# Latest

**URL:** https://discuss.elastic.co/latest.md?page=392

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 393

---

## [Search for exact value is not having a good score](https://discuss.elastic.co/t/search-for-exact-value-is-not-having-a-good-score/353914)

<div class="topic-metadata">

**Author:** [@tonnyfrancis](https://discuss.elastic.co/u/tonnyfrancis)\
**Replies:** 0\
**Last updated:** [February 22, 2024, 7:05pm UTC](https://discuss.elastic.co/t/search-for-exact-value-is-not-having-a-good-score/353914 "2024-02-22T19:05:12Z")

</div>

When I try to search for a document using an exact value, I notice that the desired document is not being properly classified, even when the search value is identical to that contained in the document. This has a negativ…

---

## [Unable to Authenticate using api key with elasticstack Terraform provider](https://discuss.elastic.co/t/unable-to-authenticate-using-api-key-with-elasticstack-terraform-provider/353912)

<div class="topic-metadata">

**Author:** [@Andrew\_Thompson](https://discuss.elastic.co/u/Andrew_Thompson)\
**Replies:** 0\
**Last updated:** [February 22, 2024, 6:55pm UTC](https://discuss.elastic.co/t/unable-to-authenticate-using-api-key-with-elasticstack-terraform-provider/353912 "2024-02-22T18:55:13Z")

</div>

I am attempting to create an agent profile using the elastic/elasticstack terraform provider, which provides resource elasticstack\_fleet\_agent\_policy. Attempting to use this resource results in an HTTP 401 error. I have…

---

## [Snapshot doesn't complete with "failed to finalize snapshot"](https://discuss.elastic.co/t/snapshot-doesnt-complete-with-failed-to-finalize-snapshot/352418)

<div class="topic-metadata">

**Author:** [@luana](https://discuss.elastic.co/u/luana)\
**Replies:** 2\
**Last updated:** [February 22, 2024, 5:45pm UTC](https://discuss.elastic.co/t/snapshot-doesnt-complete-with-failed-to-finalize-snapshot/352418 "2024-02-22T17:45:01Z")

</div>

Hi, I'm facing issues to have a snapshot of my cluster completed. For context, this cluster used to have nightly snapshots working as expected until late November 2023, however due to an incorrect setting on beats there…

---

## [Logstash automatic config reload and config.reload.interval (high CPU usage)](https://discuss.elastic.co/t/logstash-automatic-config-reload-and-config-reload-interval-high-cpu-usage/353805)

<div class="topic-metadata">

**Author:** [@Daniel314](https://discuss.elastic.co/u/Daniel314)\
**Replies:** 2\
**Last updated:** [February 22, 2024, 5:35pm UTC](https://discuss.elastic.co/t/logstash-automatic-config-reload-and-config-reload-interval-high-cpu-usage/353805 "2024-02-22T17:35:24Z")

</div>

Hi, I've upgraded my logstash deployments multiple times over the years (starting way back in the 1.x days), and I had set Logstash to check once a minute for config changes (auto-reload) in the logstash.yml file. I re…

---

## [Salesforce Plugin](https://discuss.elastic.co/t/salesforce-plugin/353804)

<div class="topic-metadata">

**Author:** [@kkalwaysok](https://discuss.elastic.co/u/kkalwaysok)\
**Replies:** 3\
**Last updated:** [February 22, 2024, 5:26pm UTC](https://discuss.elastic.co/t/salesforce-plugin/353804 "2024-02-22T17:26:54Z")

</div>

Hi, I'm using salesforce plugin to pull the logs, and it is downloading 6months worth data that is available in Salesforce. Is there a setting that I can use to download logs from specific date? Thanks in advance.

---

## [Security Elasticsearch version 8.12](https://discuss.elastic.co/t/security-elasticsearch-version-8-12/353387)

<div class="topic-metadata">

**Author:** [@sossoulokoariel](https://discuss.elastic.co/u/sossoulokoariel)\
**Replies:** 1\
**Last updated:** [February 22, 2024, 5:20pm UTC](https://discuss.elastic.co/t/security-elasticsearch-version-8-12/353387 "2024-02-22T17:20:46Z")

</div>

Hi community. I'm trying to configure the elasticsearch security to have a login page before accessing the resource but I can't get it. After deploying version 8, I go to the elasticsearch bin file to create a password b…

---

## [Indexing Application Trace Data into Separate Indices Based on Application Names](https://discuss.elastic.co/t/indexing-application-trace-data-into-separate-indices-based-on-application-names/353437)

<div class="topic-metadata">

**Author:** [@Sayyad\_Seyidli](https://discuss.elastic.co/u/Sayyad_Seyidli)\
**Replies:** 1\
**Last updated:** [February 22, 2024, 4:11pm UTC](https://discuss.elastic.co/t/indexing-application-trace-data-into-separate-indices-based-on-application-names/353437 "2024-02-22T16:11:26Z")

</div>

I'm currently working with an Elasticsearch cluster to store and manage trace and metric data from various applications running in a Kubernetes environment. We use OpenTelemetry for instrumentation, collecting metrics an…

---

## [Gateway timeout while getting the snapshots from Azure storage account](https://discuss.elastic.co/t/gateway-timeout-while-getting-the-snapshots-from-azure-storage-account/352175)

<div class="topic-metadata">

**Author:** [@Milos\_Podunavac](https://discuss.elastic.co/u/Milos_Podunavac)\
**Replies:** 6\
**Last updated:** [February 22, 2024, 3:57pm UTC](https://discuss.elastic.co/t/gateway-timeout-while-getting-the-snapshots-from-azure-storage-account/352175 "2024-02-22T15:57:13Z")

</div>

Hi all, we are using Elastic Stack with Kibana, and we have created restore and backup option in Elastic UI, so we are connected to Azure storage account and we are doing hourly backup every day. Everything was fine unti…

---

## [Threat Intel | Alien Vault](https://discuss.elastic.co/t/threat-intel-alien-vault/353205)

<div class="topic-metadata">

**Author:** [@Jordan\_Santander](https://discuss.elastic.co/u/Jordan_Santander)\
**Replies:** 2\
**Last updated:** [February 22, 2024, 3:45pm UTC](https://discuss.elastic.co/t/threat-intel-alien-vault/353205 "2024-02-22T15:45:47Z")

</div>

Hello everobody I need to know if the objects brought to elastic through the alien vault feed are deleted if I unsubscribe from the corresponding pulse. If not, do you know of a method to remove IoC? Thanks

---

## [Scatter Plot in Kibana Dashboard](https://discuss.elastic.co/t/scatter-plot-in-kibana-dashboard/353897)

<div class="topic-metadata">

**Author:** [@robertomzc](https://discuss.elastic.co/u/robertomzc)\
**Replies:** 1\
**Last updated:** [February 22, 2024, 3:42pm UTC](https://discuss.elastic.co/t/scatter-plot-in-kibana-dashboard/353897 "2024-02-22T15:42:32Z")

</div>

Hi all, We have created a dashboard with several plots regarding the status and parameters of a bunch of batteries during their use, charge and discharge. Among other we have the classic lenses line and pie plots, for …

---

## [Keycloak authentifaction failure](https://discuss.elastic.co/t/keycloak-authentifaction-failure/353895)

<div class="topic-metadata">

**Author:** [@bouzir22](https://discuss.elastic.co/u/bouzir22)\
**Replies:** 6\
**Last updated:** [February 22, 2024, 3:07pm UTC](https://discuss.elastic.co/t/keycloak-authentifaction-failure/353895 "2024-02-22T15:07:41Z")

</div>

kibana : elasticsearch exception:\[Authentication to realm oidc1 failed - Failed to authenticate user with OpenID Connect (Caused by org.elasticsearch.ElasticsearchSecurityException: Failed to parse or validate the ID…

---

## [ElasticSearch 8.12.1 with HighLevelRestClient/JavaClient not working](https://discuss.elastic.co/t/elasticsearch-8-12-1-with-highlevelrestclient-javaclient-not-working/353888)

<div class="topic-metadata">

**Author:** [@frank-montyne](https://discuss.elastic.co/u/frank-montyne)\
**Replies:** 2\
**Last updated:** [February 22, 2024, 3:05pm UTC](https://discuss.elastic.co/t/elasticsearch-8-12-1-with-highlevelrestclient-javaclient-not-working/353888 "2024-02-22T15:05:36Z")

</div>

I'm trying to use Elasticsearch 8.12.1 with the 7.17.18 HighLevelRestClient and the new 8.12.1 JavaClient. I saw that for all the org.elasticsearch and org.elasticsearch.client artifacts there are now 8.12.1 versions ex…

---

## [Add an existing index as a backing index for a data stream](https://discuss.elastic.co/t/add-an-existing-index-as-a-backing-index-for-a-data-stream/353892)

<div class="topic-metadata">

**Author:** [@christian.k](https://discuss.elastic.co/u/christian.k)\
**Replies:** 0\
**Last updated:** [February 22, 2024, 2:25pm UTC](https://discuss.elastic.co/t/add-an-existing-index-as-a-backing-index-for-a-data-stream/353892 "2024-02-22T14:25:00Z")

</div>

The documentation for adding an existing index as a backing index for a data stream warns that this is an expert-level API and "can potentially result in improper data stream behavior" (see Modify data streams API | Elas…

---

## [Async Search - How to get list of IDs?](https://discuss.elastic.co/t/async-search-how-to-get-list-of-ids/353660)

<div class="topic-metadata">

**Author:** [@BBQigniter](https://discuss.elastic.co/u/BBQigniter)\
**Replies:** 2\
**Last updated:** [February 22, 2024, 2:10pm UTC](https://discuss.elastic.co/t/async-search-how-to-get-list-of-ids/353660 "2024-02-22T14:10:23Z")

</div>

Do I see that correctly that there is currently NO chance to retrieve an async-search ID if someone missed to save it?

---

## [Logstash http poller input not able to dynamically update the current date](https://discuss.elastic.co/t/logstash-http-poller-input-not-able-to-dynamically-update-the-current-date/353890)

<div class="topic-metadata">

**Author:** [@rajatbhardwaj1393](https://discuss.elastic.co/u/rajatbhardwaj1393)\
**Replies:** 2\
**Last updated:** [February 22, 2024, 1:56pm UTC](https://discuss.elastic.co/t/logstash-http-poller-input-not-able-to-dynamically-update-the-current-date/353890 "2024-02-22T13:56:02Z")

</div>

trying to update dynamically date in post request in http\_poller. Its not updating. Using below code "range": { "ProjectHistories.ProjectHistoryModified": { "gte": "%{+yyyy-MM-dd'T'00:00:00}", "lte": "%{+yyyy-MM-dd'…

---

## [Multiple Elasticsearch Indices in one App Search Engine](https://discuss.elastic.co/t/multiple-elasticsearch-indices-in-one-app-search-engine/353875)

<div class="topic-metadata">

**Author:** [@aisyaharifin](https://discuss.elastic.co/u/aisyaharifin)\
**Replies:** 1\
**Last updated:** [February 22, 2024, 1:21pm UTC](https://discuss.elastic.co/t/multiple-elasticsearch-indices-in-one-app-search-engine/353875 "2024-02-22T13:21:01Z")

</div>

Hi I want to ask, how do I have a one App Search engine with 2 indices in it? I have one indices connector for confluence and another one is microsoft sql connector. How do I centralize this both indices into one…

---

## [Unable to get transaction on APM server](https://discuss.elastic.co/t/unable-to-get-transaction-on-apm-server/353775)

<div class="topic-metadata">

**Author:** [@Zain\_Ul\_Abideen](https://discuss.elastic.co/u/Zain_Ul_Abideen)\
**Replies:** 2\
**Last updated:** [February 22, 2024, 1:19pm UTC](https://discuss.elastic.co/t/unable-to-get-transaction-on-apm-server/353775 "2024-02-22T13:19:07Z")

</div>

I am using running service on local on docker container, Also my APM is running on docker. Locally it is working fine and population transactions entry for every API in the service but when I am deploying my service on t…

---

## [Changing Time Zone for Elastic](https://discuss.elastic.co/t/changing-time-zone-for-elastic/352761)

<div class="topic-metadata">

**Author:** [@ruslan.yeraliyev](https://discuss.elastic.co/u/ruslan.yeraliyev)\
**Replies:** 8\
**Last updated:** [February 22, 2024, 12:49pm UTC](https://discuss.elastic.co/t/changing-time-zone-for-elastic/352761 "2024-02-22T12:49:47Z")

</div>

Hi, All. Who knows how Kafka will behave when changing time zones? We are soon switching from UTC +6 to UTC +5. Will simply changing the settings in NTP or Chrony resolve this issue? Perhaps someone has practical experie…

---

## [Around 1500 indexes to snapshot and restore in another cluster. How would you do it?](https://discuss.elastic.co/t/around-1500-indexes-to-snapshot-and-restore-in-another-cluster-how-would-you-do-it/353711)

<div class="topic-metadata">

**Author:** [@Joao\_Barreto](https://discuss.elastic.co/u/Joao_Barreto)\
**Replies:** 8\
**Last updated:** [February 22, 2024, 12:28pm UTC](https://discuss.elastic.co/t/around-1500-indexes-to-snapshot-and-restore-in-another-cluster-how-would-you-do-it/353711 "2024-02-22T12:28:44Z")

</div>

Dear community members, I recently encountered a challenge involving the migration of an entire cluster to a different version of Elasticsearch, specifically one that includes archive indexes. A few days ago, I posted …

---

## [Getting 400 Error for the Elastic Search](https://discuss.elastic.co/t/getting-400-error-for-the-elastic-search/353883)

<div class="topic-metadata">

**Author:** [@syedimran7861](https://discuss.elastic.co/u/syedimran7861)\
**Replies:** 0\
**Last updated:** [February 22, 2024, 12:21pm UTC](https://discuss.elastic.co/t/getting-400-error-for-the-elastic-search/353883 "2024-02-22T12:21:32Z")

</div>

failed to install template message= got response code '400' contacting elasticsearch Configuration { "order": 1, "index\_patterns": \[ "log-default-\*", "log-http-\*" \], "settings": { "number\_of\_shards"…

---

## [How do i output kubernetes Logs to logstash](https://discuss.elastic.co/t/how-do-i-output-kubernetes-logs-to-logstash/353880)

<div class="topic-metadata">

**Author:** [@ataylor](https://discuss.elastic.co/u/ataylor)\
**Replies:** 0\
**Last updated:** [February 22, 2024, 11:36am UTC](https://discuss.elastic.co/t/how-do-i-output-kubernetes-logs-to-logstash/353880 "2024-02-22T11:36:22Z")

</div>

Ok So for Context, we have a on prem ELK stack, where we ship via filebeats installed locally, to Logstash, then onto our elasticsearch cluster. I have now been asked by a stakeholder to help them do the same but from a…

---

## [I cannot transport data between two elasticsearch nodes](https://discuss.elastic.co/t/i-cannot-transport-data-between-two-elasticsearch-nodes/353670)

<div class="topic-metadata">

**Author:** [@quanganhhnv](https://discuss.elastic.co/u/quanganhhnv)\
**Replies:** 13\
**Last updated:** [February 22, 2024, 10:41am UTC](https://discuss.elastic.co/t/i-cannot-transport-data-between-two-elasticsearch-nodes/353670 "2024-02-22T10:41:24Z")

</div>

I have two machines using elasticSearch, each machine I have the following configuration set Machine 1 cluster.name: NDC node.name: node-1 node.roles: \[ master, data \] network.host: 30.30.30.65 http.port: 9200 discover…

---

## [How can I delete a Kibana dashboard through API?](https://discuss.elastic.co/t/how-can-i-delete-a-kibana-dashboard-through-api/353867)

<div class="topic-metadata">

**Author:** [@Lide\_Ding](https://discuss.elastic.co/u/Lide_Ding)\
**Replies:** 2\
**Last updated:** [February 22, 2024, 10:34am UTC](https://discuss.elastic.co/t/how-can-i-delete-a-kibana-dashboard-through-api/353867 "2024-02-22T10:34:03Z")

</div>

I found that APIs to delete Kibana dashboard have been deprecated, is there an API can delete dashboard?

---

## [Elasticsearch snapshot and recovery](https://discuss.elastic.co/t/elasticsearch-snapshot-and-recovery/353668)

<div class="topic-metadata">

**Author:** [@tykarthick](https://discuss.elastic.co/u/tykarthick)\
**Replies:** 5\
**Last updated:** [February 22, 2024, 10:20am UTC](https://discuss.elastic.co/t/elasticsearch-snapshot-and-recovery/353668 "2024-02-22T10:20:12Z")

</div>

Hi Team, Am using Elasticsearch three node cluster with version 8.6.2 and hosted on a Linux environment. Doing a POC in Snapshot and Recovery and external NFS storage is configured to store the snapshots. The NFS repo i…

---

## [ValueError "ca\_certs parameter is not a path"](https://discuss.elastic.co/t/valueerror-ca-certs-parameter-is-not-a-path/353874)

<div class="topic-metadata">

**Author:** [@rue1](https://discuss.elastic.co/u/rue1)\
**Replies:** 0\
**Last updated:** [February 22, 2024, 10:07am UTC](https://discuss.elastic.co/t/valueerror-ca-certs-parameter-is-not-a-path/353874 "2024-02-22T10:07:03Z")

</div>

So im trying to set up a Sharepoint Online Connector in Docker and when i do Docker run, i get following Error and logs: ~/connectors-config$ docker run -v ~/connectors-config:/config --network "elastic" --tty --rm dock…

---

## [Backward compatibility while upgrding major version of elastic search](https://discuss.elastic.co/t/backward-compatibility-while-upgrding-major-version-of-elastic-search/353858)

<div class="topic-metadata">

**Author:** [@abhadauria](https://discuss.elastic.co/u/abhadauria)\
**Replies:** 3\
**Last updated:** [February 22, 2024, 10:02am UTC](https://discuss.elastic.co/t/backward-compatibility-while-upgrding-major-version-of-elastic-search/353858 "2024-02-22T10:02:35Z")

</div>

We are upgrading the major version of Elasticsearch from 7.x to 8.x, is there any guideline/documentation for the same as there are no changes for the same in NEST client for this version upgrade but there are changes in…

---

## [How to use cummulative sum correctly for a machine learning job?](https://discuss.elastic.co/t/how-to-use-cummulative-sum-correctly-for-a-machine-learning-job/352659)

<div class="topic-metadata">

**Author:** [@Rick\_V](https://discuss.elastic.co/u/Rick_V)\
**Replies:** 11\
**Last updated:** [February 22, 2024, 9:59am UTC](https://discuss.elastic.co/t/how-to-use-cummulative-sum-correctly-for-a-machine-learning-job/352659 "2024-02-22T09:59:48Z")

</div>

Hi all, I want to create a ml job which analyses the trend in a cumulative value. So, I created the following aggregation which calculates the sum of a field every day, and then calculates the cumulative sum with the va…

---

## [Modifying Refresh Settings for BulkIngester Instances](https://discuss.elastic.co/t/modifying-refresh-settings-for-bulkingester-instances/353699)

<div class="topic-metadata">

**Author:** [@Ivelin\_Yanev](https://discuss.elastic.co/u/Ivelin_Yanev)\
**Replies:** 10\
**Last updated:** [February 22, 2024, 9:49am UTC](https://discuss.elastic.co/t/modifying-refresh-settings-for-bulkingester-instances/353699 "2024-02-22T09:49:49Z")

</div>

Hi team, I'm currently working with the BulkIngester in my Elasticsearch project and I have a question regarding the refresh setting. After creating the BulkIngester instance using the following code snippet: ingester…

---

## [How to save "total hits" results from a query, in a field](https://discuss.elastic.co/t/how-to-save-total-hits-results-from-a-query-in-a-field/353807)

<div class="topic-metadata">

**Author:** [@Andex](https://discuss.elastic.co/u/Andex)\
**Replies:** 3\
**Last updated:** [February 22, 2024, 8:26am UTC](https://discuss.elastic.co/t/how-to-save-total-hits-results-from-a-query-in-a-field/353807 "2024-02-22T08:26:00Z")

</div>

Hi, i 'm trying to using Logstash to send email. I configure the input pipeline filter witha a query, i need to find all the document that contain ERROR in the message. I do that. in the output i want to user the tota…

---

## [Changing the precision of the @timestamp field](https://discuss.elastic.co/t/changing-the-precision-of-the-timestamp-field/353728)

<div class="topic-metadata">

**Author:** [@ankh](https://discuss.elastic.co/u/ankh)\
**Replies:** 8\
**Last updated:** [February 22, 2024, 8:23am UTC](https://discuss.elastic.co/t/changing-the-precision-of-the-timestamp-field/353728 "2024-02-22T08:23:50Z")

</div>

I have been using the generated @timestamp field in our documents as a record of when a document was sent to Elastic. I have been renaming the field in Logstash to suit our document structure. rename =\> { "@timestamp" =\>…

[Previous page](https://discuss.elastic.co/latest.md?page=391)

[Next page](https://discuss.elastic.co/latest.md?page=393)
