# Latest

**URL:** https://discuss.elastic.co/latest.md?page=405

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 406

---

## [Getting the "Can't apply \[synonyms\_set\]! Loading synonyms from index is supported only for search time synonyms!" error when creating index](https://discuss.elastic.co/t/getting-the-cant-apply-synonyms-set-loading-synonyms-from-index-is-supported-only-for-search-time-synonyms-error-when-creating-index/352990)

<div class="topic-metadata">

**Author:** [@Hatef\_Alipour](https://discuss.elastic.co/u/Hatef_Alipour)\
**Replies:** 2\
**Last updated:** [February 10, 2024, 12:11pm UTC](https://discuss.elastic.co/t/getting-the-cant-apply-synonyms-set-loading-synonyms-from-index-is-supported-only-for-search-time-synonyms-error-when-creating-index/352990 "2024-02-10T12:11:58Z")

</div>

We have an index in Elasticsearch 7.17, It uses synonym files you can see the full structure below: { "my-index" : { "settings" : { "index" : { "routing" : { "allocation" : { "i…

---

## [Does plugin logstash-input-kinesis support Amazon Kinesis EFO(enhanced fan-out)?](https://discuss.elastic.co/t/does-plugin-logstash-input-kinesis-support-amazon-kinesis-efo-enhanced-fan-out/352988)

<div class="topic-metadata">

**Author:** [@ilove2git](https://discuss.elastic.co/u/ilove2git)\
**Replies:** 0\
**Last updated:** [February 10, 2024, 7:42am UTC](https://discuss.elastic.co/t/does-plugin-logstash-input-kinesis-support-amazon-kinesis-efo-enhanced-fan-out/352988 "2024-02-10T07:42:03Z")

</div>

Hi, I notice that this plugin logstash-input-kinesis \[Kinesis input plugin | Logstash Reference \[8.12\] | Elastic\] supports to receive events through \[AWS Kinesis\]http://docs.aws.amazon.com/kinesis/latest/dev/introductio…

---

## [Haproxy in front of elastic ECK](https://discuss.elastic.co/t/haproxy-in-front-of-elastic-eck/352985)

<div class="topic-metadata">

**Author:** [@saeeddeep](https://discuss.elastic.co/u/saeeddeep)\
**Replies:** 0\
**Last updated:** [February 10, 2024, 3:16am UTC](https://discuss.elastic.co/t/haproxy-in-front-of-elastic-eck/352985 "2024-02-10T03:16:24Z")

</div>

Hi I need help configure HAProxy in front of Elastic ECK Using curl, when I connect directly to the backend elasticsearch I got the correct response. example : curl -k -L -XGET 'https://192.168.0.10:31800/\_cat/nodes?v…

---

## [Super user elastic can't run as regular user](https://discuss.elastic.co/t/super-user-elastic-cant-run-as-regular-user/352974)

<div class="topic-metadata">

**Author:** [@data\_smith](https://discuss.elastic.co/u/data_smith)\
**Replies:** 1\
**Last updated:** [February 9, 2024, 10:02pm UTC](https://discuss.elastic.co/t/super-user-elastic-cant-run-as-regular-user/352974 "2024-02-09T22:02:15Z")

</div>

Shouldn't elastic user be able to run\_as anyone? I have a proxy in front of Kibana and in the past I could set it to run as a user I would use the elastic user to authenticate and then run as someone else. Now it's sa…

---

## [Filebeat: failed to parse rx\_queue: strconv.ParseInt: parsing "0000AC00": invalid syntax](https://discuss.elastic.co/t/filebeat-failed-to-parse-rx-queue-strconv-parseint-parsing-0000ac00-invalid-syntax/352893)

<div class="topic-metadata">

**Author:** [@Daniel314](https://discuss.elastic.co/u/Daniel314)\
**Replies:** 1\
**Last updated:** [February 9, 2024, 10:01pm UTC](https://discuss.elastic.co/t/filebeat-failed-to-parse-rx-queue-strconv-parseint-parsing-0000ac00-invalid-syntax/352893 "2024-02-09T22:01:31Z")

</div>

Hi, I'm using the UDP input in filebeat for collecting logs, and I'm seeing it periodically errors like this: 2024-02-08T12:48:19.399-0700 WARN \[input.udp\] map\[file.line:251 file.name:udp/input.go function:github.com/e…

---

## [How to automate query from trained ML model](https://discuss.elastic.co/t/how-to-automate-query-from-trained-ml-model/352956)

<div class="topic-metadata">

**Author:** [@federica.forti](https://discuss.elastic.co/u/federica.forti)\
**Replies:** 1\
**Last updated:** [February 9, 2024, 8:49pm UTC](https://discuss.elastic.co/t/how-to-automate-query-from-trained-ml-model/352956 "2024-02-09T20:49:56Z")

</div>

Hi, we have added a custom model among the machine learning models. During testing, we obtain, as a result, a vector that we use in the following query: GET indexname/\_search { "query": { "script\_score": { …

---

## [Search and Pagination in .Net](https://discuss.elastic.co/t/search-and-pagination-in-net/352973)

<div class="topic-metadata">

**Author:** [@eric.paul](https://discuss.elastic.co/u/eric.paul)\
**Replies:** 0\
**Last updated:** [February 9, 2024, 7:42pm UTC](https://discuss.elastic.co/t/search-and-pagination-in-net/352973 "2024-02-09T19:42:26Z")

</div>

I am looking for an example of how to use search\_after for pagination using the elastic.client in c#. I can see where the method is and that it takes a type of ICollection\<FieldValue\>? but I do not know how to get this f…

---

## [Filebeat -\> Elasticsearch ingestion: Document loss](https://discuss.elastic.co/t/filebeat-elasticsearch-ingestion-document-loss/352952)

<div class="topic-metadata">

**Author:** [@tmslara.a](https://discuss.elastic.co/u/tmslara.a)\
**Replies:** 7\
**Last updated:** [February 9, 2024, 7:24pm UTC](https://discuss.elastic.co/t/filebeat-elasticsearch-ingestion-document-loss/352952 "2024-02-09T19:24:34Z")

</div>

Hello, We are having some problems with document loss when ingesting data into Elasticsearch using Filebeat. I'll describe our approach to data ingest. We are running a process. This process generates some data that we…

---

## [Filebeat Client talking to googleusercontent](https://discuss.elastic.co/t/filebeat-client-talking-to-googleusercontent/352951)

<div class="topic-metadata">

**Author:** [@drops](https://discuss.elastic.co/u/drops)\
**Replies:** 2\
**Last updated:** [February 9, 2024, 4:40pm UTC](https://discuss.elastic.co/t/filebeat-client-talking-to-googleusercontent/352951 "2024-02-09T16:40:29Z")

</div>

Hi there, I just noticed that the filebeat agents installed on the clients are talking quite frequently to 34.111.17.235 (235.17.111.34.bc.googleusercontent.com). Is it possible to configure the agents not to do that wi…

---

## [Kibana not optimizing custom plugins](https://discuss.elastic.co/t/kibana-not-optimizing-custom-plugins/352939)

<div class="topic-metadata">

**Author:** [@ssimmons](https://discuss.elastic.co/u/ssimmons)\
**Replies:** 1\
**Last updated:** [February 9, 2024, 4:21pm UTC](https://discuss.elastic.co/t/kibana-not-optimizing-custom-plugins/352939 "2024-02-09T16:21:10Z")

</div>

I'm trying to move our custom plugins from Kibana 8.6 to 8.12. On version 8.6, I can run yarn knb bootstrap and then yarn start. This would run the optimizer on my custom plugins and then do a hot reload of Kibana when …

---

## [Display a home page other than the default](https://discuss.elastic.co/t/display-a-home-page-other-than-the-default/352954)

<div class="topic-metadata">

**Author:** [@gnatola](https://discuss.elastic.co/u/gnatola)\
**Replies:** 1\
**Last updated:** [February 9, 2024, 3:37pm UTC](https://discuss.elastic.co/t/display-a-home-page-other-than-the-default/352954 "2024-02-09T15:37:59Z")

</div>

I would like to the Elastic home page to display a particular dashboard on login, rather than the default home page. How do I accomplish that? At the bottom of the default home page there is a link, "Display a different …

---

## [Collect container logs with elastic-agent](https://discuss.elastic.co/t/collect-container-logs-with-elastic-agent/352935)

<div class="topic-metadata">

**Author:** [@lduvnjak](https://discuss.elastic.co/u/lduvnjak)\
**Replies:** 3\
**Last updated:** [February 9, 2024, 3:27pm UTC](https://discuss.elastic.co/t/collect-container-logs-with-elastic-agent/352935 "2024-02-09T15:27:08Z")

</div>

Hey Everyone, I'm having some trouble getting the Kubernetes integration to fully work on my ECK cluster. What I'm trying to do is get elastic-agent to read container logs and forward them to ES. Here's my elastic-age…

---

## [Shipping of logs](https://discuss.elastic.co/t/shipping-of-logs/352955)

<div class="topic-metadata">

**Author:** [@Arsalan\_Muhammad](https://discuss.elastic.co/u/Arsalan_Muhammad)\
**Replies:** 0\
**Last updated:** [February 9, 2024, 3:10pm UTC](https://discuss.elastic.co/t/shipping-of-logs/352955 "2024-02-09T15:10:43Z")

</div>

Hi I need to ship my logs from my application pod which is running in some abc namespace to Elasticsearch cluster I am trying to resolve the issue but I am not able to resolve it. How to resolve this ? also from dev cons…

---

## [Gettting error migrating data stream](https://discuss.elastic.co/t/gettting-error-migrating-data-stream/352947)

<div class="topic-metadata">

**Author:** [@James83](https://discuss.elastic.co/u/James83)\
**Replies:** 0\
**Last updated:** [February 9, 2024, 2:31pm UTC](https://discuss.elastic.co/t/gettting-error-migrating-data-stream/352947 "2024-02-09T14:31:43Z")

</div>

Hello, I'm in the process of migrating ELK (both servers on same version 7.17). I'm trying to restore an index wich has the ilm-history datastream. The index is restored but I'm getting this error in log : java.lang.Il…

---

## [Update ELK version](https://discuss.elastic.co/t/update-elk-version/352573)

<div class="topic-metadata">

**Author:** [@hiruni.insyncit.net](https://discuss.elastic.co/u/hiruni.insyncit.net)\
**Replies:** 7\
**Last updated:** [February 9, 2024, 2:04pm UTC](https://discuss.elastic.co/t/update-elk-version/352573 "2024-02-09T14:04:16Z")

</div>

Hi, I'm planning to update ELK version 8.2 to 8.12 version. Does ELK version 8.12 require additional CPU, RAM to deploy the new version of ELK or it's not required additional resources to upgrade the ELK version. Than…

---

## [How to improve ELSERv2 ingest throughput?](https://discuss.elastic.co/t/how-to-improve-elserv2-ingest-throughput/352636)

<div class="topic-metadata">

**Author:** [@Rakesh\_Nayak](https://discuss.elastic.co/u/Rakesh_Nayak)\
**Replies:** 3\
**Last updated:** [February 9, 2024, 1:16pm UTC](https://discuss.elastic.co/t/how-to-improve-elserv2-ingest-throughput/352636 "2024-02-09T13:16:06Z")

</div>

Hello Team, We need your guidance on "Improving ELSERv2 optimized model ingest throughput". As per the link we can't ingest more than 26docs per sec no matter what the allocations are. A little background on our inges…

---

## [How to remove text from variable. Alerts](https://discuss.elastic.co/t/how-to-remove-text-from-variable-alerts/352937)

<div class="topic-metadata">

**Author:** [@Nidro96](https://discuss.elastic.co/u/Nidro96)\
**Replies:** 0\
**Last updated:** [February 9, 2024, 1:13pm UTC](https://discuss.elastic.co/t/how-to-remove-text-from-variable-alerts/352937 "2024-02-09T13:13:31Z")

</div>

Hi. First post, so I am sorry if this is in the wrong categorie. I am trying to set up an alert for my system. I got everything working but having problems with formating the message sent to the users. I have the follow…

---

## [Identifying Duplicate Records Based on Multiple Fields in Elasticsearch](https://discuss.elastic.co/t/identifying-duplicate-records-based-on-multiple-fields-in-elasticsearch/352115)

<div class="topic-metadata">

**Author:** [@Bikash\_Hutait](https://discuss.elastic.co/u/Bikash_Hutait)\
**Replies:** 7\
**Last updated:** [February 9, 2024, 12:13pm UTC](https://discuss.elastic.co/t/identifying-duplicate-records-based-on-multiple-fields-in-elasticsearch/352115 "2024-02-09T12:13:36Z")

</div>

I have a dataset in Elasticsearch containing records related to users and their assistants. I need to identify duplicate records for a specific file\_id. A record should be considered a duplicate if the fields FirstName, L…

---

## [Problem in connecting with the Elasticsearch using python Client](https://discuss.elastic.co/t/problem-in-connecting-with-the-elasticsearch-using-python-client/352827)

<div class="topic-metadata">

**Author:** [@Shubhankar\_Satvaya](https://discuss.elastic.co/u/Shubhankar_Satvaya)\
**Replies:** 5\
**Last updated:** [February 9, 2024, 11:42am UTC](https://discuss.elastic.co/t/problem-in-connecting-with-the-elasticsearch-using-python-client/352827 "2024-02-09T11:42:58Z")

</div>

I am unable to connect to the ES Server to search from an index in my python jupyter notebook in first go, but if i re-run the cell it will get fetch the required data from the ES ES version : 7.17.3 Python Elasticsear…

---

## [Http input is not letting beat input to run](https://discuss.elastic.co/t/http-input-is-not-letting-beat-input-to-run/352912)

<div class="topic-metadata">

**Author:** [@JITENDER\_NEGI](https://discuss.elastic.co/u/JITENDER_NEGI)\
**Replies:** 1\
**Last updated:** [February 9, 2024, 11:11am UTC](https://discuss.elastic.co/t/http-input-is-not-letting-beat-input-to-run/352912 "2024-02-09T11:11:17Z")

</div>

I running in a strange situation where i have 2 seperate pipeline running on a same instance. When I run the beats pipeline alone it works properly but as soon as I create the http-input.conf in the different directory …

---

## [Correct way to have different databases connected to different elasticsearches](https://discuss.elastic.co/t/correct-way-to-have-different-databases-connected-to-different-elasticsearches/352856)

<div class="topic-metadata">

**Author:** [@mike\_mike](https://discuss.elastic.co/u/mike_mike)\
**Replies:** 2\
**Last updated:** [February 9, 2024, 9:57am UTC](https://discuss.elastic.co/t/correct-way-to-have-different-databases-connected-to-different-elasticsearches/352856 "2024-02-09T09:57:12Z")

</div>

Hello all, I am new here and kinda new to the way Elasticsearch should work (cause I am already working with it, but I miss lots of documentation principles). We mainly use ES as a faster way to retrieve important data…

---

## [Metric and multi-option controls](https://discuss.elastic.co/t/metric-and-multi-option-controls/352807)

<div class="topic-metadata">

**Author:** [@rastro](https://discuss.elastic.co/u/rastro)\
**Replies:** 3\
**Last updated:** [February 9, 2024, 9:51am UTC](https://discuss.elastic.co/t/metric-and-multi-option-controls/352807 "2024-02-09T09:51:58Z")

</div>

Here's a simplified example. I run a business with 2 locations. I have a daily document in an index that stores the number of employees in that location. Now, I'd like to have a dashboard that shows a legacy metric fo…

---

## [Why Opentelemetry spans with same trace ids could have different transaction ids?](https://discuss.elastic.co/t/why-opentelemetry-spans-with-same-trace-ids-could-have-different-transaction-ids/352916)

<div class="topic-metadata">

**Author:** [@toporovvv](https://discuss.elastic.co/u/toporovvv)\
**Replies:** 0\
**Last updated:** [February 9, 2024, 9:38am UTC](https://discuss.elastic.co/t/why-opentelemetry-spans-with-same-trace-ids-could-have-different-transaction-ids/352916 "2024-02-09T09:38:04Z")

</div>

I see a strange behavior for Opentelemetry integration. We have applications in PHP and Go which are linked with GRPC. I've made a manual Opentelemetry integration for PHP (with GRPC transport). However there is a strang…

---

## [Change mapping from text to match\_only\_text](https://discuss.elastic.co/t/change-mapping-from-text-to-match-only-text/352857)

<div class="topic-metadata">

**Author:** [@Vijayakumar\_Kannan](https://discuss.elastic.co/u/Vijayakumar_Kannan)\
**Replies:** 1\
**Last updated:** [February 9, 2024, 8:25am UTC](https://discuss.elastic.co/t/change-mapping-from-text-to-match-only-text/352857 "2024-02-09T08:25:25Z")

</div>

Existing indices having field app.message in text field type. now it has to be changed from "text" to "match\_only\_text" for new records. Will it impact any of the searches?

---

## [StackConfigPolicy ECK Index template fails to create](https://discuss.elastic.co/t/stackconfigpolicy-eck-index-template-fails-to-create/352909)

<div class="topic-metadata">

**Author:** [@PLR-KMD](https://discuss.elastic.co/u/PLR-KMD)\
**Replies:** 0\
**Last updated:** [February 9, 2024, 7:20am UTC](https://discuss.elastic.co/t/stackconfigpolicy-eck-index-template-fails-to-create/352909 "2024-02-09T07:20:45Z")

</div>

Hi, According to docs on Elastic Stack configuration policies | Elastic Cloud on Kubernetes \[2.11\] | Elastic I'm trying to deploy simple ILM and index template. Everything works fine when I deploy ILM only but I can't g…

---

## [AccessDeniedException for path.repo while starting Elasticsearch](https://discuss.elastic.co/t/accessdeniedexception-for-path-repo-while-starting-elasticsearch/322428)

<div class="topic-metadata">

**Author:** [@cr\_168328](https://discuss.elastic.co/u/cr_168328)\
**Replies:** 3\
**Last updated:** [February 9, 2024, 5:49am UTC](https://discuss.elastic.co/t/accessdeniedexception-for-path-repo-while-starting-elasticsearch/322428 "2024-02-09T05:49:19Z")

</div>

I have installed elasticsearch Debian package. In /etc/elasticsearch/elasticsearch.yml file, I have this added: path.repo: \["/home/admin/backup\_extracted/var/lib/elasticsearch/es\_bkp"\]. The ownership of backup\_exctracted …

---

## [Simple\_query\_string and query\_string not working as expected](https://discuss.elastic.co/t/simple-query-string-and-query-string-not-working-as-expected/352905)

<div class="topic-metadata">

**Author:** [@Sankar\_S](https://discuss.elastic.co/u/Sankar_S)\
**Replies:** 0\
**Last updated:** [February 9, 2024, 5:05am UTC](https://discuss.elastic.co/t/simple-query-string-and-query-string-not-working-as-expected/352905 "2024-02-09T05:05:27Z")

</div>

I have a title field in document 1 document has $kitkat as value and another has "title" : "Testing Special\_character Elastic Search in $reference entry search" { "query": { "bool": { "must": \[ …

---

## [Failed to load SSL configuration \[xpack.security.transport.ssl\] - cannot specify both \[keystore.secure\_password\] and \[keystore.password\]](https://discuss.elastic.co/t/failed-to-load-ssl-configuration-xpack-security-transport-ssl-cannot-specify-both-keystore-secure-password-and-keystore-password/352748)

<div class="topic-metadata">

**Author:** [@Karan37](https://discuss.elastic.co/u/Karan37)\
**Replies:** 2\
**Last updated:** [February 9, 2024, 4:55am UTC](https://discuss.elastic.co/t/failed-to-load-ssl-configuration-xpack-security-transport-ssl-cannot-specify-both-keystore-secure-password-and-keystore-password/352748 "2024-02-09T04:55:24Z")

</div>

when running the elasticsearch.bat command after generating the certificates with the password it is showing only this error "fatal exception while booting Elasticsearchorg.elasticsearch.ElasticsearchSecurityException: f…

---

## [Logstash Pipeline Error: JSON ParseError](https://discuss.elastic.co/t/logstash-pipeline-error-json-parseerror/352808)

<div class="topic-metadata">

**Author:** [@samuelstephens](https://discuss.elastic.co/u/samuelstephens)\
**Replies:** 7\
**Last updated:** [February 8, 2024, 10:09pm UTC](https://discuss.elastic.co/t/logstash-pipeline-error-json-parseerror/352808 "2024-02-08T22:09:58Z")

</div>

Summary I am collecting asset data for Jira using automations to generate a HTTP POST request to Logstash, the following code then takes the input from the request and filters it and sends it to OpenSearch. I have one y…

---

## [Table Dashboard color code](https://discuss.elastic.co/t/table-dashboard-color-code/352892)

<div class="topic-metadata">

**Author:** [@erlaarun](https://discuss.elastic.co/u/erlaarun)\
**Replies:** 0\
**Last updated:** [February 8, 2024, 8:47pm UTC](https://discuss.elastic.co/t/table-dashboard-color-code/352892 "2024-02-08T20:47:27Z")

</div>

Hi, I have created the Tabular Dashboard on elastic. Table data having fields called certificate name , valid from date ,valid To Date. we want to change the color code of Valid To Date ,if the certificate expiring wit…

[Previous page](https://discuss.elastic.co/latest.md?page=404)

[Next page](https://discuss.elastic.co/latest.md?page=406)
