# Latest

**URL:** https://discuss.elastic.co/latest.md?page=467

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 468

---

## [Inquiry Regarding the "Webhook - Case Management" Connector's Transition from Technical Preview](https://discuss.elastic.co/t/inquiry-regarding-the-webhook-case-management-connectors-transition-from-technical-preview/348270)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 2\
**Last updated:** [December 1, 2023, 7:57am UTC](https://discuss.elastic.co/t/inquiry-regarding-the-webhook-case-management-connectors-transition-from-technical-preview/348270 "2023-12-01T07:57:08Z")

</div>

Hello Elastic Community, I am currently considering the integration of a "Webhook - Case Management" connector with our IT Service Management (ITSM) system. Given its current status as a feature in technical preview, I'…

---

## [Cannot search my pdf files](https://discuss.elastic.co/t/cannot-search-my-pdf-files/348297)

<div class="topic-metadata">

**Author:** [@Mandy\_Poon](https://discuss.elastic.co/u/Mandy_Poon)\
**Replies:** 2\
**Last updated:** [December 1, 2023, 7:44am UTC](https://discuss.elastic.co/t/cannot-search-my-pdf-files/348297 "2023-12-01T07:44:33Z")

</div>

I have a pdf file and there is a wording "XXX Contract ID - 170458" on the pdf. However I cannot search my file if I use "Contract ID - 170458". (I can search the pdf file if I use "170458") Anyone can help? Thank yo…

---

## [Update record in Kafka-Elastic Pipelines through Logstash](https://discuss.elastic.co/t/update-record-in-kafka-elastic-pipelines-through-logstash/348401)

<div class="topic-metadata">

**Author:** [@Alberuni\_Beruni](https://discuss.elastic.co/u/Alberuni_Beruni)\
**Replies:** 0\
**Last updated:** [December 1, 2023, 7:31am UTC](https://discuss.elastic.co/t/update-record-in-kafka-elastic-pipelines-through-logstash/348401 "2023-12-01T07:31:51Z")

</div>

Hi, I am directly ingesting kafka recored from kafka topic to Elasticsearch server, if there is coming records is updated with the existing in Elasticsearch server so how can i handle it with logstash that if creation i…

---

## [Traces are not correctly ccorrelated when using an API Gateway](https://discuss.elastic.co/t/traces-are-not-correctly-ccorrelated-when-using-an-api-gateway/348400)

<div class="topic-metadata">

**Author:** [@MaxMeijer](https://discuss.elastic.co/u/MaxMeijer)\
**Replies:** 0\
**Last updated:** [December 1, 2023, 6:48am UTC](https://discuss.elastic.co/t/traces-are-not-correctly-ccorrelated-when-using-an-api-gateway/348400 "2023-12-01T06:48:21Z")

</div>

Kibana version: 8.11.1 Elasticsearch version: 8.11.1 APM Server version: Unknown/ most likely 8.11.1 APM Agent language and version: No APM Agent. .NET OpenTelemetry sending data directly to the APm server using …

---

## [AWS Integration - Poor Performance](https://discuss.elastic.co/t/aws-integration-poor-performance/348397)

<div class="topic-metadata">

**Author:** [@digital-thought](https://discuss.elastic.co/u/digital-thought)\
**Replies:** 0\
**Last updated:** [December 1, 2023, 6:20am UTC](https://discuss.elastic.co/t/aws-integration-poor-performance/348397 "2023-12-01T06:20:35Z")

</div>

I have deployed an elastic agent with the AWS Integration in order to process VPC and CloudTrail logs. The logs are being placed to seperate S3 buckets which in turn then trigger an event to an SQS queue - one for the V…

---

## [MetricBeat: System module does not seems to send any data to ES](https://discuss.elastic.co/t/metricbeat-system-module-does-not-seems-to-send-any-data-to-es/348302)

<div class="topic-metadata">

**Author:** [@blueren](https://discuss.elastic.co/u/blueren)\
**Replies:** 2\
**Last updated:** [December 1, 2023, 6:06am UTC](https://discuss.elastic.co/t/metricbeat-system-module-does-not-seems-to-send-any-data-to-es/348302 "2023-12-01T06:06:52Z")

</div>

I have metricbeat running inside a docker container, and have been able to successfully get docker and ES stack monitored. I'm trying to extend the monitoring to the system. However, I'm unable to see any of the system s…

---

## [Limit on number of remote clusters in Cross-cluster search](https://discuss.elastic.co/t/limit-on-number-of-remote-clusters-in-cross-cluster-search/348395)

<div class="topic-metadata">

**Author:** [@Naveen\_Kumar\_S](https://discuss.elastic.co/u/Naveen_Kumar_S)\
**Replies:** 0\
**Last updated:** [December 1, 2023, 5:52am UTC](https://discuss.elastic.co/t/limit-on-number-of-remote-clusters-in-cross-cluster-search/348395 "2023-12-01T05:52:03Z")

</div>

Brief Info: I am planning to create a multi-cluster (around 50 clusters) Elasticsearch setup to store a large amount of data (around 7 years of enterprise data). This number is based on thorough planning considering the…

---

## [I have installed a 7.17.3 metric beat and file beat, both the beats are unable to send data to the logstash](https://discuss.elastic.co/t/i-have-installed-a-7-17-3-metric-beat-and-file-beat-both-the-beats-are-unable-to-send-data-to-the-logstash/346018)

<div class="topic-metadata">

**Author:** [@AKAM14](https://discuss.elastic.co/u/AKAM14)\
**Replies:** 13\
**Last updated:** [December 1, 2023, 5:24am UTC](https://discuss.elastic.co/t/i-have-installed-a-7-17-3-metric-beat-and-file-beat-both-the-beats-are-unable-to-send-data-to-the-logstash/346018 "2023-12-01T05:24:15Z")

</div>

Hi Team, I have a 3 node elk cluster 7.17.3 , i have installed metricbeats and file beat on a new server , the logstash ports are opened(5044). i have checked telnet. the connection looks fine. The beats are unable to …

---

## [How to limit the dataset size of elastic/security ESRally track](https://discuss.elastic.co/t/how-to-limit-the-dataset-size-of-elastic-security-esrally-track/348281)

<div class="topic-metadata">

**Author:** [@VidR](https://discuss.elastic.co/u/VidR)\
**Replies:** 0\
**Last updated:** [November 30, 2023, 1:01am UTC](https://discuss.elastic.co/t/how-to-limit-the-dataset-size-of-elastic-security-esrally-track/348281 "2023-11-30T01:01:05Z")

</div>

I am running esrally elastic/security track on ESRally version 2.7.0. By default, it downloads the following datasets, with total size of 128GB. but I only need ~30-50GB input dataset size. rally@benchmark-bqfd7:~/.ral…

---

## [Overwriting supplied index micro-%{appName}%{+YYYY.MM.dd} with rollover alias vehicle-service](https://discuss.elastic.co/t/overwriting-supplied-index-micro-appname-yyyy-mm-dd-with-rollover-alias-vehicle-service/348354)

<div class="topic-metadata">

**Author:** [@Gaurav\_Sharma3](https://discuss.elastic.co/u/Gaurav_Sharma3)\
**Replies:** 4\
**Last updated:** [December 1, 2023, 4:05am UTC](https://discuss.elastic.co/t/overwriting-supplied-index-micro-appname-yyyy-mm-dd-with-rollover-alias-vehicle-service/348354 "2023-12-01T04:05:04Z")

</div>

input { tcp { port =\> 5000 codec =\> json } } output { if \[appName\] =="user-service"{ elasticsearch { hosts =\> \["http://localhost:9200"\] index =\> "micro-%{appName}%{+YYYY.MM.dd}" # Use date-based index names i…

---

## [Problema de thread\_pool.write.queue\_size](https://discuss.elastic.co/t/problema-de-thread-pool-write-queue-size/348387)

<div class="topic-metadata">

**Author:** [@Kelvin\_A\_Escobar\_Mor](https://discuss.elastic.co/u/Kelvin_A_Escobar_Mor)\
**Replies:** 0\
**Last updated:** [December 1, 2023, 3:41am UTC](https://discuss.elastic.co/t/problema-de-thread-pool-write-queue-size/348387 "2023-12-01T03:41:27Z")

</div>

Tengo problema con encolamiento en mis cluster esperimento problema de rendimeiento y en ocaciones mi cluster se cae por carga quisera saber cual es una buena alternativa para abordar temas de thread\_pool.write.queue\_siz…

---

## [When I try to mount some file to a docker elasticsearchcontainer, it always has some errors like no such file or directory](https://discuss.elastic.co/t/when-i-try-to-mount-some-file-to-a-docker-elasticsearchcontainer-it-always-has-some-errors-like-no-such-file-or-directory/348383)

<div class="topic-metadata">

**Author:** [@nmc10](https://discuss.elastic.co/u/nmc10)\
**Replies:** 2\
**Last updated:** [December 1, 2023, 3:39am UTC](https://discuss.elastic.co/t/when-i-try-to-mount-some-file-to-a-docker-elasticsearchcontainer-it-always-has-some-errors-like-no-such-file-or-directory/348383 "2023-12-01T03:39:14Z")

</div>

You can see these image to understand what I mean. I even run a test container and use ls command to check if the file existed but although it exist in the container, it still shows the error that it missed when I starte…

---

## [Auto email when get alerts on elastic](https://discuss.elastic.co/t/auto-email-when-get-alerts-on-elastic/348385)

<div class="topic-metadata">

**Author:** [@wang4321](https://discuss.elastic.co/u/wang4321)\
**Replies:** 0\
**Last updated:** [December 1, 2023, 3:38am UTC](https://discuss.elastic.co/t/auto-email-when-get-alerts-on-elastic/348385 "2023-12-01T03:38:01Z")

</div>

Hi! Can I know about auto emailing when I get alerts on elastic

---

## [How can I get a client ip of search request in ielasticsearch?](https://discuss.elastic.co/t/how-can-i-get-a-client-ip-of-search-request-in-ielasticsearch/348284)

<div class="topic-metadata">

**Author:** [@yunpeng.jiangyp](https://discuss.elastic.co/u/yunpeng.jiangyp)\
**Replies:** 3\
**Last updated:** [December 1, 2023, 2:44am UTC](https://discuss.elastic.co/t/how-can-i-get-a-client-ip-of-search-request-in-ielasticsearch/348284 "2023-12-01T02:44:12Z")

</div>

Hi guys: I found a slow search request , but i didn't know the search request's client ip . Can I get a client ip of search request in elasticsearch?

---

## [Un acknowledged events in PQ](https://discuss.elastic.co/t/un-acknowledged-events-in-pq/348379)

<div class="topic-metadata">

**Author:** [@kannan\_raj](https://discuss.elastic.co/u/kannan_raj)\
**Replies:** 0\
**Last updated:** [December 1, 2023, 2:29am UTC](https://discuss.elastic.co/t/un-acknowledged-events-in-pq/348379 "2023-12-01T02:29:01Z")

</div>

Hi Team, Is there any way to check the ununacknowledged events from the Persistent Queue method. Unfortunately we are not able to use the metric queue\_persisted\_growth\_events to find the ununacknowledged. Regards Kan…

---

## [Log.original field lost with upgrade 8.6.1 from 1.5.3](https://discuss.elastic.co/t/log-original-field-lost-with-upgrade-8-6-1-from-1-5-3/348363)

<div class="topic-metadata">

**Author:** [@ridvandev](https://discuss.elastic.co/u/ridvandev)\
**Replies:** 3\
**Last updated:** [November 30, 2023, 11:25pm UTC](https://discuss.elastic.co/t/log-original-field-lost-with-upgrade-8-6-1-from-1-5-3/348363 "2023-11-30T23:25:06Z")

</div>

We used to use the log.original field a lot for our searches in Kibana, but since the upgrade of Elastic.CommonSchema.Nlog package, I can't seem to find this field anymore. Also, it looks like the log template we depend …

---

## [MongoDB Output plugin 3.1.7 error](https://discuss.elastic.co/t/mongodb-output-plugin-3-1-7-error/348372)

<div class="topic-metadata">

**Author:** [@Daniela\_Juliana\_Sanc](https://discuss.elastic.co/u/Daniela_Juliana_Sanc)\
**Replies:** 1\
**Last updated:** [November 30, 2023, 11:18pm UTC](https://discuss.elastic.co/t/mongodb-output-plugin-3-1-7-error/348372 "2023-11-30T23:18:46Z")

</div>

Hi, I am not able to connect to MongoDB Compass Version 7.0.3 with below error.Using plugin version 3.1.7. \[WARN \]\[logstash.outputs.mongodb \]\[main\] MONGODB | Failed to handshake with localhost:27017: ArgumentError: wro…

---

## [Endpoint Agent clock problem in sleep mode](https://discuss.elastic.co/t/endpoint-agent-clock-problem-in-sleep-mode/347741)

<div class="topic-metadata">

**Author:** [@simoner](https://discuss.elastic.co/u/simoner)\
**Replies:** 4\
**Last updated:** [November 30, 2023, 11:14pm UTC](https://discuss.elastic.co/t/endpoint-agent-clock-problem-in-sleep-mode/347741 "2023-11-30T23:14:08Z")

</div>

Hello, I found a problem with Endpoint agent and sleep mode. When my computer wakes itself up from sleep mode Endpoint Agent logs: {"file":{"line":140,"name":"Entry.cpp"}}},"message":"Entry.cpp:140 The system clock ad…

---

## [ServiceNow SecOps connector](https://discuss.elastic.co/t/servicenow-secops-connector/348374)

<div class="topic-metadata">

**Author:** [@John\_McAfee1](https://discuss.elastic.co/u/John_McAfee1)\
**Replies:** 0\
**Last updated:** [November 30, 2023, 10:20pm UTC](https://discuss.elastic.co/t/servicenow-secops-connector/348374 "2023-11-30T22:20:09Z")

</div>

Hello, I am testing the SecOps service now connector on my Personal Development Instance provided by serive now. I have followed the instructions outlined in the documentation: ServiceNow SecOps connector and action | …

---

## [Elastic Controls show error - Not Found](https://discuss.elastic.co/t/elastic-controls-show-error-not-found/347746)

<div class="topic-metadata">

**Author:** [@rj6578](https://discuss.elastic.co/u/rj6578)\
**Replies:** 3\
**Last updated:** [November 30, 2023, 8:56pm UTC](https://discuss.elastic.co/t/elastic-controls-show-error-not-found/347746 "2023-11-30T20:56:06Z")

</div>

This is probably a basic question and something I am doing wrong. I am trying to create some Controls to filter my search. However, the Controls only seems to show data when its set to Filter Type "Number", "string, IP"…

---

## [Logstash CA error](https://discuss.elastic.co/t/logstash-ca-error/348369)

<div class="topic-metadata">

**Author:** [@Marcus\_Berglund](https://discuss.elastic.co/u/Marcus_Berglund)\
**Replies:** 2\
**Last updated:** [November 30, 2023, 8:55pm UTC](https://discuss.elastic.co/t/logstash-ca-error/348369 "2023-11-30T20:55:49Z")

</div>

Hi, I have been sitting with this issue all day! :slight\_smile: and I get the below error (on windows) \[2023-11-30T21:42:08,979\]\[ERROR\]\[logstash.outputs.elasticsearch\] Invalid setting for elasticsearch output plugin: …

---

## [Kibana degraded after upgrade](https://discuss.elastic.co/t/kibana-degraded-after-upgrade/348160)

<div class="topic-metadata">

**Author:** [@rudyfaile](https://discuss.elastic.co/u/rudyfaile)\
**Replies:** 1\
**Last updated:** [November 30, 2023, 8:53pm UTC](https://discuss.elastic.co/t/kibana-degraded-after-upgrade/348160 "2023-11-30T20:53:35Z")

</div>

Hi, I upgraded my ELK stack running on self-hosted kubernetes. My Elasticsearch cluster is green, but my kibana instance is spewing error logs like: │ kibana \[2023-11-28T15:24:58.959+00:00\]\[ERROR\]\[plugins.taskManager\] …

---

## [NodeEnvironment.assertEnvIsLocked threw java.io.IOException: The device is not ready](https://discuss.elastic.co/t/nodeenvironment-assertenvislocked-threw-java-io-ioexception-the-device-is-not-ready/348089)

<div class="topic-metadata">

**Author:** [@blademan](https://discuss.elastic.co/u/blademan)\
**Replies:** 3\
**Last updated:** [November 30, 2023, 8:46pm UTC](https://discuss.elastic.co/t/nodeenvironment-assertenvislocked-threw-java-io-ioexception-the-device-is-not-ready/348089 "2023-11-30T20:46:15Z")

</div>

ES is deployed on an Azure VMSS (Windows VMs). It's throwing java.io.IOException "The device is not ready" on some VMs when creating shards, while working well on some other VMs at the same time. Here is what the except…

---

## [Filebeat Context Error](https://discuss.elastic.co/t/filebeat-context-error/348366)

<div class="topic-metadata">

**Author:** [@bigdaddy0918](https://discuss.elastic.co/u/bigdaddy0918)\
**Replies:** 0\
**Last updated:** [November 30, 2023, 8:41pm UTC](https://discuss.elastic.co/t/filebeat-context-error/348366 "2023-11-30T20:41:57Z")

</div>

I was able to push a new CEL input to Filebeat v8.7.1 via puppet. When we launch filebeat v.8.7.1 I see this message pop up in the log: {"log.level":"info","@timestamp":"2023-11-30T19:59:28.167Z","log.logger":"input.ce…

---

## [Watcher Http Input - PKIX path building failed](https://discuss.elastic.co/t/watcher-http-input-pkix-path-building-failed/348279)

<div class="topic-metadata">

**Author:** [@Rossana](https://discuss.elastic.co/u/Rossana)\
**Replies:** 14\
**Last updated:** [November 30, 2023, 7:52pm UTC](https://discuss.elastic.co/t/watcher-http-input-pkix-path-building-failed/348279 "2023-11-30T19:52:34Z")

</div>

Hi, I create a watcher to monitoring de HEALTH of the Cluster. I did get this error on the watcher response: I also check my kibana configuration and I have TLS config : I dont know why this error happend!

---

## [Can not create a document has mutlipolygon having hole](https://discuss.elastic.co/t/can-not-create-a-document-has-mutlipolygon-having-hole/348177)

<div class="topic-metadata">

**Author:** [@Sai\_Suvam\_Patnaik](https://discuss.elastic.co/u/Sai_Suvam_Patnaik)\
**Replies:** 2\
**Last updated:** [November 30, 2023, 6:31pm UTC](https://discuss.elastic.co/t/can-not-create-a-document-has-mutlipolygon-having-hole/348177 "2023-11-30T18:31:07Z")

</div>

Hi, can anyone help me I am facing a following. Summary Can not create a document has mutlipolygon having hole. I do not know why responses reason is correct or this is bug? I have visualize the multipolygon, using …

---

## [Mapping in the new .NET client V8](https://discuss.elastic.co/t/mapping-in-the-new-net-client-v8/348357)

<div class="topic-metadata">

**Author:** [@MountainMoon](https://discuss.elastic.co/u/MountainMoon)\
**Replies:** 0\
**Last updated:** [November 30, 2023, 6:29pm UTC](https://discuss.elastic.co/t/mapping-in-the-new-net-client-v8/348357 "2023-11-30T18:29:34Z")

</div>

I'm trying to write a mapping function using V8 client library. But there is not much i can configure. For example in the NEST V7, i can specify analyzer, multifields to a certain field via fluent mapping: ''' .Text(tt…

---

## [Logstash HTTP\_POLLER issue - PKIX path bulding failed](https://discuss.elastic.co/t/logstash-http-poller-issue-pkix-path-bulding-failed/348356)

<div class="topic-metadata">

**Author:** [@Rossana](https://discuss.elastic.co/u/Rossana)\
**Replies:** 0\
**Last updated:** [November 30, 2023, 6:09pm UTC](https://discuss.elastic.co/t/logstash-http-poller-issue-pkix-path-bulding-failed/348356 "2023-11-30T18:09:48Z")

</div>

hi, I got this error when I try to extract information of Elasticsearch form logstash: cfg config on logstash Do you know what could be my error?

---

## [Specifying X-Enterprise-Search-Analytics with the Node.js client.app.searchEsSearch method?](https://discuss.elastic.co/t/specifying-x-enterprise-search-analytics-with-the-node-js-client-app-searchessearch-method/348347)

<div class="topic-metadata">

**Author:** [@gagravarr](https://discuss.elastic.co/u/gagravarr)\
**Replies:** 0\
**Last updated:** [November 30, 2023, 5:01pm UTC](https://discuss.elastic.co/t/specifying-x-enterprise-search-analytics-with-the-node-js-client-app-searchessearch-method/348347 "2023-11-30T17:01:20Z")

</div>

I'm using App Search, and for one quite complex query I need to make an Elasticsearch search rather than an App Search search As I'm working in NodeJS, I'm doing that with a client.app.searchEsSearch call In the App Se…

---

## [\[Kibana\] High and inconsistent RAM usage after upgrade to 8.11.1](https://discuss.elastic.co/t/kibana-high-and-inconsistent-ram-usage-after-upgrade-to-8-11-1/347825)

<div class="topic-metadata">

**Author:** [@byildiz](https://discuss.elastic.co/u/byildiz)\
**Replies:** 2\
**Last updated:** [November 30, 2023, 4:32pm UTC](https://discuss.elastic.co/t/kibana-high-and-inconsistent-ram-usage-after-upgrade-to-8-11-1/347825 "2023-11-30T16:32:22Z")

</div>

Hi guys, we have updated our Elastic Stack to the current latest version 8.11.1. But we have observed a higher RAM usage and data lacks related to the kibana instance, therefore we didn't continue to update our prod sta…

[Previous page](https://discuss.elastic.co/latest.md?page=466)

[Next page](https://discuss.elastic.co/latest.md?page=468)
