# Latest

**URL:** https://discuss.elastic.co/latest.md?page=466

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 467

---

## [Getting 502 bad gateway for a particular query](https://discuss.elastic.co/t/getting-502-bad-gateway-for-a-particular-query/348052)

<div class="topic-metadata">

**Author:** [@Nishant\_Garg](https://discuss.elastic.co/u/Nishant_Garg)\
**Replies:** 1\
**Last updated:** [December 1, 2023, 9:51pm UTC](https://discuss.elastic.co/t/getting-502-bad-gateway-for-a-particular-query/348052 "2023-12-01T21:51:22Z")

</div>

GET \*/\_search { "size": 10000, "query": { "bool": { "should": \[ {"match": {"imei": "value"}}, {"match": {"imei1": "value"}}, {"match": {"IMEI": "value"}} \] } } } this sa…

---

## [Compare 2 fields in different indexes in Kibana](https://discuss.elastic.co/t/compare-2-fields-in-different-indexes-in-kibana/347930)

<div class="topic-metadata">

**Author:** [@jonnyo](https://discuss.elastic.co/u/jonnyo)\
**Replies:** 1\
**Last updated:** [December 1, 2023, 9:26pm UTC](https://discuss.elastic.co/t/compare-2-fields-in-different-indexes-in-kibana/347930 "2023-12-01T21:26:47Z")

</div>

Hi. I would like to create a report in Kibana that compares the value of 2 fields that exist in different indexes, and output a True or False if they do or do not match. E.g. index1.fieldA, index2.fieldA, is\_match I wa…

---

## [Connecting Kibana to different elastic single nodes](https://discuss.elastic.co/t/connecting-kibana-to-different-elastic-single-nodes/347830)

<div class="topic-metadata">

**Author:** [@avnere](https://discuss.elastic.co/u/avnere)\
**Replies:** 1\
**Last updated:** [December 1, 2023, 9:15pm UTC](https://discuss.elastic.co/t/connecting-kibana-to-different-elastic-single-nodes/347830 "2023-12-01T21:15:04Z")

</div>

Hi, I am looking for a way to connect single Kibana to different kinds of elastic single nodes dynamically (without restarting the Kibana). When enabling Stack Monitoring, is there an option to define where to crea…

---

## [Security update associated with CVE-2023-31418 has confusing wording](https://discuss.elastic.co/t/security-update-associated-with-cve-2023-31418-has-confusing-wording/348457)

<div class="topic-metadata">

**Author:** [@jlasica](https://discuss.elastic.co/u/jlasica)\
**Replies:** 1\
**Last updated:** [December 1, 2023, 8:48pm UTC](https://discuss.elastic.co/t/security-update-associated-with-cve-2023-31418-has-confusing-wording/348457 "2023-12-01T20:48:35Z")

</div>

According to this security update: Elasticsearch 8.9.0, 7.17.13 Security Update "Elastic Cloud Enterprise up to versions 2.13.3 and 3.6.0" -- does this mean that Elastic Cloud Enterprise is vulnerable all versions prior…

---

## [Elastic agent needs elasticseach ca from elastic cloud](https://discuss.elastic.co/t/elastic-agent-needs-elasticseach-ca-from-elastic-cloud/348273)

<div class="topic-metadata">

**Author:** [@logger](https://discuss.elastic.co/u/logger)\
**Replies:** 6\
**Last updated:** [December 1, 2023, 7:38pm UTC](https://discuss.elastic.co/t/elastic-agent-needs-elasticseach-ca-from-elastic-cloud/348273 "2023-12-01T19:38:26Z")

</div>

Hi there, currently I am a bit confused with the installation of fleet and elastic-agent. I am using the elastic cloud for elasticsearch, kibana and fleet. On my testserver, debian 10, we are behind a proxy. I have ex…

---

## [Agent configuration infrastructure is not ready](https://discuss.elastic.co/t/agent-configuration-infrastructure-is-not-ready/348364)

<div class="topic-metadata">

**Author:** [@joe\_recra](https://discuss.elastic.co/u/joe_recra)\
**Replies:** 7\
**Last updated:** [December 1, 2023, 7:05pm UTC](https://discuss.elastic.co/t/agent-configuration-infrastructure-is-not-ready/348364 "2023-12-01T19:05:50Z")

</div>

Kibana version: 8.11.1 Elasticsearch version: 8.11.1 APM Server version: 8.11.1 APM Agent language and version: Nodejs v17.9.1 && elastic-apm-node 4.2.0 Browser version: Original install method (e.g. download pa…

---

## [Parsing problem when streaming a log file](https://discuss.elastic.co/t/parsing-problem-when-streaming-a-log-file/348268)

<div class="topic-metadata">

**Author:** [@Kyps](https://discuss.elastic.co/u/Kyps)\
**Replies:** 26\
**Last updated:** [December 1, 2023, 6:59pm UTC](https://discuss.elastic.co/t/parsing-problem-when-streaming-a-log-file/348268 "2023-12-01T18:59:02Z")

</div>

Hey everyone, I followed the Stream any log file guide, and have set up a local agent that listens to my log file. But every time I add a new log (manually to test) the parsing just isn't there when it gets indexed in K…

---

## [Logstash stuck](https://discuss.elastic.co/t/logstash-stuck/348442)

<div class="topic-metadata">

**Author:** [@Dor-Alter](https://discuss.elastic.co/u/Dor-Alter)\
**Replies:** 2\
**Last updated:** [December 1, 2023, 5:54pm UTC](https://discuss.elastic.co/t/logstash-stuck/348442 "2023-12-01T17:54:47Z")

</div>

I am getting to get started with logstash and simply copy a csv file to another file using the following conf: input { file{ path =\> "/Users/test/Desktop/project/test.csv" start\_position =\> "beginning" } } fi…

---

## [FScrawler "Failed to create elasticsearch client"](https://discuss.elastic.co/t/fscrawler-failed-to-create-elasticsearch-client/348438)

<div class="topic-metadata">

**Author:** [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Replies:** 1\
**Last updated:** [December 1, 2023, 5:42pm UTC](https://discuss.elastic.co/t/fscrawler-failed-to-create-elasticsearch-client/348438 "2023-12-01T17:42:45Z")

</div>

Hi, Im getting an error when I tried to run FScrawler to index a pdf to elasticsearch. Elastic version 8.9.2 on docker OS: redhat Firewall off Working curl: curl --cacert /u01/ca.crt https://localhost:9200 FScrawler…

---

## [I/O dispatch worker terminated abnormally](https://discuss.elastic.co/t/i-o-dispatch-worker-terminated-abnormally/348451)

<div class="topic-metadata">

**Author:** [@elaydi\_elagal](https://discuss.elastic.co/u/elaydi_elagal)\
**Replies:** 0\
**Last updated:** [December 1, 2023, 5:01pm UTC](https://discuss.elastic.co/t/i-o-dispatch-worker-terminated-abnormally/348451 "2023-12-01T17:01:18Z")

</div>

In our production environment we try to fetch all the records based on index, but getting exception "Request cannot be executed i/o reactor status stopped" with high concurrency, we've encountered occasional connection …

---

## [Retrieve document by id via public key](https://discuss.elastic.co/t/retrieve-document-by-id-via-public-key/348449)

<div class="topic-metadata">

**Author:** [@jin2](https://discuss.elastic.co/u/jin2)\
**Replies:** 1\
**Last updated:** [December 1, 2023, 5:00pm UTC](https://discuss.elastic.co/t/retrieve-document-by-id-via-public-key/348449 "2023-12-01T17:00:44Z")

</div>

We are switching from elasticsearch to app search. I learned that in App Search you can create public keys which are then used by the frontend to directly connect to the database instead of having an API in between. The…

---

## [Optimizing Storage Costs for Historical Data in Elasticsearch on Azure: Seeking Community Advice](https://discuss.elastic.co/t/optimizing-storage-costs-for-historical-data-in-elasticsearch-on-azure-seeking-community-advice/348440)

<div class="topic-metadata">

**Author:** [@identifysun](https://discuss.elastic.co/u/identifysun)\
**Replies:** 0\
**Last updated:** [December 1, 2023, 3:41pm UTC](https://discuss.elastic.co/t/optimizing-storage-costs-for-historical-data-in-elasticsearch-on-azure-seeking-community-advice/348440 "2023-12-01T15:41:26Z")

</div>

I have an Elasticsearch cluster deployed on Azure. I need to retain historical data in Elasticsearch and currently use snapshot policies to store snapshots in Azure Blob storage. However, over time, I noticed that the st…

---

## [ELK 8.9.0 Caniuse Error during yarn build cause missing plugin build folder](https://discuss.elastic.co/t/elk-8-9-0-caniuse-error-during-yarn-build-cause-missing-plugin-build-folder/348171)

<div class="topic-metadata">

**Author:** [@kbujold\_wr](https://discuss.elastic.co/u/kbujold_wr)\
**Replies:** 8\
**Last updated:** [December 1, 2023, 3:13pm UTC](https://discuss.elastic.co/t/elk-8-9-0-caniuse-error-during-yarn-build-cause-missing-plugin-build-folder/348171 "2023-12-01T15:13:03Z")

</div>

I am seeing this error below during yarn build of our plugin. We had no build errors a few weeks ago. We do not get a build anymore, we should see this output in the logs below from yarn build, but we do not anymore. s…

---

## [Kibana visualization - Average of sum of grouped values](https://discuss.elastic.co/t/kibana-visualization-average-of-sum-of-grouped-values/348326)

<div class="topic-metadata">

**Author:** [@Gianfranco\_Demarco](https://discuss.elastic.co/u/Gianfranco_Demarco)\
**Replies:** 4\
**Last updated:** [December 1, 2023, 3:02pm UTC](https://discuss.elastic.co/t/kibana-visualization-average-of-sum-of-grouped-values/348326 "2023-12-01T15:02:43Z")

</div>

Hello, i'm trying to achieve the following result using Kibana visualizations (Lens or others). I have an index where each document is a service delivery to a user. The documents have a cost and a user\_id. I want two…

---

## [Permanent truncate detection](https://discuss.elastic.co/t/permanent-truncate-detection/348254)

<div class="topic-metadata">

**Author:** [@terrainc](https://discuss.elastic.co/u/terrainc)\
**Replies:** 1\
**Last updated:** [December 1, 2023, 2:33pm UTC](https://discuss.elastic.co/t/permanent-truncate-detection/348254 "2023-12-01T14:33:45Z")

</div>

Each 10min filebeat resending file to ELK. In logs we can find "File was truncated. Reading file from offset 0....". File wasn't rotated (state-id the same) or truncated. This file rotated daily only by logrotate (daily,…

---

## [Transmission of logs in real time mode](https://discuss.elastic.co/t/transmission-of-logs-in-real-time-mode/348319)

<div class="topic-metadata">

**Author:** [@Aleksandr\_Terekhov](https://discuss.elastic.co/u/Aleksandr_Terekhov)\
**Replies:** 2\
**Last updated:** [December 1, 2023, 2:02pm UTC](https://discuss.elastic.co/t/transmission-of-logs-in-real-time-mode/348319 "2023-12-01T14:02:50Z")

</div>

Hello everybody Please tell me what the problem might be I have a mail server on which the filebeat agent is installed, it transfers data to another server on which logstash and elastic are installed I randomly displa…

---

## [How to change index rotation timezone for Elasticsearch 8.6 for UTC to localtimezone](https://discuss.elastic.co/t/how-to-change-index-rotation-timezone-for-elasticsearch-8-6-for-utc-to-localtimezone/348411)

<div class="topic-metadata">

**Author:** [@pix9](https://discuss.elastic.co/u/pix9)\
**Replies:** 3\
**Last updated:** [December 1, 2023, 1:49pm UTC](https://discuss.elastic.co/t/how-to-change-index-rotation-timezone-for-elasticsearch-8-6-for-utc-to-localtimezone/348411 "2023-12-01T13:49:57Z")

</div>

Hi everyone, I am facing an issue while running queries on Elasticsearch, we are unable to fetch data between 12:00 AM to 05:30 AM, issue no data can be retrived from index between given time. Upon further investigatio…

---

## [How can I contact to sales?](https://discuss.elastic.co/t/how-can-i-contact-to-sales/348404)

<div class="topic-metadata">

**Author:** [@zabtech](https://discuss.elastic.co/u/zabtech)\
**Replies:** 4\
**Last updated:** [December 1, 2023, 1:31pm UTC](https://discuss.elastic.co/t/how-can-i-contact-to-sales/348404 "2023-12-01T13:31:01Z")

</div>

First I apologize with my bad English. I try to contact with Sales but no one that send anything to my email. ( URL is https://www.elastic.co ) , So I need some advice and a lot of question to ask sale, because we intere…

---

## [Change tie breaker on aggregation](https://discuss.elastic.co/t/change-tie-breaker-on-aggregation/348434)

<div class="topic-metadata">

**Author:** [@Raphael\_Fidelis](https://discuss.elastic.co/u/Raphael_Fidelis)\
**Replies:** 0\
**Last updated:** [December 1, 2023, 1:28pm UTC](https://discuss.elastic.co/t/change-tie-breaker-on-aggregation/348434 "2023-12-01T13:28:30Z")

</div>

Hello. As defined in the terms aggregation docs, Elastic uses alphabetical order as a tie-breaker for the aggregation results. However, I wanted to use the order that is returned by the query, i.e.: hits: \[ { …

---

## [Configure Two Instances of Filebeat](https://discuss.elastic.co/t/configure-two-instances-of-filebeat/347841)

<div class="topic-metadata">

**Author:** [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Replies:** 8\
**Last updated:** [December 1, 2023, 12:51pm UTC](https://discuss.elastic.co/t/configure-two-instances-of-filebeat/347841 "2023-12-01T12:51:08Z")

</div>

Hi Team, I had requirement like, need to run two instances of filebeat and both instances will load data to a particular Index. Is it possible to achieve the same if yes could you please let us know how we can do the s…

---

## [How do we remove Help icon from top right corner in kibana 8.5.3](https://discuss.elastic.co/t/how-do-we-remove-help-icon-from-top-right-corner-in-kibana-8-5-3/347816)

<div class="topic-metadata">

**Author:** [@Abj\_Ins](https://discuss.elastic.co/u/Abj_Ins)\
**Replies:** 3\
**Last updated:** [December 1, 2023, 12:31pm UTC](https://discuss.elastic.co/t/how-do-we-remove-help-icon-from-top-right-corner-in-kibana-8-5-3/347816 "2023-12-01T12:31:40Z")

</div>

Hi Team, we are trying to hide the Help Icon from Kibana 8.5.3 on top right corner as below after we logged in. Thanks.

---

## [How dependencies are listed under Observability \> APM \> Dependencies](https://discuss.elastic.co/t/how-dependencies-are-listed-under-observability-apm-dependencies/348410)

<div class="topic-metadata">

**Author:** [@dev19](https://discuss.elastic.co/u/dev19)\
**Replies:** 1\
**Last updated:** [December 1, 2023, 12:10pm UTC](https://discuss.elastic.co/t/how-dependencies-are-listed-under-observability-apm-dependencies/348410 "2023-12-01T12:10:12Z")

</div>

Kibana version: 8.7.1 Elasticsearch version: 8.7.1 APM Server version: 8.7.1 APM Agent language and version: Java, 1.42.0 Fresh install or upgraded from other version? Fresh Install In APM\>Services, I have bunch of …

---

## [How to add custom trace id generator in elastic APM java agent code base](https://discuss.elastic.co/t/how-to-add-custom-trace-id-generator-in-elastic-apm-java-agent-code-base/348360)

<div class="topic-metadata">

**Author:** [@MadhusudanN](https://discuss.elastic.co/u/MadhusudanN)\
**Replies:** 1\
**Last updated:** [December 1, 2023, 11:52am UTC](https://discuss.elastic.co/t/how-to-add-custom-trace-id-generator-in-elastic-apm-java-agent-code-base/348360 "2023-12-01T11:52:14Z")

</div>

Can someone please let me know if there is a way to plug custom trace id generator in the elastic APM java agent code base.

---

## [Maps is shown in field statistic but not in dashboard](https://discuss.elastic.co/t/maps-is-shown-in-field-statistic-but-not-in-dashboard/348350)

<div class="topic-metadata">

**Author:** [@DVD\_MNC](https://discuss.elastic.co/u/DVD_MNC)\
**Replies:** 4\
**Last updated:** [December 1, 2023, 11:04am UTC](https://discuss.elastic.co/t/maps-is-shown-in-field-statistic-but-not-in-dashboard/348350 "2023-12-01T11:04:10Z")

</div>

Hi all, I'm facing some problem to draw a dashboard with geopoints. As you can see i have a value mapped as geopoint, minimap is shown in fields statistic tabs. But when i try to build a dashboard, kibana replies me sa…

---

## [How to correctly use \`search\_after\` for huge amount of records (100k+)?](https://discuss.elastic.co/t/how-to-correctly-use-search-after-for-huge-amount-of-records-100k/348426)

<div class="topic-metadata">

**Author:** [@MarinTakanov](https://discuss.elastic.co/u/MarinTakanov)\
**Replies:** 0\
**Last updated:** [December 1, 2023, 11:03am UTC](https://discuss.elastic.co/t/how-to-correctly-use-search-after-for-huge-amount-of-records-100k/348426 "2023-12-01T11:03:59Z")

</div>

Can someone explain how to use search\_after for more than 100k records without fetching 10k records just to get the sort value of the last record just to get the next 10k records? Here's an example: I have 100 100 reco…

---

## [Windows FIM Module - how to use custom path without recursive](https://discuss.elastic.co/t/windows-fim-module-how-to-use-custom-path-without-recursive/348423)

<div class="topic-metadata">

**Author:** [@s0p4L1n3](https://discuss.elastic.co/u/s0p4L1n3)\
**Replies:** 0\
**Last updated:** [December 1, 2023, 10:51am UTC](https://discuss.elastic.co/t/windows-fim-module-how-to-use-custom-path-without-recursive/348423 "2023-12-01T10:51:52Z")

</div>

Hello, I have Windows Client and Windows DFS Server with multiple shares. I want to monitor File/folder activities aka File Integrity Monitoring. I already tried with Winlogbeat by monitoring Event ID 4656 and 4663 bu…

---

## [When migrating logstash from Centos to Debian I get the tag "\_grokparsefailure"](https://discuss.elastic.co/t/when-migrating-logstash-from-centos-to-debian-i-get-the-tag-grokparsefailure/348328)

<div class="topic-metadata">

**Author:** [@OptimusPrimary](https://discuss.elastic.co/u/OptimusPrimary)\
**Replies:** 5\
**Last updated:** [December 1, 2023, 8:54am UTC](https://discuss.elastic.co/t/when-migrating-logstash-from-centos-to-debian-i-get-the-tag-grokparsefailure/348328 "2023-12-01T08:54:27Z")

</div>

I need to migrate the ELK stack from Centos to Debian, on the server I installed the same version of logstash and the same settings, rights and configs, but the logs are not parsed. The tag "\_grokparsefailure" is assign…

---

## [Search on Array Field in ElasticSearch](https://discuss.elastic.co/t/search-on-array-field-in-elasticsearch/348406)

<div class="topic-metadata">

**Author:** [@Rakhshunda\_Noorein\_J](https://discuss.elastic.co/u/Rakhshunda_Noorein_J)\
**Replies:** 0\
**Last updated:** [December 1, 2023, 8:12am UTC](https://discuss.elastic.co/t/search-on-array-field-in-elasticsearch/348406 "2023-12-01T08:12:00Z")

</div>

Hello, I have inserted data to an index from a csv file. And I have an Ids field like this whose datatype is a text or a keyword. "IDs": \[ "a07f1c55-e34b-467d-bfe2-f65f7e01ae61,3e7083d6-4e0c-4f7f-ac81-0d7c131ab58…

---

## [Dec 1st, 2023: \[EN\] Securing Elasticsearch with HashiCorp Vault](https://discuss.elastic.co/t/dec-1st-2023-en-securing-elasticsearch-with-hashicorp-vault/347280)

<div class="topic-metadata">

**Author:** [@framsouza](https://discuss.elastic.co/u/framsouza)\
**Replies:** 0\
**Last updated:** [December 1, 2023, 8:00am UTC](https://discuss.elastic.co/t/dec-1st-2023-en-securing-elasticsearch-with-hashicorp-vault/347280 "2023-12-01T08:00:52Z")

</div>

Are you utilizing both Elasticsearch and HashiCorp in your environment and seeking ways to connect the two? This concise article unveils the steps to effectively employ HashiCorp Vault for automated credential generat…

---

## [Filebeat not working with pipeline nor \* in csv is working](https://discuss.elastic.co/t/filebeat-not-working-with-pipeline-nor-in-csv-is-working/348388)

<div class="topic-metadata">

**Author:** [@mastinder](https://discuss.elastic.co/u/mastinder)\
**Replies:** 5\
**Last updated:** [December 1, 2023, 7:59am UTC](https://discuss.elastic.co/t/filebeat-not-working-with-pipeline-nor-in-csv-is-working/348388 "2023-12-01T07:59:35Z")

</div>

PUT \_ingest/pipeline/csv\_pipeline { "description": "A pipeline to parse CSV data", "processors": \[ { "csv": { "field": "message", "target\_fields": \["cluster", "index", "ilm\_policy", "time\_si…

[Previous page](https://discuss.elastic.co/latest.md?page=465)

[Next page](https://discuss.elastic.co/latest.md?page=467)
