# Latest

**URL:** https://discuss.elastic.co/latest.md?page=415

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 416

---

## [Exclude version conflict, document already exists from logstash.log](https://discuss.elastic.co/t/exclude-version-conflict-document-already-exists-from-logstash-log/352186)

<div class="topic-metadata">

**Author:** [@lduvnjak](https://discuss.elastic.co/u/lduvnjak)\
**Replies:** 2\
**Last updated:** [January 31, 2024, 3:42pm UTC](https://discuss.elastic.co/t/exclude-version-conflict-document-already-exists-from-logstash-log/352186 "2024-01-31T15:42:08Z")

</div>

Hey Everyone, I'm having some issues with too much noise in my Logstash logs. What's happening is because I'm using the Threat Intel integrations it's spamming my logs with version conflict, document already exists WAR…

---

## [Loop array in table markdown canvas kibana](https://discuss.elastic.co/t/loop-array-in-table-markdown-canvas-kibana/351116)

<div class="topic-metadata">

**Author:** [@Dy\_Vanrith](https://discuss.elastic.co/u/Dy_Vanrith)\
**Replies:** 1\
**Last updated:** [January 31, 2024, 3:24pm UTC](https://discuss.elastic.co/t/loop-array-in-table-markdown-canvas-kibana/351116 "2024-01-31T15:24:28Z")

</div>

Hello friend I have array value example arr = \[1, 4, 7\] and in canvas kibana i want to loop array in markdown here my code expression {{#each rows}} | All In Array | |---------------| {{arr}} {{/each}} but it loop …

---

## [I want to calculate the nginx http latency from event.original field/keyword](https://discuss.elastic.co/t/i-want-to-calculate-the-nginx-http-latency-from-event-original-field-keyword/349994)

<div class="topic-metadata">

**Author:** [@Subrahmanyam\_Veerank](https://discuss.elastic.co/u/Subrahmanyam_Veerank)\
**Replies:** 20\
**Last updated:** [January 31, 2024, 2:54pm UTC](https://discuss.elastic.co/t/i-want-to-calculate-the-nginx-http-latency-from-event-original-field-keyword/349994 "2024-01-31T14:54:47Z")

</div>

im trying to calculate the nginx http latency from event.original field. event.original 172.29.55.40 - - \[27/Dec/2023:10:08:14 +0530\] "POST /prod/requestJson HTTP/1.1" 200 607 "-" "Go-http-client/1.1" 0.486 For exampl…

---

## [Regarding elasticsearch rolling upgrades](https://discuss.elastic.co/t/regarding-elasticsearch-rolling-upgrades/352056)

<div class="topic-metadata">

**Author:** [@jaykb77](https://discuss.elastic.co/u/jaykb77)\
**Replies:** 5\
**Last updated:** [January 31, 2024, 2:54pm UTC](https://discuss.elastic.co/t/regarding-elasticsearch-rolling-upgrades/352056 "2024-01-31T14:54:53Z")

</div>

Hi, We are trying to upgrade our elasticsearch cluster from 7.17 to 8.X and we will have to do it in a rolling fashion. I found the below documentation thats for 7.x version. Do we not have similar doc for 8.x or i…

---

## [Java API - what are TDocument, TPartialDocument?](https://discuss.elastic.co/t/java-api-what-are-tdocument-tpartialdocument/352199)

<div class="topic-metadata">

**Author:** [@TimWardFS](https://discuss.elastic.co/u/TimWardFS)\
**Replies:** 0\
**Last updated:** [January 31, 2024, 2:31pm UTC](https://discuss.elastic.co/t/java-api-what-are-tdocument-tpartialdocument/352199 "2024-01-31T14:31:59Z")

</div>

We're converting some code from using the old client to the new client. The new version of UpdateRequest, to pick an example, now has type parameters TDocument and TPartialDocument ... but I can't find out (after a coup…

---

## [Suggested method to extract data in bulk](https://discuss.elastic.co/t/suggested-method-to-extract-data-in-bulk/352099)

<div class="topic-metadata">

**Author:** [@yeikel](https://discuss.elastic.co/u/yeikel)\
**Replies:** 3\
**Last updated:** [January 31, 2024, 2:23pm UTC](https://discuss.elastic.co/t/suggested-method-to-extract-data-in-bulk/352099 "2024-01-31T14:23:57Z")

</div>

Hi all, I am trying to execute a full extract of the Elasticsearch data on intervals or in a monthly based (depending on what creates less load), push it to a file and then load it to another system (Hive) for analytics…

---

## [How to change an agent name in ELK 8.11?](https://discuss.elastic.co/t/how-to-change-an-agent-name-in-elk-8-11/352196)

<div class="topic-metadata">

**Author:** [@SamuelSMendes](https://discuss.elastic.co/u/SamuelSMendes)\
**Replies:** 0\
**Last updated:** [January 31, 2024, 2:20pm UTC](https://discuss.elastic.co/t/how-to-change-an-agent-name-in-elk-8-11/352196 "2024-01-31T14:20:04Z")

</div>

In the previous version I could change it by going into the metricbeat.yml in the installation file of the agent but as I upgraded the version from 8.5.1 to 8.11.3 the files aren't there anymore.

---

## [Install Elastic Agent 8.12 via SCCM](https://discuss.elastic.co/t/install-elastic-agent-8-12-via-sccm/352032)

<div class="topic-metadata">

**Author:** [@gnatola](https://discuss.elastic.co/u/gnatola)\
**Replies:** 6\
**Last updated:** [January 31, 2024, 2:17pm UTC](https://discuss.elastic.co/t/install-elastic-agent-8-12-via-sccm/352032 "2024-01-31T14:17:00Z")

</div>

Is there a method for installing the Elastic Agent via SCCM? If yes, after installing via SCCM can upgrades be managed in the Fleet page of the Elastic Dashboard? Thank you.

---

## [PUT aliases for multiple index](https://discuss.elastic.co/t/put-aliases-for-multiple-index/350654)

<div class="topic-metadata">

**Author:** [@elk1985](https://discuss.elastic.co/u/elk1985)\
**Replies:** 3\
**Last updated:** [January 31, 2024, 2:02pm UTC](https://discuss.elastic.co/t/put-aliases-for-multiple-index/350654 "2024-01-31T14:02:53Z")

</div>

Hello. I am changing the organization of the indexes in my cluster. I have added an alias to the template and from now all indexes I need will get a correct view alias. But I have a bunch (1k of them) without view alia…

---

## [How to set query params 'from' and 'size' in latest java api 8.11](https://discuss.elastic.co/t/how-to-set-query-params-from-and-size-in-latest-java-api-8-11/352162)

<div class="topic-metadata">

**Author:** [@Darth\_vader\_22](https://discuss.elastic.co/u/Darth_vader_22)\
**Replies:** 9\
**Last updated:** [January 31, 2024, 1:58pm UTC](https://discuss.elastic.co/t/how-to-set-query-params-from-and-size-in-latest-java-api-8-11/352162 "2024-01-31T13:58:38Z")

</div>

Hello, i'm trying to send a request with a specific from and size parameters , by default there are set to ( from=0 , size=10) . here's a snippet of my code where i construct my search query Query query = NativeQuery.…

---

## [What is most stable version of 8.\*](https://discuss.elastic.co/t/what-is-most-stable-version-of-8/352189)

<div class="topic-metadata">

**Author:** [@Krishna\_Sailesh](https://discuss.elastic.co/u/Krishna_Sailesh)\
**Replies:** 2\
**Last updated:** [January 31, 2024, 1:50pm UTC](https://discuss.elastic.co/t/what-is-most-stable-version-of-8/352189 "2024-01-31T13:50:33Z")

</div>

I need to upgrade the Elasticsearch from 7.9 to 8.\* due to vulnerabilities. what is the most stable version of Elasticsearch to upgrade?

---

## [Filebeat doesn't send logs to elasticsearch](https://discuss.elastic.co/t/filebeat-doesnt-send-logs-to-elasticsearch/352187)

<div class="topic-metadata">

**Author:** [@Vladimir\_Fomin1](https://discuss.elastic.co/u/Vladimir_Fomin1)\
**Replies:** 0\
**Last updated:** [January 31, 2024, 1:15pm UTC](https://discuss.elastic.co/t/filebeat-doesnt-send-logs-to-elasticsearch/352187 "2024-01-31T13:15:50Z")

</div>

I am configuring filebeat in a kubernetes cluster. Below is my config inside Pod: cat /etc/filebeat.yml filebeat.inputs: - type: container paths: - /var/log/containers/\*.log processors: - add\_kubernetes\_metad…

---

## [Approximate KNN, Preloading & Performance](https://discuss.elastic.co/t/approximate-knn-preloading-performance/352105)

<div class="topic-metadata">

**Author:** [@robertasg](https://discuss.elastic.co/u/robertasg)\
**Replies:** 4\
**Last updated:** [January 31, 2024, 12:27pm UTC](https://discuss.elastic.co/t/approximate-knn-preloading-performance/352105 "2024-01-31T12:27:16Z")

</div>

Hi there! I'm very excited to explore Elasticsearch as an option for both ANN and hybrid search solution. The current guides provided for tuning KNN performance have been very helpful however I feel like I'm encounterin…

---

## [Metricbeat 8.8.1 MongoDB module - Error fetching data replstatus: sort operation used more than the maximum bytes of RAM](https://discuss.elastic.co/t/metricbeat-8-8-1-mongodb-module-error-fetching-data-replstatus-sort-operation-used-more-than-the-maximum-bytes-of-ram/348057)

<div class="topic-metadata">

**Author:** [@elasticforumuser5342](https://discuss.elastic.co/u/elasticforumuser5342)\
**Replies:** 1\
**Last updated:** [January 31, 2024, 11:37am UTC](https://discuss.elastic.co/t/metricbeat-8-8-1-mongodb-module-error-fetching-data-replstatus-sort-operation-used-more-than-the-maximum-bytes-of-ram/348057 "2024-01-31T11:37:45Z")

</div>

When trying to set up the mongodb.replstatus metricset on my replica set (MongoDB v3.6), I am given the error: Error fetching data for metricset mongodb.replstatus: error getting replication info: could not get last ope…

---

## [MongoDB Integration generates huge amount of temp files](https://discuss.elastic.co/t/mongodb-integration-generates-huge-amount-of-temp-files/350226)

<div class="topic-metadata">

**Author:** [@SnackK](https://discuss.elastic.co/u/SnackK)\
**Replies:** 2\
**Last updated:** [January 31, 2024, 11:32am UTC](https://discuss.elastic.co/t/mongodb-integration-generates-huge-amount-of-temp-files/350226 "2024-01-31T11:32:07Z")

</div>

Recently something generated 80Gb of temp files under 15 minutes in my primary MongoDB. I disabled the DiskUse then I got the following errors: Plan executor error during find command "stats": { "works": 88450, …

---

## [Relevance Issues in Vector Search](https://discuss.elastic.co/t/relevance-issues-in-vector-search/352180)

<div class="topic-metadata">

**Author:** [@Adrien\_Corb](https://discuss.elastic.co/u/Adrien_Corb)\
**Replies:** 0\
**Last updated:** [January 31, 2024, 11:14am UTC](https://discuss.elastic.co/t/relevance-issues-in-vector-search/352180 "2024-01-31T11:14:31Z")

</div>

Hello, I am in the process of testing self-hosted solutions. I'm encountering an issue with vector search. My goal is to index pages of a website that mainly consists of a title and content. I have created two dense\_vec…

---

## [PHP APM Agent is not picking up the routes](https://discuss.elastic.co/t/php-apm-agent-is-not-picking-up-the-routes/352080)

<div class="topic-metadata">

**Author:** [@Ali\_Mehdi](https://discuss.elastic.co/u/Ali_Mehdi)\
**Replies:** 6\
**Last updated:** [January 31, 2024, 11:01am UTC](https://discuss.elastic.co/t/php-apm-agent-is-not-picking-up-the-routes/352080 "2024-01-31T11:01:56Z")

</div>

Kibana version: 8.11 Elasticsearch version:8.11 APM Server version:fleet managed apm 8.11 APM Agent language and version:apm-agent-php v1.12.0 Browser version: Version 121.0.6167.85 Original install method (e.g. do…

---

## [Trying to index from Logstash Kubernetes pod into an Elasticsearch Docker container](https://discuss.elastic.co/t/trying-to-index-from-logstash-kubernetes-pod-into-an-elasticsearch-docker-container/351991)

<div class="topic-metadata">

**Author:** [@rowish](https://discuss.elastic.co/u/rowish)\
**Replies:** 3\
**Last updated:** [January 31, 2024, 10:04am UTC](https://discuss.elastic.co/t/trying-to-index-from-logstash-kubernetes-pod-into-an-elasticsearch-docker-container/351991 "2024-01-31T10:04:42Z")

</div>

On the same cloud, I have an instance of Logstash 6.6.1 running within a certain Kubernetes pod that I am trying to make it index into an Elasticsearch 8.6.1 running on a Docker container hosted on an VM with IP address …

---

## [Transform is only partially updated](https://discuss.elastic.co/t/transform-is-only-partially-updated/351935)

<div class="topic-metadata">

**Author:** [@Doron\_Abramovich](https://discuss.elastic.co/u/Doron_Abramovich)\
**Replies:** 9\
**Last updated:** [January 31, 2024, 9:54am UTC](https://discuss.elastic.co/t/transform-is-only-partially-updated/351935 "2024-01-31T09:54:19Z")

</div>

Hi everyone, I have an transform that suppose to track the latest doc of some index. The transform I made is based on field called "etl\_id" and for some reason it is updated only for few "etl\_id" but not all of them, h…

---

## [节点信息中统计不到的堆内存都去哪了？](https://discuss.elastic.co/t/topic/352164)

<div class="topic-metadata">

**Author:** [@huajun\_qi](https://discuss.elastic.co/u/huajun_qi)\
**Replies:** 0\
**Last updated:** [January 31, 2024, 9:44am UTC](https://discuss.elastic.co/t/topic/352164 "2024-01-31T09:44:43Z")

</div>

id version type jdk heap.current heap.percent heap.max ram.current ram.percent ram.max fielddata.memory\_size query\_cache.memory\_size request\_cache.memory\_size segments.memory segments.index\_writer\_memory segments.…

---

## [Elasticsearch 7 and JVM 21](https://discuss.elastic.co/t/elasticsearch-7-and-jvm-21/351238)

<div class="topic-metadata">

**Author:** [@ondrokrc](https://discuss.elastic.co/u/ondrokrc)\
**Replies:** 3\
**Last updated:** [January 31, 2024, 9:43am UTC](https://discuss.elastic.co/t/elasticsearch-7-and-jvm-21/351238 "2024-01-31T09:43:09Z")

</div>

I noticed that elasticsearch 7.17.15 comes with bundled JDK 21.0.1. But in Support Matrix | Elastic in documentation, JDK 21 is not listed as supported. Is it an inaccuracy in the Support Matrix and should I consider J…

---

## [Where did uncounted heap memory go?](https://discuss.elastic.co/t/where-did-uncounted-heap-memory-go/352163)

<div class="topic-metadata">

**Author:** [@huajun\_qi](https://discuss.elastic.co/u/huajun_qi)\
**Replies:** 0\
**Last updated:** [January 31, 2024, 9:40am UTC](https://discuss.elastic.co/t/where-did-uncounted-heap-memory-go/352163 "2024-01-31T09:40:30Z")

</div>

our cluster keeps running in high heap memory, but we can't find where are memories consumed? here is the output from /\_cate/nodes api: id version type jdk heap.current heap.percent heap.max ram.current ram.perc…

---

## [How to monitor kafka using metricbeat?](https://discuss.elastic.co/t/how-to-monitor-kafka-using-metricbeat/352146)

<div class="topic-metadata">

**Author:** [@kriti\_dabas](https://discuss.elastic.co/u/kriti_dabas)\
**Replies:** 7\
**Last updated:** [January 31, 2024, 9:37am UTC](https://discuss.elastic.co/t/how-to-monitor-kafka-using-metricbeat/352146 "2024-01-31T09:37:40Z")

</div>

I have a cluster of kafka consisting three nodes. I want to monitor kafka topic/broker /partitions/data using metricbeat. I want the dashboard on kibana. I have a setup consisting kafka-logstash-elasticsearch-kibana. …

---

## [Transformation 'pivot' has value null](https://discuss.elastic.co/t/transformation-pivot-has-value-null/351257)

<div class="topic-metadata">

**Author:** [@minova94](https://discuss.elastic.co/u/minova94)\
**Replies:** 7\
**Last updated:** [January 31, 2024, 9:19am UTC](https://discuss.elastic.co/t/transformation-pivot-has-value-null/351257 "2024-01-31T09:19:00Z")

</div>

Hello :wave: I have a question regarding transforms. There is source index which has dedicated transformation with grouping by 'pivot'. The pivot can be one field or concatenation of multiple fields. For ex: 'fullNa…

---

## [Enable wildcard for AppSearch search API](https://discuss.elastic.co/t/enable-wildcard-for-appsearch-search-api/352161)

<div class="topic-metadata">

**Author:** [@Disha\_Bodade](https://discuss.elastic.co/u/Disha_Bodade)\
**Replies:** 0\
**Last updated:** [January 31, 2024, 9:11am UTC](https://discuss.elastic.co/t/enable-wildcard-for-appsearch-search-api/352161 "2024-01-31T09:11:13Z")

</div>

Hi Team, There is already closed discussion with above requirement. I know that App Search don't support wildcard, instead it supports prefix matching. But recently we switch from some other search solution to appsear…

---

## [Elastic installation on Robin cloud](https://discuss.elastic.co/t/elastic-installation-on-robin-cloud/352158)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 1\
**Last updated:** [January 31, 2024, 8:44am UTC](https://discuss.elastic.co/t/elastic-installation-on-robin-cloud/352158 "2024-01-31T08:44:41Z")

</div>

To set up elastic (on K8s) - say platinum version on robin cloud, is there any limitations? I can see elastic set up on robin from robin's website but no details on whether the paid version can work with robin, could so…

---

## [Logstash Gone Wrong After force shutdown](https://discuss.elastic.co/t/logstash-gone-wrong-after-force-shutdown/351867)

<div class="topic-metadata">

**Author:** [@akrog79](https://discuss.elastic.co/u/akrog79)\
**Replies:** 12\
**Last updated:** [January 31, 2024, 8:37am UTC](https://discuss.elastic.co/t/logstash-gone-wrong-after-force-shutdown/351867 "2024-01-31T08:37:15Z")

</div>

I have logstash installed as a service on a machine with Logstash+Kibana+Elastic. My logstash was updated, so its seems that doesn't shutdown properly and now show an error with a pipeline: Jan 26 10:19:56 esearch logs…

---

## [Kibana cannot use elasticsearch normally - Cluster Red](https://discuss.elastic.co/t/kibana-cannot-use-elasticsearch-normally-cluster-red/352149)

<div class="topic-metadata">

**Author:** [@kei\_ru](https://discuss.elastic.co/u/kei_ru)\
**Replies:** 3\
**Last updated:** [January 31, 2024, 8:19am UTC](https://discuss.elastic.co/t/kibana-cannot-use-elasticsearch-normally-cluster-red/352149 "2024-01-31T08:19:24Z")

</div>

Configuration environment: es-7.17.8 kibana-7.17.8 filebeat-7.17.8 (Elasticsearch is a single node, and the data mount point is the efs file system of AWS) Problem Description: I started to find that kibanan was …

---

## [Difference in Shard & Index count during Snapshot & Restore](https://discuss.elastic.co/t/difference-in-shard-index-count-during-snapshot-restore/352154)

<div class="topic-metadata">

**Author:** [@Vadiraj\_Prahalad](https://discuss.elastic.co/u/Vadiraj_Prahalad)\
**Replies:** 0\
**Last updated:** [January 31, 2024, 6:46am UTC](https://discuss.elastic.co/t/difference-in-shard-index-count-during-snapshot-restore/352154 "2024-01-31T06:46:18Z")

</div>

Hello All, We are performing Elastic Upgrade by building parallel cluster for the existing cluster ( due to organization issues ) I have created Snapshot Policy in Source Cluster to run the snapshot at 5:30 PM PST ever…

---

## [Unable to add additional role to elastic instance in elastic cloud](https://discuss.elastic.co/t/unable-to-add-additional-role-to-elastic-instance-in-elastic-cloud/352081)

<div class="topic-metadata">

**Author:** [@RajuParipelly](https://discuss.elastic.co/u/RajuParipelly)\
**Replies:** 7\
**Last updated:** [January 31, 2024, 6:41am UTC](https://discuss.elastic.co/t/unable-to-add-additional-role-to-elastic-instance-in-elastic-cloud/352081 "2024-01-31T06:41:26Z")

</div>

Hello, I was trying to add additional role to the existing elasticsearch instance in the elastic cloud. I added node.roles : \[remote\_cluster\_client\] but while saving it throws the below error, could any one help me wit…

[Previous page](https://discuss.elastic.co/latest.md?page=414)

[Next page](https://discuss.elastic.co/latest.md?page=416)
