# Latest

**URL:** https://discuss.elastic.co/latest.md?page=458

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 459

---

## [How to shift to elastic-apm-agent-java8](https://discuss.elastic.co/t/how-to-shift-to-elastic-apm-agent-java8/349003)

<div class="topic-metadata">

**Author:** [@Vijeya\_Nidhi](https://discuss.elastic.co/u/Vijeya_Nidhi)\
**Replies:** 1\
**Last updated:** [December 11, 2023, 1:34pm UTC](https://discuss.elastic.co/t/how-to-shift-to-elastic-apm-agent-java8/349003 "2023-12-11T13:34:32Z")

</div>

elastic-apm-agent is supporting java 7, so it is compiled with log4j 2.12.4 But I am also seeing elastic-apm-agent-java8 which has the higher log4j version. Can I know where to find the jar file for the same for downlo…

---

## [Java 7 support drop dates](https://discuss.elastic.co/t/java-7-support-drop-dates/349004)

<div class="topic-metadata">

**Author:** [@Vijeya\_Nidhi](https://discuss.elastic.co/u/Vijeya_Nidhi)\
**Replies:** 1\
**Last updated:** [December 11, 2023, 1:26pm UTC](https://discuss.elastic.co/t/java-7-support-drop-dates/349004 "2023-12-11T13:26:58Z")

</div>

Hi, apm-agent-java is still supporting Java 7. Can I know if there is a plan in the future to drop the support and make the lowest supported version to be Java 8?

---

## [Uprading Elastic search upgrade from 6.6.1 to 7.16.3](https://discuss.elastic.co/t/uprading-elastic-search-upgrade-from-6-6-1-to-7-16-3/348851)

<div class="topic-metadata">

**Author:** [@Abhishek\_Gangadharai](https://discuss.elastic.co/u/Abhishek_Gangadharai)\
**Replies:** 3\
**Last updated:** [December 11, 2023, 1:20pm UTC](https://discuss.elastic.co/t/uprading-elastic-search-upgrade-from-6-6-1-to-7-16-3/348851 "2023-12-11T13:20:36Z")

</div>

Uprading Elastic search upgrade from 6.6.1 to 7.16.3 in Bitbucket datacenter cluster nodes we are facing challenges can please help for proper documentation for Upgrading Elastic search Instructions, It will help us fo…

---

## [Write structured log but field is never recognized as 'date'](https://discuss.elastic.co/t/write-structured-log-but-field-is-never-recognized-as-date/348920)

<div class="topic-metadata">

**Author:** [@Heija](https://discuss.elastic.co/u/Heija)\
**Replies:** 2\
**Last updated:** [December 11, 2023, 12:01pm UTC](https://discuss.elastic.co/t/write-structured-log-but-field-is-never-recognized-as-date/348920 "2023-12-11T12:01:29Z")

</div>

Hi! I have a .net application which write log entries per nlog direct to Elasticsearch. It works with strings, numbers and booleans. Now I need to transfer a 'date' as structured log entry to Elasticsearch, but it wil…

---

## [I am facing issue with apm related indices "illegal\_argument\_exception: index.lifecycle.rollover\_alias \[apm-7.9.1-transaction\] does not point to index \[apm-7.9.1-transaction-000087\]"](https://discuss.elastic.co/t/i-am-facing-issue-with-apm-related-indices-illegal-argument-exception-index-lifecycle-rollover-alias-apm-7-9-1-transaction-does-not-point-to-index-apm-7-9-1-transaction-000087/349039)

<div class="topic-metadata">

**Author:** [@vaiagr](https://discuss.elastic.co/u/vaiagr)\
**Replies:** 0\
**Last updated:** [December 11, 2023, 11:53am UTC](https://discuss.elastic.co/t/i-am-facing-issue-with-apm-related-indices-illegal-argument-exception-index-lifecycle-rollover-alias-apm-7-9-1-transaction-does-not-point-to-index-apm-7-9-1-transaction-000087/349039 "2023-12-11T11:53:28Z")

</div>

illegal\_argument\_exception: index.lifecycle.rollover\_alias \[apm-7.9.1-transaction\] does not point to index \[apm-7.9.1-transaction-000087\]

---

## [One of our nodes is constantly leaving with "master not discovered yet"](https://discuss.elastic.co/t/one-of-our-nodes-is-constantly-leaving-with-master-not-discovered-yet/349031)

<div class="topic-metadata">

**Author:** [@coudenysj](https://discuss.elastic.co/u/coudenysj)\
**Replies:** 1\
**Last updated:** [December 11, 2023, 10:58am UTC](https://discuss.elastic.co/t/one-of-our-nodes-is-constantly-leaving-with-master-not-discovered-yet/349031 "2023-12-11T10:58:22Z")

</div>

We have a cluster with 33 nodes, and one server (always the same one) is leaving the cluster quite often. After restarting the service, it joins immediately. The exact error is: \[2023-12-11T11:23:29,293\]\[WARN \]\[o.e.c.…

---

## [Elastic APM not instrumenting nested routes in separate files on Express server](https://discuss.elastic.co/t/elastic-apm-not-instrumenting-nested-routes-in-separate-files-on-express-server/348813)

<div class="topic-metadata">

**Author:** [@HemdeepSaini](https://discuss.elastic.co/u/HemdeepSaini)\
**Replies:** 2\
**Last updated:** [December 11, 2023, 10:51am UTC](https://discuss.elastic.co/t/elastic-apm-not-instrumenting-nested-routes-in-separate-files-on-express-server/348813 "2023-12-11T10:51:03Z")

</div>

Problem: I am using Elastic APM to monitor Express application. However, APM is not able to instrument any HTTP requests when nested routing is implemented across multiple files. It only works when all routes are define…

---

## [Is there any way to update the \`last\_run\_metadata\_file\` in the output plugin?](https://discuss.elastic.co/t/is-there-any-way-to-update-the-last-run-metadata-file-in-the-output-plugin/348919)

<div class="topic-metadata">

**Author:** [@gayatri\_SN](https://discuss.elastic.co/u/gayatri_SN)\
**Replies:** 2\
**Last updated:** [December 11, 2023, 10:02am UTC](https://discuss.elastic.co/t/is-there-any-way-to-update-the-last-run-metadata-file-in-the-output-plugin/348919 "2023-12-11T10:02:30Z")

</div>

My scenario is as follows: I am using the JDBC input plugin with a tracking column and last\_run\_metadata\_file, and it is working as expected. However, when the ETL host is down or unreachable, the filter API throws an er…

---

## [Dec 10th, 2023: \[EN\] Ensuring compatibility with two Elasticsearch versions (or more) in automated tests](https://discuss.elastic.co/t/dec-10th-2023-en-ensuring-compatibility-with-two-elasticsearch-versions-or-more-in-automated-tests/348229)

<div class="topic-metadata">

**Author:** [@piotrprz](https://discuss.elastic.co/u/piotrprz)\
**Replies:** 0\
**Last updated:** [December 10, 2023, 8:00am UTC](https://discuss.elastic.co/t/dec-10th-2023-en-ensuring-compatibility-with-two-elasticsearch-versions-or-more-in-automated-tests/348229 "2023-12-10T08:00:11Z")

</div>

Upgrades of key dependencies can be tedious and scary. What if your system won’t work, because we haven’t tested one of the key flows? To avoid that we test our systems in staging, but that takes time and effort. Resu…

---

## [Elasticsearch node disconnect](https://discuss.elastic.co/t/elasticsearch-node-disconnect/349010)

<div class="topic-metadata">

**Author:** [@Farid\_Niasti](https://discuss.elastic.co/u/Farid_Niasti)\
**Replies:** 1\
**Last updated:** [December 11, 2023, 8:48am UTC](https://discuss.elastic.co/t/elasticsearch-node-disconnect/349010 "2023-12-11T08:48:47Z")

</div>

I have 3 nodes of Elasticsearch, sometimes one of my node leave cluster with bellow log: org.elasticsearch.cluster.block.ClusterBlockException: blocked by: \[SERVICE\_UNAVAILABLE/1/state not recovered / initialized\]; …

---

## [Lets Encrypt not working from console but does from firefox](https://discuss.elastic.co/t/lets-encrypt-not-working-from-console-but-does-from-firefox/349000)

<div class="topic-metadata">

**Author:** [@Donovan\_Hoare](https://discuss.elastic.co/u/Donovan_Hoare)\
**Replies:** 3\
**Last updated:** [December 11, 2023, 8:04am UTC](https://discuss.elastic.co/t/lets-encrypt-not-working-from-console-but-does-from-firefox/349000 "2023-12-11T08:04:42Z")

</div>

Good Day All. I have setup a 2-node cluster ith Elasticsearch and kibana. I took me quite some time on how to get lets-encrypt real certs to work. The cert now seems to be ok with kibana and Elasticsearch communicatio…

---

## [Dec 11th, 2023: \[EN\] Relevant Search Combining ELSER and BM25 Text Queries](https://discuss.elastic.co/t/dec-11th-2023-en-relevant-search-combining-elser-and-bm25-text-queries/348153)

<div class="topic-metadata">

**Author:** [@Kathleen\_DeRusso](https://discuss.elastic.co/u/Kathleen_DeRusso)\
**Replies:** 0\
**Last updated:** [December 11, 2023, 8:00am UTC](https://discuss.elastic.co/t/dec-11th-2023-en-relevant-search-combining-elser-and-bm25-text-queries/348153 "2023-12-11T08:00:21Z")

</div>

The Elastic Learned Spare EncodeR (ELSER) allows you to perform semantic search for more relevant search results. Sometimes, however, it’s more useful to combine semantic search results with regular keyword search res…

---

## [Tenable.sc integration not visible on the intergations tab](https://discuss.elastic.co/t/tenable-sc-integration-not-visible-on-the-intergations-tab/349019)

<div class="topic-metadata">

**Author:** [@Kotsos](https://discuss.elastic.co/u/Kotsos)\
**Replies:** 0\
**Last updated:** [December 11, 2023, 7:48am UTC](https://discuss.elastic.co/t/tenable-sc-integration-not-visible-on-the-intergations-tab/349019 "2023-12-11T07:48:42Z")

</div>

Hello, I am trying to install the Tenable.sc integration with the ELK stack, which according to the documentation collects and parses data from the Tenable.sc APIs. However it is nowhere to be found on the "Browse inter…

---

## [Watcher with different thresholds](https://discuss.elastic.co/t/watcher-with-different-thresholds/347276)

<div class="topic-metadata">

**Author:** [@shayn](https://discuss.elastic.co/u/shayn)\
**Replies:** 2\
**Last updated:** [December 11, 2023, 6:15am UTC](https://discuss.elastic.co/t/watcher-with-different-thresholds/347276 "2023-12-11T06:15:49Z")

</div>

hi im trying to figure up if I've the ability to alert different thresholds in same watcher task . i have index that's contains some different devices with numer of events i want to create watcher that will have diffe…

---

## [Kibana Log In Error](https://discuss.elastic.co/t/kibana-log-in-error/348861)

<div class="topic-metadata">

**Author:** [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Replies:** 2\
**Last updated:** [December 11, 2023, 5:31am UTC](https://discuss.elastic.co/t/kibana-log-in-error/348861 "2023-12-11T05:31:12Z")

</div>

Hi Team, When my mount point in Elasticsearch server reaches between 85-90 percent , we are not able to login the Kibana UI as per screenshot. While checking log in Kibana show disk usage issue and after adding space a…

---

## [Getting the error as "agent\_id\_status": "auth\_metadata\_missing" in the file beat data stream on elastic agent standalone deployed on k8s cluster](https://discuss.elastic.co/t/getting-the-error-as-agent-id-status-auth-metadata-missing-in-the-file-beat-data-stream-on-elastic-agent-standalone-deployed-on-k8s-cluster/349007)

<div class="topic-metadata">

**Author:** [@Subrahmanyam\_Veerank](https://discuss.elastic.co/u/Subrahmanyam_Veerank)\
**Replies:** 0\
**Last updated:** [December 11, 2023, 5:14am UTC](https://discuss.elastic.co/t/getting-the-error-as-agent-id-status-auth-metadata-missing-in-the-file-beat-data-stream-on-elastic-agent-standalone-deployed-on-k8s-cluster/349007 "2023-12-11T05:14:04Z")

</div>

Deployed the elastic agent standalone in a kubernetes cluster and a agent policy is created with a kubernetes integration. Getting some of the metric visualizations of the pods,nodes,etc but when i checked the filebeat d…

---

## [Custom Index Creation Issue](https://discuss.elastic.co/t/custom-index-creation-issue/348979)

<div class="topic-metadata">

**Author:** [@Mani\_Manikanta](https://discuss.elastic.co/u/Mani_Manikanta)\
**Replies:** 4\
**Last updated:** [December 11, 2023, 4:01am UTC](https://discuss.elastic.co/t/custom-index-creation-issue/348979 "2023-12-11T04:01:57Z")

</div>

Hello, I am New to ELK Stack, Trying to Setup ELK Stack in Single Server following Elastic Documentation and I am Stuck here now Can Anyone Please Look into this and help me out Unable to Create a Custom Index from Lo…

---

## [CCR - auto-follow problem on data streams](https://discuss.elastic.co/t/ccr-auto-follow-problem-on-data-streams/348789)

<div class="topic-metadata">

**Author:** [@Wojciech\_Kwiecien](https://discuss.elastic.co/u/Wojciech_Kwiecien)\
**Replies:** 5\
**Last updated:** [December 11, 2023, 1:13am UTC](https://discuss.elastic.co/t/ccr-auto-follow-problem-on-data-streams/348789 "2023-12-11T01:13:10Z")

</div>

I found this topic Elastic Cross Cluster Replication of Data Stream But I do not find a solution for me. I was able to create CCR auto-follow pattern and nothing happened when I ran GET /\_ccr/stats After I follow inst…

---

## [Gave up on setting up ELK](https://discuss.elastic.co/t/gave-up-on-setting-up-elk/348984)

<div class="topic-metadata">

**Author:** [@Aamira](https://discuss.elastic.co/u/Aamira)\
**Replies:** 2\
**Last updated:** [December 10, 2023, 10:38pm UTC](https://discuss.elastic.co/t/gave-up-on-setting-up-elk/348984 "2023-12-10T22:38:45Z")

</div>

After 12 years of Linux background and infrastructure management, I accepted defeat setting up ELK for monitoring. I struggled for over 2 weeks trying every guide. but it seems that ELK is not worth the headache. The g…

---

## [Beats\_input\_raw\_event](https://discuss.elastic.co/t/beats-input-raw-event/348575)

<div class="topic-metadata">

**Author:** [@Yuval\_Algresi](https://discuss.elastic.co/u/Yuval_Algresi)\
**Replies:** 3\
**Last updated:** [December 10, 2023, 10:28pm UTC](https://discuss.elastic.co/t/beats-input-raw-event/348575 "2023-12-10T22:28:42Z")

</div>

Hello, I use winlogbeat to ship event viewer logs to my elastic stack. It first goes to logstash and from there to elastic - I use beats input plugin. Usually there is an event.original field that contains the raw eve…

---

## [What is the impact on a live system doing a change in elasticsearch.yml file to change the node.attr.storage\_term: to be none?](https://discuss.elastic.co/t/what-is-the-impact-on-a-live-system-doing-a-change-in-elasticsearch-yml-file-to-change-the-node-attr-storage-term-to-be-none/348980)

<div class="topic-metadata">

**Author:** [@mpniel](https://discuss.elastic.co/u/mpniel)\
**Replies:** 3\
**Last updated:** [December 10, 2023, 2:25pm UTC](https://discuss.elastic.co/t/what-is-the-impact-on-a-live-system-doing-a-change-in-elasticsearch-yml-file-to-change-the-node-attr-storage-term-to-be-none/348980 "2023-12-10T14:25:17Z")

</div>

Hello, I run GET /\_cat/nodeattrs?v and found that the node have storage\_term attribute as cold. What is the impact on a live system doing a change in elasticsearch.yml file to change the node.attr.storage\_term: to be…

---

## [Error: master not discovered yet , Elasticsearch cluster using docker swarm with three nodes on three separate servers](https://discuss.elastic.co/t/error-master-not-discovered-yet-elasticsearch-cluster-using-docker-swarm-with-three-nodes-on-three-separate-servers/348973)

<div class="topic-metadata">

**Author:** [@hossein\_rahmatei](https://discuss.elastic.co/u/hossein_rahmatei)\
**Replies:** 1\
**Last updated:** [December 10, 2023, 12:42pm UTC](https://discuss.elastic.co/t/error-master-not-discovered-yet-elasticsearch-cluster-using-docker-swarm-with-three-nodes-on-three-separate-servers/348973 "2023-12-10T12:42:24Z")

</div>

I want to set up an elasticsearch cluster using docker swarm with three nodes on three separate servers. But when I do the docker stack deploy command and the service comes up, but I get docker logs from the containe…

---

## [Kibana UI Dashboard Access Issue](https://discuss.elastic.co/t/kibana-ui-dashboard-access-issue/348971)

<div class="topic-metadata">

**Author:** [@Mani\_Manikanta](https://discuss.elastic.co/u/Mani_Manikanta)\
**Replies:** 11\
**Last updated:** [December 10, 2023, 8:55am UTC](https://discuss.elastic.co/t/kibana-ui-dashboard-access-issue/348971 "2023-12-10T08:55:27Z")

</div>

Unable to Access Kibana UI Dashboard Getting Below Error, Getting Please upgrade browser in Google Chrome/Edge/Firefox Kibana - 8.3.3 Elasticsearch - 8.3.3 No Domain Mapped Trying to Access using kibana-ip:5601

---

## [How filebeat custom parse rules?](https://discuss.elastic.co/t/how-filebeat-custom-parse-rules/348878)

<div class="topic-metadata">

**Author:** [@fansehep](https://discuss.elastic.co/u/fansehep)\
**Replies:** 11\
**Last updated:** [December 10, 2023, 6:42am UTC](https://discuss.elastic.co/t/how-filebeat-custom-parse-rules/348878 "2023-12-10T06:42:11Z")

</div>

I have a project. it will output a spiecal log like: | xxx | xxx | xxx | | xxx | xxx | xxx | | xxx | xxx | xxx | I want to know it there anyway to custom self parse rules or some plugins to help me ?

---

## [Kafka integration plug v11.3.2 with AWS MSK 2.8.1](https://discuss.elastic.co/t/kafka-integration-plug-v11-3-2-with-aws-msk-2-8-1/348963)

<div class="topic-metadata">

**Author:** [@bbenne821](https://discuss.elastic.co/u/bbenne821)\
**Replies:** 2\
**Last updated:** [December 9, 2023, 6:38pm UTC](https://discuss.elastic.co/t/kafka-integration-plug-v11-3-2-with-aws-msk-2-8-1/348963 "2023-12-09T18:38:41Z")

</div>

We have a TLS-enabled AWS MSK (Managed Streaming Kafka) 2.8.1 cluster and using logstash kafka integration plug v11.3.2 to read from topics. Our input logstash pipeline: input { kafka { id =\> "sentinel\_one-…

---

## [Error: fail to enroll: fail to execute request to fleet-server: http: server gave HTTP response to HTTPS client](https://discuss.elastic.co/t/error-fail-to-enroll-fail-to-execute-request-to-fleet-server-http-server-gave-http-response-to-https-client/348678)

<div class="topic-metadata">

**Author:** [@Virtual\_Box](https://discuss.elastic.co/u/Virtual_Box)\
**Replies:** 3\
**Last updated:** [December 9, 2023, 6:47pm UTC](https://discuss.elastic.co/t/error-fail-to-enroll-fail-to-execute-request-to-fleet-server-http-server-gave-http-response-to-https-client/348678 "2023-12-09T18:47:56Z")

</div>

Hey there, I've tried to install elastic-agent on ubuntu host and get the next error: Enrolling Elastic Agent with Fleet...{"log.level":"warn","@timestamp":"2023-12-05T20:38:37.405Z","log.logger":"tls","log.origin":{"f…

---

## [Could you advise me on determining which version of JDK is embedded with Elasticsearch 7.17.14 on RHEL7 - OpenJDK 20 or 21?](https://discuss.elastic.co/t/could-you-advise-me-on-determining-which-version-of-jdk-is-embedded-with-elasticsearch-7-17-14-on-rhel7-openjdk-20-or-21/347294)

<div class="topic-metadata">

**Author:** [@Domnic\_Raj\_D](https://discuss.elastic.co/u/Domnic_Raj_D)\
**Replies:** 3\
**Last updated:** [December 9, 2023, 5:52pm UTC](https://discuss.elastic.co/t/could-you-advise-me-on-determining-which-version-of-jdk-is-embedded-with-elasticsearch-7-17-14-on-rhel7-openjdk-20-or-21/347294 "2023-12-09T17:52:37Z")

</div>

I have collected all breaking changes and deprecations of the ELK stack (Elasticsearch, Kibana, Logstash, Beats) for 7.9 to 7.17.14. Is there anything I need to focus on before moving to the upgrade plan? If you don't mi…

---

## [ILM policy implement for different enviornment](https://discuss.elastic.co/t/ilm-policy-implement-for-different-enviornment/347281)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 1\
**Last updated:** [December 9, 2023, 4:25pm UTC](https://discuss.elastic.co/t/ilm-policy-implement-for-different-enviornment/347281 "2023-12-09T16:25:35Z")

</div>

Hello All, I want to know better way to implement lifecycle policy for diff env like(DEV,QA,PROD). I have around 60 indices and lifecycle policy for different env would be different. ex: DEV-90 days, PROD -30 days and…

---

## [Elasticsearch Query DSL Filter Including Middle Occurrences](https://discuss.elastic.co/t/elasticsearch-query-dsl-filter-including-middle-occurrences/348143)

<div class="topic-metadata">

**Author:** [@Dokh\_Ahmed](https://discuss.elastic.co/u/Dokh_Ahmed)\
**Replies:** 1\
**Last updated:** [December 9, 2023, 4:18pm UTC](https://discuss.elastic.co/t/elasticsearch-query-dsl-filter-including-middle-occurrences/348143 "2023-12-09T16:18:18Z")

</div>

Hello I am facing an issue with Elastisearch Query DSL while using a prefix filter for the "log\_message" field. The goal is to display logs where the "log\_message" field has a prefix of "Started". However, the filter i…

---

## [Can't find "enableEsql" option on advanced settings](https://discuss.elastic.co/t/cant-find-enableesql-option-on-advanced-settings/348933)

<div class="topic-metadata">

**Author:** [@ton1uwu](https://discuss.elastic.co/u/ton1uwu)\
**Replies:** 1\
**Last updated:** [December 9, 2023, 3:50pm UTC](https://discuss.elastic.co/t/cant-find-enableesql-option-on-advanced-settings/348933 "2023-12-09T15:50:19Z")

</div>

Hello there guys, I have kibana 8.11.1 running, went to stack management and to advanced settings, I search for discover: or esql and the only option showing up is discover:enableSql, the option discover:enableESQL is n…

[Previous page](https://discuss.elastic.co/latest.md?page=457)

[Next page](https://discuss.elastic.co/latest.md?page=459)
