# Latest

**URL:** https://discuss.elastic.co/latest.md?page=453

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 454

---

## [I Want to remove the duplicate events inside Logstash filter how could I do that? I mention the events below please have a look and suggest](https://discuss.elastic.co/t/i-want-to-remove-the-duplicate-events-inside-logstash-filter-how-could-i-do-that-i-mention-the-events-below-please-have-a-look-and-suggest/349175)

<div class="topic-metadata">

**Author:** [@Subrato1](https://discuss.elastic.co/u/Subrato1)\
**Replies:** 6\
**Last updated:** [December 15, 2023, 1:35pm UTC](https://discuss.elastic.co/t/i-want-to-remove-the-duplicate-events-inside-logstash-filter-how-could-i-do-that-i-mention-the-events-below-please-have-a-look-and-suggest/349175 "2023-12-15T13:35:00Z")

</div>

{ "date" =\> 2023-12-12T00:00:00.000Z, "category" =\> "AUTH", "username" =\> "cassandra", "event\_time" =\> "ab390a7b-98e7-11ee-af20-4b75abbb029d", "node" =\> "172.31.57.239",…

---

## [Fatal exception while booting Elasticsearchorg.elasticsearch.ElasticsearchSecurityException: failed to load SSL configuration \[xpack.security.transport.ssl\] - cannot read configured \[PKCS12\] keystore](https://discuss.elastic.co/t/fatal-exception-while-booting-elasticsearchorg-elasticsearch-elasticsearchsecurityexception-failed-to-load-ssl-configuration-xpack-security-transport-ssl-cannot-read-configured-pkcs12-keystore/349427)

<div class="topic-metadata">

**Author:** [@9631](https://discuss.elastic.co/u/9631)\
**Replies:** 7\
**Last updated:** [December 15, 2023, 10:58am UTC](https://discuss.elastic.co/t/fatal-exception-while-booting-elasticsearchorg-elasticsearch-elasticsearchsecurityexception-failed-to-load-ssl-configuration-xpack-security-transport-ssl-cannot-read-configured-pkcs12-keystore/349427 "2023-12-15T10:58:50Z")

</div>

\[2023-12-15T12:36:37,084\]\[ERROR\]\[o.e.b.Elasticsearch \] \[LAPTOP-ECGDD83N\] fatal exception while booting Elasticsearchorg.elasticsearch.ElasticsearchSecurityException: failed to load SSL configuration \[xpack.security.…

---

## [Searchable Snapshot - S3 - Object Lock](https://discuss.elastic.co/t/searchable-snapshot-s3-object-lock/349418)

<div class="topic-metadata">

**Author:** [@digital-thought](https://discuss.elastic.co/u/digital-thought)\
**Replies:** 3\
**Last updated:** [December 15, 2023, 10:45am UTC](https://discuss.elastic.co/t/searchable-snapshot-s3-object-lock/349418 "2023-12-15T10:45:22Z")

</div>

I have implemented a Frozen Tier with Searchable Snapshots within AWS S3. To further protect the data and prevent deletion, I am looking to setup "Object Lock". Will the use of "Object Lock" interfere in anyway with El…

---

## [How bad is it for Elasticsearch peformance to use external disk storage?](https://discuss.elastic.co/t/how-bad-is-it-for-elasticsearch-peformance-to-use-external-disk-storage/349442)

<div class="topic-metadata">

**Author:** [@mtovmassian](https://discuss.elastic.co/u/mtovmassian)\
**Replies:** 0\
**Last updated:** [December 15, 2023, 9:36am UTC](https://discuss.elastic.co/t/how-bad-is-it-for-elasticsearch-peformance-to-use-external-disk-storage/349442 "2023-12-15T09:36:45Z")

</div>

I am currently running a small cluster of 3 nodes with a size (shards considered) of =~ 200GB. But disk usage keeps increasing and hard drives are about to reach saturation. I know that Elasticsearch need to be as clo…

---

## [Dec 15th, 2023: \[ES\] Haciendo mapas navideños con Elasticsearch y MapLibre](https://discuss.elastic.co/t/dec-15th-2023-es-haciendo-mapas-navidenos-con-elasticsearch-y-maplibre/349051)

<div class="topic-metadata">

**Author:** [@jsanz](https://discuss.elastic.co/u/jsanz)\
**Replies:** 0\
**Last updated:** [December 15, 2023, 8:00am UTC](https://discuss.elastic.co/t/dec-15th-2023-es-haciendo-mapas-navidenos-con-elasticsearch-y-maplibre/349051 "2023-12-15T08:00:37Z")

</div>

Este artículo está también disponible en Inglés Introducción Una de las sugerencias de seguridad más habituales relacionadas con Elasticsearch es que nunca debes exponer tu clúster en Internet. Pero como estamos en l…

---

## [Dec 15th, 2023: \[EN\] Mapping Christmas places with Elasticsearch and MapLibre](https://discuss.elastic.co/t/dec-15th-2023-en-mapping-christmas-places-with-elasticsearch-and-maplibre/346727)

<div class="topic-metadata">

**Author:** [@jsanz](https://discuss.elastic.co/u/jsanz)\
**Replies:** 0\
**Last updated:** [December 15, 2023, 8:00am UTC](https://discuss.elastic.co/t/dec-15th-2023-en-mapping-christmas-places-with-elasticsearch-and-maplibre/346727 "2023-12-15T08:00:37Z")

</div>

This post is also available in Spanish Introduction One of the most well-known security practices is to never expose your Elasticsearch cluster to the Internet. But we are in the Christmas season, and we like to be f…

---

## [Search, filtering and faceting on date range and sum price](https://discuss.elastic.co/t/search-filtering-and-faceting-on-date-range-and-sum-price/349430)

<div class="topic-metadata">

**Author:** [@milovindo](https://discuss.elastic.co/u/milovindo)\
**Replies:** 0\
**Last updated:** [December 15, 2023, 8:00am UTC](https://discuss.elastic.co/t/search-filtering-and-faceting-on-date-range-and-sum-price/349430 "2023-12-15T08:00:10Z")

</div>

I index with these mappings { "mappings": { "properties": { "coords": { "type": "geo\_point" }, "id": { "type": "text", "fields": { "keyword": { "type…

---

## [Problems with simple python Elastic connection. Documentation Wrong?](https://discuss.elastic.co/t/problems-with-simple-python-elastic-connection-documentation-wrong/349400)

<div class="topic-metadata">

**Author:** [@allan.silverstein](https://discuss.elastic.co/u/allan.silverstein)\
**Replies:** 2\
**Last updated:** [December 15, 2023, 6:49am UTC](https://discuss.elastic.co/t/problems-with-simple-python-elastic-connection-documentation-wrong/349400 "2023-12-15T06:49:00Z")

</div>

I spent about an hour on what seems like a simple getting started exercise. Just connecting to the elastic stack with the python client. Leaving out all of the trial and error detail. The documentation shows that the …

---

## [How to specify a default value for my field in grok pattern match](https://discuss.elastic.co/t/how-to-specify-a-default-value-for-my-field-in-grok-pattern-match/349310)

<div class="topic-metadata">

**Author:** [@ameeto17](https://discuss.elastic.co/u/ameeto17)\
**Replies:** 9\
**Last updated:** [December 15, 2023, 5:53am UTC](https://discuss.elastic.co/t/how-to-specify-a-default-value-for-my-field-in-grok-pattern-match/349310 "2023-12-15T05:53:26Z")

</div>

I have a pattern to match using GROK Dec 14 03:13:01 ppddc1kfep302 my-checker: Context SHA of VSP Logger Software da39a3ee5e6b4b0d3255bfef95601890afd80709 I have the format below for the match %{SYSLOGTIMESTAMP}%{SPAC…

---

## [APM latency statistics - what is it exactly? why does it not align with "transaction.duration.us"?](https://discuss.elastic.co/t/apm-latency-statistics-what-is-it-exactly-why-does-it-not-align-with-transaction-duration-us/349412)

<div class="topic-metadata">

**Author:** [@cozog](https://discuss.elastic.co/u/cozog)\
**Replies:** 2\
**Last updated:** [December 15, 2023, 5:07am UTC](https://discuss.elastic.co/t/apm-latency-statistics-what-is-it-exactly-why-does-it-not-align-with-transaction-duration-us/349412 "2023-12-15T05:07:53Z")

</div>

Kibana version: 8.5.3 Elasticsearch version: 8.5.3 APM Server version: 8.5.3 APM Agent language and version: Java, 1.26.0 Hi, We have APM visualizations that are showing us average latency: now i am also trying …

---

## [Support for CloudWatch Metric Streams](https://discuss.elastic.co/t/support-for-cloudwatch-metric-streams/349399)

<div class="topic-metadata">

**Author:** [@RichiCoder](https://discuss.elastic.co/u/RichiCoder)\
**Replies:** 0\
**Last updated:** [December 14, 2023, 11:24pm UTC](https://discuss.elastic.co/t/support-for-cloudwatch-metric-streams/349399 "2023-12-14T23:24:35Z")

</div>

Elastic recently added the ability to receive CloudWatch logs via Kinesis Data Firehouse, which offers and excellent (and cheaper) way to forward log data into Elastic. I'd love to see a similar capability like that for…

---

## [Behaviour of match\_phrase\_prefix in ES ES 8.9.0 is different from that in 7.17.7](https://discuss.elastic.co/t/behaviour-of-match-phrase-prefix-in-es-es-8-9-0-is-different-from-that-in-7-17-7/348283)

<div class="topic-metadata">

**Author:** [@elastic-a](https://discuss.elastic.co/u/elastic-a)\
**Replies:** 1\
**Last updated:** [December 14, 2023, 10:06pm UTC](https://discuss.elastic.co/t/behaviour-of-match-phrase-prefix-in-es-es-8-9-0-is-different-from-that-in-7-17-7/348283 "2023-12-14T22:06:45Z")

</div>

ES 8.9.0 With a query having match\_phrase\_prefix of just one term, the search returns expected match; with the same query, percolate by id does not return expected match. The same (both search and percolate) work as ex…

---

## [Please point me to a good article on how to "Optimally size Elasticsearch Thread Pools"](https://discuss.elastic.co/t/please-point-me-to-a-good-article-on-how-to-optimally-size-elasticsearch-thread-pools/349397)

<div class="topic-metadata">

**Author:** [@andrew3](https://discuss.elastic.co/u/andrew3)\
**Replies:** 2\
**Last updated:** [December 14, 2023, 9:38pm UTC](https://discuss.elastic.co/t/please-point-me-to-a-good-article-on-how-to-optimally-size-elasticsearch-thread-pools/349397 "2023-12-14T21:38:33Z")

</div>

We're pushing a lot of data in the form of bulk indexing requests and saturating the available thread pools. Can you point me to a good article on optimally sizing ES thread pools? Thanks.

---

## [Monitor and alert on custom company windows services](https://discuss.elastic.co/t/monitor-and-alert-on-custom-company-windows-services/349202)

<div class="topic-metadata">

**Author:** [@CodeCraft](https://discuss.elastic.co/u/CodeCraft)\
**Replies:** 8\
**Last updated:** [December 14, 2023, 9:12pm UTC](https://discuss.elastic.co/t/monitor-and-alert-on-custom-company-windows-services/349202 "2023-12-14T21:12:01Z")

</div>

We need to monitor custom company windows services and send an alert when one of them stops. We have added the Windows Integration to the agent profile for the server that we want to monitor the Windows services on. We …

---

## [Logstash runs on the linux container and extremely slow](https://discuss.elastic.co/t/logstash-runs-on-the-linux-container-and-extremely-slow/349249)

<div class="topic-metadata">

**Author:** [@ranjini](https://discuss.elastic.co/u/ranjini)\
**Replies:** 3\
**Last updated:** [December 14, 2023, 6:22pm UTC](https://discuss.elastic.co/t/logstash-runs-on-the-linux-container-and-extremely-slow/349249 "2023-12-14T18:22:56Z")

</div>

logstash runs on linux container. Below is my configuration. It is very slow. Sharing my configuration for reference. This is my service configuration. file { path =\> "/common/logs/\*\*/\*.log" start\_posit…

---

## [Running ANN with num\_candidates \> 10000](https://discuss.elastic.co/t/running-ann-with-num-candidates-10000/349387)

<div class="topic-metadata">

**Author:** [@rajivhs](https://discuss.elastic.co/u/rajivhs)\
**Replies:** 1\
**Last updated:** [December 14, 2023, 5:02pm UTC](https://discuss.elastic.co/t/running-ann-with-num-candidates-10000/349387 "2023-12-14T17:02:36Z")

</div>

Hi. Given millions of documents in our index, we would like to run ANN in order to get the top-X documents, where X is greater than 10,000. However, we're running into the num\_candidates cannot exceed 10000 error. We do…

---

## [Help for configuring index and query for autocomplete full\_text\_search on addresses](https://discuss.elastic.co/t/help-for-configuring-index-and-query-for-autocomplete-full-text-search-on-addresses/349386)

<div class="topic-metadata">

**Author:** [@Queepyl](https://discuss.elastic.co/u/Queepyl)\
**Replies:** 1\
**Last updated:** [December 14, 2023, 4:30pm UTC](https://discuss.elastic.co/t/help-for-configuring-index-and-query-for-autocomplete-full-text-search-on-addresses/349386 "2023-12-14T16:30:15Z")

</div>

Hello, I am creating an index to search existing addresses. Unfortunately I don't have some good results at all and I would like to ask for advices on how to improove these results. So the aim is to let a user enter i…

---

## [How to story a JSON Array in an index via the Java client?](https://discuss.elastic.co/t/how-to-story-a-json-array-in-an-index-via-the-java-client/349390)

<div class="topic-metadata">

**Author:** [@Itsman-AT](https://discuss.elastic.co/u/Itsman-AT)\
**Replies:** 0\
**Last updated:** [December 14, 2023, 4:25pm UTC](https://discuss.elastic.co/t/how-to-story-a-json-array-in-an-index-via-the-java-client/349390 "2023-12-14T16:25:45Z")

</div>

I am trying to store a JSON array (coming from an SQL Table field) within an Elasticsearch index. The JSON Array coming from the DB looks like this: \["Texas", "Texas", "Sidebet City"\] I get this array as a String from …

---

## [Limit GitHub Connector to only index files](https://discuss.elastic.co/t/limit-github-connector-to-only-index-files/349295)

<div class="topic-metadata">

**Author:** [@itsmed](https://discuss.elastic.co/u/itsmed)\
**Replies:** 5\
**Last updated:** [December 14, 2023, 4:03pm UTC](https://discuss.elastic.co/t/limit-github-connector-to-only-index-files/349295 "2023-12-14T16:03:37Z")

</div>

When configuring the Github connector the docs say that it should be possible to limit what is indexed. Is there a way to index only files ( ie not pull requests and issues ) ?

---

## [ElasticSearch in WordPress headless setup](https://discuss.elastic.co/t/elasticsearch-in-wordpress-headless-setup/349237)

<div class="topic-metadata">

**Author:** [@andreasdiehl](https://discuss.elastic.co/u/andreasdiehl)\
**Replies:** 2\
**Last updated:** [December 14, 2023, 3:34pm UTC](https://discuss.elastic.co/t/elasticsearch-in-wordpress-headless-setup/349237 "2023-12-14T15:34:24Z")

</div>

We are setting up a headless frontend (Nuxt, Vue) for our WordPress site. We pull data via GraphQL. Now we explore if / hot to make use of Elasticsearch. Any experiences / recommendations how to do the setup? So far we…

---

## [Correct way of mapping some structure to Elasticsearch document](https://discuss.elastic.co/t/correct-way-of-mapping-some-structure-to-elasticsearch-document/349379)

<div class="topic-metadata">

**Author:** [@Vadym\_Romanenko](https://discuss.elastic.co/u/Vadym_Romanenko)\
**Replies:** 0\
**Last updated:** [December 14, 2023, 2:54pm UTC](https://discuss.elastic.co/t/correct-way-of-mapping-some-structure-to-elasticsearch-document/349379 "2023-12-14T14:54:18Z")

</div>

Good day, community! At this moment we're posting some items from our solution to the ES index. Everything works fine. But we want to enlarge our decision. Our project gives ability to categorize items. We want to have …

---

## ["Multiple mapping types and custom mapping types in index templates" issue when upgrading to v8](https://discuss.elastic.co/t/multiple-mapping-types-and-custom-mapping-types-in-index-templates-issue-when-upgrading-to-v8/349185)

<div class="topic-metadata">

**Author:** [@preetish\_P](https://discuss.elastic.co/u/preetish_P)\
**Replies:** 1\
**Last updated:** [December 14, 2023, 2:46pm UTC](https://discuss.elastic.co/t/multiple-mapping-types-and-custom-mapping-types-in-index-templates-issue-when-upgrading-to-v8/349185 "2023-12-14T14:46:36Z")

</div>

Hi folks, We are in the process of upgrading ELK stack from version 7.17.2 to 8.9.2. When going through the list of Elasticsearch deprecation issues I spotted the below in Prod: (not seen in non-prod) Multiple mapping …

---

## [njava.lang.NoClassDefFoundError: Could not initialize class org.elasticsearch.xcontent.json.JsonXContent](https://discuss.elastic.co/t/njava-lang-noclassdeffounderror-could-not-initialize-class-org-elasticsearch-xcontent-json-jsonxcontent/349373)

<div class="topic-metadata">

**Author:** [@Jhalak43](https://discuss.elastic.co/u/Jhalak43)\
**Replies:** 0\
**Last updated:** [December 14, 2023, 2:08pm UTC](https://discuss.elastic.co/t/njava-lang-noclassdeffounderror-could-not-initialize-class-org-elasticsearch-xcontent-json-jsonxcontent/349373 "2023-12-14T14:08:18Z")

</div>

Previously we were using 7.17.12 version of below dependency org.elasticsearch elasticsearch But now when i update version from 7.17.12 to 8.6.1 or 8.8.2 i get below exception Could not initialize class org.elast…

---

## [Access Elasticsearch Data as a Remote Oracle Database](https://discuss.elastic.co/t/access-elasticsearch-data-as-a-remote-oracle-database/349350)

<div class="topic-metadata">

**Author:** [@onr1onr1](https://discuss.elastic.co/u/onr1onr1)\
**Replies:** 11\
**Last updated:** [December 14, 2023, 2:38pm UTC](https://discuss.elastic.co/t/access-elasticsearch-data-as-a-remote-oracle-database/349350 "2023-12-14T14:38:03Z")

</div>

We want to set up a dblink from the Oracle database to eleastic search and pull information, but we get the following error in the dblink. We could not find a source on this site, so we did it by following the steps in …

---

## [Not able to read the data from external json file in logstash config](https://discuss.elastic.co/t/not-able-to-read-the-data-from-external-json-file-in-logstash-config/349257)

<div class="topic-metadata">

**Author:** [@subash\_k](https://discuss.elastic.co/u/subash_k)\
**Replies:** 10\
**Last updated:** [December 14, 2023, 1:26pm UTC](https://discuss.elastic.co/t/not-able-to-read-the-data-from-external-json-file-in-logstash-config/349257 "2023-12-14T13:26:32Z")

</div>

I'm trying to search the host value from current event and looking for same value in json file. If Json block has the host value I'm just converting the block into struct value and inserting as a new column in index. ou…

---

## [Advanced Watcher to send alert of condition has been met for more than 1 hour](https://discuss.elastic.co/t/advanced-watcher-to-send-alert-of-condition-has-been-met-for-more-than-1-hour/349247)

<div class="topic-metadata">

**Author:** [@ChrisKelly](https://discuss.elastic.co/u/ChrisKelly)\
**Replies:** 9\
**Last updated:** [December 14, 2023, 1:08pm UTC](https://discuss.elastic.co/t/advanced-watcher-to-send-alert-of-condition-has-been-met-for-more-than-1-hour/349247 "2023-12-14T13:08:02Z")

</div>

I want to create an advanced Watcher that will only send an alert email out if my conditions have been met more over an hour. Essentially, I am monitoring specific servers and watching if their CPU exceeds 50%. If it go…

---

## [Is there any recommended ratio between the number of master, data, coordinator and ingestion nodes?](https://discuss.elastic.co/t/is-there-any-recommended-ratio-between-the-number-of-master-data-coordinator-and-ingestion-nodes/349270)

<div class="topic-metadata">

**Author:** [@calin](https://discuss.elastic.co/u/calin)\
**Replies:** 13\
**Last updated:** [December 14, 2023, 1:05pm UTC](https://discuss.elastic.co/t/is-there-any-recommended-ratio-between-the-number-of-master-data-coordinator-and-ingestion-nodes/349270 "2023-12-14T13:05:23Z")

</div>

Currently working with equal number of master, data and coordinator nodes (10). Need to add some ingestion nodes. They all have 2 CPU/node, master and coordinator have 4 GB each, data has 16 GB. I haven't done the sizi…

---

## [How can we ingest fields dynamically in integation package](https://discuss.elastic.co/t/how-can-we-ingest-fields-dynamically-in-integation-package/349338)

<div class="topic-metadata">

**Author:** [@Niraj\_Rathod](https://discuss.elastic.co/u/Niraj_Rathod)\
**Replies:** 0\
**Last updated:** [December 14, 2023, 9:05am UTC](https://discuss.elastic.co/t/how-can-we-ingest-fields-dynamically-in-integation-package/349338 "2023-12-14T09:05:13Z")

</div>

We are trying to fetch MongoDB Atlas logs. In MongoDB Atlas Activity Logs there is an object named “attr” under which there are many dynamic fields that change depending on logs, these fields can't be mentioned in “field…

---

## [Decode xml file](https://discuss.elastic.co/t/decode-xml-file/349292)

<div class="topic-metadata">

**Author:** [@Claudio\_Ract\_Costa](https://discuss.elastic.co/u/Claudio_Ract_Costa)\
**Replies:** 1\
**Last updated:** [December 14, 2023, 12:51pm UTC](https://discuss.elastic.co/t/decode-xml-file/349292 "2023-12-14T12:51:16Z")

</div>

Hi, I have a file with the following information as example: \<sDPCallDataRecord\> \<accountAdjustment\> \<information1\>aloha\</information1\> \<information2\>ola\</information2\> \</accoun…

---

## [Elasticsearch Upgrade issue](https://discuss.elastic.co/t/elasticsearch-upgrade-issue/349159)

<div class="topic-metadata">

**Author:** [@Ifteakhar\_ali](https://discuss.elastic.co/u/Ifteakhar_ali)\
**Replies:** 1\
**Last updated:** [December 12, 2023, 2:23pm UTC](https://discuss.elastic.co/t/elasticsearch-upgrade-issue/349159 "2023-12-12T14:23:43Z")

</div>

Hello Team, I am facing issue while upgrading elasticsearch from elasticsearch-6.8.11-1.noarch to elasticsearch-7.10.2-aarch64.rpm. Kindly advise Current ES Version : elasticsearch-6.8.11-1.noarch Current OS Version :…

[Previous page](https://discuss.elastic.co/latest.md?page=452)

[Next page](https://discuss.elastic.co/latest.md?page=454)
