# Latest

**URL:** https://discuss.elastic.co/latest.md?page=432

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 433

---

## [Panw.panos TCP grok errors](https://discuss.elastic.co/t/panw-panos-tcp-grok-errors/350993)

<div class="topic-metadata">

**Author:** [@CodeMonky](https://discuss.elastic.co/u/CodeMonky)\
**Replies:** 0\
**Last updated:** [January 12, 2024, 10:03pm UTC](https://discuss.elastic.co/t/panw-panos-tcp-grok-errors/350993 "2024-01-12T22:03:55Z")

</div>

Good day all. I have a question about the Palo Alto Next-Gen Firewall integration. It has two input types, TCP and UDP. We have a client that wanted to move from the UDP to the TCP/SSL connection for security, so we did…

---

## [Support for script\_score in function\_score in Golang client](https://discuss.elastic.co/t/support-for-script-score-in-function-score-in-golang-client/350991)

<div class="topic-metadata">

**Author:** [@rajivhs](https://discuss.elastic.co/u/rajivhs)\
**Replies:** 0\
**Last updated:** [January 12, 2024, 9:34pm UTC](https://discuss.elastic.co/t/support-for-script-score-in-function-score-in-golang-client/350991 "2024-01-12T21:34:41Z")

</div>

Hi. The docs show the following example for using script\_score within function\_score: "query" : { "score\_mode": "multiply", "rescore\_query" : { "function\_score" : { "script\_s…

---

## [Plugin logstash.inputs.tcp debug logging showing many "initialized channel" messages](https://discuss.elastic.co/t/plugin-logstash-inputs-tcp-debug-logging-showing-many-initialized-channel-messages/350990)

<div class="topic-metadata">

**Author:** [@bbenne821](https://discuss.elastic.co/u/bbenne821)\
**Replies:** 0\
**Last updated:** [January 12, 2024, 9:30pm UTC](https://discuss.elastic.co/t/plugin-logstash-inputs-tcp-debug-logging-showing-many-initialized-channel-messages/350990 "2024-01-12T21:30:53Z")

</div>

Running OSS logstash 2.8.2, bundled JDK, on CentOS 7 Linux plugin tcp input specifying "tcp\_keep\_alive=true". Experiencing recurring "closing due: java.net.SocketException: Connection reset" errors for this pipeline (var…

---

## [Force new field to type "keyword" or "text"](https://discuss.elastic.co/t/force-new-field-to-type-keyword-or-text/349665)

<div class="topic-metadata">

**Author:** [@yquirion](https://discuss.elastic.co/u/yquirion)\
**Replies:** 3\
**Last updated:** [January 12, 2024, 8:49pm UTC](https://discuss.elastic.co/t/force-new-field-to-type-keyword-or-text/349665 "2024-01-12T20:49:30Z")

</div>

Hello, I'm currently struggling with an annoying problem who lead to many lost logs into my Elastic cluster. The problem happen when a field that hasn't been defined into the default filebeat template is created. When …

---

## [Errors: reason\\":\\"Unrecognized compile-time parameter(s)](https://discuss.elastic.co/t/errors-reason-unrecognized-compile-time-parameter-s/350988)

<div class="topic-metadata">

**Author:** [@ElasticDev1](https://discuss.elastic.co/u/ElasticDev1)\
**Replies:** 0\
**Last updated:** [January 12, 2024, 8:28pm UTC](https://discuss.elastic.co/t/errors-reason-unrecognized-compile-time-parameter-s/350988 "2024-01-12T20:28:40Z")

</div>

I have written a scriptquery that should work but I keep getting this error "Unrecognized compile-time parameter(s)". I have even super simplified my script where I just "return true", and continue to get the same error…

---

## [Return just some fields using Transform](https://discuss.elastic.co/t/return-just-some-fields-using-transform/350887)

<div class="topic-metadata">

**Author:** [@jcruz](https://discuss.elastic.co/u/jcruz)\
**Replies:** 7\
**Last updated:** [January 12, 2024, 7:24pm UTC](https://discuss.elastic.co/t/return-just-some-fields-using-transform/350887 "2024-01-12T19:24:41Z")

</div>

Hi there! I'm setting up a latest transform, and I would like to know if is it possible to return just some fields (from the original index) into the new transform index. I've tried to copy those needed fields and then …

---

## [Using elasticsearch enterprise app search with langchain for vector query](https://discuss.elastic.co/t/using-elasticsearch-enterprise-app-search-with-langchain-for-vector-query/349810)

<div class="topic-metadata">

**Author:** [@elitzur\_e](https://discuss.elastic.co/u/elitzur_e)\
**Replies:** 1\
**Last updated:** [January 12, 2024, 6:36pm UTC](https://discuss.elastic.co/t/using-elasticsearch-enterprise-app-search-with-langchain-for-vector-query/349810 "2024-01-12T18:36:53Z")

</div>

Hi. i have a working website with app-search and the web crwaler that crewals my site and uses the system created index. i am trying to use that data in that index and use it as a source for ai queries. i keep getting …

---

## [Unable to start Logstash as a service. Errors with: Unable to locate required config /etc/logstash/logstash.conf](https://discuss.elastic.co/t/unable-to-start-logstash-as-a-service-errors-with-unable-to-locate-required-config-etc-logstash-logstash-conf/350938)

<div class="topic-metadata">

**Author:** [@Maiky](https://discuss.elastic.co/u/Maiky)\
**Replies:** 3\
**Last updated:** [January 12, 2024, 6:33pm UTC](https://discuss.elastic.co/t/unable-to-start-logstash-as-a-service-errors-with-unable-to-locate-required-config-etc-logstash-logstash-conf/350938 "2024-01-12T18:33:40Z")

</div>

Hi, On RHEL7 I'm able to run logstash v 7.17 directly as root like so: logstash -f /home/maiky/first-pipeline.conf --config.reload.automatic However when trying to run it as a service, I get the following error: Job …

---

## [Toggling rules on or off](https://discuss.elastic.co/t/toggling-rules-on-or-off/350435)

<div class="topic-metadata">

**Author:** [@Gromit27](https://discuss.elastic.co/u/Gromit27)\
**Replies:** 1\
**Last updated:** [January 12, 2024, 5:53pm UTC](https://discuss.elastic.co/t/toggling-rules-on-or-off/350435 "2024-01-12T17:53:52Z")

</div>

Is there any way of knowing if a rule is toggled on or off, can I see that in an index or something? I would like to create a rule that is triggered when a rule is toggeld from status on to status off. BR

---

## [Native SOAR in Elastic](https://discuss.elastic.co/t/native-soar-in-elastic/350977)

<div class="topic-metadata">

**Author:** [@blueoreo](https://discuss.elastic.co/u/blueoreo)\
**Replies:** 1\
**Last updated:** [January 12, 2024, 5:39pm UTC](https://discuss.elastic.co/t/native-soar-in-elastic/350977 "2024-01-12T17:39:24Z")

</div>

Hi Team, I wanted some help in clarifying the capabilities of Elastic Products. For native SOAR Capabilities, is it provided by Elastic Security? Additionally, what are the features of the native SOAR Platform? Thank…

---

## [Group results in visualization](https://discuss.elastic.co/t/group-results-in-visualization/350735)

<div class="topic-metadata">

**Author:** [@KaBergmanis](https://discuss.elastic.co/u/KaBergmanis)\
**Replies:** 5\
**Last updated:** [January 12, 2024, 5:31pm UTC](https://discuss.elastic.co/t/group-results-in-visualization/350735 "2024-01-12T17:31:05Z")

</div>

Hello! I've set up search that pulls out OS versions from VPN data feed. All working as expected. Then I created pie chart showing count of OS versions, again, so far so good, please see attached. Issue: There are mul…

---

## [Invalid UTF-8](https://discuss.elastic.co/t/invalid-utf-8/350978)

<div class="topic-metadata">

**Author:** [@cyberzlo](https://discuss.elastic.co/u/cyberzlo)\
**Replies:** 7\
**Last updated:** [January 12, 2024, 5:10pm UTC](https://discuss.elastic.co/t/invalid-utf-8/350978 "2024-01-12T17:10:44Z")

</div>

I've been using ruby to decode hex to ascii if (\[field\]) { mutate { gsub =\> \[ "\[field\]", ":", "" \] } ruby { code =\> 'event.set("\[field\]", \[event.get("\[field\]")\].pack("H\*"))' } } but I'v…

---

## [Need Help Monitoring Windows Logs with ELK Stack](https://discuss.elastic.co/t/need-help-monitoring-windows-logs-with-elk-stack/350130)

<div class="topic-metadata">

**Author:** [@qu\_c\_th\_nguy\_n](https://discuss.elastic.co/u/qu_c_th_nguy_n)\
**Replies:** 1\
**Last updated:** [January 12, 2024, 4:59pm UTC](https://discuss.elastic.co/t/need-help-monitoring-windows-logs-with-elk-stack/350130 "2024-01-12T16:59:40Z")

</div>

Hey everyone, I'm a newbie trying to figure out how to monitor Windows log events using ELK Stack and Winlogbeat. I've got them installed, but now I'm a bit lost on what to do with all the info. Any advice, tutorials, …

---

## [Is there a way to access old documentation search system?](https://discuss.elastic.co/t/is-there-a-way-to-access-old-documentation-search-system/350869)

<div class="topic-metadata">

**Author:** [@Incauto](https://discuss.elastic.co/u/Incauto)\
**Replies:** 2\
**Last updated:** [January 12, 2024, 4:56pm UTC](https://discuss.elastic.co/t/is-there-a-way-to-access-old-documentation-search-system/350869 "2024-01-12T16:56:13Z")

</div>

Just yesterday I was studing for a certifcation, and I was able to reach anything I want with just a couple of words and some filtering (version, documentation, plataform) but now I reach page 10 (got bored) in the searc…

---

## [Sum average](https://discuss.elastic.co/t/sum-average/350945)

<div class="topic-metadata">

**Author:** [@francieliton\_araujo](https://discuss.elastic.co/u/francieliton_araujo)\
**Replies:** 1\
**Last updated:** [January 12, 2024, 4:51pm UTC](https://discuss.elastic.co/t/sum-average/350945 "2024-01-12T16:51:24Z")

</div>

could you help me create a dashboard and a canvas, which first adds up to a group and then makes an average, dividing

---

## [Setting default number of replicas for new indexes?](https://discuss.elastic.co/t/setting-default-number-of-replicas-for-new-indexes/350835)

<div class="topic-metadata">

**Author:** [@emoxam](https://discuss.elastic.co/u/emoxam)\
**Replies:** 4\
**Last updated:** [January 12, 2024, 4:49pm UTC](https://discuss.elastic.co/t/setting-default-number-of-replicas-for-new-indexes/350835 "2024-01-12T16:49:49Z")

</div>

addidng index.number\_of\_replicas: 0 to /etc/elasticsearch/elasticsearch.yml doesn't work. With this option elasticsearch doesn't start. at the log i see fatal exception while booting Elasticsearch java.lang.IllegalArgu…

---

## [Declaring static string array](https://discuss.elastic.co/t/declaring-static-string-array/350880)

<div class="topic-metadata">

**Author:** [@dat\_boi](https://discuss.elastic.co/u/dat_boi)\
**Replies:** 2\
**Last updated:** [January 12, 2024, 3:57pm UTC](https://discuss.elastic.co/t/declaring-static-string-array/350880 "2024-01-12T15:57:07Z")

</div>

So i'v been trying to create a very simple array of strings like so : String\[\] painfull\_lang = \[ "word1","word2","word3"\]; but i keep getting syntax errors Cannot cast from \[java.util.ArrayList\] to \[java.lang.String…

---

## [\[Upgrade from 7.6.2 to 7.17.15\] Cannot find symbol import org.elasticsearch.client.RestClientBuilder;](https://discuss.elastic.co/t/upgrade-from-7-6-2-to-7-17-15-cannot-find-symbol-import-org-elasticsearch-client-restclientbuilder/350894)

<div class="topic-metadata">

**Author:** [@chrisssss](https://discuss.elastic.co/u/chrisssss)\
**Replies:** 0\
**Last updated:** [January 12, 2024, 12:55am UTC](https://discuss.elastic.co/t/upgrade-from-7-6-2-to-7-17-15-cannot-find-symbol-import-org-elasticsearch-client-restclientbuilder/350894 "2024-01-12T00:55:16Z")

</div>

Hello, I am trying to upgrade the elasticsearch for java from 7.6.2 to 7.16.15, but the following classes seem to be deprecated: .......Producer.java:15: error: cannot find symbol import org.elasticsearch.client.RestCl…

---

## [Time range based on timestamp in DSL query](https://discuss.elastic.co/t/time-range-based-on-timestamp-in-dsl-query/350962)

<div class="topic-metadata">

**Author:** [@LeCalve](https://discuss.elastic.co/u/LeCalve)\
**Replies:** 3\
**Last updated:** [January 12, 2024, 2:57pm UTC](https://discuss.elastic.co/t/time-range-based-on-timestamp-in-dsl-query/350962 "2024-01-12T14:57:31Z")

</div>

Hello, I want to make a filter based on the time of a timestamp. I would like to extract all timestamps which have a time \< 8 or time \> 20. I don't know how to make the DSL query for that :slight\_smile: {

---

## [Elastic Agents on Openshift cluster agent name set incorrectly to pod name](https://discuss.elastic.co/t/elastic-agents-on-openshift-cluster-agent-name-set-incorrectly-to-pod-name/350964)

<div class="topic-metadata">

**Author:** [@HansPeterSloot](https://discuss.elastic.co/u/HansPeterSloot)\
**Replies:** 3\
**Last updated:** [January 12, 2024, 2:40pm UTC](https://discuss.elastic.co/t/elastic-agents-on-openshift-cluster-agent-name-set-incorrectly-to-pod-name/350964 "2024-01-12T14:40:24Z")

</div>

Hello all In our environment I do have multiple Openshift/Kubernetes clusters. We do use Observability and Security and configured multiple Fleet Policies to separate the different Operating Systems. In addition we al…

---

## [Utilize serilog sinks to elastic search](https://discuss.elastic.co/t/utilize-serilog-sinks-to-elastic-search/350969)

<div class="topic-metadata">

**Author:** [@minh.tran](https://discuss.elastic.co/u/minh.tran)\
**Replies:** 0\
**Last updated:** [January 12, 2024, 2:36pm UTC](https://discuss.elastic.co/t/utilize-serilog-sinks-to-elastic-search/350969 "2024-01-12T14:36:01Z")

</div>

Hi there, we are currently using seirlog elastic sink. Details can be found here GitHub - serilog-contrib/serilog-sinks-elasticsearch: A Serilog sink that writes events to Elasticsearch Is there a way we can make the si…

---

## [Mapping conflict](https://discuss.elastic.co/t/mapping-conflict/350919)

<div class="topic-metadata">

**Author:** [@mb19](https://discuss.elastic.co/u/mb19)\
**Replies:** 7\
**Last updated:** [January 12, 2024, 2:30pm UTC](https://discuss.elastic.co/t/mapping-conflict/350919 "2024-01-12T14:30:14Z")

</div>

Hello everyone, I am new to using the Elasticsearch and Kiabana stack, I do not currently have Logstash installed and would prefer not to install it. I recently had this error: I don't know how to fix it, I think I…

---

## [Analysis is not available for this field](https://discuss.elastic.co/t/analysis-is-not-available-for-this-field/350965)

<div class="topic-metadata">

**Author:** [@cyberzlo](https://discuss.elastic.co/u/cyberzlo)\
**Replies:** 1\
**Last updated:** [January 12, 2024, 2:25pm UTC](https://discuss.elastic.co/t/analysis-is-not-available-for-this-field/350965 "2024-01-12T14:25:19Z")

</div>

Kibana for some fields that used to work now returns me a Analysis is not available for this field. message and they do not show up in Discover tables etc. It is also impossible to search using these fields such as field…

---

## [Facing issue in elasticsearch - /usr/share/elasticsearch/config/elasticsearch.keystore: Device or resource busy](https://discuss.elastic.co/t/facing-issue-in-elasticsearch-usr-share-elasticsearch-config-elasticsearch-keystore-device-or-resource-busy/350905)

<div class="topic-metadata">

**Author:** [@Akshay04](https://discuss.elastic.co/u/Akshay04)\
**Replies:** 1\
**Last updated:** [January 12, 2024, 2:23pm UTC](https://discuss.elastic.co/t/facing-issue-in-elasticsearch-usr-share-elasticsearch-config-elasticsearch-keystore-device-or-resource-busy/350905 "2024-01-12T14:23:49Z")

</div>

Hello, I'm trying to enable Google OAuth with Elasticsearch using - Set up OpenID Connect with Azure, Google, or Okta | Elasticsearch Service Documentation | Elastic I'm deploying this to Kubernetes and using Elastic …

---

## [Jenkins logstash plugin don't send build log](https://discuss.elastic.co/t/jenkins-logstash-plugin-dont-send-build-log/350967)

<div class="topic-metadata">

**Author:** [@khergner](https://discuss.elastic.co/u/khergner)\
**Replies:** 0\
**Last updated:** [January 12, 2024, 2:09pm UTC](https://discuss.elastic.co/t/jenkins-logstash-plugin-dont-send-build-log/350967 "2024-01-12T14:09:22Z")

</div>

Hi everyone I have a problem. ı want to use logstash plugin with jenkins. İt isn't send build log elasticsearch but ı have bellow error. I don't upgrade logstash latest plugin because many plugin must upgrade from jenk…

---

## [Custom logs from Logstash to Cloudwatch](https://discuss.elastic.co/t/custom-logs-from-logstash-to-cloudwatch/350955)

<div class="topic-metadata">

**Author:** [@Vadsgator](https://discuss.elastic.co/u/Vadsgator)\
**Replies:** 1\
**Last updated:** [January 12, 2024, 1:55pm UTC](https://discuss.elastic.co/t/custom-logs-from-logstash-to-cloudwatch/350955 "2024-01-12T13:55:28Z")

</div>

Hiya, Currently there is no actual support to send custom logs from Logstash to Cloudwatch. (There is a way to send metrics data using the Cloudwatch Output Plugin) and there was some support for a plugin called logstas…

---

## [Managing Large Document Uploads: Performance and Limitations in Elasticsearch vs. Standard App Search Engines](https://discuss.elastic.co/t/managing-large-document-uploads-performance-and-limitations-in-elasticsearch-vs-standard-app-search-engines/350948)

<div class="topic-metadata">

**Author:** [@Chenko](https://discuss.elastic.co/u/Chenko)\
**Replies:** 1\
**Last updated:** [January 12, 2024, 1:49pm UTC](https://discuss.elastic.co/t/managing-large-document-uploads-performance-and-limitations-in-elasticsearch-vs-standard-app-search-engines/350948 "2024-01-12T13:49:33Z")

</div>

Hello, We're encountering a challenge with a client who needs to upload large documents using App Search — larger than 10MB per individual document and up to 100MB in total for bulk requests. Our current setup utilizes …

---

## [How can I implement this with the latest Elasticsearch C# client version, v8?](https://discuss.elastic.co/t/how-can-i-implement-this-with-the-latest-elasticsearch-c-client-version-v8/350951)

<div class="topic-metadata">

**Author:** [@David\_Silwal](https://discuss.elastic.co/u/David_Silwal)\
**Replies:** 0\
**Last updated:** [January 12, 2024, 12:49pm UTC](https://discuss.elastic.co/t/how-can-i-implement-this-with-the-latest-elasticsearch-c-client-version-v8/350951 "2024-01-12T12:49:04Z")

</div>

How can I implement this with the latest Elasticsearch C# client version, v8? var searchResponse = elasticClient .Search\<Case\>(s =\> s .Index(IndexNames.Cases) .Query(q =\> q .Match(m =\> m .Field("Description") .Query(que…

---

## [Transfer indices to new cluster](https://discuss.elastic.co/t/transfer-indices-to-new-cluster/350946)

<div class="topic-metadata">

**Author:** [@JimJ](https://discuss.elastic.co/u/JimJ)\
**Replies:** 0\
**Last updated:** [January 12, 2024, 12:40pm UTC](https://discuss.elastic.co/t/transfer-indices-to-new-cluster/350946 "2024-01-12T12:40:19Z")

</div>

I put in place a new Elastic cluster v8.7 to replace an old one in v7.12. In Elastic cluster v8.7, I started using Datastreams. My question: what is the best way to transfer indices' data from old cluster to datastream…

---

## [System indexes stuck initializing state](https://discuss.elastic.co/t/system-indexes-stuck-initializing-state/350937)

<div class="topic-metadata">

**Author:** [@joao-subtil](https://discuss.elastic.co/u/joao-subtil)\
**Replies:** 0\
**Last updated:** [January 12, 2024, 11:24am UTC](https://discuss.elastic.co/t/system-indexes-stuck-initializing-state/350937 "2024-01-12T11:24:58Z")

</div>

Hello, I am using Elastic 8.11 and was attempting to setup a cluster with ilm for hot/warm/cold. However after creating the instance and roles and users I get the system indices stuck in initializing state and cannot m…

[Previous page](https://discuss.elastic.co/latest.md?page=431)

[Next page](https://discuss.elastic.co/latest.md?page=433)
