# Latest

**URL:** https://discuss.elastic.co/latest.md?page=391

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 392

---

## [Elasticsearch in Windows with gMSA](https://discuss.elastic.co/t/elasticsearch-in-windows-with-gmsa/353990)

<div class="topic-metadata">

**Author:** [@Palla](https://discuss.elastic.co/u/Palla)\
**Replies:** 0\
**Last updated:** [February 23, 2024, 1:34pm UTC](https://discuss.elastic.co/t/elasticsearch-in-windows-with-gmsa/353990 "2024-02-23T13:34:23Z")

</div>

Hi all, I have a quick question: is it possible to use Elasticsearch in Windows with a service account gMSA? I'm not sure if it needs a Local System account. Thanks.

---

## [How can I increase maximum allowed value of "max\_matches" option for enrich processor](https://discuss.elastic.co/t/how-can-i-increase-maximum-allowed-value-of-max-matches-option-for-enrich-processor/353985)

<div class="topic-metadata">

**Author:** [@pataposha](https://discuss.elastic.co/u/pataposha)\
**Replies:** 0\
**Last updated:** [February 23, 2024, 12:57pm UTC](https://discuss.elastic.co/t/how-can-i-increase-maximum-allowed-value-of-max-matches-option-for-enrich-processor/353985 "2024-02-23T12:57:40Z")

</div>

I use enrich pipeline for matching docs from "source" index to "destination" index. For my data there are "many" docs from "source" index matched into "single" doc from "destination" index. Often, number of "source" docs…

---

## [Ingest data from a relational database - STDOUT Duplicates](https://discuss.elastic.co/t/ingest-data-from-a-relational-database-stdout-duplicates/353984)

<div class="topic-metadata">

**Author:** [@MaikLinnemann](https://discuss.elastic.co/u/MaikLinnemann)\
**Replies:** 0\
**Last updated:** [February 23, 2024, 12:50pm UTC](https://discuss.elastic.co/t/ingest-data-from-a-relational-database-stdout-duplicates/353984 "2024-02-23T12:50:29Z")

</div>

Dear all, when i follow the article to ingest data from a relational database (MSSQL), which is that one: Klick and i stdout the results to console, i receive duplicates. Exactly i use: stdout { codec =\> json } for th…

---

## [Is it possible to modify Managed Pipelines, Component Templates, and Index Templates?](https://discuss.elastic.co/t/is-it-possible-to-modify-managed-pipelines-component-templates-and-index-templates/353901)

<div class="topic-metadata">

**Author:** [@fredyfredburger1](https://discuss.elastic.co/u/fredyfredburger1)\
**Replies:** 17\
**Last updated:** [February 23, 2024, 12:40pm UTC](https://discuss.elastic.co/t/is-it-possible-to-modify-managed-pipelines-component-templates-and-index-templates/353901 "2024-02-23T12:40:44Z")

</div>

Good morning. I'm on a project using OpenTelementry to collect system health and status metrics for servers, and we are integrated with Elasticsearch through APM. There is a field we are setting in the data which I nee…

---

## [C# - Auto instrumentation of Confluent Kafka](https://discuss.elastic.co/t/c-auto-instrumentation-of-confluent-kafka/353979)

<div class="topic-metadata">

**Author:** [@Premysl\_Capek](https://discuss.elastic.co/u/Premysl_Capek)\
**Replies:** 2\
**Last updated:** [February 23, 2024, 12:00pm UTC](https://discuss.elastic.co/t/c-auto-instrumentation-of-confluent-kafka/353979 "2024-02-23T12:00:29Z")

</div>

Hello, is possible enable auto instrumentation of Confluent Kafka for versions 2.x. Actual version is 2.3.0.

---

## [Loading data from elasticsearch to hadoop](https://discuss.elastic.co/t/loading-data-from-elasticsearch-to-hadoop/353817)

<div class="topic-metadata">

**Author:** [@Hussain\_Sain](https://discuss.elastic.co/u/Hussain_Sain)\
**Replies:** 2\
**Last updated:** [February 23, 2024, 11:48am UTC](https://discuss.elastic.co/t/loading-data-from-elasticsearch-to-hadoop/353817 "2024-02-23T11:48:36Z")

</div>

Hi, we are using Elasticsearch 7.6.1 and CDH 6.2. we need to get data from elasticsearch to hive in CSV format but we dont know the way. any document which i go through have steps for loading data from hive to elaticse…

---

## [Get dataset into Elastic](https://discuss.elastic.co/t/get-dataset-into-elastic/353710)

<div class="topic-metadata">

**Author:** [@CD9820](https://discuss.elastic.co/u/CD9820)\
**Replies:** 4\
**Last updated:** [February 23, 2024, 11:43am UTC](https://discuss.elastic.co/t/get-dataset-into-elastic/353710 "2024-02-23T11:43:26Z")

</div>

Hello, I developed a script that gathers information from a range of physical servers (hardware health state, firmware versions, security settings, ...). The gathered dataset is written to a json file. As a test I 've …

---

## [Unrecognized signal name: "\_source" when using calculate in Vega-Lite](https://discuss.elastic.co/t/unrecognized-signal-name-source-when-using-calculate-in-vega-lite/353976)

<div class="topic-metadata">

**Author:** [@robertomzc](https://discuss.elastic.co/u/robertomzc)\
**Replies:** 0\
**Last updated:** [February 23, 2024, 10:48am UTC](https://discuss.elastic.co/t/unrecognized-signal-name-source-when-using-calculate-in-vega-lite/353976 "2024-02-23T10:48:19Z")

</div>

Hi all, I am trying to compute the sum of the absolute value of three fields in a dataset but I am getting an 'Unrecognized signal name: "\_source" ' error in the calculate clause. I tried substituting the '\_source' for…

---

## [Timestamp field mismatching with server time](https://discuss.elastic.co/t/timestamp-field-mismatching-with-server-time/353975)

<div class="topic-metadata">

**Author:** [@Fahdel\_Achmad](https://discuss.elastic.co/u/Fahdel_Achmad)\
**Replies:** 0\
**Last updated:** [February 23, 2024, 10:43am UTC](https://discuss.elastic.co/t/timestamp-field-mismatching-with-server-time/353975 "2024-02-23T10:43:25Z")

</div>

I have a problem, where the timestamp on Kibana and on the server is different. I have changed the advanced settings to GMT-7 but there is no change. Apart from that, the time on the server is correct. Thank You

---

## [Rovided Grok patterns do not match data in the input, create array for each field while it's a string](https://discuss.elastic.co/t/rovided-grok-patterns-do-not-match-data-in-the-input-create-array-for-each-field-while-its-a-string/353963)

<div class="topic-metadata">

**Author:** [@hsam](https://discuss.elastic.co/u/hsam)\
**Replies:** 1\
**Last updated:** [February 23, 2024, 10:29am UTC](https://discuss.elastic.co/t/rovided-grok-patterns-do-not-match-data-in-the-input-create-array-for-each-field-while-its-a-string/353963 "2024-02-23T10:29:46Z")

</div>

\-csv exemple: A;B;C as991m;tr;lbr-expl/trd/jcl/as991m as991mb;tr;lbr-expl/trd/jcl/as991mb as991t;tr;lbr-expl/trd/jcl/as991t as991tb;tr;lbr-expl/trd/jcl/as991tb as991w;tr;lbr-expl/trd/jcl/as991w as991wb;tr;lbr-expl/trd/j…

---

## [APM- server not connecting to the elasticsearch which is running on the same server](https://discuss.elastic.co/t/apm-server-not-connecting-to-the-elasticsearch-which-is-running-on-the-same-server/353971)

<div class="topic-metadata">

**Author:** [@vijjay](https://discuss.elastic.co/u/vijjay)\
**Replies:** 0\
**Last updated:** [February 23, 2024, 10:15am UTC](https://discuss.elastic.co/t/apm-server-not-connecting-to-the-elasticsearch-which-is-running-on-the-same-server/353971 "2024-02-23T10:15:23Z")

</div>

\*\*Kibana version\*\*: 8.12.2 \*\*Elasticsearch version\*\*: 8.12.2 \*\*APM Server version\*\*:8.12.2 \*\*APM Agent language and version\*\*: \*\*Browser version\*\*: \*\*Original install method - download page \*\*Description of the problem i…

---

## [Rally benchmark results have much smaller latency than real](https://discuss.elastic.co/t/rally-benchmark-results-have-much-smaller-latency-than-real/353943)

<div class="topic-metadata">

**Author:** [@fatcloud](https://discuss.elastic.co/u/fatcloud)\
**Replies:** 2\
**Last updated:** [February 23, 2024, 10:05am UTC](https://discuss.elastic.co/t/rally-benchmark-results-have-much-smaller-latency-than-real/353943 "2024-02-23T10:05:17Z")

</div>

I wrote a Rally benchmark with a single search query operation. The Rally benchmark result shows a much smaller p50 latency(~200ms) compared to the latency I observe when i just use curl command to send same query(severa…

---

## [KIBANA UI is not coming up even all services are UP Without any error in Logs](https://discuss.elastic.co/t/kibana-ui-is-not-coming-up-even-all-services-are-up-without-any-error-in-logs/352763)

<div class="topic-metadata">

**Author:** [@2328943\_dc](https://discuss.elastic.co/u/2328943_dc)\
**Replies:** 5\
**Last updated:** [February 23, 2024, 10:02am UTC](https://discuss.elastic.co/t/kibana-ui-is-not-coming-up-even-all-services-are-up-without-any-error-in-logs/352763 "2024-02-23T10:02:03Z")

</div>

Dear Team We are newly installing KIBANA Setup on new server, After configuration of services all services are up From Backend also no any error observed in Elasticsearch/kibana logs ,but UI URL is not coming up we are…

---

## [Need Help with Multi-Index Search and Boosting for Petstore Project](https://discuss.elastic.co/t/need-help-with-multi-index-search-and-boosting-for-petstore-project/353651)

<div class="topic-metadata">

**Author:** [@SwathiAngaluru](https://discuss.elastic.co/u/SwathiAngaluru)\
**Replies:** 2\
**Last updated:** [February 23, 2024, 9:34am UTC](https://discuss.elastic.co/t/need-help-with-multi-index-search-and-boosting-for-petstore-project/353651 "2024-02-23T09:34:44Z")

</div>

Hi Elastic community, I'm currently working on a petstore project where we have three different pet providers (a, b, c), and their data is stored in three separate indices (provider-a, provider-b, provider-c). All three…

---

## [Native memory pressure in deployemnts](https://discuss.elastic.co/t/native-memory-pressure-in-deployemnts/353962)

<div class="topic-metadata">

**Author:** [@Die\_Viera](https://discuss.elastic.co/u/Die_Viera)\
**Replies:** 0\
**Last updated:** [February 23, 2024, 9:13am UTC](https://discuss.elastic.co/t/native-memory-pressure-in-deployemnts/353962 "2024-02-23T09:13:18Z")

</div>

Hi. I want to know what process use the antive memory pressure of an node in elasticsearch, what can cause i high elasticsearch native memory pressure and what implications has a high native memory pressure in elasticse…

---

## [Filebeat Docker Autodiscovery stopped working when I upgraded to 8.12.0](https://discuss.elastic.co/t/filebeat-docker-autodiscovery-stopped-working-when-i-upgraded-to-8-12-0/353103)

<div class="topic-metadata">

**Author:** [@jerrac](https://discuss.elastic.co/u/jerrac)\
**Replies:** 19\
**Last updated:** [February 23, 2024, 9:00am UTC](https://discuss.elastic.co/t/filebeat-docker-autodiscovery-stopped-working-when-i-upgraded-to-8-12-0/353103 "2024-02-23T09:00:20Z")

</div>

Hey, Last week I was trying to use the logs from my Docker Swarm containers that were supposed to be in my test elasticsearch stack, when I found that said logs were not present. A bit of digging later and I can see tha…

---

## [Cannot create new data stream from auto-create](https://discuss.elastic.co/t/cannot-create-new-data-stream-from-auto-create/353958)

<div class="topic-metadata">

**Author:** [@hti](https://discuss.elastic.co/u/hti)\
**Replies:** 0\
**Last updated:** [February 23, 2024, 8:59am UTC](https://discuss.elastic.co/t/cannot-create-new-data-stream-from-auto-create/353958 "2024-02-23T08:59:28Z")

</div>

Hello, since the last update from 8.10.3 to 8.12.1 we have issues creating new data streams. We do see error messages such as "no such index \[composable template \[logs-cape.\*\] forbids index auto creation\]" The cluster…

---

## [Create a rule / alert using dashboard formula](https://discuss.elastic.co/t/create-a-rule-alert-using-dashboard-formula/353952)

<div class="topic-metadata">

**Author:** [@Samuele\_Lolli](https://discuss.elastic.co/u/Samuele_Lolli)\
**Replies:** 0\
**Last updated:** [February 23, 2024, 8:25am UTC](https://discuss.elastic.co/t/create-a-rule-alert-using-dashboard-formula/353952 "2024-02-23T08:25:58Z")

</div>

Hi, i need to create an alert using the rule page but im not able to replicate the formula that im using on the dashboard. Someone can help me? unique\_count(event.metadata.correlationId, kql=' event.metadata.tracePoint…

---

## [C# Integration Testing with WebApplicationFactory fail due to missing CurrentTransaction](https://discuss.elastic.co/t/c-integration-testing-with-webapplicationfactory-fail-due-to-missing-currenttransaction/353951)

<div class="topic-metadata">

**Author:** [@PeterLech](https://discuss.elastic.co/u/PeterLech)\
**Replies:** 0\
**Last updated:** [February 23, 2024, 7:13am UTC](https://discuss.elastic.co/t/c-integration-testing-with-webapplicationfactory-fail-due-to-missing-currenttransaction/353951 "2024-02-23T07:13:05Z")

</div>

Hi @ all, did somebody faced issues in dotnet Integration Testing that the Agent.Tracer.CurrentTransaction was null for the second test? I'm using dotnet 8 and the Elastic.Apm.NetCoreAll Version=1.26.0 nuget package. …

---

## [Auto Discovery not Working on Azure kubernetes service](https://discuss.elastic.co/t/auto-discovery-not-working-on-azure-kubernetes-service/353947)

<div class="topic-metadata">

**Author:** [@srinikar87](https://discuss.elastic.co/u/srinikar87)\
**Replies:** 0\
**Last updated:** [February 23, 2024, 6:39am UTC](https://discuss.elastic.co/t/auto-discovery-not-working-on-azure-kubernetes-service/353947 "2024-02-23T06:39:36Z")

</div>

Filebeat autodiscovery not working on AKS cluster failing with below error as soon i include auto discovery \< ax\_events":4096}}},"registrar":{"states":{"cleanup":0,"current":0,"update":51},"writes":{"fail":0,"success":…

---

## [Which connector to use to establish connection via logstash 8.11?](https://discuss.elastic.co/t/which-connector-to-use-to-establish-connection-via-logstash-8-11/352333)

<div class="topic-metadata">

**Author:** [@ALTAMASH80](https://discuss.elastic.co/u/ALTAMASH80)\
**Replies:** 1\
**Last updated:** [February 23, 2024, 6:38am UTC](https://discuss.elastic.co/t/which-connector-to-use-to-establish-connection-via-logstash-8-11/352333 "2024-02-23T06:38:14Z")

</div>

Hi, I've installed Kibana and Elasticsearch and I wanted to insert data in an index via logstash from MySQL. But, the documentation uses JDBC connectors. You guys have an official connector repository which has Mysql an…

---

## [Filebeat fingerprint excessive logs](https://discuss.elastic.co/t/filebeat-fingerprint-excessive-logs/352440)

<div class="topic-metadata">

**Author:** [@kbujold\_wr](https://discuss.elastic.co/u/kbujold_wr)\
**Replies:** 14\
**Last updated:** [February 23, 2024, 6:14am UTC](https://discuss.elastic.co/t/filebeat-fingerprint-excessive-logs/352440 "2024-02-23T06:14:11Z")

</div>

Hi We have turned on fingerprinting in our lab. We see a lot of these logs. Is there a way to disabled those 0 bytes logs? Or make fingerprint ignore those files? {"log.level":"warn","@timestamp":"2024-02-02T18:16:22.…

---

## [Unknown error occurred sending a bulk request to Elasticsearch](https://discuss.elastic.co/t/unknown-error-occurred-sending-a-bulk-request-to-elasticsearch/353920)

<div class="topic-metadata">

**Author:** [@JRicha](https://discuss.elastic.co/u/JRicha)\
**Replies:** 1\
**Last updated:** [February 22, 2024, 10:41pm UTC](https://discuss.elastic.co/t/unknown-error-occurred-sending-a-bulk-request-to-elasticsearch/353920 "2024-02-22T22:41:19Z")

</div>

Hello community, I have found other posts here to be helpful in solving my previous issues so I am hoping that someone can help me resolve this issue. I researched my problem in the community pages and have not found an…

---

## [How to Install and configure elasticsearchn (ECK) in openshift onPrem](https://discuss.elastic.co/t/how-to-install-and-configure-elasticsearchn-eck-in-openshift-onprem/353942)

<div class="topic-metadata">

**Author:** [@rhowin](https://discuss.elastic.co/u/rhowin)\
**Replies:** 0\
**Last updated:** [February 23, 2024, 4:04am UTC](https://discuss.elastic.co/t/how-to-install-and-configure-elasticsearchn-eck-in-openshift-onprem/353942 "2024-02-23T04:04:58Z")

</div>

Hi everyone, I need to install ECK in openshift onPrem, does anyone know how to configure and setup this operator?

---

## [Transforms - Latest and Pivot](https://discuss.elastic.co/t/transforms-latest-and-pivot/353925)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 1\
**Last updated:** [February 23, 2024, 3:28am UTC](https://discuss.elastic.co/t/transforms-latest-and-pivot/353925 "2024-02-23T03:28:47Z")

</div>

Hello, I was wondering if its possible to do something like a combination of latest and pivot or maybe more understanding of what I can do with each. So use case: I have status field(keyword) reported for object field…

---

## [Data race condition in automaton queries](https://discuss.elastic.co/t/data-race-condition-in-automaton-queries/353937)

<div class="topic-metadata">

**Author:** [@yfful](https://discuss.elastic.co/u/yfful)\
**Replies:** 0\
**Last updated:** [February 22, 2024, 11:46pm UTC](https://discuss.elastic.co/t/data-race-condition-in-automaton-queries/353937 "2024-02-22T23:46:48Z")

</div>

Hello, In a local unit test involving a runtime field and a regexp query with ES 8.12.1, I have experienced search inconsistencies with the result count. The query shown below uses the script parity which returns even o…

---

## [Do terms queries behave differently with runtime mappings?](https://discuss.elastic.co/t/do-terms-queries-behave-differently-with-runtime-mappings/353931)

<div class="topic-metadata">

**Author:** [@nicole.oresme](https://discuss.elastic.co/u/nicole.oresme)\
**Replies:** 0\
**Last updated:** [February 22, 2024, 9:42pm UTC](https://discuss.elastic.co/t/do-terms-queries-behave-differently-with-runtime-mappings/353931 "2024-02-22T21:42:56Z")

</div>

I have a query: { "query": { "bool": { "filter": \[ { "terms": { "foo": ... (1000 terms) } }, { "terms": { "bar": ... (1000 terms) } } \] } } } which works just fine as is. But if I run those term…

---

## [Passing credentials for S3 snapshot repository in Terraform](https://discuss.elastic.co/t/passing-credentials-for-s3-snapshot-repository-in-terraform/353924)

<div class="topic-metadata">

**Author:** [@acormier-spectrumai](https://discuss.elastic.co/u/acormier-spectrumai)\
**Replies:** 0\
**Last updated:** [February 22, 2024, 8:45pm UTC](https://discuss.elastic.co/t/passing-credentials-for-s3-snapshot-repository-in-terraform/353924 "2024-02-22T20:45:12Z")

</div>

Hello, I am trying to setup a new ELK stack in Terraform, that also includes our configurations/settings/etc. One of the settings I would like to configure is snapshot lifecycle management, and a snapshot repository. I…

---

## [Logstash input with Ruby filter to Opensearch output](https://discuss.elastic.co/t/logstash-input-with-ruby-filter-to-opensearch-output/353635)

<div class="topic-metadata">

**Author:** [@samuelstephens](https://discuss.elastic.co/u/samuelstephens)\
**Replies:** 1\
**Last updated:** [February 20, 2024, 12:15am UTC](https://discuss.elastic.co/t/logstash-input-with-ruby-filter-to-opensearch-output/353635 "2024-02-20T00:15:52Z")

</div>

I have rewritten the Ruby filter mentioned here: The filter now reads as such and I am able to at minimum pass the event to OpenSearch: input: |- http { port =\> 8080 codec =\> "json" filter: |- json { source …

---

## [Kabana pdf reporting error](https://discuss.elastic.co/t/kabana-pdf-reporting-error/353820)

<div class="topic-metadata">

**Author:** [@mst3r25](https://discuss.elastic.co/u/mst3r25)\
**Replies:** 1\
**Last updated:** [February 22, 2024, 7:20pm UTC](https://discuss.elastic.co/t/kabana-pdf-reporting-error/353820 "2024-02-22T19:20:27Z")

</div>

When I try to export a dashboard to pdf I get a "err\_bad\_ssl\_client\_auth\_cert https://{ip}:5601/s/....." This only happens when running pdf reports. All my users and transport connection work fine using SSL. I have a 5 …

[Previous page](https://discuss.elastic.co/latest.md?page=390)

[Next page](https://discuss.elastic.co/latest.md?page=392)
