# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=354

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 355

---

## [Kafka integration plug v11.3.2 with AWS MSK 2.8.1](https://discuss.elastic.co/t/kafka-integration-plug-v11-3-2-with-aws-msk-2-8-1/348963)

<div class="topic-metadata">

**Author:** [@bbenne821](https://discuss.elastic.co/u/bbenne821)\
**Replies:** 2\
**Last updated:** [December 9, 2023, 6:38pm UTC](https://discuss.elastic.co/t/kafka-integration-plug-v11-3-2-with-aws-msk-2-8-1/348963 "2023-12-09T18:38:41Z")

</div>

We have a TLS-enabled AWS MSK (Managed Streaming Kafka) 2.8.1 cluster and using logstash kafka integration plug v11.3.2 to read from topics. Our input logstash pipeline: input { kafka { id =\> "sentinel\_one-…

---

## [Error: fail to enroll: fail to execute request to fleet-server: http: server gave HTTP response to HTTPS client](https://discuss.elastic.co/t/error-fail-to-enroll-fail-to-execute-request-to-fleet-server-http-server-gave-http-response-to-https-client/348678)

<div class="topic-metadata">

**Author:** [@Virtual\_Box](https://discuss.elastic.co/u/Virtual_Box)\
**Replies:** 3\
**Last updated:** [December 9, 2023, 6:47pm UTC](https://discuss.elastic.co/t/error-fail-to-enroll-fail-to-execute-request-to-fleet-server-http-server-gave-http-response-to-https-client/348678 "2023-12-09T18:47:56Z")

</div>

Hey there, I've tried to install elastic-agent on ubuntu host and get the next error: Enrolling Elastic Agent with Fleet...{"log.level":"warn","@timestamp":"2023-12-05T20:38:37.405Z","log.logger":"tls","log.origin":{"f…

---

## [Could you advise me on determining which version of JDK is embedded with Elasticsearch 7.17.14 on RHEL7 - OpenJDK 20 or 21?](https://discuss.elastic.co/t/could-you-advise-me-on-determining-which-version-of-jdk-is-embedded-with-elasticsearch-7-17-14-on-rhel7-openjdk-20-or-21/347294)

<div class="topic-metadata">

**Author:** [@Domnic\_Raj\_D](https://discuss.elastic.co/u/Domnic_Raj_D)\
**Replies:** 3\
**Last updated:** [December 9, 2023, 5:52pm UTC](https://discuss.elastic.co/t/could-you-advise-me-on-determining-which-version-of-jdk-is-embedded-with-elasticsearch-7-17-14-on-rhel7-openjdk-20-or-21/347294 "2023-12-09T17:52:37Z")

</div>

I have collected all breaking changes and deprecations of the ELK stack (Elasticsearch, Kibana, Logstash, Beats) for 7.9 to 7.17.14. Is there anything I need to focus on before moving to the upgrade plan? If you don't mi…

---

## [ILM policy implement for different enviornment](https://discuss.elastic.co/t/ilm-policy-implement-for-different-enviornment/347281)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 1\
**Last updated:** [December 9, 2023, 4:25pm UTC](https://discuss.elastic.co/t/ilm-policy-implement-for-different-enviornment/347281 "2023-12-09T16:25:35Z")

</div>

Hello All, I want to know better way to implement lifecycle policy for diff env like(DEV,QA,PROD). I have around 60 indices and lifecycle policy for different env would be different. ex: DEV-90 days, PROD -30 days and…

---

## [Elasticsearch Query DSL Filter Including Middle Occurrences](https://discuss.elastic.co/t/elasticsearch-query-dsl-filter-including-middle-occurrences/348143)

<div class="topic-metadata">

**Author:** [@Dokh\_Ahmed](https://discuss.elastic.co/u/Dokh_Ahmed)\
**Replies:** 1\
**Last updated:** [December 9, 2023, 4:18pm UTC](https://discuss.elastic.co/t/elasticsearch-query-dsl-filter-including-middle-occurrences/348143 "2023-12-09T16:18:18Z")

</div>

Hello I am facing an issue with Elastisearch Query DSL while using a prefix filter for the "log\_message" field. The goal is to display logs where the "log\_message" field has a prefix of "Started". However, the filter i…

---

## [Can't find "enableEsql" option on advanced settings](https://discuss.elastic.co/t/cant-find-enableesql-option-on-advanced-settings/348933)

<div class="topic-metadata">

**Author:** [@ton1uwu](https://discuss.elastic.co/u/ton1uwu)\
**Replies:** 1\
**Last updated:** [December 9, 2023, 3:50pm UTC](https://discuss.elastic.co/t/cant-find-enableesql-option-on-advanced-settings/348933 "2023-12-09T15:50:19Z")

</div>

Hello there guys, I have kibana 8.11.1 running, went to stack management and to advanced settings, I search for discover: or esql and the only option showing up is discover:enableSql, the option discover:enableESQL is n…

---

## [How to enable CORS in Kibana server](https://discuss.elastic.co/t/how-to-enable-cors-in-kibana-server/348703)

<div class="topic-metadata">

**Author:** [@Prakash\_Gupta](https://discuss.elastic.co/u/Prakash_Gupta)\
**Replies:** 4\
**Last updated:** [December 9, 2023, 3:49pm UTC](https://discuss.elastic.co/t/how-to-enable-cors-in-kibana-server/348703 "2023-12-09T15:49:18Z")

</div>

Hi, I am using Kibana dashboards as iframes under a web application. The problem is that the Kibana server is authenticated by SSO and there is no guarantee that the user's browser session is having a valid active sessi…

---

## [Index rollover due to policy does not copy mapping](https://discuss.elastic.co/t/index-rollover-due-to-policy-does-not-copy-mapping/348932)

<div class="topic-metadata">

**Author:** [@twilight](https://discuss.elastic.co/u/twilight)\
**Replies:** 15\
**Last updated:** [December 9, 2023, 3:18pm UTC](https://discuss.elastic.co/t/index-rollover-due-to-policy-does-not-copy-mapping/348932 "2023-12-09T15:18:39Z")

</div>

Hello, I have setup an index with a 'date' field in milliseconds (epoch\_millis), I did set this explicitly while creating the index. Then I attached a policy to rollover after x days. After x days, a new index is creat…

---

## [ELSER2 | Ingest - Cannot switch alias for sparse\_vector](https://discuss.elastic.co/t/elser2-ingest-cannot-switch-alias-for-sparse-vector/348948)

<div class="topic-metadata">

**Author:** [@Rakesh\_Nayak](https://discuss.elastic.co/u/Rakesh_Nayak)\
**Replies:** 2\
**Last updated:** [December 9, 2023, 1:13pm UTC](https://discuss.elastic.co/t/elser2-ingest-cannot-switch-alias-for-sparse-vector/348948 "2023-12-09T13:13:14Z")

</div>

Hello Team, We use elasticsearch-java client 8.1.3 to ingest the data and switch the alias. We are utilising the same logic with additional mapping and pipeline added for ingesting the data for Elser2. We observed that …

---

## [PHP-FPM (or nginx) isn't able to index to elasticsearch](https://discuss.elastic.co/t/php-fpm-or-nginx-isnt-able-to-index-to-elasticsearch/348938)

<div class="topic-metadata">

**Author:** [@Ahriss](https://discuss.elastic.co/u/Ahriss)\
**Replies:** 12\
**Last updated:** [December 9, 2023, 1:08pm UTC](https://discuss.elastic.co/t/php-fpm-or-nginx-isnt-able-to-index-to-elasticsearch/348938 "2023-12-09T13:08:27Z")

</div>

Hi, it's me again, and still having the same issue I was having in this topic: File not found when attempting to index . However, I have made some progress. I now know that when I attempt to, I get the following: 2023-1…

---

## [Fleet integration for Barracauda Firewall logs](https://discuss.elastic.co/t/fleet-integration-for-barracauda-firewall-logs/348882)

<div class="topic-metadata">

**Author:** [@maadhav](https://discuss.elastic.co/u/maadhav)\
**Replies:** 10\
**Last updated:** [December 9, 2023, 5:46am UTC](https://discuss.elastic.co/t/fleet-integration-for-barracauda-firewall-logs/348882 "2023-12-09T05:46:04Z")

</div>

Hi Team We have configured Fleet server and added Elastic Agents. Output is configured using Logstash. Agent policy is added which contains system integration, its working fine and sending logs to logstash output. When…

---

## [The following is the code for creating a user dictionary Kibana plugin. However, when executed, it cannot reference the module named 'files:Filesetup', resulting in an error with 'undefined'. Is there anything I might be missing in my plugin development?](https://discuss.elastic.co/t/the-following-is-the-code-for-creating-a-user-dictionary-kibana-plugin-however-when-executed-it-cannot-reference-the-module-named-files-filesetup-resulting-in-an-error-with-undefined-is-there-anything-i-might-be-missing-in-my-plugin-development/348845)

<div class="topic-metadata">

**Author:** [@choije](https://discuss.elastic.co/u/choije)\
**Replies:** 1\
**Last updated:** [December 9, 2023, 2:23am UTC](https://discuss.elastic.co/t/the-following-is-the-code-for-creating-a-user-dictionary-kibana-plugin-however-when-executed-it-cannot-reference-the-module-named-files-filesetup-resulting-in-an-error-with-undefined-is-there-anything-i-might-be-missing-in-my-plugin-development/348845 "2023-12-09T02:23:45Z")

</div>

The following is the code for creating a user dictionary Kibana plugin. However, when executed, it cannot reference the module named 'files:Filesetup', resulting in an error with 'undefined'. Is there anything I might be…

---

## [Logstash sflow plugin install by default](https://discuss.elastic.co/t/logstash-sflow-plugin-install-by-default/346670)

<div class="topic-metadata">

**Author:** [@VamPikmin](https://discuss.elastic.co/u/VamPikmin)\
**Replies:** 4\
**Last updated:** [December 9, 2023, 12:25am UTC](https://discuss.elastic.co/t/logstash-sflow-plugin-install-by-default/346670 "2023-12-09T00:25:59Z")

</div>

Hi all, Is it possible to turn on a setting so that with each new Elastic Stack upgrade this logstash plugin with install automatically. Currently I have to stop logstash, upgrade the stack and run /usr/share/logstash…

---

## [Using official nodejs elasticsearch npm package on AWS Lambda Docker container sets the Content-Type header to \[text/plain\]](https://discuss.elastic.co/t/using-official-nodejs-elasticsearch-npm-package-on-aws-lambda-docker-container-sets-the-content-type-header-to-text-plain/348766)

<div class="topic-metadata">

**Author:** [@asnyameeteen](https://discuss.elastic.co/u/asnyameeteen)\
**Replies:** 1\
**Last updated:** [December 8, 2023, 11:12pm UTC](https://discuss.elastic.co/t/using-official-nodejs-elasticsearch-npm-package-on-aws-lambda-docker-container-sets-the-content-type-header-to-text-plain/348766 "2023-12-08T23:12:43Z")

</div>

I am trying to publish a document to my self-hosted elasticsearch running on AWS. I wrote my code in nodejs, using v18 LTS, using @elastic/elasticsearch npm module version 8.10.0. When I run my code locally, outside of D…

---

## [Advance settings - Time filter quick ranges - Date math](https://discuss.elastic.co/t/advance-settings-time-filter-quick-ranges-date-math/348939)

<div class="topic-metadata">

**Author:** [@Amphagory](https://discuss.elastic.co/u/Amphagory)\
**Replies:** 3\
**Last updated:** [December 8, 2023, 9:50pm UTC](https://discuss.elastic.co/t/advance-settings-time-filter-quick-ranges-date-math/348939 "2023-12-08T21:50:15Z")

</div>

Hello, I'm try to create some custom time range filters. I would like to create two new ones named as follows: This Year - Time range is from the beginning of the current year to now. Last Year - Time range is from t…

---

## [filebeat-main.service: Failed with result 'resources'](https://discuss.elastic.co/t/filebeat-main-service-failed-with-result-resources/348944)

<div class="topic-metadata">

**Author:** [@Loka\_Sandeep\_Reddy](https://discuss.elastic.co/u/Loka_Sandeep_Reddy)\
**Replies:** 0\
**Last updated:** [December 8, 2023, 9:26pm UTC](https://discuss.elastic.co/t/filebeat-main-service-failed-with-result-resources/348944 "2023-12-08T21:26:24Z")

</div>

Hello, Here is my config OS: Amazon Linux 2023 filebeat: 6.5.4 Service is failing with the below reason, I am unable to figure out why, same config is working on Amazon Linux 2 filebeat-main.service - Filebeat sends…

---

## [How to show one entry per day](https://discuss.elastic.co/t/how-to-show-one-entry-per-day/348913)

<div class="topic-metadata">

**Author:** [@soad20000](https://discuss.elastic.co/u/soad20000)\
**Replies:** 10\
**Last updated:** [December 8, 2023, 9:06pm UTC](https://discuss.elastic.co/t/how-to-show-one-entry-per-day/348913 "2023-12-08T21:06:14Z")

</div>

Hello, I am on Elastic V8.10.4 and I have a dashboard for NTP that looks like this: I want it to show only one entry per day, instead of multiple per day like it currently does. How can I accomplish this?

---

## [Subtracting one value out of another and showing the percentage difference](https://discuss.elastic.co/t/subtracting-one-value-out-of-another-and-showing-the-percentage-difference/348926)

<div class="topic-metadata">

**Author:** [@Dor-Alter](https://discuss.elastic.co/u/Dor-Alter)\
**Replies:** 9\
**Last updated:** [December 8, 2023, 7:18pm UTC](https://discuss.elastic.co/t/subtracting-one-value-out-of-another-and-showing-the-percentage-difference/348926 "2023-12-08T19:18:22Z")

</div>

I am trying to get a pie dashboard of successful vs abendent processes out of my logs. My issue is that there is no way to filter the abendent processes. So what I can do is filter based on the values that are successf…

---

## [Removal of packages from the tar file due to vulnerability (log4j)](https://discuss.elastic.co/t/removal-of-packages-from-the-tar-file-due-to-vulnerability-log4j/348902)

<div class="topic-metadata">

**Author:** [@Vijeya\_Nidhi](https://discuss.elastic.co/u/Vijeya_Nidhi)\
**Replies:** 5\
**Last updated:** [December 8, 2023, 7:02pm UTC](https://discuss.elastic.co/t/removal-of-packages-from-the-tar-file-due-to-vulnerability-log4j/348902 "2023-12-08T19:02:19Z")

</div>

So we are deploying elasticsearch using docker file. it is the same steps followed in the official docker file linked below. We are trying to do a Version upgrade from 8.2.0 to 8.11.2 The problem is that the scans re…

---

## [Ruby script with dynamic variables in logstash](https://discuss.elastic.co/t/ruby-script-with-dynamic-variables-in-logstash/348870)

<div class="topic-metadata">

**Author:** [@Dor-Alter](https://discuss.elastic.co/u/Dor-Alter)\
**Replies:** 3\
**Last updated:** [December 8, 2023, 3:24pm UTC](https://discuss.elastic.co/t/ruby-script-with-dynamic-variables-in-logstash/348870 "2023-12-08T15:24:34Z")

</div>

Is it possible to have a dynamic variables in ruby that changes based on the input values I am getting from the inputfile? For example I have 5 input values which the attribute linked, if the value of link is 'connected…

---

## [Creating dynamic index name with Filebeat based on custom event field fails](https://discuss.elastic.co/t/creating-dynamic-index-name-with-filebeat-based-on-custom-event-field-fails/348835)

<div class="topic-metadata">

**Author:** [@allan.silverstein](https://discuss.elastic.co/u/allan.silverstein)\
**Replies:** 1\
**Last updated:** [December 8, 2023, 3:16pm UTC](https://discuss.elastic.co/t/creating-dynamic-index-name-with-filebeat-based-on-custom-event-field-fails/348835 "2023-12-08T15:16:59Z")

</div>

I'm trying to have filebeat create a dynamic index name based on a custom event field and it is not working. Can custom event fields be used in the index name? If I use a non custom event field everything works fine (e…

---

## [Elasticsearch NEST client 7.17 productivity investigation](https://discuss.elastic.co/t/elasticsearch-nest-client-7-17-productivity-investigation/347868)

<div class="topic-metadata">

**Author:** [@Vadym\_Romanenko](https://discuss.elastic.co/u/Vadym_Romanenko)\
**Replies:** 2\
**Last updated:** [December 8, 2023, 3:10pm UTC](https://discuss.elastic.co/t/elasticsearch-nest-client-7-17-productivity-investigation/347868 "2023-12-08T15:10:10Z")

</div>

Hi, Team! We created solution that generates documents and posts them to Elastic. After that users can search for data located in Elastic. Our solution is web app implemented with ASP.NET, c# on the backend. We use Elas…

---

## [Elasticsearch throws 503 Server Unavailable error](https://discuss.elastic.co/t/elasticsearch-throws-503-server-unavailable-error/348898)

<div class="topic-metadata">

**Author:** [@Kalidastate](https://discuss.elastic.co/u/Kalidastate)\
**Replies:** 1\
**Last updated:** [December 8, 2023, 2:37pm UTC](https://discuss.elastic.co/t/elasticsearch-throws-503-server-unavailable-error/348898 "2023-12-08T14:37:48Z")

</div>

I am facing one issue with the Elasticsearch in the production environment. Elasticsearch stops responding to the API calls and it needs to be restarted. Logs collected from Elasticsearch are as follows When the issue…

---

## [Elastic Agent causing VM connectivity issues](https://discuss.elastic.co/t/elastic-agent-causing-vm-connectivity-issues/348445)

<div class="topic-metadata">

**Author:** [@Jordan\_Altmann](https://discuss.elastic.co/u/Jordan_Altmann)\
**Replies:** 2\
**Last updated:** [December 8, 2023, 2:32pm UTC](https://discuss.elastic.co/t/elastic-agent-causing-vm-connectivity-issues/348445 "2023-12-08T14:32:51Z")

</div>

We've deployed the 8.11.0 elastic agents to windows and use both the system and windows integration to consume windows logs and host metrics. Since installing the agent, we've been having intermittent connectivity issue…

---

## [Elasticsearch upgrade](https://discuss.elastic.co/t/elasticsearch-upgrade/348815)

<div class="topic-metadata">

**Author:** [@Siva\_Karan](https://discuss.elastic.co/u/Siva_Karan)\
**Replies:** 3\
**Last updated:** [December 8, 2023, 2:02pm UTC](https://discuss.elastic.co/t/elasticsearch-upgrade/348815 "2023-12-08T14:02:46Z")

</div>

Hi Team, We are using the ES version as 7.3.2 for our environment. Now we are planning to upgrade our elasticsearch to 7.17.3. May i know is there any search speed or indexing speed will increase after upgrade?

---

## [Hi! i want to write dynamic query help me!](https://discuss.elastic.co/t/hi-i-want-to-write-dynamic-query-help-me/348895)

<div class="topic-metadata">

**Author:** [@slowup](https://discuss.elastic.co/u/slowup)\
**Replies:** 0\
**Last updated:** [December 8, 2023, 1:50pm UTC](https://discuss.elastic.co/t/hi-i-want-to-write-dynamic-query-help-me/348895 "2023-12-08T13:50:37Z")

</div>

hi! I want to create logic to create dynamic queries, for example ("a": "1" or "b": "2" and "h": "3") and ("d": "5" and "e": "6") When the above input comes in as a keyword, I want to make it into querydsl. Like Kiban…

---

## [Exec output plugin](https://discuss.elastic.co/t/exec-output-plugin/348869)

<div class="topic-metadata">

**Author:** [@Dor-Alter](https://discuss.elastic.co/u/Dor-Alter)\
**Replies:** 2\
**Last updated:** [December 8, 2023, 1:43pm UTC](https://discuss.elastic.co/t/exec-output-plugin/348869 "2023-12-08T13:43:32Z")

</div>

I am trying to create a pipeline that takes a csv file as input write it out to a different file and then run some bash script on the output file and create a new output file. Input\_file.csv -\> logstash -\> temp\_file -\> …

---

## [Search Not Applying Scores Properly - Ignoring Boosts](https://discuss.elastic.co/t/search-not-applying-scores-properly-ignoring-boosts/348097)

<div class="topic-metadata">

**Author:** [@mmobley](https://discuss.elastic.co/u/mmobley)\
**Replies:** 2\
**Last updated:** [December 8, 2023, 1:37pm UTC](https://discuss.elastic.co/t/search-not-applying-scores-properly-ignoring-boosts/348097 "2023-12-08T13:37:40Z")

</div>

I'm working on a complex query with multiple keyword fields that are weighted differently (one for category, one for brand, etc) but the query seems to be ignoring the boosts and scoring weird. Here's my query: Summary{…

---

## [How do rollover up index everyday on index lifeincycle](https://discuss.elastic.co/t/how-do-rollover-up-index-everyday-on-index-lifeincycle/348863)

<div class="topic-metadata">

**Author:** [@vanhaiit90](https://discuss.elastic.co/u/vanhaiit90)\
**Replies:** 1\
**Last updated:** [December 8, 2023, 1:27pm UTC](https://discuss.elastic.co/t/how-do-rollover-up-index-everyday-on-index-lifeincycle/348863 "2023-12-08T13:27:14Z")

</div>

Hi everyone! I have an elasticsearch index that needs to be rolled over every day, but after I configured it and observed the policy, it doesn't seem to work And Details are in the following picture: The problem…

---

## [Certificate renewal and Fleet](https://discuss.elastic.co/t/certificate-renewal-and-fleet/348828)

<div class="topic-metadata">

**Author:** [@slash24](https://discuss.elastic.co/u/slash24)\
**Replies:** 4\
**Last updated:** [December 8, 2023, 1:06pm UTC](https://discuss.elastic.co/t/certificate-renewal-and-fleet/348828 "2023-12-08T13:06:55Z")

</div>

My designated fleet-server (windows) has a internal Enterprise-certificate that is gonna expire soon. I know how to request the new CSR and issue the CER/PEM from my elastic -nodes, but I can't figure out where the Flee…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=353)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=355)
