.elastic.co/t/how-to-support-complex-filters-in-nested-aggregation/337444)

<div class="topic-metadata">

**Author:** [@crowod](https://discuss.elastic.co/u/crowod)\
**Replies:** 1\
**Last updated:** [July 13, 2023, 8:51am UTC](https://discuss.elastic.co/t/how-to-support-complex-filters-in-nested-aggregation/337444 "2023-07-13T08:51:56Z")

</div>

Here is my index mapping: { "mappings": { "properties": { "non\_nested\_field": { "type": "keyword" }, "nested\_field": { "type": "nested", "properties": { "subfiel…

---

## [My ELK CLuster health is showing yellow](https://discuss.elastic.co/t/my-elk-cluster-health-is-showing-yellow/338292)

<div class="topic-metadata">

**Author:** [@bbkunbi](https://discuss.elastic.co/u/bbkunbi)\
**Replies:** 0\
**Last updated:** [July 13, 2023, 8:39am UTC](https://discuss.elastic.co/t/my-elk-cluster-health-is-showing-yellow/338292 "2023-07-13T08:39:55Z")

</div>

My ELK Cluster health is showing yellow. Missing replica shards. i am creating index using python code es.index , in that where i have to define replica shard. image is attached.

---

## [Do we need to install nginx to bypass authentication of kibana dashboards when embeded in an external application?](https://discuss.elastic.co/t/do-we-need-to-install-nginx-to-bypass-authentication-of-kibana-dashboards-when-embeded-in-an-external-application/338168)

<div class="topic-metadata">

**Author:** [@Jvv\_Satya](https://discuss.elastic.co/u/Jvv_Satya)\
**Replies:** 4\
**Last updated:** [July 13, 2023, 8:39am UTC](https://discuss.elastic.co/t/do-we-need-to-install-nginx-to-bypass-authentication-of-kibana-dashboards-when-embeded-in-an-external-application/338168 "2023-07-13T08:39:19Z")

</div>

I have created Kibana Dashboards and embedded the iFrame URL in an application. It is asking to enter the username/password inside iFrame. So, how can we bypass and get rid of the login. The kibana version i am uisng is …

---

## [Issue with logstash](https://discuss.elastic.co/t/issue-with-logstash/338290)

<div class="topic-metadata">

**Author:** [@Hanni](https://discuss.elastic.co/u/Hanni)\
**Replies:** 0\
**Last updated:** [July 13, 2023, 8:15am UTC](https://discuss.elastic.co/t/issue-with-logstash/338290 "2023-07-13T08:15:05Z")

</div>

Hello, I have a question: when you have two different configuration files in the logstash conf.d directory, does this cause a problem when importing them into elasticsearch?

---

## [Want to create technical support case in Elastic Search](https://discuss.elastic.co/t/want-to-create-technical-support-case-in-elastic-search/338277)

<div class="topic-metadata">

**Author:** [@swapnalimag](https://discuss.elastic.co/u/swapnalimag)\
**Replies:** 1\
**Last updated:** [July 13, 2023, 7:02am UTC](https://discuss.elastic.co/t/want-to-create-technical-support-case-in-elastic-search/338277 "2023-07-13T07:02:44Z")

</div>

I want access to the technical support in Elastic Search. I am Organisational owner but not able to access to the technical support. I have only access to account or billing.

---

## [Need assistance for Uninstalling fleet agent on multiple workstation remotely](https://discuss.elastic.co/t/need-assistance-for-uninstalling-fleet-agent-on-multiple-workstation-remotely/338282)

<div class="topic-metadata">

**Author:** [@swapnalimag](https://discuss.elastic.co/u/swapnalimag)\
**Replies:** 0\
**Last updated:** [July 13, 2023, 6:06am UTC](https://discuss.elastic.co/t/need-assistance-for-uninstalling-fleet-agent-on-multiple-workstation-remotely/338282 "2023-07-13T06:06:24Z")

</div>

Hello, Recently we have deployed fleet agent on windows workstations remotely through GPO. Some of the workstations are facing high CPU usage issue. For That we need assistance for uninstalling the agents remotely. I ca…

---

## [Is leader sync cluster state to node when new node join cluster?](https://discuss.elastic.co/t/is-leader-sync-cluster-state-to-node-when-new-node-join-cluster/338185)

<div class="topic-metadata">

**Author:** [@cm\_z](https://discuss.elastic.co/u/cm_z)\
**Replies:** 4\
**Last updated:** [July 13, 2023, 5:54am UTC](https://discuss.elastic.co/t/is-leader-sync-cluster-state-to-node-when-new-node-join-cluster/338185 "2023-07-13T05:54:58Z")

</div>

When a new node or a previously joined node that was later expelled joins a stable cluster, will the leader synchronize the latest cluster status with them? If so, who can tell me where to find this functionality? I have…

---

## [LogStash::Json::ParserError: Unexpected character (':' (code 58))](https://discuss.elastic.co/t/logstash-unexpected-character-code-58/337864)

<div class="topic-metadata">

**Author:** [@shailendra1](https://discuss.elastic.co/u/shailendra1)\
**Replies:** 1\
**Last updated:** [July 13, 2023, 5:17am UTC](https://discuss.elastic.co/t/logstash-unexpected-character-code-58/337864 "2023-07-13T05:17:49Z")

</div>

i am facing the unexpected character error code 58 in my json data. even after validation of the data the logstash is reporting the errors . below is the sample data , can anyone help why logstash reporting an error here…

---

## [Elasticsearch 8.8: Master not discovered or elected yet, an election requires at least 2 nodes with ids from \[..\]](https://discuss.elastic.co/t/elasticsearch-8-8-master-not-discovered-or-elected-yet-an-election-requires-at-least-2-nodes-with-ids-from/338034)

<div class="topic-metadata">

**Author:** [@bhavya](https://discuss.elastic.co/u/bhavya)\
**Replies:** 2\
**Last updated:** [July 13, 2023, 5:17am UTC](https://discuss.elastic.co/t/elasticsearch-8-8-master-not-discovered-or-elected-yet-an-election-requires-at-least-2-nodes-with-ids-from/338034 "2023-07-13T05:17:48Z")

</div>

I am creating a multinode cluster (3 Master Nodes), having the configuration like xpack.ml.enabled: false xpack.security.enabled: false network.host: \[\_local\_, \_site\_\] path.data: /data/esdata path.logs: /data/logs xpack…

---

## [Calculate Unix timestamp difference in kibana](https://discuss.elastic.co/t/calculate-unix-timestamp-difference-in-kibana/338241)

<div class="topic-metadata">

**Author:** [@Babu72](https://discuss.elastic.co/u/Babu72)\
**Replies:** 4\
**Last updated:** [July 13, 2023, 5:13am UTC](https://discuss.elastic.co/t/calculate-unix-timestamp-difference-in-kibana/338241 "2023-07-13T05:13:49Z")

</div>

Hi All, I need help for new scripted field to calculate Unix timestamp difference in kibana as a Metric stop\_timestamp : start\_timestamp : output: hh:mm:ss:SS:SS 1 = 1 Nanosecond 1000 = 1 Microsecond 1000000 = 1 Milli…

---

## [Documentation on running our own elastic package storage](https://discuss.elastic.co/t/documentation-on-running-our-own-elastic-package-storage/338274)

<div class="topic-metadata">

**Author:** [@hari\_ibm](https://discuss.elastic.co/u/hari_ibm)\
**Replies:** 0\
**Last updated:** [July 13, 2023, 4:43am UTC](https://discuss.elastic.co/t/documentation-on-running-our-own-elastic-package-storage/338274 "2023-07-13T04:43:09Z")

</div>

Documentation on running our own elastic package storage I have build custom integration and also have setup our own elastic package registry? I couldn't able to find documentation on pushing the package to my registry

---

## [Installing elastic agent using K8S is not normal](https://discuss.elastic.co/t/installing-elastic-agent-using-k8s-is-not-normal/337064)

<div class="topic-metadata">

**Author:** [@L1NG](https://discuss.elastic.co/u/L1NG)\
**Replies:** 9\
**Last updated:** [July 13, 2023, 2:11am UTC](https://discuss.elastic.co/t/installing-elastic-agent-using-k8s-is-not-normal/337064 "2023-07-13T02:11:26Z")

</div>

1.Install the elastic agent using K8S and check if the pod is running. The result is that it is running 2.But it's not normal to see it in Kibana 3.View detailed proxy information, which shows that there is an issue wi…

---

## [Multiple events processing and runtime fields](https://discuss.elastic.co/t/multiple-events-processing-and-runtime-fields/338115)

<div class="topic-metadata">

**Author:** [@Thibadu](https://discuss.elastic.co/u/Thibadu)\
**Replies:** 1\
**Last updated:** [July 12, 2023, 11:23pm UTC](https://discuss.elastic.co/t/multiple-events-processing-and-runtime-fields/338115 "2023-07-12T23:23:45Z")

</div>

Hello there, I am currently working on how to raise an alert in Kibana in case a field's value is identical across two different events. Here's how my setup is configured : Network traffic -\> Suricata -\> log file -\> F…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=340)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=342)
