# Top

**URL:** https://discuss.elastic.co/top.md?period=monthly

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

---

## [java.nio.file.NoSuchFileException: /usr/share/elasticsearch/data/\_state/\_pu2t.cfs](https://discuss.elastic.co/t/java-nio-file-nosuchfileexception-usr-share-elasticsearch-data-state-pu2t-cfs/390250)

<div class="topic-metadata">

**Author:** [@TheJ](https://discuss.elastic.co/u/TheJ)\
**Replies:** 15\
**Last updated:** [September 19, 2026, 6:07pm UTC](https://discuss.elastic.co/t/java-nio-file-nosuchfileexception-usr-share-elasticsearch-data-state-pu2t-cfs/390250 "2026-09-19T18:07:12Z")

</div>

Hi, I have a problem with one of my elasticsearch node. For some reason node was shutdown due to some error. When I look into the log, I get the error java.nio.file.NoSuchFileException: /usr/share/elasticsearch/data/\_st…

---

## [Forwarding detection alert status changes (acknowledged / closed) to an external system](https://discuss.elastic.co/t/forwarding-detection-alert-status-changes-acknowledged-closed-to-an-external-system/390784)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 2\
**Last updated:** [September 30, 2026, 6:17pm UTC](https://discuss.elastic.co/t/forwarding-detection-alert-status-changes-acknowledged-closed-to-an-external-system/390784 "2026-09-30T18:17:33Z")

</div>

Hello, We forward Elastic Security detection alerts to an external system through a Webhook connector configured as a rule action. That works well for new alerts. However, the receiving side also requires every subseque…

---

## [Elasticsearch 8.19.22, 9.4.7, 9.5.3 Security Update (ESA-2026-184)](https://discuss.elastic.co/t/elasticsearch-8-19-22-9-4-7-9-5-3-security-update-esa-2026-184/390688)

<div class="topic-metadata">

**Author:** [@kruskall](https://discuss.elastic.co/u/kruskall)\
**Replies:** 0\
**Last updated:** [September 25, 2026, 8:35am UTC](https://discuss.elastic.co/t/elasticsearch-8-19-22-9-4-7-9-5-3-security-update-esa-2026-184/390688 "2026-09-25T08:35:53Z")

</div>

Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130) Affected Vers…

---

## [POSTFIX Ingest and the future of Logstash](https://discuss.elastic.co/t/postfix-ingest-and-the-future-of-logstash/390279)

<div class="topic-metadata">

**Author:** [@RalphDibney](https://discuss.elastic.co/u/RalphDibney)\
**Replies:** 6\
**Last updated:** [September 16, 2026, 12:40pm UTC](https://discuss.elastic.co/t/postfix-ingest-and-the-future-of-logstash/390279 "2026-09-16T12:40:22Z")

</div>

We have a mail gateway based on Postfix, and we want to get these logs into Elastic. For our product, our MSP that helps us with it has a logstash based integration that is also merges the mutliline log of postfix to on…

---

## [Elasticsearch 8.19.21, 9.4.6, 9.5.3 Security Update (ESA-2026-170)](https://discuss.elastic.co/t/elasticsearch-8-19-21-9-4-6-9-5-3-security-update-esa-2026-170/390681)

<div class="topic-metadata">

**Author:** [@kruskall](https://discuss.elastic.co/u/kruskall)\
**Replies:** 0\
**Last updated:** [September 25, 2026, 8:33am UTC](https://discuss.elastic.co/t/elasticsearch-8-19-21-9-4-6-9-5-3-security-update-esa-2026-170/390681 "2026-09-25T08:33:09Z")

</div>

Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). Affected …

---

## [Elasticsearch 8.19.22, 9.4.7, 9.5.4 Security Update (ESA-2026-183)](https://discuss.elastic.co/t/elasticsearch-8-19-22-9-4-7-9-5-4-security-update-esa-2026-183/390687)

<div class="topic-metadata">

**Author:** [@kruskall](https://discuss.elastic.co/u/kruskall)\
**Replies:** 0\
**Last updated:** [September 25, 2026, 8:35am UTC](https://discuss.elastic.co/t/elasticsearch-8-19-22-9-4-7-9-5-4-security-update-esa-2026-183/390687 "2026-09-25T08:35:28Z")

</div>

Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130) Affected Vers…

---

## [Kibana 8.19.22, 9.4.6 Security Update (ESA-2026-103)](https://discuss.elastic.co/t/kibana-8-19-22-9-4-6-security-update-esa-2026-103/390679)

<div class="topic-metadata">

**Author:** [@kruskall](https://discuss.elastic.co/u/kruskall)\
**Replies:** 0\
**Last updated:** [September 25, 2026, 8:32am UTC](https://discuss.elastic.co/t/kibana-8-19-22-9-4-6-security-update-esa-2026-103/390679 "2026-09-25T08:32:22Z")

</div>

Authorization Bypass Through User-Controlled Key in Kibana Leading to Unauthorized Disclosure, Modification, and Deletion of Data Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthor…

---

## [Kibana 9.4.7, 9.5.0 Security Update (ESA-2026-85)](https://discuss.elastic.co/t/kibana-9-4-7-9-5-0-security-update-esa-2026-85/390678)

<div class="topic-metadata">

**Author:** [@kruskall](https://discuss.elastic.co/u/kruskall)\
**Replies:** 0\
**Last updated:** [September 25, 2026, 8:31am UTC](https://discuss.elastic.co/t/kibana-9-4-7-9-5-0-security-update-esa-2026-85/390678 "2026-09-25T08:31:59Z")

</div>

Unintended Proxy or Intermediary ('Confused Deputy') in Kibana Leading to Privilege Escalation Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana Agent Builder can lead to privilege escalation. A n…

---

## [Elasticsearch 8.19.22, 9.4.7, 9.5.4 Security Update (ESA-2026-176)](https://discuss.elastic.co/t/elasticsearch-8-19-22-9-4-7-9-5-4-security-update-esa-2026-176/390682)

<div class="topic-metadata">

**Author:** [@kruskall](https://discuss.elastic.co/u/kruskall)\
**Replies:** 0\
**Last updated:** [September 25, 2026, 8:33am UTC](https://discuss.elastic.co/t/elasticsearch-8-19-22-9-4-7-9-5-4-security-update-esa-2026-176/390682 "2026-09-25T08:33:33Z")

</div>

Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). Affected …

---

## [Elasticsearch 9.4.7, 9.5.4 Security Update (ESA-2026-182)](https://discuss.elastic.co/t/elasticsearch-9-4-7-9-5-4-security-update-esa-2026-182/390686)

<div class="topic-metadata">

**Author:** [@kruskall](https://discuss.elastic.co/u/kruskall)\
**Replies:** 0\
**Last updated:** [September 25, 2026, 8:35am UTC](https://discuss.elastic.co/t/elasticsearch-9-4-7-9-5-4-security-update-esa-2026-182/390686 "2026-09-25T08:35:05Z")

</div>

Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130) Affected Vers…

---

## [Elasticsearch 8.19.22, 9.4.7, 9.5.4 Security Update (ESA-2026-179)](https://discuss.elastic.co/t/elasticsearch-8-19-22-9-4-7-9-5-4-security-update-esa-2026-179/390683)

<div class="topic-metadata">

**Author:** [@kruskall](https://discuss.elastic.co/u/kruskall)\
**Replies:** 0\
**Last updated:** [September 25, 2026, 8:33am UTC](https://discuss.elastic.co/t/elasticsearch-8-19-22-9-4-7-9-5-4-security-update-esa-2026-179/390683 "2026-09-25T08:33:56Z")

</div>

Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130) Affected Vers…

---

## [Kibana 8.19.22, 9.4.7, 9.5.3 Security Update (ESA-2026-181)](https://discuss.elastic.co/t/kibana-8-19-22-9-4-7-9-5-3-security-update-esa-2026-181/390685)

<div class="topic-metadata">

**Author:** [@kruskall](https://discuss.elastic.co/u/kruskall)\
**Replies:** 0\
**Last updated:** [September 25, 2026, 8:34am UTC](https://discuss.elastic.co/t/kibana-8-19-22-9-4-7-9-5-3-security-update-esa-2026-181/390685 "2026-09-25T08:34:42Z")

</div>

Uncontrolled Resource Consumption in Kibana Leading to denial of service Uncontrolled Resource Consumption (CWE-400) in Kibana can lead denial of service via Excessive Allocation (CAPEC-130) Affected Versions: 8.x: A…

---

## [Elasticsearch 8.19.22, 9.4.7, 9.5.4 Security Update (ESA-2026-180)](https://discuss.elastic.co/t/elasticsearch-8-19-22-9-4-7-9-5-4-security-update-esa-2026-180/390684)

<div class="topic-metadata">

**Author:** [@kruskall](https://discuss.elastic.co/u/kruskall)\
**Replies:** 0\
**Last updated:** [September 25, 2026, 8:34am UTC](https://discuss.elastic.co/t/elasticsearch-8-19-22-9-4-7-9-5-4-security-update-esa-2026-180/390684 "2026-09-25T08:34:19Z")

</div>

Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130) Affected Vers…

---

## [Kibana 8.19.22, 9.4.7, 9.5.3 Security Update (ESA-2026-139)](https://discuss.elastic.co/t/kibana-8-19-22-9-4-7-9-5-3-security-update-esa-2026-139/390680)

<div class="topic-metadata">

**Author:** [@kruskall](https://discuss.elastic.co/u/kruskall)\
**Replies:** 0\
**Last updated:** [September 25, 2026, 8:32am UTC](https://discuss.elastic.co/t/kibana-8-19-22-9-4-7-9-5-3-security-update-esa-2026-139/390680 "2026-09-25T08:32:46Z")

</div>

Missing Authorization in Kibana Leading to Unauthorized Deletion of Data Missing Authorization (CWE-862) in Kibana can lead to unauthorized deletion of data via Exploiting Incorrectly Configured Access Control Security …

---

## [Elasticsearch 8.19.23, 9.4.8, 9.5.5 Security Update (ESA-2026-199)](https://discuss.elastic.co/t/elasticsearch-8-19-23-9-4-8-9-5-5-security-update-esa-2026-199/390874)

<div class="topic-metadata">

**Author:** [@cronosda](https://discuss.elastic.co/u/cronosda)\
**Replies:** 0\
**Last updated:** [October 6, 2026, 6:53pm UTC](https://discuss.elastic.co/t/elasticsearch-8-19-23-9-4-8-9-5-5-security-update-esa-2026-199/390874 "2026-10-06T18:53:22Z")

</div>

Authorization Bypass Through User-Controlled Key in Elasticsearch Leading to Information Disclosure Authorization Bypass Through User-Controlled Key (CWE-639) in Elasticsearch can lead to Information Disclosure via a sp…

---

## [External Inference using google vertex ai and gemini-3.6-flash error](https://discuss.elastic.co/t/external-inference-using-google-vertex-ai-and-gemini-3-6-flash-error/390296)

<div class="topic-metadata">

**Author:** [@tallakh](https://discuss.elastic.co/u/tallakh)\
**Replies:** 2\
**Last updated:** [September 11, 2026, 7:13am UTC](https://discuss.elastic.co/t/external-inference-using-google-vertex-ai-and-gemini-3-6-flash-error/390296 "2026-09-11T07:13:06Z")

</div>

Hi! I'm trying to set up an external inference using our Google vertex ai account and the model gemini-3.6-flash. The inference creation works, but trying to use it as a chat-completion fails with an error: Error: Rec…

---

## [Kibana 8.19.22, 9.4.7, 9.5.4 Security Update (ESA-2026-187)](https://discuss.elastic.co/t/kibana-8-19-22-9-4-7-9-5-4-security-update-esa-2026-187/390860)

<div class="topic-metadata">

**Author:** [@cronosda](https://discuss.elastic.co/u/cronosda)\
**Replies:** 0\
**Last updated:** [October 6, 2026, 6:36pm UTC](https://discuss.elastic.co/t/kibana-8-19-22-9-4-7-9-5-4-security-update-esa-2026-187/390860 "2026-10-06T18:36:48Z")

</div>

Authorization Bypass Through User-Controlled Key in Kibana Leading to Cross-Tenant Data Interception Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana could lead to cross-tenant data interception. In …

---

## [Upgrade from 7.17.9 to 8.19.18 to 9.4.3](https://discuss.elastic.co/t/upgrade-from-7-17-9-to-8-19-18-to-9-4-3/390473)

<div class="topic-metadata">

**Author:** [@sundar.s](https://discuss.elastic.co/u/sundar.s)\
**Replies:** 4\
**Last updated:** [September 17, 2026, 10:17am UTC](https://discuss.elastic.co/t/upgrade-from-7-17-9-to-8-19-18-to-9-4-3/390473 "2026-09-17T10:17:24Z")

</div>

Hi Team, I am trying to run upgrades on a dockerized ES environment. With indices created in 7.17.9, I am able to successfuly migrate to 8.19.18, by just bringing up a new container of ES 8.19.18 pointing to the same v…

---

## [Kibana 9.4.8, 9.5.5 Security Update (ESA-2026-193)](https://discuss.elastic.co/t/kibana-9-4-8-9-5-5-security-update-esa-2026-193/390866)

<div class="topic-metadata">

**Author:** [@cronosda](https://discuss.elastic.co/u/cronosda)\
**Replies:** 0\
**Last updated:** [October 6, 2026, 6:44pm UTC](https://discuss.elastic.co/t/kibana-9-4-8-9-5-5-security-update-esa-2026-193/390866 "2026-10-06T18:44:15Z")

</div>

Incorrect Authorization in Kibana Leading to Sensitive Information Disclosure Incorrect Authorization (CWE-863) in Kibana can lead to sensitive information disclosure via Accessing Functionality Not Properly Constrained…

---

## [New release of elastic-apm gem](https://discuss.elastic.co/t/new-release-of-elastic-apm-gem/390553)

<div class="topic-metadata">

**Author:** [@opiotrek](https://discuss.elastic.co/u/opiotrek)\
**Replies:** 2\
**Last updated:** [September 23, 2026, 5:56am UTC](https://discuss.elastic.co/t/new-release-of-elastic-apm-gem/390553 "2026-09-23T05:56:31Z")

</div>

Hello! The master branch contains an important fix that will unblock our upgrade to Ruby 4.0+. Can you release a new gem version?

---

## [Elasticsearch 8.19.22, 9.4.7, 9.5.4 Security Update (ESA-2026-197)](https://discuss.elastic.co/t/elasticsearch-8-19-22-9-4-7-9-5-4-security-update-esa-2026-197/390871)

<div class="topic-metadata">

**Author:** [@cronosda](https://discuss.elastic.co/u/cronosda)\
**Replies:** 0\
**Last updated:** [October 6, 2026, 6:51pm UTC](https://discuss.elastic.co/t/elasticsearch-8-19-22-9-4-7-9-5-4-security-update-esa-2026-197/390871 "2026-10-06T18:51:14Z")

</div>

Incorrect Authorization in Elasticsearch Leading to Privilege Escalation Incorrect Authorization (CWE-863) in Elasticsearch can lead to Privilege Escalation via a delegated administrative privilege whose scope is not fu…

---

## [Elasticsearch 8.19.23, 9.4.8, 9.5.5 Security Update (ESA-2026-198)](https://discuss.elastic.co/t/elasticsearch-8-19-23-9-4-8-9-5-5-security-update-esa-2026-198/390872)

<div class="topic-metadata">

**Author:** [@cronosda](https://discuss.elastic.co/u/cronosda)\
**Replies:** 0\
**Last updated:** [October 6, 2026, 6:52pm UTC](https://discuss.elastic.co/t/elasticsearch-8-19-23-9-4-8-9-5-5-security-update-esa-2026-198/390872 "2026-10-06T18:52:02Z")

</div>

Uncontrolled Recursion in Elasticsearch Leading to Denial of Service Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to Denial of Service via a specially crafted request that causes the server to construct an…

---

## [Elasticsearch 8.19.23, 9.4.8, 9.5.5 Security Update (ESA-2026-185)](https://discuss.elastic.co/t/elasticsearch-8-19-23-9-4-8-9-5-5-security-update-esa-2026-185/390859)

<div class="topic-metadata">

**Author:** [@cronosda](https://discuss.elastic.co/u/cronosda)\
**Replies:** 0\
**Last updated:** [October 6, 2026, 6:34pm UTC](https://discuss.elastic.co/t/elasticsearch-8-19-23-9-4-8-9-5-5-security-update-esa-2026-185/390859 "2026-10-06T18:34:52Z")

</div>

Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). A low-priv…

---

## [How do you verify that an eland-imported tree model matches the original?](https://discuss.elastic.co/t/how-do-you-verify-that-an-eland-imported-tree-model-matches-the-original/390787)

<div class="topic-metadata">

**Author:** [@Milivoje\_Simonovic](https://discuss.elastic.co/u/Milivoje_Simonovic)\
**Replies:** 1\
**Last updated:** [October 1, 2026, 1:34am UTC](https://discuss.elastic.co/t/how-do-you-verify-that-an-eland-imported-tree-model-matches-the-original/390787 "2026-10-01T01:34:37Z")

</div>

Hi, Laura Trotta at Elastic suggested I post this here. When eland imports an XGBoost, LightGBM or scikit-learn model into Elasticsearch, what Elasticsearch runs is a converted copy of the trained model. I am curious h…

---

## [Elasticsearch 8.19.23, 9.4.8, 9.5.5 Security Update (ESA-2026-195)](https://discuss.elastic.co/t/elasticsearch-8-19-23-9-4-8-9-5-5-security-update-esa-2026-195/390869)

<div class="topic-metadata">

**Author:** [@cronosda](https://discuss.elastic.co/u/cronosda)\
**Replies:** 0\
**Last updated:** [October 6, 2026, 6:49pm UTC](https://discuss.elastic.co/t/elasticsearch-8-19-23-9-4-8-9-5-5-security-update-esa-2026-195/390869 "2026-10-06T18:49:46Z")

</div>

Memory Allocation with Excessive Size Value in Elasticsearch Leading to Denial of Service Memory Allocation with Excessive Size Value (CWE-789) in Elasticsearch can lead to denial of service via Excessive Allocation (CA…

---

## [RFC: Disable automatic refresh in event analyzer](https://discuss.elastic.co/t/rfc-disable-automatic-refresh-in-event-analyzer/390600)

<div class="topic-metadata">

**Author:** [@michael-a](https://discuss.elastic.co/u/michael-a)\
**Replies:** 0\
**Last updated:** [September 23, 2026, 8:35am UTC](https://discuss.elastic.co/t/rfc-disable-automatic-refresh-in-event-analyzer/390600 "2026-09-23T08:35:03Z")

</div>

When analyzing events from detections/alerts with automatic refresh, the analyze view automatically refresh too which isn't necessarily what one wants. Therefore it would be better if the automatic refresh either would t…

---

## [Elastic Agent 9.3.7 CPU spikes](https://discuss.elastic.co/t/elastic-agent-9-3-7-cpu-spikes/390264)

<div class="topic-metadata">

**Author:** [@etrevino-lumificyber](https://discuss.elastic.co/u/etrevino-lumificyber)\
**Replies:** 1\
**Last updated:** [September 9, 2026, 1:36am UTC](https://discuss.elastic.co/t/elastic-agent-9-3-7-cpu-spikes/390264 "2026-09-09T01:36:06Z")

</div>

I mostly see the spiking when apps are being opened or occasionally while they are being used. I tested using standard apps like Outlook, Excel, Word, Chrome. Doing a search in Chrome for example caused a spike from 7% t…

---

## [Elasticsearch 8.19.22, 9.4.8, and 9.5.5 Security Update (ESA-2026-189)](https://discuss.elastic.co/t/elasticsearch-8-19-22-9-4-8-and-9-5-5-security-update-esa-2026-189/390862)

<div class="topic-metadata">

**Author:** [@cronosda](https://discuss.elastic.co/u/cronosda)\
**Replies:** 0\
**Last updated:** [October 6, 2026, 6:39pm UTC](https://discuss.elastic.co/t/elasticsearch-8-19-22-9-4-8-and-9-5-5-security-update-esa-2026-189/390862 "2026-10-06T18:39:39Z")

</div>

Inefficient Regular Expression Complexity in Elasticsearch Leading to Denial of Service Inefficient Regular Expression Complexity (CWE-1333) in Elasticsearch can lead to denial of service via Regular Expression Exponent…

---

## [Elasticsearch 8.19.21, 9.4.6, 9.5.2 Security Update (ESA-2026-196)](https://discuss.elastic.co/t/elasticsearch-8-19-21-9-4-6-9-5-2-security-update-esa-2026-196/390870)

<div class="topic-metadata">

**Author:** [@cronosda](https://discuss.elastic.co/u/cronosda)\
**Replies:** 0\
**Last updated:** [October 6, 2026, 6:50pm UTC](https://discuss.elastic.co/t/elasticsearch-8-19-21-9-4-6-9-5-2-security-update-esa-2026-196/390870 "2026-10-06T18:50:30Z")

</div>

Uncontrolled Recursion in Elasticsearch Leading to Denial of Service Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to Denial of Service via a specially crafted, deeply nested request submitted to the aggreg…

---

## [Elastic Agent / Endpoint 8.19.22, 9.4.8, and 9.5.5 Security Update (ESA-2026-194)](https://discuss.elastic.co/t/elastic-agent-endpoint-8-19-22-9-4-8-and-9-5-5-security-update-esa-2026-194/390868)

<div class="topic-metadata">

**Author:** [@cronosda](https://discuss.elastic.co/u/cronosda)\
**Replies:** 0\
**Last updated:** [October 6, 2026, 6:47pm UTC](https://discuss.elastic.co/t/elastic-agent-endpoint-8-19-22-9-4-8-and-9-5-5-security-update-esa-2026-194/390868 "2026-10-06T18:47:56Z")

</div>

Uncaught Exception in Elastic Endpoint Leading to Denial of Service Uncaught Exception (CWE-248) in Elastic Endpoint can lead to denial of service via a specially crafted file name. When Elastic Defend's Elastic Endpoin…

---

## [Elasticsearch 9.4.8, 9.5.5 Security Update (ESA-2026-190)](https://discuss.elastic.co/t/elasticsearch-9-4-8-9-5-5-security-update-esa-2026-190/390863)

<div class="topic-metadata">

**Author:** [@cronosda](https://discuss.elastic.co/u/cronosda)\
**Replies:** 0\
**Last updated:** [October 6, 2026, 6:41pm UTC](https://discuss.elastic.co/t/elasticsearch-9-4-8-9-5-5-security-update-esa-2026-190/390863 "2026-10-06T18:41:32Z")

</div>

Uncontrolled Recursion in Elasticsearch Leading to Denial of Service Uncontrolled Recursion (CWE-674) in Elasticsearch can allow an authenticated user with low privileges to terminate an Elasticsearch node, resulting in…

---

## [Upgrade adding new nodes of newer version instead of rolling upgrade](https://discuss.elastic.co/t/upgrade-adding-new-nodes-of-newer-version-instead-of-rolling-upgrade/390839)

<div class="topic-metadata">

**Author:** [@carlosmg1](https://discuss.elastic.co/u/carlosmg1)\
**Replies:** 6\
**Last updated:** [October 6, 2026, 11:04am UTC](https://discuss.elastic.co/t/upgrade-adding-new-nodes-of-newer-version-instead-of-rolling-upgrade/390839 "2026-10-06T11:04:28Z")

</div>

Hi, We've done plenty of upgrades of newer version in a cluster with around 40 nodes, upgrading 8.x version. For an upgrade from the 8.x to the 9.x we're analyzing how viable is to add new nodes during the upgrade of 9.…

---

## [Elasticsearch 9.4.7, 9.5.3, 8.19.23 Security Update (ESA-2026-192)](https://discuss.elastic.co/t/elasticsearch-9-4-7-9-5-3-8-19-23-security-update-esa-2026-192/390865)

<div class="topic-metadata">

**Author:** [@cronosda](https://discuss.elastic.co/u/cronosda)\
**Replies:** 0\
**Last updated:** [October 6, 2026, 6:43pm UTC](https://discuss.elastic.co/t/elasticsearch-9-4-7-9-5-3-8-19-23-security-update-esa-2026-192/390865 "2026-10-06T18:43:29Z")

</div>

Allocation of Resources Without Limits or Throttling in Elasticsearch Leading to Denial of Service Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to Denial of Service via Excess…

---

## [Elasticsearch 8.19.19, 9.3.8, 9.4.4 Security Update (ESA-2026-188)](https://discuss.elastic.co/t/elasticsearch-8-19-19-9-3-8-9-4-4-security-update-esa-2026-188/390861)

<div class="topic-metadata">

**Author:** [@cronosda](https://discuss.elastic.co/u/cronosda)\
**Replies:** 0\
**Last updated:** [October 6, 2026, 6:37pm UTC](https://discuss.elastic.co/t/elasticsearch-8-19-19-9-3-8-9-4-4-security-update-esa-2026-188/390861 "2026-10-06T18:37:40Z")

</div>

Incorrect Authorization in Elasticsearch Leading to Unauthorized Data Stream Modification Incorrect Authorization (CWE-863) in Elasticsearch can lead to unauthorized data stream modification via Accessing Functionality …

---

## [Kibana 9.4.0 Security Update (ESA-2026-191)](https://discuss.elastic.co/t/kibana-9-4-0-security-update-esa-2026-191/390864)

<div class="topic-metadata">

**Author:** [@cronosda](https://discuss.elastic.co/u/cronosda)\
**Replies:** 0\
**Last updated:** [October 6, 2026, 6:42pm UTC](https://discuss.elastic.co/t/kibana-9-4-0-security-update-esa-2026-191/390864 "2026-10-06T18:42:33Z")

</div>

Missing Authorization in Kibana Leading to Information Disclosure Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An i…

---

## [Time picker in ES|QL query - esql](https://discuss.elastic.co/t/time-picker-in-es-ql-query-esql/390631)

<div class="topic-metadata">

**Author:** [@dot-mike](https://discuss.elastic.co/u/dot-mike)\
**Replies:** 2\
**Last updated:** [September 25, 2026, 1:55pm UTC](https://discuss.elastic.co/t/time-picker-in-es-ql-query-esql/390631 "2026-09-25T13:55:30Z")

</div>

Hi community, I was wondering about a weird behaviour that might catch some people off-guard. How does the time picker affect ES|QL searches? For example the following query implies a 24-hour search, but yet the data d…

---

## [Elasticsearch Sometimes Returns Incomplete Search Results From My Website Even Though the Documents Are Indexed](https://discuss.elastic.co/t/elasticsearch-sometimes-returns-incomplete-search-results-from-my-website-even-though-the-documents-are-indexed/390803)

<div class="topic-metadata">

**Author:** [@joeroot](https://discuss.elastic.co/u/joeroot)\
**Replies:** 3\
**Last updated:** [October 5, 2026, 8:16am UTC](https://discuss.elastic.co/t/elasticsearch-sometimes-returns-incomplete-search-results-from-my-website-even-though-the-documents-are-indexed/390803 "2026-10-05T08:16:53Z")

</div>

Hi All, I am having an issue with Elasticsearch on my website where search requests sometimes return incomplete results even though the relevant documents are already present in the Elasticsearch index. The website uses…

---

## [License dection rules](https://discuss.elastic.co/t/license-dection-rules/390802)

<div class="topic-metadata">

**Author:** [@vas-vas777](https://discuss.elastic.co/u/vas-vas777)\
**Replies:** 1\
**Last updated:** [October 6, 2026, 3:53pm UTC](https://discuss.elastic.co/t/license-dection-rules/390802 "2026-10-06T15:53:00Z")

</div>

Hello, everyone! I develope my self-made EDR application. In this application I use YARA app from VirusTotal. In future. I will plan sell my software for third parties. Can I use your yara rules (protections-artifacts/ya…

---

## [Capture Elasticsearch diagnostics](https://discuss.elastic.co/t/capture-elasticsearch-diagnostics/390628)

<div class="topic-metadata">

**Author:** [@smm](https://discuss.elastic.co/u/smm)\
**Replies:** 2\
**Last updated:** [September 28, 2026, 7:19am UTC](https://discuss.elastic.co/t/capture-elasticsearch-diagnostics/390628 "2026-09-28T07:19:28Z")

</div>

Hi there, very soon I am going to purchase elastic licence. In a prior company I had also elastic licences and was used to use the Elasticsearch diagnostics script by the support to collect cluster health parameters. M…

---

## [Field formatters in ES|QL table panels](https://discuss.elastic.co/t/field-formatters-in-es-ql-table-panels/390418)

<div class="topic-metadata">

**Author:** [@tallakh](https://discuss.elastic.co/u/tallakh)\
**Replies:** 1\
**Last updated:** [September 23, 2026, 8:07am UTC](https://discuss.elastic.co/t/field-formatters-in-es-ql-table-panels/390418 "2026-09-23T08:07:19Z")

</div>

Hi! We have started to use ES|QL a lot in our Kibana dashboards, and I love the flexibility it brings! One of the few missing features compared to Lens table panels is to set formatting on a text/keyword field. F ex a l…

---

## [Filebeat postgresql log module produces timestamp fields that are not indexable when using ECS](https://discuss.elastic.co/t/filebeat-postgresql-log-module-produces-timestamp-fields-that-are-not-indexable-when-using-ecs/390640)

<div class="topic-metadata">

**Author:** [@kriller](https://discuss.elastic.co/u/kriller)\
**Replies:** 3\
**Last updated:** [September 29, 2026, 1:41pm UTC](https://discuss.elastic.co/t/filebeat-postgresql-log-module-produces-timestamp-fields-that-are-not-indexable-when-using-ecs/390640 "2026-09-29T13:41:32Z")

</div>

When using the ingest-pipeline that filebeat creates for postgresql logs, the resulting event contains the field postgresql.log.timestamp which conflicts with the ecs@mappings component template. The filebeat-9.5.4-post…

---

## [SAN required in cert?](https://discuss.elastic.co/t/san-required-in-cert/390541)

<div class="topic-metadata">

**Author:** [@rik](https://discuss.elastic.co/u/rik)\
**Replies:** 2\
**Last updated:** [September 20, 2026, 7:06pm UTC](https://discuss.elastic.co/t/san-required-in-cert/390541 "2026-09-20T19:06:49Z")

</div>

I am trying to use an ES service from a remote machine, using the cert copied from the container: podman cp app:/usr/share/elasticsearch/config/certs But simply doing a client.info() I am getting a elastic\_transport.Co…

---

## [Kibana 9 - Detail pane is a bad replacement for Expandable row for my use cases](https://discuss.elastic.co/t/kibana-9-detail-pane-is-a-bad-replacement-for-expandable-row-for-my-use-cases/390555)

<div class="topic-metadata">

**Author:** [@poifir](https://discuss.elastic.co/u/poifir)\
**Replies:** 3\
**Last updated:** [October 5, 2026, 8:57am UTC](https://discuss.elastic.co/t/kibana-9-detail-pane-is-a-bad-replacement-for-expandable-row-for-my-use-cases/390555 "2026-10-05T08:57:00Z")

</div>

In Kibana 8 we continued to use the "old" UI that offered to expand each row individually to show it's detail values. This works good as the full width of the windows is also available to the detailed attributes and so …

---

## [GC occurred in the Elasticsearch cluster](https://discuss.elastic.co/t/gc-occurred-in-the-elasticsearch-cluster/390606)

<div class="topic-metadata">

**Author:** [@Siva\_Karan](https://discuss.elastic.co/u/Siva_Karan)\
**Replies:** 1\
**Last updated:** [September 28, 2026, 12:00pm UTC](https://discuss.elastic.co/t/gc-occurred-in-the-elasticsearch-cluster/390606 "2026-09-28T12:00:23Z")

</div>

Hi Team, \[2026-09-22T22:20:13,448\]\[WARN \]\[o.e.m.j.JvmGcMonitorService\] \[node2\] \[gc\]\[435482\] overhead, spent \[4s\] collecting in the last \[4.6s\]. we are faced the GC issue with low heap usage and also we are unable to ac…

---

## [The impact of /etc/timezone on the ES cluster](https://discuss.elastic.co/t/the-impact-of-etc-timezone-on-the-es-cluster/390756)

<div class="topic-metadata">

**Author:** [@mloine](https://discuss.elastic.co/u/mloine)\
**Replies:** 1\
**Last updated:** [September 29, 2026, 12:25pm UTC](https://discuss.elastic.co/t/the-impact-of-etc-timezone-on-the-es-cluster/390756 "2026-09-29T12:25:39Z")

</div>

I'm facing a situation now: There are two batches of nodes in an ES cluster. One batch loads 'user.timezone=Asia/Bangkok' from etc/timezone at startup, while the other batch loads 'user.timezone=America/Bogota'. Even tho…

---

## [Elastic defend (Automatic Response Action Isnt Working )](https://discuss.elastic.co/t/elastic-defend-automatic-response-action-isnt-working/390597)

<div class="topic-metadata">

**Author:** [@jatin3101](https://discuss.elastic.co/u/jatin3101)\
**Replies:** 1\
**Last updated:** [September 25, 2026, 9:17am UTC](https://discuss.elastic.co/t/elastic-defend-automatic-response-action-isnt-working/390597 "2026-09-25T09:17:29Z")

</div>

Hi , i came across this problem that my response action arent working & somehad the same issue but their was solved and i dont undertsand how detection rule- firewall disabled issue- want to run a script for enablin…

---

## [Integration-level Outputs](https://discuss.elastic.co/t/integration-level-outputs/390582)

<div class="topic-metadata">

**Author:** [@jameswiggins](https://discuss.elastic.co/u/jameswiggins)\
**Replies:** 3\
**Last updated:** [September 22, 2026, 8:17pm UTC](https://discuss.elastic.co/t/integration-level-outputs/390582 "2026-09-22T20:17:35Z")

</div>

I'm trying to determine how to configure integration-level outputs: Set integration-level outputs | Elastic Docs I followed the instructions for configuring, but do not see the option. Can someone share a screenshot of…

---

## [Filebeat with Salesforce input and batch](https://discuss.elastic.co/t/filebeat-with-salesforce-input-and-batch/390433)

<div class="topic-metadata">

**Author:** [@stephaniearce](https://discuss.elastic.co/u/stephaniearce)\
**Replies:** 1\
**Last updated:** [September 16, 2026, 5:59pm UTC](https://discuss.elastic.co/t/filebeat-with-salesforce-input-and-batch/390433 "2026-09-16T17:59:51Z")

</div>

Can anyone explain why I'm running into this issue? I copied the exact config from the docs here: Salesforce input | Beats Salesforce input: object.batch.enabled: true fails with "map has no entry for key batch\_start\_ti…

---

## [Processing Heterogeneous IoT Logs with Fluent Bit and Elasticsearch Ingest Pipelines](https://discuss.elastic.co/t/processing-heterogeneous-iot-logs-with-fluent-bit-and-elasticsearch-ingest-pipelines/390311)

<div class="topic-metadata">

**Author:** [@cchaussat](https://discuss.elastic.co/u/cchaussat)\
**Replies:** 0\
**Last updated:** [September 10, 2026, 4:26pm UTC](https://discuss.elastic.co/t/processing-heterogeneous-iot-logs-with-fluent-bit-and-elasticsearch-ingest-pipelines/390311 "2026-09-10T16:26:18Z")

</div>

I would like to report on the experience of developing a simple home automation data collection and processing pipeline able to work with data and metrics from Domoticz and from many other various IoT devices and scripts…

---

## [Kibana Alert Email - URL broken in SMTP email notifications](https://discuss.elastic.co/t/kibana-alert-email-url-broken-in-smtp-email-notifications/390797)

<div class="topic-metadata">

**Author:** [@Omar2](https://discuss.elastic.co/u/Omar2)\
**Replies:** 2\
**Last updated:** [October 2, 2026, 7:56am UTC](https://discuss.elastic.co/t/kibana-alert-email-url-broken-in-smtp-email-notifications/390797 "2026-10-02T07:56:01Z")

</div>

Hello, I'm experiencing an issue with Kibana alert emails sent through an SMTP connector. Kibana version: 9.4.3 Alert message: La règle Kibana {{rule.name}} s'est déclenchée: Nombre d'erreurs : {{context.value}} …

[Next page](https://discuss.elastic.co/top.md?page=1&per_page=50&period=monthly)
