# Top

**URL:** https://discuss.elastic.co/top.md?page=1&period=monthly

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 2

---

## [Elastic siem and EDR architecture validation](https://discuss.elastic.co/t/elastic-siem-and-edr-architecture-validation/390884)

<div class="topic-metadata">

**Author:** [@chandrakt](https://discuss.elastic.co/u/chandrakt)\
**Replies:** 3\
**Last updated:** [October 7, 2026, 11:29am UTC](https://discuss.elastic.co/t/elastic-siem-and-edr-architecture-validation/390884 "2026-10-07T11:29:44Z")

</div>

please let me know isthis correct diagram for 50gb par day dat ingestion and i need DC and DR both

---

## [Kibana error](https://discuss.elastic.co/t/kibana-error/390521)

<div class="topic-metadata">

**Author:** [@vanhung0709](https://discuss.elastic.co/u/vanhung0709)\
**Replies:** 1\
**Last updated:** [September 18, 2026, 4:17am UTC](https://discuss.elastic.co/t/kibana-error/390521 "2026-09-18T04:17:51Z")

</div>

I have set up elasticsearch and kibana. All steps have been done. Although i can curl es from kibana pod, kibana doesn’t put request to create index .kibana. When searching logs in pod kibana, it loop curl get nodes, but…

---

## [Elasticsearch Netflow Top-N dashboard showing data in bytes instead of MB.GB etc](https://discuss.elastic.co/t/elasticsearch-netflow-top-n-dashboard-showing-data-in-bytes-instead-of-mb-gb-etc/390772)

<div class="topic-metadata">

**Author:** [@ahsan0331](https://discuss.elastic.co/u/ahsan0331)\
**Replies:** 2\
**Last updated:** [October 2, 2026, 7:59am UTC](https://discuss.elastic.co/t/elasticsearch-netflow-top-n-dashboard-showing-data-in-bytes-instead-of-mb-gb-etc/390772 "2026-10-02T07:59:56Z")

</div>

Hi i have upgraded "or so to speak" from filebeat netflow module to elastic netflow fleet based. And while i see its dashboards are somewhat good compared to the filebeat ones. but one dashboard that i used a lot in fil…

---

## [Kibana 9.5.4 / Node 24 V8Worker triggers Linux kernel NULL pointer dereference and RCU stall](https://discuss.elastic.co/t/kibana-9-5-4-node-24-v8worker-triggers-linux-kernel-null-pointer-dereference-and-rcu-stall/390830)

<div class="topic-metadata">

**Author:** [@Beta](https://discuss.elastic.co/u/Beta)\
**Replies:** 1\
**Last updated:** [October 5, 2026, 1:28pm UTC](https://discuss.elastic.co/t/kibana-9-5-4-node-24-v8worker-triggers-linux-kernel-null-pointer-dereference-and-rcu-stall/390830 "2026-10-05T13:28:48Z")

</div>

I'm experiencing a recurring kernel crash on a Debian 13 VM running Kibana 9.5.4 (I have had this issue for a while now and have upgraded Kibana and the Linux kernel multiple times). The crash occurs in the Linux kernel …

---

## [Missing Export button for custom role despite enabling "Generate PDF or PNG report" privilege (v8.19.11)](https://discuss.elastic.co/t/missing-export-button-for-custom-role-despite-enabling-generate-pdf-or-png-report-privilege-v8-19-11/390775)

<div class="topic-metadata">

**Author:** [@WANASANAN815](https://discuss.elastic.co/u/WANASANAN815)\
**Replies:** 1\
**Last updated:** [October 1, 2026, 12:02am UTC](https://discuss.elastic.co/t/missing-export-button-for-custom-role-despite-enabling-generate-pdf-or-png-report-privilege-v8-19-11/390775 "2026-10-01T00:02:38Z")

</div>

Hi everyone, I’m currently having an issue creating a custom role in Elastic SIEM. I am trying to create a role that allows users to export dashboards as PDFs. Environment: Elastic Version: 8.19.11 License: Enter…

---

## [Logstash at Tenant end or server end?](https://discuss.elastic.co/t/logstash-at-tenant-end-or-server-end/390608)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 1\
**Last updated:** [September 25, 2026, 10:59pm UTC](https://discuss.elastic.co/t/logstash-at-tenant-end-or-server-end/390608 "2026-09-25T22:59:52Z")

</div>

I’m trying to design an architecture where multiple tenants ingest their logs into Elastic. My understanding is that if the requirement is primarily log collection, I can use Elastic Agent, and if additional enrichment,…

---

## [Kibana 8.17.3 – Malware Detection of security\_labs Knowledge Base File (TROJ\_FRS.VSNTIA26)](https://discuss.elastic.co/t/kibana-8-17-3-malware-detection-of-security-labs-knowledge-base-file-troj-frs-vsntia26/390482)

<div class="topic-metadata">

**Author:** [@shiva3](https://discuss.elastic.co/u/shiva3)\
**Replies:** 0\
**Last updated:** [September 16, 2026, 10:21pm UTC](https://discuss.elastic.co/t/kibana-8-17-3-malware-detection-of-security-labs-knowledge-base-file-troj-frs-vsntia26/390482 "2026-09-16T22:21:06Z")

</div>

Hello Elastic Team, We are investigating a security alert involving the Kibana 8.17.3 Docker image deployed in our OpenShift environment. Our endpoint security product detected the following file as: Detection: TROJ\_F…

---

## [Missing Export button for custom role despite enabling "Generate PDF or PNG report" privilege (v8.19.11)](https://discuss.elastic.co/t/missing-export-button-for-custom-role-despite-enabling-generate-pdf-or-png-report-privilege-v8-19-11/390774)

<div class="topic-metadata">

**Author:** [@WANASANAN815](https://discuss.elastic.co/u/WANASANAN815)\
**Replies:** 1\
**Last updated:** [September 30, 2026, 2:25pm UTC](https://discuss.elastic.co/t/missing-export-button-for-custom-role-despite-enabling-generate-pdf-or-png-report-privilege-v8-19-11/390774 "2026-09-30T14:25:19Z")

</div>

Hi everyone, I’m currently having an issue creating a custom role in Elastic SIEM. I am trying to create a role that allows users to export dashboards as PDFs. Environment: Elastic Version: 8.19.11 License: Enter…

---

## [False Positive](https://discuss.elastic.co/t/false-positive/390842)

<div class="topic-metadata">

**Author:** [@JasperHedge](https://discuss.elastic.co/u/JasperHedge)\
**Replies:** 0\
**Last updated:** [October 5, 2026, 1:15pm UTC](https://discuss.elastic.co/t/false-positive/390842 "2026-10-05T13:15:41Z")

</div>

Hi there, I know I should report false positives through the form. And I did, but nothing happened. No response and it still keeps flagging as malicious. We've got it with almost all our software, somehow. And we don't …

---

## [ILM unable to delete old index since upgrade to 8.19.20](https://discuss.elastic.co/t/ilm-unable-to-delete-old-index-since-upgrade-to-8-19-20/390601)

<div class="topic-metadata">

**Author:** [@numpty-boy](https://discuss.elastic.co/u/numpty-boy)\
**Replies:** 0\
**Last updated:** [September 23, 2026, 8:58am UTC](https://discuss.elastic.co/t/ilm-unable-to-delete-old-index-since-upgrade-to-8-19-20/390601 "2026-09-23T08:58:47Z")

</div>

Morning Team, Since upgrading to 8.19.20, I've started getting these errors: policy \[.fleet-actions-results-ilm-policy\] for index \[.ds-.fleet-actions-results-2026.05.02-000014\] on an error step due to a transient error…

---

## [Downsampling non-dimension labels to last value is misleading](https://discuss.elastic.co/t/downsampling-non-dimension-labels-to-last-value-is-misleading/390779)

<div class="topic-metadata">

**Author:** [@pmcc](https://discuss.elastic.co/u/pmcc)\
**Replies:** 0\
**Last updated:** [September 30, 2026, 11:36am UTC](https://discuss.elastic.co/t/downsampling-non-dimension-labels-to-last-value-is-misleading/390779 "2026-09-30T11:36:22Z")

</div>

I'm upgrading from v7 to 9.5 - lots of great new features! For my application, TSDS look ideal, and downsampling will be a major improvement. There appears to be one flaw with downsampling for my use cases. Keyword fiel…

---

## [Filebeat performance, 430 containers](https://discuss.elastic.co/t/filebeat-performance-430-containers/390622)

<div class="topic-metadata">

**Author:** [@zerkms](https://discuss.elastic.co/u/zerkms)\
**Replies:** 0\
**Last updated:** [September 24, 2026, 5:18am UTC](https://discuss.elastic.co/t/filebeat-performance-430-containers/390622 "2026-09-24T05:18:13Z")

</div>

I'm migrating from quite an old ES+fluentbit configuration (logging solution for a small kubernetes cluster). And this is quite simple yet inefficient (?) config I came up with (this file is generated by ECK using the B…

---

## [Support for metrics for kafka consumer group using new Consumer Rebalance Protocol](https://discuss.elastic.co/t/support-for-metrics-for-kafka-consumer-group-using-new-consumer-rebalance-protocol/390766)

<div class="topic-metadata">

**Author:** [@rakesh.iitism95](https://discuss.elastic.co/u/rakesh.iitism95)\
**Replies:** 0\
**Last updated:** [September 29, 2026, 8:29pm UTC](https://discuss.elastic.co/t/support-for-metrics-for-kafka-consumer-group-using-new-consumer-rebalance-protocol/390766 "2026-09-29T20:29:36Z")

</div>

We are currently using elastic agent to collect kafka consumer group metric. After a consumer group was configured to use the new consumer rebalance protocol available in Kafka 4.0 , the agent was not collecting the metr…

---

## [Integration with omega-scan](https://discuss.elastic.co/t/integration-with-omega-scan/390677)

<div class="topic-metadata">

**Author:** [@wessorh](https://discuss.elastic.co/u/wessorh)\
**Replies:** 0\
**Last updated:** [September 25, 2026, 8:07am UTC](https://discuss.elastic.co/t/integration-with-omega-scan/390677 "2026-09-25T08:07:24Z")

</div>

I'm interested in testing a opensource sample scanner called omega-scan and am looking for documentation on what capabilities there are for calling 3rd party file scanners. A pointer would be greatly appreciated.

---

## [Why is the operator run as a statefulset?](https://discuss.elastic.co/t/why-is-the-operator-run-as-a-statefulset/390605)

<div class="topic-metadata">

**Author:** [@Frederic\_PEGE](https://discuss.elastic.co/u/Frederic_PEGE)\
**Replies:** 0\
**Last updated:** [September 23, 2026, 11:37am UTC](https://discuss.elastic.co/t/why-is-the-operator-run-as-a-statefulset/390605 "2026-09-23T11:37:14Z")

</div>

Hi, Why is the operator run as a STS ? I'm talking about the ES cluster, but the actual operator ?

---

## [Kibana 9 - Detail dialog also shows "Truncated string" as configured for the overview](https://discuss.elastic.co/t/kibana-9-detail-dialog-also-shows-truncated-string-as-configured-for-the-overview/390551)

<div class="topic-metadata">

**Author:** [@poifir](https://discuss.elastic.co/u/poifir)\
**Replies:** 0\
**Last updated:** [September 21, 2026, 11:49am UTC](https://discuss.elastic.co/t/kibana-9-detail-dialog-also-shows-truncated-string-as-configured-for-the-overview/390551 "2026-09-21T11:49:22Z")

</div>

In the new Kibana 9 UI it's possible to customize the column visualization with "Edit data view field". This allows to e.g. enable to truncate a field to the first x characters so it only needs a reasonable size i…

---

## [Best way to analyze secure document activity logs in Elasticsearch?](https://discuss.elastic.co/t/best-way-to-analyze-secure-document-activity-logs-in-elasticsearch/390834)

<div class="topic-metadata">

**Author:** [@George4](https://discuss.elastic.co/u/George4)\
**Replies:** 0\
**Last updated:** [October 5, 2026, 8:14am UTC](https://discuss.elastic.co/t/best-way-to-analyze-secure-document-activity-logs-in-elasticsearch/390834 "2026-10-05T08:14:44Z")

</div>

I’m exploring how to structure document activity data in Elasticsearch for a secure document-sharing / virtual data room workflow. One of the platforms I’m looking at is SendNow. The activity data includes document ope…

---

## [Elastic Connectors Is Not Connecting to Elasticsearch with SSL](https://discuss.elastic.co/t/elastic-connectors-is-not-connecting-to-elasticsearch-with-ssl/390845)

<div class="topic-metadata">

**Author:** [@jsingleton71](https://discuss.elastic.co/u/jsingleton71)\
**Replies:** 0\
**Last updated:** [October 5, 2026, 4:25pm UTC](https://discuss.elastic.co/t/elastic-connectors-is-not-connecting-to-elasticsearch-with-ssl/390845 "2026-10-05T16:25:00Z")

</div>

Hey everyone, I have a standard ELK deployment on a single VM. I am trying to setup and configure the Elastic Connectors as described here: Content connectors | Elasticsearch Reference I am hitting an issue where the i…

---

## [Architecture Desing CCR](https://discuss.elastic.co/t/architecture-desing-ccr/390890)

<div class="topic-metadata">

**Author:** [@chandrakt](https://discuss.elastic.co/u/chandrakt)\
**Replies:** 5\
**Last updated:** [October 7, 2026, 7:48pm UTC](https://discuss.elastic.co/t/architecture-desing-ccr/390890 "2026-10-07T19:48:14Z")

</div>

Dear Team, We are planning to implement an on-premises Elastic SIEM/EDR solution for an OT/IT security environment comprising approximately 60 endpoints and an estimated daily log ingestion volume of 50 GB/day. Before …

[Previous page](https://discuss.elastic.co/top.md?per_page=50&period=monthly)
