# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=389

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 390

---

## [Can't install Elastic Agent on MacOS Ventura (13.3.1) - Symlink](https://discuss.elastic.co/t/cant-install-elastic-agent-on-macos-ventura-13-3-1-symlink/330665)

<div class="topic-metadata">

**Author:** [@maof97](https://discuss.elastic.co/u/maof97)\
**Replies:** 6\
**Last updated:** [April 27, 2023, 9:44pm UTC](https://discuss.elastic.co/t/cant-install-elastic-agent-on-macos-ventura-13-3-1-symlink/330665 "2023-04-27T21:44:29Z")

</div>

Hey guys, I can't install elastic agent on my new MacBook running MacOS Ventura 13.3.1. Installing I get the following message: martin@Martins-MacBook-Pro-14 elastic-agent-8.7.0-darwin-aarch64 % sudo ./elastic-agent in…

---

## [Definition of plugin "runtimeFields" not found and may have failed to load](https://discuss.elastic.co/t/definition-of-plugin-runtimefields-not-found-and-may-have-failed-to-load/330556)

<div class="topic-metadata">

**Author:** [@Alfredo\_Casanova](https://discuss.elastic.co/u/Alfredo_Casanova)\
**Replies:** 2\
**Last updated:** [April 27, 2023, 7:17pm UTC](https://discuss.elastic.co/t/definition-of-plugin-runtimefields-not-found-and-may-have-failed-to-load/330556 "2023-04-27T19:17:34Z")

</div>

Hi. I just had to reboot my box and now when i submit my password in kibana i'm getting this message. my log file says not about it. Obviously i've tried "clearing my session" as suggested but it did't work.

---

## [Watcher - trying to print all document hits from search results](https://discuss.elastic.co/t/watcher-trying-to-print-all-document-hits-from-search-results/330978)

<div class="topic-metadata">

**Author:** [@vee](https://discuss.elastic.co/u/vee)\
**Replies:** 1\
**Last updated:** [April 27, 2023, 6:16pm UTC](https://discuss.elastic.co/t/watcher-trying-to-print-all-document-hits-from-search-results/330978 "2023-04-27T18:16:38Z")

</div>

Hi, trying to create a watcher to just print all hits on the message field which matches a particular string. All I was able to get to is print individual hits by using this pattern in the actions to send email: Message…

---

## [Logstash on windows sends data directly to the security onion SOC, not elasticsearch on windows?](https://discuss.elastic.co/t/logstash-on-windows-sends-data-directly-to-the-security-onion-soc-not-elasticsearch-on-windows/330985)

<div class="topic-metadata">

**Author:** [@iqworks](https://discuss.elastic.co/u/iqworks)\
**Replies:** 0\
**Last updated:** [April 27, 2023, 6:09pm UTC](https://discuss.elastic.co/t/logstash-on-windows-sends-data-directly-to-the-security-onion-soc-not-elasticsearch-on-windows/330985 "2023-04-27T18:09:06Z")

</div>

Hi, I am still learning about the sysmon data going to security onion. It seems that using elasticsearch on windows handles only windows data and does not send the data to security onion kibana. You can download kibana…

---

## [Handling ambiguous field names in search query](https://discuss.elastic.co/t/handling-ambiguous-field-names-in-search-query/329941)

<div class="topic-metadata">

**Author:** [@denvaar](https://discuss.elastic.co/u/denvaar)\
**Replies:** 1\
**Last updated:** [April 27, 2023, 4:59pm UTC](https://discuss.elastic.co/t/handling-ambiguous-field-names-in-search-query/329941 "2023-04-27T16:59:25Z")

</div>

I have a query that I run against multiple indices. Some of the indices being searched share some common field names, and I'm not sure what the best way to differentiate between them would be. I can get the desired resu…

---

## [Export Users Data Traffic](https://discuss.elastic.co/t/export-users-data-traffic/330937)

<div class="topic-metadata">

**Author:** [@Mursel](https://discuss.elastic.co/u/Mursel)\
**Replies:** 1\
**Last updated:** [April 27, 2023, 4:58pm UTC](https://discuss.elastic.co/t/export-users-data-traffic/330937 "2023-04-27T16:58:47Z")

</div>

Hello everyone. I want to export all users' Traffic Data. How can I do ?

---

## [Custom Charting](https://discuss.elastic.co/t/custom-charting/330968)

<div class="topic-metadata">

**Author:** [@dawiro](https://discuss.elastic.co/u/dawiro)\
**Replies:** 1\
**Last updated:** [April 27, 2023, 4:57pm UTC](https://discuss.elastic.co/t/custom-charting/330968 "2023-04-27T16:57:55Z")

</div>

Hi, Is it possible to create a chart which shows data for today overlaid against the same data from yesterday in order to compare patterns and volumes? Thx D

---

## [Discovery.seed\_hosts and cluster.initial\_master\_nodes](https://discuss.elastic.co/t/discovery-seed-hosts-and-cluster-initial-master-nodes/330945)

<div class="topic-metadata">

**Author:** [@mikewillis](https://discuss.elastic.co/u/mikewillis)\
**Replies:** 2\
**Last updated:** [April 27, 2023, 4:43pm UTC](https://discuss.elastic.co/t/discovery-seed-hosts-and-cluster-initial-master-nodes/330945 "2023-04-27T16:43:40Z")

</div>

I'm struggling to understand the discovery settings now that discovery.zen.minimum\_master\_nodes has gone away. (where current is 8.7) says that discovery.seed\_hosts Provides a list of the addresses of the master-el…

---

## [How to color a header in table lens](https://discuss.elastic.co/t/how-to-color-a-header-in-table-lens/330851)

<div class="topic-metadata">

**Author:** [@fatousouleymane.mben](https://discuss.elastic.co/u/fatousouleymane.mben)\
**Replies:** 3\
**Last updated:** [April 27, 2023, 3:36pm UTC](https://discuss.elastic.co/t/how-to-color-a-header-in-table-lens/330851 "2023-04-27T15:36:43Z")

</div>

how to color a header in table lens

---

## [Kibana not updating index in Discover](https://discuss.elastic.co/t/kibana-not-updating-index-in-discover/330885)

<div class="topic-metadata">

**Author:** [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Replies:** 11\
**Last updated:** [April 27, 2023, 3:30pm UTC](https://discuss.elastic.co/t/kibana-not-updating-index-in-discover/330885 "2023-04-27T15:30:19Z")

</div>

Hi All, I see this issue where Kibana is not updating index on the "Discover" page while there is a definite increase in the size of the related index. Also for some reason Discover page shows data with one hour interva…

---

## [Return JSON Array of Arrays from elastic](https://discuss.elastic.co/t/return-json-array-of-arrays-from-elastic/330971)

<div class="topic-metadata">

**Author:** [@Akaash\_Mukherjee](https://discuss.elastic.co/u/Akaash_Mukherjee)\
**Replies:** 4\
**Last updated:** [April 27, 2023, 3:23pm UTC](https://discuss.elastic.co/t/return-json-array-of-arrays-from-elastic/330971 "2023-04-27T15:23:10Z")

</div>

Hi, We've noticed that the overhead of the JSON object structure is creating some performance problems for us. One of the largest parts of this overhead is the repetitiveness of the object properties in each object. We'…

---

## [Protobuf data decode issue](https://discuss.elastic.co/t/protobuf-data-decode-issue/330976)

<div class="topic-metadata">

**Author:** [@Nithingowda](https://discuss.elastic.co/u/Nithingowda)\
**Replies:** 0\
**Last updated:** [April 27, 2023, 3:21pm UTC](https://discuss.elastic.co/t/protobuf-data-decode-issue/330976 "2023-04-27T15:21:12Z")

</div>

Here is the code to read the protobuf data from pubsub and decode in logstash but we are unable to decode the protobuf data. Code: input { google\_pubsub { project\_id =\> "project\_id" topic =\> "topic…

---

## [Can logstash.yml can be reloaded?](https://discuss.elastic.co/t/can-logstash-yml-can-be-reloaded/330942)

<div class="topic-metadata">

**Author:** [@prashant1](https://discuss.elastic.co/u/prashant1)\
**Replies:** 2\
**Last updated:** [April 27, 2023, 2:42pm UTC](https://discuss.elastic.co/t/can-logstash-yml-can-be-reloaded/330942 "2023-04-27T14:42:34Z")

</div>

We have deployed logstash in kubernetes platform. For one usecase we want to update queue.page\_capacity: 64mb to 1mb. So if we update these changes it can't be reloaded until restart. So is there any way so that this ca…

---

## [Logstash startup error-) Could not load FFI Provider: (NotImplementedError) FFI not available](https://discuss.elastic.co/t/logstash-startup-error-could-not-load-ffi-provider-notimplementederror-ffi-not-available/330904)

<div class="topic-metadata">

**Author:** [@karthic](https://discuss.elastic.co/u/karthic)\
**Replies:** 1\
**Last updated:** [April 27, 2023, 2:40pm UTC](https://discuss.elastic.co/t/logstash-startup-error-could-not-load-ffi-provider-notimplementederror-ffi-not-available/330904 "2023-04-27T14:40:32Z")

</div>

Tried to load logstash in a Centos environment \[INFO \]\[logstash.runner \] JVM bootstrap flags: \[-Xms1g, -Xmx1g, -Djava.awt.headless=true, -Dfile.encoding=UTF-8, -Djruby.compile.invokedynamic=true, -XX:+HeapDumpO…

---

## [ESET Protect Cloud logs](https://discuss.elastic.co/t/eset-protect-cloud-logs/330925)

<div class="topic-metadata">

**Author:** [@rodmontgt](https://discuss.elastic.co/u/rodmontgt)\
**Replies:** 2\
**Last updated:** [April 27, 2023, 1:50pm UTC](https://discuss.elastic.co/t/eset-protect-cloud-logs/330925 "2023-04-27T13:50:24Z")

</div>

Hi everyone, I've been playing around with logtash for days but still have not found a solution for this, my ESET console is configured to send syslog/BSD logs but I am getting this odd character set in my logstash inst…

---

## [Failed to start Logstash - S3 output plugin is not working](https://discuss.elastic.co/t/failed-to-start-logstash-s3-output-plugin-is-not-working/330096)

<div class="topic-metadata">

**Author:** [@WonhyeongCho](https://discuss.elastic.co/u/WonhyeongCho)\
**Replies:** 4\
**Last updated:** [April 27, 2023, 1:46pm UTC](https://discuss.elastic.co/t/failed-to-start-logstash-s3-output-plugin-is-not-working/330096 "2023-04-27T13:46:17Z")

</div>

Hi. I'm using Logstash. I recently upgraded Logstash to version 8.7.0, but it's not working. I'm getting an error message. Failed to execute action {:action=\>LogStash::PipelineAction::Create/pipeline\_id:OSQUERY, :excep…

---

## [Observability Engineer 7.9 - Lab 5.4 unable to get petclinic-react to appear](https://discuss.elastic.co/t/observability-engineer-7-9-lab-5-4-unable-to-get-petclinic-react-to-appear/328661)

<div class="topic-metadata">

**Author:** [@deccman](https://discuss.elastic.co/u/deccman)\
**Replies:** 11\
**Last updated:** [April 27, 2023, 1:23pm UTC](https://discuss.elastic.co/t/observability-engineer-7-9-lab-5-4-unable-to-get-petclinic-react-to-appear/328661 "2023-04-27T13:23:37Z")

</div>

Course: Elastic Observability Engineer Version: 7.9 Question: I have not been successful with getting petclinic-react to appear in the list of Services in APM. I can get the other three services to appear fine in APM…

---

## [Network scan](https://discuss.elastic.co/t/network-scan/330717)

<div class="topic-metadata">

**Author:** [@TheMadmax](https://discuss.elastic.co/u/TheMadmax)\
**Replies:** 2\
**Last updated:** [April 27, 2023, 12:39pm UTC](https://discuss.elastic.co/t/network-scan/330717 "2023-04-27T12:39:30Z")

</div>

Hello, I try to create a rule to detect a network scan. For example, generate an alert if more than 10 unique destinations have been accessed from the same source IP within 1 minute. but I don't see how to indicate …

---

## [Cannot deploy ECK 2.7.0 with PSP](https://discuss.elastic.co/t/cannot-deploy-eck-2-7-0-with-psp/330743)

<div class="topic-metadata">

**Author:** [@sebastianboelling](https://discuss.elastic.co/u/sebastianboelling)\
**Replies:** 3\
**Last updated:** [April 27, 2023, 11:09am UTC](https://discuss.elastic.co/t/cannot-deploy-eck-2-7-0-with-psp/330743 "2023-04-27T11:09:33Z")

</div>

Hi, I tried to deploy ECK 2.7.0 on my Tanzu Kubernetes environment and get the following error message: Warning Failed 5m6s (x2 over 5m7s) kubelet Error: container has runAsNonRoot and image will run a…

---

## [ElasticSearch 8.7 initial single node setting fails](https://discuss.elastic.co/t/elasticsearch-8-7-initial-single-node-setting-fails/330870)

<div class="topic-metadata">

**Author:** [@Pfiffikus](https://discuss.elastic.co/u/Pfiffikus)\
**Replies:** 2\
**Last updated:** [April 27, 2023, 7:22am UTC](https://discuss.elastic.co/t/elasticsearch-8-7-initial-single-node-setting-fails/330870 "2023-04-27T07:22:09Z")

</div>

I get elasticsearch-create-enrollment-token -s kibana ERROR: Failed to determine the health of the cluster. Unexpected http status \[401\] for xpack: security: authc: realms: file: file1: …

---

## [Extracting Detection Rule](https://discuss.elastic.co/t/extracting-detection-rule/330549)

<div class="topic-metadata">

**Author:** [@Aliz6](https://discuss.elastic.co/u/Aliz6)\
**Replies:** 1\
**Last updated:** [April 27, 2023, 10:49am UTC](https://discuss.elastic.co/t/extracting-detection-rule/330549 "2023-04-27T10:49:20Z")

</div>

Hi there, I was wondering if there is a way to extract all of the detection use cases (built-in and custom) in an excel sheet rather a json format file. Any suggestions would be helpful. Thanks.

---

## [Domain gets resolved to IP before cert verification](https://discuss.elastic.co/t/domain-gets-resolved-to-ip-before-cert-verification/330935)

<div class="topic-metadata">

**Author:** [@Octelly](https://discuss.elastic.co/u/Octelly)\
**Replies:** 0\
**Last updated:** [April 27, 2023, 9:52am UTC](https://discuss.elastic.co/t/domain-gets-resolved-to-ip-before-cert-verification/330935 "2023-04-27T09:52:31Z")

</div>

I have a Step-CA instance from which I obtain certificates through lego's CLI. The CA is trusted on all nodes system-wide and the certificates are generated for their domains. Elasticsearch is configured to use these dom…

---

## [Best practice for running Elastic Agents in EKS](https://discuss.elastic.co/t/best-practice-for-running-elastic-agents-in-eks/330931)

<div class="topic-metadata">

**Author:** [@mikkoc](https://discuss.elastic.co/u/mikkoc)\
**Replies:** 0\
**Last updated:** [April 27, 2023, 9:16am UTC](https://discuss.elastic.co/t/best-practice-for-running-elastic-agents-in-eks/330931 "2023-04-27T09:16:11Z")

</div>

Hello, We run Elastic Agents via Fleet in our EKS cluster, as DaemonSet, with about 20 nodes. We want to monitor and collect AWS Cloudwatch metrics, in addition to Kubernetes logs on each node. How do we go about inst…

---

## [How to parse API HTTP output data](https://discuss.elastic.co/t/how-to-parse-api-http-output-data/330829)

<div class="topic-metadata">

**Author:** [@sonirajil](https://discuss.elastic.co/u/sonirajil)\
**Replies:** 2\
**Last updated:** [April 27, 2023, 9:00am UTC](https://discuss.elastic.co/t/how-to-parse-api-http-output-data/330829 "2023-04-27T09:00:03Z")

</div>

Hello Team, I am running an API to get servicestatus data which looks like : { "recordcount": 11906, "servicestatus": \[ { "host\_name": "unixteam.abc.com", "service\_description": …

---

## [Retrieve the value of ca\_trusted\_fingerprint](https://discuss.elastic.co/t/retrieve-the-value-of-ca-trusted-fingerprint/330923)

<div class="topic-metadata">

**Author:** [@Jaud](https://discuss.elastic.co/u/Jaud)\
**Replies:** 0\
**Last updated:** [April 27, 2023, 8:43am UTC](https://discuss.elastic.co/t/retrieve-the-value-of-ca-trusted-fingerprint/330923 "2023-04-27T08:43:06Z")

</div>

Hello here. I was trying to configure my kibana and I've deleted the ca\_trusted\_fingerprint value. I searched online for any solution but I founded nothing. Do you know where can I found this value? Thank for reading …

---

## [Wrong documents' count after inserting](https://discuss.elastic.co/t/wrong-documents-count-after-inserting/330284)

<div class="topic-metadata">

**Author:** [@Gregory\_Kovalchuk](https://discuss.elastic.co/u/Gregory_Kovalchuk)\
**Replies:** 4\
**Last updated:** [April 27, 2023, 8:07am UTC](https://discuss.elastic.co/t/wrong-documents-count-after-inserting/330284 "2023-04-27T08:07:51Z")

</div>

Hello, please help, I inserted data with spark several times but the count was all the time bigger than expected, how it can be? The version of ES is 8.5.0. The query that I used to check: GET index/\_count.

---

## [Handling Kuberenets Labels Mapping Conflict](https://discuss.elastic.co/t/handling-kuberenets-labels-mapping-conflict/330915)

<div class="topic-metadata">

**Author:** [@Noa](https://discuss.elastic.co/u/Noa)\
**Replies:** 0\
**Last updated:** [April 27, 2023, 7:50am UTC](https://discuss.elastic.co/t/handling-kuberenets-labels-mapping-conflict/330915 "2023-04-27T07:50:35Z")

</div>

I have two kinds of labels which are causing a mapping conflict: app: \* vs. app.kubernetes.io/instance: \* (type text vs. type object) The second label is predefined by Kubernetes and is used to differentiate between d…

---

## [Why does this field exist in my output even though I have removed this?](https://discuss.elastic.co/t/why-does-this-field-exist-in-my-output-even-though-i-have-removed-this/330890)

<div class="topic-metadata">

**Author:** [@CyberGuy](https://discuss.elastic.co/u/CyberGuy)\
**Replies:** 0\
**Last updated:** [April 26, 2023, 11:15pm UTC](https://discuss.elastic.co/t/why-does-this-field-exist-in-my-output-even-though-i-have-removed-this/330890 "2023-04-26T23:15:39Z")

</div>

HI guys, I'm trying to create a logstash pipeline that parses incoming CEF logs, apply some logic and then outputs the log in JSON format to the console. For some reason, a field is generated with the name "Virtual Syst…

---

## [Elastic search 8.5.3 Aggregations query erroring](https://discuss.elastic.co/t/elastic-search-8-5-3-aggregations-query-erroring/330777)

<div class="topic-metadata">

**Author:** [@ramyogi](https://discuss.elastic.co/u/ramyogi)\
**Replies:** 13\
**Last updated:** [April 26, 2023, 5:51pm UTC](https://discuss.elastic.co/t/elastic-search-8-5-3-aggregations-query-erroring/330777 "2023-04-26T17:51:13Z")

</div>

Elastic search 8.5.3 not at all running aggregation queries , Even for small index ( just 5 documents ) Below Thread information. Same query works perfectly fine in Elastic Search 7.17 100.2% \[cpu=100.2%, other=0.0%…

---

## [How do you limit how long a search query will run for or how much resources one query can use?](https://discuss.elastic.co/t/how-do-you-limit-how-long-a-search-query-will-run-for-or-how-much-resources-one-query-can-use/330858)

<div class="topic-metadata">

**Author:** [@pushshift](https://discuss.elastic.co/u/pushshift)\
**Replies:** 2\
**Last updated:** [April 26, 2023, 5:04pm UTC](https://discuss.elastic.co/t/how-do-you-limit-how-long-a-search-query-will-run-for-or-how-much-resources-one-query-can-use/330858 "2023-04-26T17:04:53Z")

</div>

My Googlefu must not be strong. When using Elasticsearch 8.x, how does one limit how long a query runs or how many resources a query consumes. We're noticing possible denial of service attacks from certain people running…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=388)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=390)
