# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=393

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 394

---

## [Elastic Agent upgrade option is grayed out on Fleet Server](https://discuss.elastic.co/t/elastic-agent-upgrade-option-is-grayed-out-on-fleet-server/344753)

<div class="topic-metadata">

**Author:** [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Replies:** 5\
**Last updated:** [October 21, 2023, 7:25pm UTC](https://discuss.elastic.co/t/elastic-agent-upgrade-option-is-grayed-out-on-fleet-server/344753 "2023-10-21T19:25:49Z")

</div>

Hello, In the product compatibility support matrix page it says that Elasticsearch 8.10.X is compatible with Elastic Agent 7.17.x - 8.10.X, so I would expect the there is no incompatibility issues between patch versions…

---

## [Index with multiple replicas turned red when node with primary went down](https://discuss.elastic.co/t/index-with-multiple-replicas-turned-red-when-node-with-primary-went-down/345439)

<div class="topic-metadata">

**Author:** [@jaykb77](https://discuss.elastic.co/u/jaykb77)\
**Replies:** 10\
**Last updated:** [October 21, 2023, 6:46pm UTC](https://discuss.elastic.co/t/index-with-multiple-replicas-turned-red-when-node-with-primary-went-down/345439 "2023-10-21T18:46:33Z")

</div>

Hi all, I saw an unusual issue in our cluster where one of the indices configured with 1p:2r turned red when the node with primary shard went down. By the time I was checking the node was already back in cluster and the…

---

## [How to excute size function in script Plainess when I want access my field with type nested?](https://discuss.elastic.co/t/how-to-excute-size-function-in-script-plainess-when-i-want-access-my-field-with-type-nested/345429)

<div class="topic-metadata">

**Author:** [@duyhunter1001](https://discuss.elastic.co/u/duyhunter1001)\
**Replies:** 1\
**Last updated:** [October 21, 2023, 3:58pm UTC](https://discuss.elastic.co/t/how-to-excute-size-function-in-script-plainess-when-i-want-access-my-field-with-type-nested/345429 "2023-10-21T15:58:18Z")

</div>

Example, I have index following: PUT candidates { "mappings": { "language": { type: "nested" } } } POST candidates/\_doc { "firstname": "Mike", "age": 31, "city": "New York", "language":\[ { …

---

## [Does Spring Boot 3.1 require Elasticsearch 8?](https://discuss.elastic.co/t/does-spring-boot-3-1-require-elasticsearch-8/345335)

<div class="topic-metadata">

**Author:** [@Michal\_Stefaniuk](https://discuss.elastic.co/u/Michal_Stefaniuk)\
**Replies:** 7\
**Last updated:** [October 21, 2023, 3:31pm UTC](https://discuss.elastic.co/t/does-spring-boot-3-1-require-elasticsearch-8/345335 "2023-10-21T15:31:29Z")

</div>

Hey, quick question. We're working on an application that is currently using java 11, spring boot 2.7 and elasticsearch 7.17.10. We are migrating to java 17 and spring boot 3.1. Recently we stumbled upon a document tha…

---

## [Unable to segregate messages from two Input files](https://discuss.elastic.co/t/unable-to-segregate-messages-from-two-input-files/345492)

<div class="topic-metadata">

**Author:** [@Blason](https://discuss.elastic.co/u/Blason)\
**Replies:** 3\
**Last updated:** [October 21, 2023, 1:26pm UTC](https://discuss.elastic.co/t/unable-to-segregate-messages-from-two-input-files/345492 "2023-10-21T13:26:44Z")

</div>

Hi Team, I posted this message on stack but not getting any replies. Can someone please help? I need help in seggregrating messages from my two different conf files. I am bit confused about ingestion Here is my first f…

---

## [How do I stringify entire event object in logstash and put it in one field](https://discuss.elastic.co/t/how-do-i-stringify-entire-event-object-in-logstash-and-put-it-in-one-field/345496)

<div class="topic-metadata">

**Author:** [@ghanshyam\_baviskar](https://discuss.elastic.co/u/ghanshyam_baviskar)\
**Replies:** 4\
**Last updated:** [October 21, 2023, 1:24pm UTC](https://discuss.elastic.co/t/how-do-i-stringify-entire-event-object-in-logstash-and-put-it-in-one-field/345496 "2023-10-21T13:24:30Z")

</div>

I am trying to implement a dead letter queue pipeline, I want to take entire event , stringify it and put it into a field "strigified\_event". so that it can be monitored for elasticsearch mapper errors input { dead\_le…

---

## [Logstash failing to starting due to the error related to the "i18n" gem](https://discuss.elastic.co/t/logstash-failing-to-starting-due-to-the-error-related-to-the-i18n-gem/345341)

<div class="topic-metadata">

**Author:** [@akhilatham](https://discuss.elastic.co/u/akhilatham)\
**Replies:** 3\
**Last updated:** [October 21, 2023, 12:41am UTC](https://discuss.elastic.co/t/logstash-failing-to-starting-due-to-the-error-related-to-the-i18n-gem/345341 "2023-10-21T00:41:35Z")

</div>

I am getting the below error: \[2023-10-18T17:37:02,573\]\[FATAL\]\[logstash.runner\] An unexpected error occurred! {:error=\>#\<ArgumentError: wrong number of arguments (given 2, expected 0..1)\>, :backtrace=\>\["/usr/share/logst…

---

## [Splitting query returns](https://discuss.elastic.co/t/splitting-query-returns/345416)

<div class="topic-metadata">

**Author:** [@ken.s](https://discuss.elastic.co/u/ken.s)\
**Replies:** 0\
**Last updated:** [October 19, 2023, 7:09pm UTC](https://discuss.elastic.co/t/splitting-query-returns/345416 "2023-10-19T19:09:36Z")

</div>

Hi there. I'm working on returning multple query results based on an inner array. For instance, I have an object that looks like this: { "customer\_order\_number": "T391704031545", "aggregation\_date\_time": "2023-…

---

## [Web crawler and semantic search](https://discuss.elastic.co/t/web-crawler-and-semantic-search/345485)

<div class="topic-metadata">

**Author:** [@Michal\_Stoklasa](https://discuss.elastic.co/u/Michal_Stoklasa)\
**Replies:** 0\
**Last updated:** [October 20, 2023, 8:13pm UTC](https://discuss.elastic.co/t/web-crawler-and-semantic-search/345485 "2023-10-20T20:13:18Z")

</div>

Hi, im looking for web crawler connected to similarity search for my chatbot product. I have to be able to crawl website and then search similar parts based on query. Something like classic vector search with embedding…

---

## [Filebeat Grok pattern for access log](https://discuss.elastic.co/t/filebeat-grok-pattern-for-access-log/345455)

<div class="topic-metadata">

**Author:** [@tucker](https://discuss.elastic.co/u/tucker)\
**Replies:** 5\
**Last updated:** [October 20, 2023, 6:52pm UTC](https://discuss.elastic.co/t/filebeat-grok-pattern-for-access-log/345455 "2023-10-20T18:52:15Z")

</div>

Hi, I have an access log for which I am trying to write a Grok pattern but in the filebeat log, I always see "Provided Grok expressions do not match field value:". The log entries look like: \[20/Oct/2023:09:52:33 +000…

---

## [Output syslog plugin \[Unable to load plugin\]](https://discuss.elastic.co/t/output-syslog-plugin-unable-to-load-plugin/344676)

<div class="topic-metadata">

**Author:** [@ans\_k](https://discuss.elastic.co/u/ans_k)\
**Replies:** 5\
**Last updated:** [October 20, 2023, 6:17pm UTC](https://discuss.elastic.co/t/output-syslog-plugin-unable-to-load-plugin/344676 "2023-10-20T18:17:05Z")

</div>

Hello, I followed this documentation : to install offline output syslog plugin in my machine, the plugin is successfully installed, but when i try to call syslog as output in my config file (logstash), i got "Unable …

---

## [DELETE index command returns varying JSON objects](https://discuss.elastic.co/t/delete-index-command-returns-varying-json-objects/345410)

<div class="topic-metadata">

**Author:** [@mrodent](https://discuss.elastic.co/u/mrodent)\
**Replies:** 1\
**Last updated:** [October 20, 2023, 6:03pm UTC](https://discuss.elastic.co/t/delete-index-command-returns-varying-json-objects/345410 "2023-10-20T18:03:02Z")

</div>

(ES 8.6.2, W10) In Insomnia, when I try to delete an non-existent index, using command DELETE and url https://localhost:9500/my\_test\_index, I always seem to get a JSON object like this: { "error": { "root\_cause": \[ …

---

## [Background Count (bg\_count) Remains Zero in Nested and Filtered significant\_terms Aggregation](https://discuss.elastic.co/t/background-count-bg-count-remains-zero-in-nested-and-filtered-significant-terms-aggregation/345413)

<div class="topic-metadata">

**Author:** [@Emporea](https://discuss.elastic.co/u/Emporea)\
**Replies:** 2\
**Last updated:** [October 20, 2023, 3:38pm UTC](https://discuss.elastic.co/t/background-count-bg-count-remains-zero-in-nested-and-filtered-significant-terms-aggregation/345413 "2023-10-20T15:38:20Z")

</div>

Hi everyone, I've recently started using the significant\_terms aggregation with a nested field in my index, and I've noticed that the results are very similar to those of a standard terms aggregation. This leads me to b…

---

## [Installing Logstash plugin while service is running](https://discuss.elastic.co/t/installing-logstash-plugin-while-service-is-running/345469)

<div class="topic-metadata">

**Author:** [@Samuele\_Lolli](https://discuss.elastic.co/u/Samuele_Lolli)\
**Replies:** 2\
**Last updated:** [October 20, 2023, 2:34pm UTC](https://discuss.elastic.co/t/installing-logstash-plugin-while-service-is-running/345469 "2023-10-20T14:34:14Z")

</div>

Hi everyone, just one quick question. I have on a linux server logstash running with systemctl. I need to try some new pipelines but i need to add a plugin. I can add a new plugin while the service is running? The plug…

---

## [Cannot generate enrollment token](https://discuss.elastic.co/t/cannot-generate-enrollment-token/345465)

<div class="topic-metadata">

**Author:** [@Diego667](https://discuss.elastic.co/u/Diego667)\
**Replies:** 1\
**Last updated:** [October 20, 2023, 2:25pm UTC](https://discuss.elastic.co/t/cannot-generate-enrollment-token/345465 "2023-10-20T14:25:03Z")

</div>

Hello, I'm using ELK 8.10. I have a working cluster composed by : 1 master + data node 1 data node Security layer has been configured manually using those documentation : TLS/SSL HTTP I did not entered any …

---

## [Java API for terms](https://discuss.elastic.co/t/java-api-for-terms/345461)

<div class="topic-metadata">

**Author:** [@mfrob](https://discuss.elastic.co/u/mfrob)\
**Replies:** 2\
**Last updated:** [October 20, 2023, 1:34pm UTC](https://discuss.elastic.co/t/java-api-for-terms/345461 "2023-10-20T13:34:02Z")

</div>

Hi, I hope someone finds this. I am very new to elasticsearch. Currently I have this code snippet in my java file to search based on customer identification card (IC) number. I am able to fetch and search based off just…

---

## [Elastic APM server Elastic search connection not able to establish](https://discuss.elastic.co/t/elastic-apm-server-elastic-search-connection-not-able-to-establish/345459)

<div class="topic-metadata">

**Author:** [@Rajat\_Gupta1](https://discuss.elastic.co/u/Rajat_Gupta1)\
**Replies:** 0\
**Last updated:** [October 20, 2023, 12:34pm UTC](https://discuss.elastic.co/t/elastic-apm-server-elastic-search-connection-not-able-to-establish/345459 "2023-10-20T12:34:21Z")

</div>

Hi All need Some help with existing elastic stack.I have used official helm charts for deployment of the elastic stack I have apm-server Elastic Search and Kibana to be deployed When I try to get health of Elastics…

---

## [How to change or replace the SSL Certificate used by Fleet Server](https://discuss.elastic.co/t/how-to-change-or-replace-the-ssl-certificate-used-by-fleet-server/344930)

<div class="topic-metadata">

**Author:** [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Replies:** 6\
**Last updated:** [October 20, 2023, 12:06pm UTC](https://discuss.elastic.co/t/how-to-change-or-replace-the-ssl-certificate-used-by-fleet-server/344930 "2023-10-20T12:06:57Z")

</div>

Hello, I'm looking for the steps that need to be done to change or replace the SSL Certificate for a existing Fleet Server and I could not find anything in the documentation. All documentation that I found is about how…

---

## [Managing Real-time and Batch Processing in Elasticsearch to Prevent Document Resurrection](https://discuss.elastic.co/t/managing-real-time-and-batch-processing-in-elasticsearch-to-prevent-document-resurrection/345452)

<div class="topic-metadata">

**Author:** [@taichi](https://discuss.elastic.co/u/taichi)\
**Replies:** 0\
**Last updated:** [October 20, 2023, 10:17am UTC](https://discuss.elastic.co/t/managing-real-time-and-batch-processing-in-elasticsearch-to-prevent-document-resurrection/345452 "2023-10-20T10:17:41Z")

</div>

Hello, I'm facing a challenge and need your expertise. In our system, we have a real-time process that adds or removes documents in an Elasticsearch index based on changes in an RDBMS. Alongside, we also have a batch pr…

---

## [Cloudflare logpush to http elastic agent](https://discuss.elastic.co/t/cloudflare-logpush-to-http-elastic-agent/344383)

<div class="topic-metadata">

**Author:** [@gyterpena](https://discuss.elastic.co/u/gyterpena)\
**Replies:** 1\
**Last updated:** [October 20, 2023, 9:44am UTC](https://discuss.elastic.co/t/cloudflare-logpush-to-http-elastic-agent/344383 "2023-10-20T09:44:03Z")

</div>

Hello I'm trying to set up logpush integration with CF. I have set up elastic agent per documentation and I'm trying to enable logpush on CF by API but I'm getting {"errors":\[{"code":1002,"message":"error validatin…

---

## [After Spring boot upgrade to 3.0.6 cannot see trace of requests in Transaction section in Kibana](https://discuss.elastic.co/t/after-spring-boot-upgrade-to-3-0-6-cannot-see-trace-of-requests-in-transaction-section-in-kibana/345123)

<div class="topic-metadata">

**Author:** [@anthonyvks](https://discuss.elastic.co/u/anthonyvks)\
**Replies:** 2\
**Last updated:** [October 20, 2023, 8:51am UTC](https://discuss.elastic.co/t/after-spring-boot-upgrade-to-3-0-6-cannot-see-trace-of-requests-in-transaction-section-in-kibana/345123 "2023-10-20T08:51:41Z")

</div>

After Spring boot upgrade to 3.0.6 cannot see trace of requests in Transaction section in Kibana. Before upgrading the Java Spring boot application to 3.0.6 and upgrading the Java to 17, the traces of requests was seen …

---

## [Are comments supported in the synonyms file?](https://discuss.elastic.co/t/are-comments-supported-in-the-synonyms-file/345442)

<div class="topic-metadata">

**Author:** [@peterge1998](https://discuss.elastic.co/u/peterge1998)\
**Replies:** 1\
**Last updated:** [October 20, 2023, 8:08am UTC](https://discuss.elastic.co/t/are-comments-supported-in-the-synonyms-file/345442 "2023-10-20T08:08:32Z")

</div>

We set up a new way to deploy the synonyms file to our elasticsearch hosts in our company using gitlab ci cd and ansible. Now we would like to include a comment into the synonyms file, some this like "Ansible managed, ed…

---

## [Is Elastic	Winlogbeat MSI still beta version?](https://discuss.elastic.co/t/is-elastic-winlogbeat-msi-still-beta-version/345437)

<div class="topic-metadata">

**Author:** [@Metaad](https://discuss.elastic.co/u/Metaad)\
**Replies:** 1\
**Last updated:** [October 20, 2023, 7:01am UTC](https://discuss.elastic.co/t/is-elastic-winlogbeat-msi-still-beta-version/345437 "2023-10-20T07:01:15Z")

</div>

Am downloading ElasticWinlogbeat from Download Winlogbeat | Ship Windows Event Logs | Elastic | Elastic The name of the .msi shows beta. Can anyone please confirm if its still version or just the name itself is beta. A…

---

## [Deleting Events From Frozen Data Tier](https://discuss.elastic.co/t/deleting-events-from-frozen-data-tier/345395)

<div class="topic-metadata">

**Author:** [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Replies:** 3\
**Last updated:** [October 20, 2023, 6:50am UTC](https://discuss.elastic.co/t/deleting-events-from-frozen-data-tier/345395 "2023-10-20T06:50:17Z")

</div>

Attempting to delete by query events in a frozen data tier index belonging to a data stream. I've tried targeting the specific index the events are in as well as the datastream name, but I get the following error: { …

---

## [Elasticsearch is processing incoming events/messages from Logstash in a non-sequential order](https://discuss.elastic.co/t/elasticsearch-is-processing-incoming-events-messages-from-logstash-in-a-non-sequential-order/345295)

<div class="topic-metadata">

**Author:** [@Aman\_Yadav1](https://discuss.elastic.co/u/Aman_Yadav1)\
**Replies:** 3\
**Last updated:** [October 20, 2023, 6:44am UTC](https://discuss.elastic.co/t/elasticsearch-is-processing-incoming-events-messages-from-logstash-in-a-non-sequential-order/345295 "2023-10-20T06:44:27Z")

</div>

We have a system that synchronises data from MongoDB to Elasticsearch . Here are the key components: MongoDB Source Connector: This component reads events from the MongoDB oplog and produces messages on a Kafka topic. L…

---

## [Error json parsing opensearch logs with logstash](https://discuss.elastic.co/t/error-json-parsing-opensearch-logs-with-logstash/345398)

<div class="topic-metadata">

**Author:** [@Xhar](https://discuss.elastic.co/u/Xhar)\
**Replies:** 3\
**Last updated:** [October 20, 2023, 6:44am UTC](https://discuss.elastic.co/t/error-json-parsing-opensearch-logs-with-logstash/345398 "2023-10-20T06:44:21Z")

</div>

Hello, i'm trying to parse suricata, logstash and opensearch logs with dictionary filter, here's part of my config input { file { path =\> "/opt/logs/opensearchTest/opensearch\_server.json" codec =\> "json" t…

---

## [What happens if index.store.type set as niofs when create index and change to default](https://discuss.elastic.co/t/what-happens-if-index-store-type-set-as-niofs-when-create-index-and-change-to-default/345427)

<div class="topic-metadata">

**Author:** [@jonathanjxsq](https://discuss.elastic.co/u/jonathanjxsq)\
**Replies:** 0\
**Last updated:** [October 20, 2023, 3:23am UTC](https://discuss.elastic.co/t/what-happens-if-index-store-type-set-as-niofs-when-create-index-and-change-to-default/345427 "2023-10-20T03:23:07Z")

</div>

I created index with index.store type as niofs. if I change the config to default, which type the system is really running with? Based on my test, it seems the system changed from niofs to default. I saw performance ben…

---

## [Shard numbers no longer equal (not even close) among cluster nodes](https://discuss.elastic.co/t/shard-numbers-no-longer-equal-not-even-close-among-cluster-nodes/345342)

<div class="topic-metadata">

**Author:** [@Hao\_Yellow](https://discuss.elastic.co/u/Hao_Yellow)\
**Replies:** 6\
**Last updated:** [October 20, 2023, 1:58am UTC](https://discuss.elastic.co/t/shard-numbers-no-longer-equal-not-even-close-among-cluster-nodes/345342 "2023-10-20T01:58:34Z")

</div>

Hello, I've been recently upgraded an Elasticsearch cluster, with 5 nodes, from version 7.3 to 7.17 then 8.9. As always, I've never disabled shard allocation and rebalancing, so until 7.17 it's observed, and as I unders…

---

## [How can i increment cursor by one for each run in httpjson](https://discuss.elastic.co/t/how-can-i-increment-cursor-by-one-for-each-run-in-httpjson/345421)

<div class="topic-metadata">

**Author:** [@German\_Bravo](https://discuss.elastic.co/u/German_Bravo)\
**Replies:** 0\
**Last updated:** [October 19, 2023, 10:16pm UTC](https://discuss.elastic.co/t/how-can-i-increment-cursor-by-one-for-each-run-in-httpjson/345421 "2023-10-19T22:16:54Z")

</div>

Hi im using the httpjson input module in filebeat and im trying to achieve the following without any luck In words: I need to fetch an API every 10s In the first run i need to set query param page = 0 In the following…

---

## [Sysmon/Sysmon64 not visible in metricbeats for sysmon version 15](https://discuss.elastic.co/t/sysmon-sysmon64-not-visible-in-metricbeats-for-sysmon-version-15/345308)

<div class="topic-metadata">

**Author:** [@shani\_angarkadu](https://discuss.elastic.co/u/shani_angarkadu)\
**Replies:** 5\
**Last updated:** [October 19, 2023, 8:29pm UTC](https://discuss.elastic.co/t/sysmon-sysmon64-not-visible-in-metricbeats-for-sysmon-version-15/345308 "2023-10-19T20:29:36Z")

</div>

Hi there, We are using the system module and metricsets process. I can see all the other CPU/memory metrics except the Sysmon. Sysmon is completely missing in the output. Here is my system.yml - module: system per…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=392)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=394)
