# Latest

**URL:** https://discuss.elastic.co/latest.md?page=461

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 462

---

## [Extract specific string from a field in ELK](https://discuss.elastic.co/t/extract-specific-string-from-a-field-in-elk/348799)

<div class="topic-metadata">

**Author:** [@Satheesh](https://discuss.elastic.co/u/Satheesh)\
**Replies:** 1\
**Last updated:** [December 7, 2023, 12:07pm UTC](https://discuss.elastic.co/t/extract-specific-string-from-a-field-in-elk/348799 "2023-12-07T12:07:43Z")

</div>

I am newbie in ELK. In my ELK, a single document has multiple fields (k8s.pod,k8s.ns,timestamp,logtag,stream and message etc.,). In the message field, I am getting the logs like below e\[36m15:25:47.508e\[0;39m e\[1;30m\[de…

---

## [Hide all panels, using control or filter](https://discuss.elastic.co/t/hide-all-panels-using-control-or-filter/348804)

<div class="topic-metadata">

**Author:** [@Arshukla](https://discuss.elastic.co/u/Arshukla)\
**Replies:** 1\
**Last updated:** [December 7, 2023, 12:03pm UTC](https://discuss.elastic.co/t/hide-all-panels-using-control-or-filter/348804 "2023-12-07T12:03:15Z")

</div>

Hello Team, Please help to tell how to hide all panels, of a dashboard using controls or filter

---

## [Not able to get file logs from otel collector to elasticsearch using APM server](https://discuss.elastic.co/t/not-able-to-get-file-logs-from-otel-collector-to-elasticsearch-using-apm-server/348214)

<div class="topic-metadata">

**Author:** [@Akshay\_Ranka](https://discuss.elastic.co/u/Akshay_Ranka)\
**Replies:** 5\
**Last updated:** [December 7, 2023, 11:56am UTC](https://discuss.elastic.co/t/not-able-to-get-file-logs-from-otel-collector-to-elasticsearch-using-apm-server/348214 "2023-12-07T11:56:08Z")

</div>

extensions: health\_check: pprof: endpoint: 0.0.0.0:1777 zpages: endpoint: 0.0.0.0:55679 receivers: filelog: include: \[/path/to log/.log\] operators: - type: regex\_parser regex: '^(?P\\d{4}-\\d{2}-\\d{2} \\d{2}:\\d{2…

---

## [Running Logstah in Windows](https://discuss.elastic.co/t/running-logstah-in-windows/348749)

<div class="topic-metadata">

**Author:** [@Alberto\_Jimenez1](https://discuss.elastic.co/u/Alberto_Jimenez1)\
**Replies:** 1\
**Last updated:** [December 7, 2023, 10:52am UTC](https://discuss.elastic.co/t/running-logstah-in-windows/348749 "2023-12-07T10:52:37Z")

</div>

Im running in Windows Logstah the basic Test Official website recommends: logstash.bat -e "input { stdin { } } output { stdout {} }" but I receive following error in the cmd: \`\`\` "\[FATAL\] 2023-12-06 14:24:21.428 \[ma…

---

## [Is possible to print debug message in Filebeat Script Processor](https://discuss.elastic.co/t/is-possible-to-print-debug-message-in-filebeat-script-processor/348801)

<div class="topic-metadata">

**Author:** [@Chen\_Wei](https://discuss.elastic.co/u/Chen_Wei)\
**Replies:** 0\
**Last updated:** [December 7, 2023, 10:29am UTC](https://discuss.elastic.co/t/is-possible-to-print-debug-message-in-filebeat-script-processor/348801 "2023-12-07T10:29:42Z")

</div>

I am using Filebeat to index log file and want to drop duplicated messages in the log file. So I write a JS script and load it with the Script Processor. Now I want to report the duplication in the filebeat log. Add som…

---

## [Upsert a document when document id is autogenerated using upsert?](https://discuss.elastic.co/t/upsert-a-document-when-document-id-is-autogenerated-using-upsert/348747)

<div class="topic-metadata">

**Author:** [@iby\_dev](https://discuss.elastic.co/u/iby_dev)\
**Replies:** 2\
**Last updated:** [December 7, 2023, 9:46am UTC](https://discuss.elastic.co/t/upsert-a-document-when-document-id-is-autogenerated-using-upsert/348747 "2023-12-07T09:46:31Z")

</div>

According to the docs, on the Update API The \<\_id\> field is required. I have a bulk insert process which is sometimes known to insert duplicates given a particular scenario. The ids for us, are auto generated so how d…

---

## [ES create indexes\\reindex are slow when using a synonym file](https://discuss.elastic.co/t/es-create-indexes-reindex-are-slow-when-using-a-synonym-file/348718)

<div class="topic-metadata">

**Author:** [@ryzhovas](https://discuss.elastic.co/u/ryzhovas)\
**Replies:** 6\
**Last updated:** [December 7, 2023, 9:29am UTC](https://discuss.elastic.co/t/es-create-indexes-reindex-are-slow-when-using-a-synonym-file/348718 "2023-12-07T09:29:50Z")

</div>

We have synonym file 38M when we create index with filter "dictionary": { "expand": false, "lenient": true, "synonyms\_path": "linguistics/expert\_20231123/em\_dictionary.txt", …

---

## [Dec 7th, 2023: \[EN\] Find book about Christmas without searching for Christmas](https://discuss.elastic.co/t/dec-7th-2023-en-find-book-about-christmas-without-searching-for-christmas/348129)

<div class="topic-metadata">

**Author:** [@lio](https://discuss.elastic.co/u/lio)\
**Replies:** 0\
**Last updated:** [November 28, 2023, 11:12am UTC](https://discuss.elastic.co/t/dec-7th-2023-en-find-book-about-christmas-without-searching-for-christmas/348129 "2023-11-28T11:12:58Z")

</div>

As we’re getting closer to the holiday season, I’m looking forward to getting cozy, picking up a new book and having a relaxing time. But book discovery online using a search bar is not as easy as it seems.... Most reta…

---

## [Discuss: Security Vulnerabilities: ESA-2023-14 - CVE-2023-31419](https://discuss.elastic.co/t/discuss-security-vulnerabilities-esa-2023-14-cve-2023-31419/348769)

<div class="topic-metadata">

**Author:** [@devkgk](https://discuss.elastic.co/u/devkgk)\
**Replies:** 2\
**Last updated:** [December 7, 2023, 8:32am UTC](https://discuss.elastic.co/t/discuss-security-vulnerabilities-esa-2023-14-cve-2023-31419/348769 "2023-12-07T08:32:44Z")

</div>

Hello, everybody. According to the community's safety announcement: " Elasticsearch StackOverflow vulnerability (ESA-2023-14) A flaw was discovered in Elasticsearch, affecting the \_search API that allowed a specially …

---

## [How to display the search result with nested data](https://discuss.elastic.co/t/how-to-display-the-search-result-with-nested-data/348039)

<div class="topic-metadata">

**Author:** [@sandhya15](https://discuss.elastic.co/u/sandhya15)\
**Replies:** 1\
**Last updated:** [December 7, 2023, 8:29am UTC](https://discuss.elastic.co/t/how-to-display-the-search-result-with-nested-data/348039 "2023-12-07T08:29:43Z")

</div>

Hi, I am trying to implement search screen using Search UI with Elasticsearch connector. The problem i m facing during displaying search result where the response data contains Json object. The response from the elastic…

---

## [Elastic search certificate issue](https://discuss.elastic.co/t/elastic-search-certificate-issue/348788)

<div class="topic-metadata">

**Author:** [@Dasara\_Saarthak](https://discuss.elastic.co/u/Dasara_Saarthak)\
**Replies:** 0\
**Last updated:** [December 7, 2023, 8:05am UTC](https://discuss.elastic.co/t/elastic-search-certificate-issue/348788 "2023-12-07T08:05:29Z")

</div>

hi iam using helm to deploy elasticsearch this is my statefulset.yml file apiVersion: apps/v1 kind: StatefulSet metadata: annotations: esMajorVersion: "8" meta.helm.sh/release-name: esarticle meta.helm.sh…

---

## [Does date-format of ES7.5.2 not support YYYY?](https://discuss.elastic.co/t/does-date-format-of-es7-5-2-not-support-yyyy/348787)

<div class="topic-metadata">

**Author:** [@MiuNice](https://discuss.elastic.co/u/MiuNice)\
**Replies:** 2\
**Last updated:** [December 7, 2023, 7:54am UTC](https://discuss.elastic.co/t/does-date-format-of-es7-5-2-not-support-yyyy/348787 "2023-12-07T07:54:02Z")

</div>

I created a field named "created" in the index as shown below: "created": { "type": "date", "format": "YYYY-MM-dd'T'HH:mm:ss'Z'" } When I used the range method for querying, I got unexpected results. There is a…

---

## [Postal address autocomplete](https://discuss.elastic.co/t/postal-address-autocomplete/348022)

<div class="topic-metadata">

**Author:** [@johnwc](https://discuss.elastic.co/u/johnwc)\
**Replies:** 2\
**Last updated:** [December 7, 2023, 5:09am UTC](https://discuss.elastic.co/t/postal-address-autocomplete/348022 "2023-12-07T05:09:39Z")

</div>

We are currently evaluating an installation and trying to setup an index for address autocompletion for our users on our site. So that as a user starts typing an address, and possible matches start showing up for them to…

---

## [Elastic Search Indices Migration from Version 5.6 to Version 8.11 (New ES cluster)](https://discuss.elastic.co/t/elastic-search-indices-migration-from-version-5-6-to-version-8-11-new-es-cluster/348784)

<div class="topic-metadata">

**Author:** [@chateesh](https://discuss.elastic.co/u/chateesh)\
**Replies:** 1\
**Last updated:** [December 7, 2023, 7:01am UTC](https://discuss.elastic.co/t/elastic-search-indices-migration-from-version-5-6-to-version-8-11-new-es-cluster/348784 "2023-12-07T07:01:39Z")

</div>

Hi Team, Indices in ES version 5.6 are compatible with ES version 8.11 (New ES Cluster) if we restore these indices by pointing snapshot repository of ES 5.6 cluster to new ES 8.11 cluster? Can you please share the ste…

---

## [Elasticsearch false mapping](https://discuss.elastic.co/t/elasticsearch-false-mapping/348722)

<div class="topic-metadata">

**Author:** [@vladislav](https://discuss.elastic.co/u/vladislav)\
**Replies:** 6\
**Last updated:** [December 7, 2023, 6:50am UTC](https://discuss.elastic.co/t/elasticsearch-false-mapping/348722 "2023-12-07T06:50:20Z")

</div>

Hello everyone and thanks for help. I've installed latest versions of elasticsearch, kibana and logstash (8.11.1) on test cluster. Next, created new simple logstash pipeline that listens tcp port, next send data to elas…

---

## [All system.process.memory.rss.pct doesn't add up to give system.memory.used.pct](https://discuss.elastic.co/t/all-system-process-memory-rss-pct-doesnt-add-up-to-give-system-memory-used-pct/348210)

<div class="topic-metadata">

**Author:** [@aviral\_srivastava](https://discuss.elastic.co/u/aviral_srivastava)\
**Replies:** 1\
**Last updated:** [December 7, 2023, 6:09am UTC](https://discuss.elastic.co/t/all-system-process-memory-rss-pct-doesnt-add-up-to-give-system-memory-used-pct/348210 "2023-12-07T06:09:27Z")

</div>

Hi, Windows Server 2019 Standard metricbeat 8.10.4 System is showing high Memory Usage of 99% in Task Manager. But all the system.process.memory.rss.pct doesn't add up to give that memory usage. No where near it. Try…

---

## [We are getting two different offset values for same message](https://discuss.elastic.co/t/we-are-getting-two-different-offset-values-for-same-message/348779)

<div class="topic-metadata">

**Author:** [@prashant1](https://discuss.elastic.co/u/prashant1)\
**Replies:** 0\
**Last updated:** [December 7, 2023, 5:44am UTC](https://discuss.elastic.co/t/we-are-getting-two-different-offset-values-for-same-message/348779 "2023-12-07T05:44:39Z")

</div>

Hi, We have two logstash pods which are reading the data from elasticsearch from one index for last 24 hr data and then sending data to Kafka server. We can see two different offset are created for similar log message. …

---

## [Thread is missing when i send logs from ECS fargate to Elastic search](https://discuss.elastic.co/t/thread-is-missing-when-i-send-logs-from-ecs-fargate-to-elastic-search/348774)

<div class="topic-metadata">

**Author:** [@NitinKalburgii](https://discuss.elastic.co/u/NitinKalburgii)\
**Replies:** 1\
**Last updated:** [December 7, 2023, 4:47am UTC](https://discuss.elastic.co/t/thread-is-missing-when-i-send-logs-from-ecs-fargate-to-elastic-search/348774 "2023-12-07T04:47:57Z")

</div>

Hi! I was running my application in ECS fargate(AWS Service) and in AWS monitoring i was getting logs like 2023-12-06T15:28:53.745+05:30 06-12-2023 09:58:53.745 \[main\] INFO \[\] o.a.coyote.http11.Http11NioProtocol.log - I…

---

## [Kibana Failed to parse value 4.0 for setting node.processors must be = 1](https://discuss.elastic.co/t/kibana-failed-to-parse-value-4-0-for-setting-node-processors-must-be-1/347894)

<div class="topic-metadata">

**Author:** [@VijayIQA](https://discuss.elastic.co/u/VijayIQA)\
**Replies:** 6\
**Last updated:** [December 7, 2023, 3:19am UTC](https://discuss.elastic.co/t/kibana-failed-to-parse-value-4-0-for-setting-node-processors-must-be-1/347894 "2023-12-07T03:19:29Z")

</div>

Hi Team, Unable to start Kibana throwing an error as kibana Failed to parse value 4.0 for setting node.processors must be = 1) Elasticsearch cluster running on docker container. Kibana version: 8.8.1 Elasticsearch v…

---

## [Can't Create Enrollment Token](https://discuss.elastic.co/t/cant-create-enrollment-token/348460)

<div class="topic-metadata">

**Author:** [@Bethanie\_Tipton](https://discuss.elastic.co/u/Bethanie_Tipton)\
**Replies:** 6\
**Last updated:** [December 6, 2023, 9:06pm UTC](https://discuss.elastic.co/t/cant-create-enrollment-token/348460 "2023-12-06T21:06:53Z")

</div>

When I try to open elasticsearch-create-enrollment-token, it crashes. I can't do anything with it; I click it, it pops up on my screen for half a second, and then closes.

---

## [Bundling elasticsearch into an offline Electronjs application](https://discuss.elastic.co/t/bundling-elasticsearch-into-an-offline-electronjs-application/348768)

<div class="topic-metadata">

**Author:** [@Joel\_Crawford](https://discuss.elastic.co/u/Joel_Crawford)\
**Replies:** 0\
**Last updated:** [December 7, 2023, 12:56am UTC](https://discuss.elastic.co/t/bundling-elasticsearch-into-an-offline-electronjs-application/348768 "2023-12-07T00:56:59Z")

</div>

Hello, We've been trying to bundle Elasticsearch into an offline Electron application without success. Our goal is to provide offline full-text search functionality in an Electron app. We've used Elasticsearch extensiv…

---

## [Embedding Certificate in configuration file fails with environment variable](https://discuss.elastic.co/t/embedding-certificate-in-configuration-file-fails-with-environment-variable/347554)

<div class="topic-metadata">

**Author:** [@asnyameeteen](https://discuss.elastic.co/u/asnyameeteen)\
**Replies:** 3\
**Last updated:** [December 6, 2023, 11:32pm UTC](https://discuss.elastic.co/t/embedding-certificate-in-configuration-file-fails-with-environment-variable/347554 "2023-12-06T23:32:49Z")

</div>

Running versions 8.10.2 of Kibana, Filebeat, Elasticsearch and APM Server. They are currently running on AWS ECS as Docker containers. I am attempting to configure the output.elasticsearch portion of the apm-server.yml …

---

## [Pagination Search - page 1 to page 5](https://discuss.elastic.co/t/pagination-search-page-1-to-page-5/348668)

<div class="topic-metadata">

**Author:** [@Jasonespo](https://discuss.elastic.co/u/Jasonespo)\
**Replies:** 1\
**Last updated:** [December 6, 2023, 9:30pm UTC](https://discuss.elastic.co/t/pagination-search-page-1-to-page-5/348668 "2023-12-06T21:30:06Z")

</div>

Hi, We're trying to implement pagination for our application. We are displaying a table with 10 results per page. And we're wondering if it's possible to go from page 1 (record 1-10) to page 5 (record 51-60) in one jump…

---

## [Multi Index, Kibana Dashboard Controls dropdown](https://discuss.elastic.co/t/multi-index-kibana-dashboard-controls-dropdown/348557)

<div class="topic-metadata">

**Author:** [@Nikhil\_G\_P](https://discuss.elastic.co/u/Nikhil_G_P)\
**Replies:** 1\
**Last updated:** [December 6, 2023, 9:21pm UTC](https://discuss.elastic.co/t/multi-index-kibana-dashboard-controls-dropdown/348557 "2023-12-06T21:21:37Z")

</div>

Hi Team, I hope this message finds you well. I wanted to bring to your attention a small challenge we're currently facing with our Kibana dashboards. We are utilizing Kibana version 8.11.1 and have set up two indices, n…

---

## [Dec 6th, 2023: \[EN\] "He's making a list 🎶" and now needs to sort it — with Elasticsearch](https://discuss.elastic.co/t/dec-6th-2023-en-hes-making-a-list-and-now-needs-to-sort-it-with-elasticsearch/348128)

<div class="topic-metadata">

**Author:** [@xeraa](https://discuss.elastic.co/u/xeraa)\
**Replies:** 0\
**Last updated:** [December 6, 2023, 8:00am UTC](https://discuss.elastic.co/t/dec-6th-2023-en-hes-making-a-list-and-now-needs-to-sort-it-with-elasticsearch/348128 "2023-12-06T08:00:49Z")

</div>

While you might be picturing Santa Claus when singing this song, European folklore, particularly in the Alpine regions, has the two legendary figures Saint Nicholas and Krampus. Saint Nicholas, symbolizing generosity …

---

## [Logstash service is active, enabled but netstat output shows port not listening](https://discuss.elastic.co/t/logstash-service-is-active-enabled-but-netstat-output-shows-port-not-listening/348695)

<div class="topic-metadata">

**Author:** [@jayadevp](https://discuss.elastic.co/u/jayadevp)\
**Replies:** 17\
**Last updated:** [December 6, 2023, 7:54pm UTC](https://discuss.elastic.co/t/logstash-service-is-active-enabled-but-netstat-output-shows-port-not-listening/348695 "2023-12-06T19:54:58Z")

</div>

If i run the command to manually run logstash " sudo /usr/share/logstash/bin/logstash -f "/etc/logstash/conf.d/fortigate.conf" --config.reload.automatic" im able to see the output and netstat also shows port listening …

---

## [How to configure a text scoring algorithm in App Search Engine](https://discuss.elastic.co/t/how-to-configure-a-text-scoring-algorithm-in-app-search-engine/346762)

<div class="topic-metadata">

**Author:** [@AlanNggg](https://discuss.elastic.co/u/AlanNggg)\
**Replies:** 1\
**Last updated:** [December 6, 2023, 7:53pm UTC](https://discuss.elastic.co/t/how-to-configure-a-text-scoring-algorithm-in-app-search-engine/346762 "2023-12-06T19:53:47Z")

</div>

Hello, I am developing a searching platform. I want to configure the text scoring algorithm in the engine, so that the more the number of terms that matched my query, the higher the score the engine gives. Just like htt…

---

## [KNN/ANN Search on a parent-child documents](https://discuss.elastic.co/t/knn-ann-search-on-a-parent-child-documents/347162)

<div class="topic-metadata">

**Author:** [@Senchok](https://discuss.elastic.co/u/Senchok)\
**Replies:** 1\
**Last updated:** [December 6, 2023, 7:50pm UTC](https://discuss.elastic.co/t/knn-ann-search-on-a-parent-child-documents/347162 "2023-12-06T19:50:08Z")

</div>

We are trying to find a solution to indexing and retrieving documents as vectors. The idea is to index the paragraphs of the document as a child and the document to be the parent document (join solution). Is there anot…

---

## [Master node not discovered yet](https://discuss.elastic.co/t/master-node-not-discovered-yet/347241)

<div class="topic-metadata">

**Author:** [@Casper\_Koch](https://discuss.elastic.co/u/Casper_Koch)\
**Replies:** 1\
**Last updated:** [December 6, 2023, 7:46pm UTC](https://discuss.elastic.co/t/master-node-not-discovered-yet/347241 "2023-12-06T19:46:00Z")

</div>

I created a new node which i want to join an already existing single-node cluster. For the life of me i cannot make it work The configuraiton file for the existing cluster is cluster.name: syslog node.name: syslog01 #p…

---

## [Scroll inner\_hits in Elasticsearch](https://discuss.elastic.co/t/scroll-inner-hits-in-elasticsearch/348757)

<div class="topic-metadata">

**Author:** [@TomTom](https://discuss.elastic.co/u/TomTom)\
**Replies:** 0\
**Last updated:** [December 6, 2023, 7:38pm UTC](https://discuss.elastic.co/t/scroll-inner-hits-in-elasticsearch/348757 "2023-12-06T19:38:04Z")

</div>

I have a document that has nested items, and in some cases I need to query documents that have nested items that match the filter applied in the search and return all nested items that match. To do this, in the search q…

[Previous page](https://discuss.elastic.co/latest.md?page=460)

[Next page](https://discuss.elastic.co/latest.md?page=462)
