# Latest

**URL:** https://discuss.elastic.co/latest.md?page=451

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 452

---

## [Is it possible to add configuration options when using hints based autodiscover with heartbeat?](https://discuss.elastic.co/t/is-it-possible-to-add-configuration-options-when-using-hints-based-autodiscover-with-heartbeat/349478)

<div class="topic-metadata">

**Author:** [@dfinn](https://discuss.elastic.co/u/dfinn)\
**Replies:** 2\
**Last updated:** [December 18, 2023, 10:01pm UTC](https://discuss.elastic.co/t/is-it-possible-to-add-configuration-options-when-using-hints-based-autodiscover-with-heartbeat/349478 "2023-12-18T22:01:40Z")

</div>

We are using heartbeat to monitor our k8s service and we are doing this with hints based auto discovery via annotations that we set on a service. I would like to have this service include the response body and I see tha…

---

## [Elasticsearch Query Multiple Must Nots](https://discuss.elastic.co/t/elasticsearch-query-multiple-must-nots/349570)

<div class="topic-metadata">

**Author:** [@Elk\_huh](https://discuss.elastic.co/u/Elk_huh)\
**Replies:** 7\
**Last updated:** [December 18, 2023, 7:28pm UTC](https://discuss.elastic.co/t/elasticsearch-query-multiple-must-nots/349570 "2023-12-18T19:28:37Z")

</div>

Is it possible to have 2 different must not query strings across two different fields I have this but it doesnt let me have 2 query strings GET winevents/\_search { "query": { "bool": { "must": \[ { …

---

## [Rules failing](https://discuss.elastic.co/t/rules-failing/349470)

<div class="topic-metadata">

**Author:** [@bbreer](https://discuss.elastic.co/u/bbreer)\
**Replies:** 2\
**Last updated:** [December 18, 2023, 7:25pm UTC](https://discuss.elastic.co/t/rules-failing/349470 "2023-12-18T19:25:17Z")

</div>

Hi, I have several rules that come back as Failed after running. I'm getting the following error for many rules. The field names for the unknown column message varies among the different rules. An error occurred during…

---

## [Logstash not connecting to Elasticsearch - using Docker-Compose](https://discuss.elastic.co/t/logstash-not-connecting-to-elasticsearch-using-docker-compose/349461)

<div class="topic-metadata">

**Author:** [@zewcro](https://discuss.elastic.co/u/zewcro)\
**Replies:** 12\
**Last updated:** [December 18, 2023, 6:19pm UTC](https://discuss.elastic.co/t/logstash-not-connecting-to-elasticsearch-using-docker-compose/349461 "2023-12-18T18:19:57Z")

</div>

Hello, I'm trying to create indexes in elasticsearch from a postgresql database. So I set up docker compose: version: '3.8' services: postgres: image: postgres:latest volumes: - C:\\Users\\theor\\desktop…

---

## [OIDC without TLS](https://discuss.elastic.co/t/oidc-without-tls/349580)

<div class="topic-metadata">

**Author:** [@Jo\_han](https://discuss.elastic.co/u/Jo_han)\
**Replies:** 0\
**Last updated:** [December 18, 2023, 4:39pm UTC](https://discuss.elastic.co/t/oidc-without-tls/349580 "2023-12-18T16:39:01Z")

</div>

Hello, I am deploying ECK in an on-premise Kubernetes cluster with Istio installed. We drew a security perimeter at our gateway. Meaning all the services are only reachable through the gateway, where TLS and authentica…

---

## [Massive performance degradation when terms filter has over 16 values?](https://discuss.elastic.co/t/massive-performance-degradation-when-terms-filter-has-over-16-values/349106)

<div class="topic-metadata">

**Author:** [@elastic\_dude](https://discuss.elastic.co/u/elastic_dude)\
**Replies:** 9\
**Last updated:** [December 18, 2023, 4:19pm UTC](https://discuss.elastic.co/t/massive-performance-degradation-when-terms-filter-has-over-16-values/349106 "2023-12-18T16:19:50Z")

</div>

Came across some odd behavior. We have a query that performs in the tens of milliseconds until we go over 16 values in our terms filter. When 17 or more are included the performance degrades by 15-20 multiples. Here is …

---

## [Highlight the not correct matching keyword](https://discuss.elastic.co/t/highlight-the-not-correct-matching-keyword/349576)

<div class="topic-metadata">

**Author:** [@ahyh](https://discuss.elastic.co/u/ahyh)\
**Replies:** 0\
**Last updated:** [December 18, 2023, 4:05pm UTC](https://discuss.elastic.co/t/highlight-the-not-correct-matching-keyword/349576 "2023-12-18T16:05:50Z")

</div>

Hello, I got a problem about highlight query, the highlight result maybe not matching the filter, I am not sure is this a problem with Elasticsearch or not, could you please help confirm? This is my data in /test: { "…

---

## [Match phrase and multi\_match together](https://discuss.elastic.co/t/match-phrase-and-multi-match-together/349574)

<div class="topic-metadata">

**Author:** [@varindert](https://discuss.elastic.co/u/varindert)\
**Replies:** 0\
**Last updated:** [December 18, 2023, 3:51pm UTC](https://discuss.elastic.co/t/match-phrase-and-multi-match-together/349574 "2023-12-18T15:51:29Z")

</div>

Hello, just wondering how I can implement match phrase (on multiple fields) and multi\_match together. I have a basic query going, but I am not able to figure out phrase match on multiple fields. I want results return in …

---

## [Index template - settings](https://discuss.elastic.co/t/index-template-settings/349568)

<div class="topic-metadata">

**Author:** [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Replies:** 0\
**Last updated:** [December 18, 2023, 2:56pm UTC](https://discuss.elastic.co/t/index-template-settings/349568 "2023-12-18T14:56:12Z")

</div>

Hi All, I set up ILM for a particular index pattern. After applying this when I check index settings I see the following output: GET abc-90010-2023.12.18/\_settings { "abc-90010-2023.12.18": { "settings": { …

---

## [Runtime script: access list of fields](https://discuss.elastic.co/t/runtime-script-access-list-of-fields/349561)

<div class="topic-metadata">

**Author:** [@dao](https://discuss.elastic.co/u/dao)\
**Replies:** 1\
**Last updated:** [December 18, 2023, 2:44pm UTC](https://discuss.elastic.co/t/runtime-script-access-list-of-fields/349561 "2023-12-18T14:44:51Z")

</div>

hello, I try to create a field that is an array of strings. Each string is the name of a field example: I have docs like this: { a: 1, b:2, toto: 'processed', tata:'processed' } I want to create a field that will be…

---

## [APM Server Fleet managed vs Legacy: incompatible?](https://discuss.elastic.co/t/apm-server-fleet-managed-vs-legacy-incompatible/349074)

<div class="topic-metadata">

**Author:** [@Attila\_Szeremi](https://discuss.elastic.co/u/Attila_Szeremi)\
**Replies:** 1\
**Last updated:** [December 18, 2023, 2:26pm UTC](https://discuss.elastic.co/t/apm-server-fleet-managed-vs-legacy-incompatible/349074 "2023-12-18T14:26:37Z")

</div>

In our company with APM before Fleet, we used to not only view transactions in APM, but also create dashboard charts about the transactions in Kibana; statistics about how fast HTTP requests take and things like that. F…

---

## [Help needed for certificate configuration](https://discuss.elastic.co/t/help-needed-for-certificate-configuration/349194)

<div class="topic-metadata">

**Author:** [@litronics](https://discuss.elastic.co/u/litronics)\
**Replies:** 13\
**Last updated:** [December 18, 2023, 2:14pm UTC](https://discuss.elastic.co/t/help-needed-for-certificate-configuration/349194 "2023-12-18T14:14:11Z")

</div>

Elasticsearch drives me nuts when it comes to certificates and how they are used / configured. This is my current configuration: ## Cluster Settings cluster.name: "elk-tls-cluster" node.name: node-1 network.host: "0.0.…

---

## [Manually execute ILM policy](https://discuss.elastic.co/t/manually-execute-ilm-policy/349560)

<div class="topic-metadata">

**Author:** [@rschirin](https://discuss.elastic.co/u/rschirin)\
**Replies:** 1\
**Last updated:** [December 18, 2023, 1:44pm UTC](https://discuss.elastic.co/t/manually-execute-ilm-policy/349560 "2023-12-18T13:44:59Z")

</div>

Hey there, is there a way to manually execute an ILMm policy? If I modify the mapping template for example, I would like to immediately create and use a new updated index, avoiding to wait for example date threshold or …

---

## [How to deploy elastic alert plugin though ECK deployment](https://discuss.elastic.co/t/how-to-deploy-elastic-alert-plugin-though-eck-deployment/349530)

<div class="topic-metadata">

**Author:** [@MahithaSarala](https://discuss.elastic.co/u/MahithaSarala)\
**Replies:** 1\
**Last updated:** [December 18, 2023, 12:40pm UTC](https://discuss.elastic.co/t/how-to-deploy-elastic-alert-plugin-though-eck-deployment/349530 "2023-12-18T12:40:39Z")

</div>

Hi Team, Is it possible to deploy elastic alert plugin on cluster, We deployed already kibana and elasticsearch through eck deployment.I'm refering to this document to install elasticsearch alert. please suggest right p…

---

## [Elastic service stops unexpectedly](https://discuss.elastic.co/t/elastic-service-stops-unexpectedly/349555)

<div class="topic-metadata">

**Author:** [@mreddy9](https://discuss.elastic.co/u/mreddy9)\
**Replies:** 0\
**Last updated:** [December 18, 2023, 12:35pm UTC](https://discuss.elastic.co/t/elastic-service-stops-unexpectedly/349555 "2023-12-18T12:35:51Z")

</div>

Hi all, Sometime Elasticsearch service stops unexpectedly in the weekend and there are no details in logs to identify the exact issue. Please suggest any solution if you already come across this issue in past. log deta…

---

## [Kibana discover show wrong result when filter by date type field](https://discuss.elastic.co/t/kibana-discover-show-wrong-result-when-filter-by-date-type-field/349316)

<div class="topic-metadata">

**Author:** [@bbhhhh](https://discuss.elastic.co/u/bbhhhh)\
**Replies:** 3\
**Last updated:** [December 18, 2023, 12:08pm UTC](https://discuss.elastic.co/t/kibana-discover-show-wrong-result-when-filter-by-date-type-field/349316 "2023-12-18T12:08:01Z")

</div>

I created an index template 'order-index-template' which defined a date type mapping: ... "index\_patterns": \[ "order-index" \], "mappings": { "properties": { "orderTime": { "type": "date" …

---

## [Logstash error Cpu.cfs\_period\_us cannot be found](https://discuss.elastic.co/t/logstash-error-cpu-cfs-period-us-cannot-be-found/349515)

<div class="topic-metadata">

**Author:** [@Lena\_Yoon](https://discuss.elastic.co/u/Lena_Yoon)\
**Replies:** 9\
**Last updated:** [December 18, 2023, 11:43am UTC](https://discuss.elastic.co/t/logstash-error-cpu-cfs-period-us-cannot-be-found/349515 "2023-12-18T11:43:11Z")

</div>

Hello, I have been working with Logstash this week but stuck with below error. The error occurs when retrieving data from Oracle DB using the JDBC input plugin, filtering it in the pipeline, and despite the index being…

---

## [Options for automatic synonyms?](https://discuss.elastic.co/t/options-for-automatic-synonyms/349553)

<div class="topic-metadata">

**Author:** [@Aroueterra](https://discuss.elastic.co/u/Aroueterra)\
**Replies:** 0\
**Last updated:** [December 18, 2023, 10:50am UTC](https://discuss.elastic.co/t/options-for-automatic-synonyms/349553 "2023-12-18T10:50:53Z")

</div>

Hello, just getting started with elastic as a free user. We are currently using a search engine that allows us to search well and rapidly, based on a tag system. So from what I can gather, the tags are similar to the co…

---

## [Merge two buckets muli\_level inside buckets](https://discuss.elastic.co/t/merge-two-buckets-muli-level-inside-buckets/349547)

<div class="topic-metadata">

**Author:** [@Azizi\_BESSEM](https://discuss.elastic.co/u/Azizi_BESSEM)\
**Replies:** 0\
**Last updated:** [December 18, 2023, 10:14am UTC](https://discuss.elastic.co/t/merge-two-buckets-muli-level-inside-buckets/349547 "2023-12-18T10:14:55Z")

</div>

{ "aggregations" : { "alert\_types" : { "doc\_count\_error\_upper\_bound" : 0, "sum\_other\_doc\_count" : 0, "buckets" : \[ { "key" : "1", "doc\_count" : 3, "device\_ref…

---

## [One logstash instance per kubernetes cluster](https://discuss.elastic.co/t/one-logstash-instance-per-kubernetes-cluster/349546)

<div class="topic-metadata">

**Author:** [@codedoings](https://discuss.elastic.co/u/codedoings)\
**Replies:** 0\
**Last updated:** [December 18, 2023, 10:11am UTC](https://discuss.elastic.co/t/one-logstash-instance-per-kubernetes-cluster/349546 "2023-12-18T10:11:01Z")

</div>

Hi, What would be the best approach for configuring logstash in an environment where: Elasticsearch and Kibana are running in their own kubernetes cluster (deployed with ECK). Elasticsearch and Kibana instance is shar…

---

## [Fleet server configurations for elk-apm setup in AKS cluster](https://discuss.elastic.co/t/fleet-server-configurations-for-elk-apm-setup-in-aks-cluster/349542)

<div class="topic-metadata">

**Author:** [@mahimakha](https://discuss.elastic.co/u/mahimakha)\
**Replies:** 2\
**Last updated:** [December 18, 2023, 9:49am UTC](https://discuss.elastic.co/t/fleet-server-configurations-for-elk-apm-setup-in-aks-cluster/349542 "2023-12-18T09:49:35Z")

</div>

Hi I am trying to configure the ELK-APM on AKS cluster. I have been following the documentation as per the given link Run Elastic Agent on Kubernetes managed by Fleet | Fleet and Elastic Agent Guide \[8.5\] | Elastic I a…

---

## [Upgrade from 7.17.14 to 8.11.3 failes](https://discuss.elastic.co/t/upgrade-from-7-17-14-to-8-11-3-failes/349538)

<div class="topic-metadata">

**Author:** [@Ingo\_Voland](https://discuss.elastic.co/u/Ingo_Voland)\
**Replies:** 1\
**Last updated:** [December 18, 2023, 9:39am UTC](https://discuss.elastic.co/t/upgrade-from-7-17-14-to-8-11-3-failes/349538 "2023-12-18T09:39:22Z")

</div>

We have a 1 node elastic installation (7.17.14), upgrading to 8.11.3 failes wiith the error message Caused by: org.elasticsearch.gateway.CorruptStateException: Format version is not supported. Upgrading to \[8.11.3\] is o…

---

## [Dec 18th, 2023: \[EN\] The most magical time of the year: Using semantic search to find the most festive Harry Potter moments](https://discuss.elastic.co/t/dec-18th-2023-en-the-most-magical-time-of-the-year-using-semantic-search-to-find-the-most-festive-harry-potter-moments/347615)

<div class="topic-metadata">

**Author:** [@iulia](https://discuss.elastic.co/u/iulia)\
**Replies:** 0\
**Last updated:** [December 18, 2023, 8:00am UTC](https://discuss.elastic.co/t/dec-18th-2023-en-the-most-magical-time-of-the-year-using-semantic-search-to-find-the-most-festive-harry-potter-moments/347615 "2023-12-18T08:00:30Z")

</div>

Christmas at Hogwarts, anyone? I don't know about you, but for me, Christmas usually means starting (yet another) Harry Potter marathon. While I'm a fan of the Wizarding World year-round, there is something extra fest…

---

## [Filebeat registry file and log.json are not updated](https://discuss.elastic.co/t/filebeat-registry-file-and-log-json-are-not-updated/349535)

<div class="topic-metadata">

**Author:** [@sheldonyip](https://discuss.elastic.co/u/sheldonyip)\
**Replies:** 0\
**Last updated:** [December 18, 2023, 7:39am UTC](https://discuss.elastic.co/t/filebeat-registry-file-and-log-json-are-not-updated/349535 "2023-12-18T07:39:20Z")

</div>

Pls help to find the root cause. The file beat was originally uploaded to ELK, but suddenly the registry and log.json did not update. Filebeat version is 7.17.7, and the OS is Red Hat Enterprise Linux release 8.8 (Ootp…

---

## [Unable to observe Security alerts in Elastic Security](https://discuss.elastic.co/t/unable-to-observe-security-alerts-in-elastic-security/349502)

<div class="topic-metadata">

**Author:** [@shrikantgulia](https://discuss.elastic.co/u/shrikantgulia)\
**Replies:** 1\
**Last updated:** [December 18, 2023, 5:22am UTC](https://discuss.elastic.co/t/unable-to-observe-security-alerts-in-elastic-security/349502 "2023-12-18T05:22:41Z")

</div>

Dear Team, I have setup a test environment on elastic cloud and i am ingesting windows events. I created an index with below mapping PUT alerts-security { "settings" : { "number\_of\_shards" : 1 }, "mappings" : { …

---

## [Elastic 8.11.3 on docker in OSX silicon has disk volume sizing issues](https://discuss.elastic.co/t/elastic-8-11-3-on-docker-in-osx-silicon-has-disk-volume-sizing-issues/349522)

<div class="topic-metadata">

**Author:** [@matthal](https://discuss.elastic.co/u/matthal)\
**Replies:** 6\
**Last updated:** [December 18, 2023, 3:09am UTC](https://discuss.elastic.co/t/elastic-8-11-3-on-docker-in-osx-silicon-has-disk-volume-sizing-issues/349522 "2023-12-18T03:09:07Z")

</div>

Trying to run elasticsearch locally for development using docker compose (Getting started with the Elastic Stack and Docker-Compose | Elastic Blog) I end up getting disk pressure issues, well a warning, but it ends up …

---

## [Why does es v8 ship a bundled JDK?](https://discuss.elastic.co/t/why-does-es-v8-ship-a-bundled-jdk/349519)

<div class="topic-metadata">

**Author:** [@buitcj](https://discuss.elastic.co/u/buitcj)\
**Replies:** 2\
**Last updated:** [December 18, 2023, 1:22am UTC](https://discuss.elastic.co/t/why-does-es-v8-ship-a-bundled-jdk/349519 "2023-12-18T01:22:35Z")

</div>

Just curious, are there any customizations done to the JDK that require elasticsearch v8 to require the bundled JDK? What is special about the bundled one? Why can we no longer use our own JDK? TIA!

---

## [Date time with time multifield](https://discuss.elastic.co/t/date-time-with-time-multifield/349513)

<div class="topic-metadata">

**Author:** [@RRGTHWAR1](https://discuss.elastic.co/u/RRGTHWAR1)\
**Replies:** 1\
**Last updated:** [December 18, 2023, 1:18am UTC](https://discuss.elastic.co/t/date-time-with-time-multifield/349513 "2023-12-18T01:18:58Z")

</div>

This has come up from time to time, but I haven’t seen any definitive answers. Is it possible to have a time-only multi-field in a date time field? For example, created\_date would be the full datetime, and created\_date.t…

---

## [Logstash error(no data ) while ingesting CSV data with ELK version 8.9.2](https://discuss.elastic.co/t/logstash-error-no-data-while-ingesting-csv-data-with-elk-version-8-9-2/349510)

<div class="topic-metadata">

**Author:** [@raemonx](https://discuss.elastic.co/u/raemonx)\
**Replies:** 2\
**Last updated:** [December 17, 2023, 10:08pm UTC](https://discuss.elastic.co/t/logstash-error-no-data-while-ingesting-csv-data-with-elk-version-8-9-2/349510 "2023-12-17T22:08:44Z")

</div>

I was facing an issue while ingesting an csv file called housing\_price\_data.csv using logstash. I was using ELK with docker. I was using ELK version 8.11 I did not want to add any security so there is no SSL, passwords o…

---

## [Circuit breaker in Elasticsearch](https://discuss.elastic.co/t/circuit-breaker-in-elasticsearch/349508)

<div class="topic-metadata">

**Author:** [@pksinghal](https://discuss.elastic.co/u/pksinghal)\
**Replies:** 9\
**Last updated:** [December 17, 2023, 5:01pm UTC](https://discuss.elastic.co/t/circuit-breaker-in-elasticsearch/349508 "2023-12-17T17:01:15Z")

</div>

we are running an Elasticsearch cluster with 3 nodes. sometimes a heavy agg query comes(run manually from Kibana dev tools) and one of the nodes becomes inaccessible. So full cluster becomes inaccessible as ES takes so…

[Previous page](https://discuss.elastic.co/latest.md?page=450)

[Next page](https://discuss.elastic.co/latest.md?page=452)
