# Latest

**URL:** https://discuss.elastic.co/latest.md?page=394

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 395

---

## [How to make a match query with aggregations?](https://discuss.elastic.co/t/how-to-make-a-match-query-with-aggregations/353692)

<div class="topic-metadata">

**Author:** [@Oerlikon](https://discuss.elastic.co/u/Oerlikon)\
**Replies:** 4\
**Last updated:** [February 21, 2024, 2:30pm UTC](https://discuss.elastic.co/t/how-to-make-a-match-query-with-aggregations/353692 "2024-02-21T14:30:58Z")

</div>

Hi to all. I'm working on my university project, where I use Elasticsearch to find similar texts using a "match" query. Here is an example of one document from my dataset: ""\_ident": "5/425/2020", "versions": \[ { …

---

## [Import / update value list (items) via api](https://discuss.elastic.co/t/import-update-value-list-items-via-api/353770)

<div class="topic-metadata">

**Author:** [@maan](https://discuss.elastic.co/u/maan)\
**Replies:** 4\
**Last updated:** [February 21, 2024, 2:21pm UTC](https://discuss.elastic.co/t/import-update-value-list-items-via-api/353770 "2024-02-21T14:21:08Z")

</div>

Using the lists api you can easily import items to a list. Now consider this imported source list have been updated and I want to reflect that in elastic. I would love it if I could just simple re-import it with some ki…

---

## [Manually promoted results (in curations) randomly change after a webcrawl](https://discuss.elastic.co/t/manually-promoted-results-in-curations-randomly-change-after-a-webcrawl/353791)

<div class="topic-metadata">

**Author:** [@mvh-solidaris](https://discuss.elastic.co/u/mvh-solidaris)\
**Replies:** 0\
**Last updated:** [February 21, 2024, 1:20pm UTC](https://discuss.elastic.co/t/manually-promoted-results-in-curations-randomly-change-after-a-webcrawl/353791 "2024-02-21T13:20:50Z")

</div>

Hello, We have an Angular application using App Search. The web crawler uses 1 domain , and all the webcrawls are always successfull. After a webcrawl is done, the promoted results (that were added manually) in active …

---

## [Connection is closed after setting CompatibilityMode(true) of RHLC](https://discuss.elastic.co/t/connection-is-closed-after-setting-compatibilitymode-true-of-rhlc/353708)

<div class="topic-metadata">

**Author:** [@Andreas\_Pichler](https://discuss.elastic.co/u/Andreas_Pichler)\
**Replies:** 1\
**Last updated:** [February 21, 2024, 12:39pm UTC](https://discuss.elastic.co/t/connection-is-closed-after-setting-compatibilitymode-true-of-rhlc/353708 "2024-02-21T12:39:28Z")

</div>

Hello dear community, I am currently working on making my ES7 client compatible with the ES8 cluster, but since the migration from Spring-Boot 2.3.x to 2.7.18 I am encountering the error below. To make the RestHighLevel…

---

## [Filter date histogram buckets](https://discuss.elastic.co/t/filter-date-histogram-buckets/353623)

<div class="topic-metadata">

**Author:** [@mwitsas](https://discuss.elastic.co/u/mwitsas)\
**Replies:** 3\
**Last updated:** [February 21, 2024, 12:32pm UTC](https://discuss.elastic.co/t/filter-date-histogram-buckets/353623 "2024-02-21T12:32:38Z")

</div>

Could anyone help me to understand how to filter the following query just to return minute buckets containing zero documents? Equivalent of a GROUP BY with a HAVING statement in SQL. My aim is to return a list of minutes…

---

## [Crea index with new fields](https://discuss.elastic.co/t/crea-index-with-new-fields/353157)

<div class="topic-metadata">

**Author:** [@goncalobsantos](https://discuss.elastic.co/u/goncalobsantos)\
**Replies:** 1\
**Last updated:** [February 21, 2024, 12:17pm UTC](https://discuss.elastic.co/t/crea-index-with-new-fields/353157 "2024-02-21T12:17:09Z")

</div>

I have an index that contains 1 document. This document has a field1 with value "B" and a field2 with value "C, D, E" (that is, the value in field2 is comma separated and can have variable lenght). I want to create a …

---

## [Issue with elasticsearch shards: \[search\_phase\_execution\_exception\] all shards failed](https://discuss.elastic.co/t/issue-with-elasticsearch-shards-search-phase-execution-exception-all-shards-failed/353783)

<div class="topic-metadata">

**Author:** [@Javier\_Sotoca](https://discuss.elastic.co/u/Javier_Sotoca)\
**Replies:** 0\
**Last updated:** [February 21, 2024, 11:09am UTC](https://discuss.elastic.co/t/issue-with-elasticsearch-shards-search-phase-execution-exception-all-shards-failed/353783 "2024-02-21T11:09:18Z")

</div>

Hello everyone. Since last week, we've ben having an issue with our elasticsearch in our project. We are using ES 7.2.0 and the error that appears when we run the starting scipt is the following: FATAL \[search\_phase\_e…

---

## [How to assess the ES resource cost before migrating to it](https://discuss.elastic.co/t/how-to-assess-the-es-resource-cost-before-migrating-to-it/353780)

<div class="topic-metadata">

**Author:** [@dusty-cjh](https://discuss.elastic.co/u/dusty-cjh)\
**Replies:** 0\
**Last updated:** [February 21, 2024, 10:50am UTC](https://discuss.elastic.co/t/how-to-assess-the-es-resource-cost-before-migrating-to-it/353780 "2024-02-21T10:50:02Z")

</div>

we are considering migrating around 200 million customer info into ES, but before doing it, I need to assess the ES hardware resource requirement to leverage the cost and profit. The use case of these data is to filter …

---

## [Elasticsearch keeps restarting](https://discuss.elastic.co/t/elasticsearch-keeps-restarting/351963)

<div class="topic-metadata">

**Author:** [@Moe\_Hmaidan](https://discuss.elastic.co/u/Moe_Hmaidan)\
**Replies:** 7\
**Last updated:** [February 21, 2024, 10:35am UTC](https://discuss.elastic.co/t/elasticsearch-keeps-restarting/351963 "2024-02-21T10:35:19Z")

</div>

Morning, We have an elasticsearch cluster consist of (3 master, 12 data) one of our data nodes keeps restarting due to the following error in logs. \[2024-01-29T10:52:57,011\]\[ERROR\]\[o.e.b.ElasticsearchUncaughtException…

---

## [Data dosent show in Elasicsearch](https://discuss.elastic.co/t/data-dosent-show-in-elasicsearch/353695)

<div class="topic-metadata">

**Author:** [@yannik-rabenstein](https://discuss.elastic.co/u/yannik-rabenstein)\
**Replies:** 1\
**Last updated:** [February 21, 2024, 10:39am UTC](https://discuss.elastic.co/t/data-dosent-show-in-elasicsearch/353695 "2024-02-21T10:39:18Z")

</div>

I try to setup elasticstack in docker with Elasticsearch, Kibana and fleet-server as components. All components use the version 8.12.1 docker-compose.yml: services: setup: image: elasticsearch:${STACK\_VERSION} …

---

## [Elasticsearch Policy](https://discuss.elastic.co/t/elasticsearch-policy/353741)

<div class="topic-metadata">

**Author:** [@Myungji\_Kim](https://discuss.elastic.co/u/Myungji_Kim)\
**Replies:** 1\
**Last updated:** [February 21, 2024, 10:34am UTC](https://discuss.elastic.co/t/elasticsearch-policy/353741 "2024-02-21T10:34:13Z")

</div>

Hello, I am currently using Elasticsearch v 7.10.2. For the indexes that are created, the policy is applied by creating a policy in the state management policies and applying policy to the indices. Is there a way to app…

---

## [Failed to deserialize APM server response and HTTP 502](https://discuss.elastic.co/t/failed-to-deserialize-apm-server-response-and-http-502/353776)

<div class="topic-metadata">

**Author:** [@andysjoholm](https://discuss.elastic.co/u/andysjoholm)\
**Replies:** 0\
**Last updated:** [February 21, 2024, 10:27am UTC](https://discuss.elastic.co/t/failed-to-deserialize-apm-server-response-and-http-502/353776 "2024-02-21T10:27:45Z")

</div>

I have a Java APM Agent running in my Openshift container application. My application/apm agent prints the following exception when trying to send metrics to APM Server. What is going on and where/what to fix? tjavax.ne…

---

## [Index.mapping.dimension\_fields.limit ignored - Limit of total dimension fields \[21\] has been exceeded](https://discuss.elastic.co/t/index-mapping-dimension-fields-limit-ignored-limit-of-total-dimension-fields-21-has-been-exceeded/353774)

<div class="topic-metadata">

**Author:** [@matled](https://discuss.elastic.co/u/matled)\
**Replies:** 0\
**Last updated:** [February 21, 2024, 10:23am UTC](https://discuss.elastic.co/t/index-mapping-dimension-fields-limit-ignored-limit-of-total-dimension-fields-21-has-been-exceeded/353774 "2024-02-21T10:23:34Z")

</div>

Elastic-Stack 8.12.1 We are currently trying to use a downsample ILM on Netflow Data using the elastiflow integration. It seems as the setting for the dimension fields is ignored from the index settings as there is the …

---

## [Can I apply index template to two index](https://discuss.elastic.co/t/can-i-apply-index-template-to-two-index/353747)

<div class="topic-metadata">

**Author:** [@Frances\_Chu](https://discuss.elastic.co/u/Frances_Chu)\
**Replies:** 0\
**Last updated:** [February 21, 2024, 6:26am UTC](https://discuss.elastic.co/t/can-i-apply-index-template-to-two-index/353747 "2024-02-21T06:26:14Z")

</div>

I create a ilm policy, then index template\_A Can I apply the index template\_A to two different index. e.g index\_A\* and index\_B\*. If yes how to set the rollover\_alias in the template's setting? ========================…

---

## [Illegal\_argument\_exception: index.lifecycle.rollover\_alias does not point to index](https://discuss.elastic.co/t/illegal-argument-exception-index-lifecycle-rollover-alias-does-not-point-to-index/353745)

<div class="topic-metadata">

**Author:** [@martianzz](https://discuss.elastic.co/u/martianzz)\
**Replies:** 0\
**Last updated:** [February 21, 2024, 5:18am UTC](https://discuss.elastic.co/t/illegal-argument-exception-index-lifecycle-rollover-alias-does-not-point-to-index/353745 "2024-02-21T05:18:28Z")

</div>

Illegal\_argument\_exception: index.lifecycle.rollover\_alias does not point to index. How to solve this issue. Index is for logstash documents.

---

## [How to replacing ECK data node with minimal downtime/data moving?](https://discuss.elastic.co/t/how-to-replacing-eck-data-node-with-minimal-downtime-data-moving/353739)

<div class="topic-metadata">

**Author:** [@elastic13](https://discuss.elastic.co/u/elastic13)\
**Replies:** 0\
**Last updated:** [February 21, 2024, 2:03am UTC](https://discuss.elastic.co/t/how-to-replacing-eck-data-node-with-minimal-downtime-data-moving/353739 "2024-02-21T02:03:03Z")

</div>

Hello, we running an ES cluster using ECK installed on AWS EKS, with each ES instance per node. We often need to update the underlying AWS worker nodes for many scenarios: fixing runC CVE-2024-21626 upgrade K8S versi…

---

## [Logstash plugin issue](https://discuss.elastic.co/t/logstash-plugin-issue/353392)

<div class="topic-metadata">

**Author:** [@derekorr](https://discuss.elastic.co/u/derekorr)\
**Replies:** 1\
**Last updated:** [February 21, 2024, 1:51am UTC](https://discuss.elastic.co/t/logstash-plugin-issue/353392 "2024-02-21T01:51:40Z")

</div>

Hi all, I'm having an issue with any logstash plugin deployment. I tried logstash-plugin install logstash-output-google\_cloud\_storage several times and I was met with several different error messages that seemed to be …

---

## [Filebeat gets error "harvester:: error while connecting to output with pipeline: wrong type, expect map accessing 'processors.0.drop\_event.when.contains' (source:'/etc/filebeat/prospector-clickhouse.yml')"](https://discuss.elastic.co/t/filebeat-gets-error-harvester-error-while-connecting-to-output-with-pipeline-wrong-type-expect-map-accessing-processors-0-drop-event-when-contains-source-etc-filebeat-prospector-clickhouse-yml/353732)

<div class="topic-metadata">

**Author:** [@silentfilm](https://discuss.elastic.co/u/silentfilm)\
**Replies:** 1\
**Last updated:** [February 21, 2024, 12:19am UTC](https://discuss.elastic.co/t/filebeat-gets-error-harvester-error-while-connecting-to-output-with-pipeline-wrong-type-expect-map-accessing-processors-0-drop-event-when-contains-source-etc-filebeat-prospector-clickhouse-yml/353732 "2024-02-21T00:19:44Z")

</div>

I am setting up a new prospector for my clickhouse logs, but am seeing this error below. What does it mean?: {"log.level":"debug","@timestamp":"2024-02-20T22:46:51.999Z","log.logger":"input.filestream","log.origin":{"fi…

---

## [Can I filter a separate set of logs through logstash rather than straight to Elasticsearch?](https://discuss.elastic.co/t/can-i-filter-a-separate-set-of-logs-through-logstash-rather-than-straight-to-elasticsearch/353726)

<div class="topic-metadata">

**Author:** [@jreyes25](https://discuss.elastic.co/u/jreyes25)\
**Replies:** 2\
**Last updated:** [February 21, 2024, 12:07am UTC](https://discuss.elastic.co/t/can-i-filter-a-separate-set-of-logs-through-logstash-rather-than-straight-to-elasticsearch/353726 "2024-02-21T00:07:59Z")

</div>

Hello, I currently have Elasticsearch and Kibana installed and configured. I installed fleet-server to manage my elastic-agents and installed elastic-agents to all my hosts and everything is working as should. My elast…

---

## [Enterprise app search duplicate engine data documents](https://discuss.elastic.co/t/enterprise-app-search-duplicate-engine-data-documents/351738)

<div class="topic-metadata">

**Author:** [@pradeepjanga](https://discuss.elastic.co/u/pradeepjanga)\
**Replies:** 3\
**Last updated:** [February 20, 2024, 10:28pm UTC](https://discuss.elastic.co/t/enterprise-app-search-duplicate-engine-data-documents/351738 "2024-02-20T22:28:32Z")

</div>

We are using Enterprise app search to ingest some documents into the engine. Now we want the same engine documents duplicated into a different engine. Is there a copy and paste the data in one engine to another new engi…

---

## [Configure global retention time (ILM) for all logs and metrics](https://discuss.elastic.co/t/configure-global-retention-time-ilm-for-all-logs-and-metrics/353722)

<div class="topic-metadata">

**Author:** [@lpeter](https://discuss.elastic.co/u/lpeter)\
**Replies:** 3\
**Last updated:** [February 20, 2024, 9:54pm UTC](https://discuss.elastic.co/t/configure-global-retention-time-ilm-for-all-logs-and-metrics/353722 "2024-02-20T21:54:59Z")

</div>

Hello! I'm using Elastic Agent with Fleet and Integrations. I'd like all collected data (metrics and logs) to be deleted after about N days. Is there a more elegant solution to this other than modifying the default "man…

---

## [ElasticSearch with FsCrawler Eror](https://discuss.elastic.co/t/elasticsearch-with-fscrawler-eror/353712)

<div class="topic-metadata">

**Author:** [@DAVID\_MARIN\_ALVAREZ](https://discuss.elastic.co/u/DAVID_MARIN_ALVAREZ)\
**Replies:** 3\
**Last updated:** [February 20, 2024, 9:42pm UTC](https://discuss.elastic.co/t/elasticsearch-with-fscrawler-eror/353712 "2024-02-20T21:42:37Z")

</div>

I need help please ! I'm using Fscrawler for process diferent documents with diferents formats (pdf, wxcel, word, RTF, etc) but i'm have a stranger error: \` 10:03:29,868 INFO \[f.p.e.c.f.c.BootstrapChecks\] Memory \[Free/…

---

## [Logstash - Syslog Timestamp](https://discuss.elastic.co/t/logstash-syslog-timestamp/353719)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 1\
**Last updated:** [February 20, 2024, 9:38pm UTC](https://discuss.elastic.co/t/logstash-syslog-timestamp/353719 "2024-02-20T21:38:10Z")

</div>

Hello, I am attempting to parse out a timestamp from syslog. The timestamp comes out to 2024-02-04 02:04:03+00:00 Using the date filter how would I be able to take into account the suffix "+00:00"

---

## [Discover not filtering for date properly](https://discuss.elastic.co/t/discover-not-filtering-for-date-properly/353495)

<div class="topic-metadata">

**Author:** [@Divya\_Kd](https://discuss.elastic.co/u/Divya_Kd)\
**Replies:** 6\
**Last updated:** [February 20, 2024, 8:13pm UTC](https://discuss.elastic.co/t/discover-not-filtering-for-date-properly/353495 "2024-02-20T20:13:25Z")

</div>

Elastic Search for a date filter is not working. If I give my filter as "logintime is 2024-01-25" , I was expecting it would bring all data with login time 2024-01-25 but it also bring data for login time = 2024-01-24 as…

---

## [Elasticsearch Query: using match query with AND operator, fetching all the data](https://discuss.elastic.co/t/elasticsearch-query-using-match-query-with-and-operator-fetching-all-the-data/353724)

<div class="topic-metadata">

**Author:** [@Mohan\_T](https://discuss.elastic.co/u/Mohan_T)\
**Replies:** 2\
**Last updated:** [February 20, 2024, 8:32pm UTC](https://discuss.elastic.co/t/elasticsearch-query-using-match-query-with-and-operator-fetching-all-the-data/353724 "2024-02-20T20:32:03Z")

</div>

Query { "query": { "bool": { "should": \[ { "match": { "keywords.keyword\_values": { "query"…

---

## [How can i do a manual rollover for all indices to the newest index policy?](https://discuss.elastic.co/t/how-can-i-do-a-manual-rollover-for-all-indices-to-the-newest-index-policy/353416)

<div class="topic-metadata">

**Author:** [@idan\_amar](https://discuss.elastic.co/u/idan_amar)\
**Replies:** 3\
**Last updated:** [February 20, 2024, 7:20pm UTC](https://discuss.elastic.co/t/how-can-i-do-a-manual-rollover-for-all-indices-to-the-newest-index-policy/353416 "2024-02-20T19:20:32Z")

</div>

Is it possible to force a rollover for my indices to the latest updated policy? So they would be in the correct phase? GET \_ilm/policy/netlogstash\_policy { "netlogstash\_policy": { "version": 1, "modified\_date…

---

## [Pie chart with multiple terms](https://discuss.elastic.co/t/pie-chart-with-multiple-terms/350482)

<div class="topic-metadata">

**Author:** [@CargoBikoMeter](https://discuss.elastic.co/u/CargoBikoMeter)\
**Replies:** 7\
**Last updated:** [February 20, 2024, 7:21pm UTC](https://discuss.elastic.co/t/pie-chart-with-multiple-terms/350482 "2024-02-20T19:21:52Z")

</div>

Hi, I want to create a pie chart with four different terms car\_total, heavy\_total, bike\_total and ped\_total. For the terms the percentage from the sum (car\_total +heavy\_total +bike\_total + ped\_total) should be visible. …

---

## [Logstash TCP Zero Windows](https://discuss.elastic.co/t/logstash-tcp-zero-windows/351178)

<div class="topic-metadata">

**Author:** [@SilasMuniz1](https://discuss.elastic.co/u/SilasMuniz1)\
**Replies:** 17\
**Last updated:** [February 20, 2024, 6:22pm UTC](https://discuss.elastic.co/t/logstash-tcp-zero-windows/351178 "2024-02-20T18:22:21Z")

</div>

Hi everyone, I am receiving TCP Zero Windowns in my tcpdumps. I saw in other topics that problem is resolved change pipeline.workes in pipeline file. I am using tcp input in logstash and this input doesn't accepted thi…

---

## [Getting lots of "failed to load publisher metadata for" into winlogbeat](https://discuss.elastic.co/t/getting-lots-of-failed-to-load-publisher-metadata-for-into-winlogbeat/353709)

<div class="topic-metadata">

**Author:** [@yquirion](https://discuss.elastic.co/u/yquirion)\
**Replies:** 3\
**Last updated:** [February 20, 2024, 4:59pm UTC](https://discuss.elastic.co/t/getting-lots-of-failed-to-load-publisher-metadata-for-into-winlogbeat/353709 "2024-02-20T16:59:02Z")

</div>

Dear all, I have configures my Windows servers to send their logs to a Windows Event Collector (WEC). On this server, I created a "subscription" to send System and Security event logs to that WEC server. On the WEC ser…

---

## [Issue to run logstash](https://discuss.elastic.co/t/issue-to-run-logstash/353717)

<div class="topic-metadata">

**Author:** [@boubou](https://discuss.elastic.co/u/boubou)\
**Replies:** 1\
**Last updated:** [February 20, 2024, 5:07pm UTC](https://discuss.elastic.co/t/issue-to-run-logstash/353717 "2024-02-20T17:07:43Z")

</div>

Hello everyone, I am using Redhat and logstash8.2.0. I want to start my logstash instance, so I execute the following command: bin/logstash -f /bin/logstash-8.2.0/config/logstash.yml Here's the error I get: \[2024-02-…

[Previous page](https://discuss.elastic.co/latest.md?page=393)

[Next page](https://discuss.elastic.co/latest.md?page=395)
