# Latest

**URL:** https://discuss.elastic.co/latest.md?page=468

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 469

---

## [Failed to CompressedXContent on RestHighLevelClient 7.13](https://discuss.elastic.co/t/failed-to-compressedxcontent-on-resthighlevelclient-7-13/348345)

<div class="topic-metadata">

**Author:** [@avnere](https://discuss.elastic.co/u/avnere)\
**Replies:** 0\
**Last updated:** [November 30, 2023, 4:30pm UTC](https://discuss.elastic.co/t/failed-to-compressedxcontent-on-resthighlevelclient-7-13/348345 "2023-11-30T16:30:20Z")

</div>

Hi, I am getting the following exception when creatin new CompressedXContent for Template instance ElasticsearchParseException\[Failed to parse content to map\]; nested: JsonParseException\[Unexpected character ('p' (code…

---

## [How to use snapshot repo url](https://discuss.elastic.co/t/how-to-use-snapshot-repo-url/348274)

<div class="topic-metadata">

**Author:** [@Harper\_S1](https://discuss.elastic.co/u/Harper_S1)\
**Replies:** 1\
**Last updated:** [November 30, 2023, 4:19pm UTC](https://discuss.elastic.co/t/how-to-use-snapshot-repo-url/348274 "2023-11-30T16:19:03Z")

</div>

Hi, We are creating a parallel cluster and we need to migrate all the data. I saw the option where we can take the snapshot on existing cluster and create a repo url which can be used by another cluster and we can resto…

---

## [How can fill logstash output in filebeat.yml file](https://discuss.elastic.co/t/how-can-fill-logstash-output-in-filebeat-yml-file/346556)

<div class="topic-metadata">

**Author:** [@baber1223](https://discuss.elastic.co/u/baber1223)\
**Replies:** 1\
**Last updated:** [November 30, 2023, 4:05pm UTC](https://discuss.elastic.co/t/how-can-fill-logstash-output-in-filebeat-yml-file/346556 "2023-11-30T16:05:07Z")

</div>

This my elasticsearch output part in filebeat.yml file but I want to send logs to logstash # ---------------------------- Elasticsearch Output ---------------------------- output.elasticsearch: # Array of hosts to con…

---

## [Filebeat ignoring closing bracket {](https://discuss.elastic.co/t/filebeat-ignoring-closing-bracket/348312)

<div class="topic-metadata">

**Author:** [@Venkata\_Raja](https://discuss.elastic.co/u/Venkata_Raja)\
**Replies:** 9\
**Last updated:** [November 30, 2023, 3:06pm UTC](https://discuss.elastic.co/t/filebeat-ignoring-closing-bracket/348312 "2023-11-30T15:06:19Z")

</div>

Hi Team,, I have a multiline JSON message in a file , I used custom log integration to parse it with below multiline config. multiline: match: after negate: true pattern: '^{' I was getting all the data except last…

---

## [Trouble Finding Most Efficient Way to Optimize My Elastic Stack](https://discuss.elastic.co/t/trouble-finding-most-efficient-way-to-optimize-my-elastic-stack/348342)

<div class="topic-metadata">

**Author:** [@jreyes25](https://discuss.elastic.co/u/jreyes25)\
**Replies:** 0\
**Last updated:** [November 30, 2023, 3:36pm UTC](https://discuss.elastic.co/t/trouble-finding-most-efficient-way-to-optimize-my-elastic-stack/348342 "2023-11-30T15:36:47Z")

</div>

Hello, I've been trying to play around with my settings to try to optimize my Elastic Stack. My main goal, right now, is to have my searches load faster. For example, when I load my dashboards, it takes 30 seconds to 1+…

---

## [Create a Kibana Rule](https://discuss.elastic.co/t/create-a-kibana-rule/348333)

<div class="topic-metadata">

**Author:** [@Claudia\_Tavares](https://discuss.elastic.co/u/Claudia_Tavares)\
**Replies:** 2\
**Last updated:** [November 30, 2023, 3:05pm UTC](https://discuss.elastic.co/t/create-a-kibana-rule/348333 "2023-11-30T15:05:54Z")

</div>

Kibana: version 7.17.3 I am trying to create a Rule in Kibana Alerts and Insights, but I'm having some difficults. To contextualize: 1- I want to calculate the total of documents in last 5 minutes 2- Calculate the nu…

---

## [ML Anomaly Job with exclude\_frequent option](https://discuss.elastic.co/t/ml-anomaly-job-with-exclude-frequent-option/348047)

<div class="topic-metadata">

**Author:** [@marmai16](https://discuss.elastic.co/u/marmai16)\
**Replies:** 1\
**Last updated:** [November 30, 2023, 2:53pm UTC](https://discuss.elastic.co/t/ml-anomaly-job-with-exclude-frequent-option/348047 "2023-11-30T14:53:51Z")

</div>

Hello everyone, i was reading through the docs and became curious Say i create two detectors. One detector is high\_sum(a) over b The other detector is high\_sum(a) by c. Now, if i define exclude\_frequent = over for …

---

## [Elasticsearch Query](https://discuss.elastic.co/t/elasticsearch-query/347768)

<div class="topic-metadata">

**Author:** [@Brian-cf1](https://discuss.elastic.co/u/Brian-cf1)\
**Replies:** 3\
**Last updated:** [November 30, 2023, 2:41pm UTC](https://discuss.elastic.co/t/elasticsearch-query/347768 "2023-11-30T14:41:57Z")

</div>

How do i exclude multiple keywords from a field ? I need the following logic but its not letting me include 2 wild cards "must\_not": \[ { "wildcard": { "error.message": { "value": …

---

## [Customizing Elastic Map Service Basemaps](https://discuss.elastic.co/t/customizing-elastic-map-service-basemaps/348276)

<div class="topic-metadata">

**Author:** [@m.hanna](https://discuss.elastic.co/u/m.hanna)\
**Replies:** 5\
**Last updated:** [November 30, 2023, 2:29pm UTC](https://discuss.elastic.co/t/customizing-elastic-map-service-basemaps/348276 "2023-11-30T14:29:55Z")

</div>

I am testing using Elastic Map Service on a disconnected network. I am able to get the server installed and running, but the basemaps are quite busy and not that nice to look at. I was able to clean up the basemaps by m…

---

## [Filebeat reads logs from various locations?](https://discuss.elastic.co/t/filebeat-reads-logs-from-various-locations/348332)

<div class="topic-metadata">

**Author:** [@Satsan](https://discuss.elastic.co/u/Satsan)\
**Replies:** 1\
**Last updated:** [November 30, 2023, 2:16pm UTC](https://discuss.elastic.co/t/filebeat-reads-logs-from-various-locations/348332 "2023-11-30T14:16:27Z")

</div>

Filebeat reads logs from various locations in same yml file and sends them to the ELK (Elasticsearch, Logstash, and Kibana) stack for processing and analysis? For instance: -log.file.path: /etc/home/usr/logs -log.fil…

---

## [Unexpected Behavior of Kibana Query for Filtering Logs with Specific Keywords](https://discuss.elastic.co/t/unexpected-behavior-of-kibana-query-for-filtering-logs-with-specific-keywords/348055)

<div class="topic-metadata">

**Author:** [@Dokh\_Ahmed](https://discuss.elastic.co/u/Dokh_Ahmed)\
**Replies:** 1\
**Last updated:** [November 30, 2023, 2:04pm UTC](https://discuss.elastic.co/t/unexpected-behavior-of-kibana-query-for-filtering-logs-with-specific-keywords/348055 "2023-11-30T14:04:30Z")

</div>

I'm using a Kibana query (log\_message:(Started\* OR Disabled\*)) to filter logs that start with the keywords "Started" or "Disabled". However, I've noticed that this query also returns log lines containing these keywords i…

---

## [Watcher logging action - where do (which index) these logs come in?](https://discuss.elastic.co/t/watcher-logging-action-where-do-which-index-these-logs-come-in/348334)

<div class="topic-metadata">

**Author:** [@Edy\_Silva](https://discuss.elastic.co/u/Edy_Silva)\
**Replies:** 1\
**Last updated:** [November 30, 2023, 1:58pm UTC](https://discuss.elastic.co/t/watcher-logging-action-where-do-which-index-these-logs-come-in/348334 "2023-11-30T13:58:53Z")

</div>

I have a watcher that is supposed to perform a logging action. When I execute the watch it says it went well but I can't find this log anywhere.

---

## [No logs for Elasticsearch](https://discuss.elastic.co/t/no-logs-for-elasticsearch/347732)

<div class="topic-metadata">

**Author:** [@mbby](https://discuss.elastic.co/u/mbby)\
**Replies:** 3\
**Last updated:** [November 30, 2023, 12:34pm UTC](https://discuss.elastic.co/t/no-logs-for-elasticsearch/347732 "2023-11-30T12:34:47Z")

</div>

When I open the Stack monitoring page in Kibana it tells me that there are No logs for Elasticsearch and Follow these directions to set up Elasticsearch. Unfortunately the link doesn't really help me. Right at the beginn…

---

## [Elastic docs in PDF](https://discuss.elastic.co/t/elastic-docs-in-pdf/348305)

<div class="topic-metadata">

**Author:** [@lduvnjak](https://discuss.elastic.co/u/lduvnjak)\
**Replies:** 3\
**Last updated:** [November 30, 2023, 11:58am UTC](https://discuss.elastic.co/t/elastic-docs-in-pdf/348305 "2023-11-30T11:58:32Z")

</div>

This is a very simple question but I just wanna make sure. Does Elasticsearch have it's documentation in PDF format available for download anywhere? Thanks for any help in advance! Cheers, Luka

---

## [Profile file cannot be null Logstash error](https://discuss.elastic.co/t/profile-file-cannot-be-null-logstash-error/348224)

<div class="topic-metadata">

**Author:** [@laale1](https://discuss.elastic.co/u/laale1)\
**Replies:** 6\
**Last updated:** [November 30, 2023, 10:50am UTC](https://discuss.elastic.co/t/profile-file-cannot-be-null-logstash-error/348224 "2023-11-30T10:50:20Z")

</div>

Hello Community I have an issue in Logstash kinesis input plugin, when I run /usr/share/logstash/bin/logstash -f /etc/logstash/conf.d/kinesis.conf I can see logs are coming from AWS and ingested into my Elasticsear…

---

## [Unable to connect to elastic search with certificates](https://discuss.elastic.co/t/unable-to-connect-to-elastic-search-with-certificates/348325)

<div class="topic-metadata">

**Author:** [@shrikar18](https://discuss.elastic.co/u/shrikar18)\
**Replies:** 0\
**Last updated:** [November 30, 2023, 10:48am UTC](https://discuss.elastic.co/t/unable-to-connect-to-elastic-search-with-certificates/348325 "2023-11-30T10:48:52Z")

</div>

hi everyone , iam new to elasticsearch i have Elasticsearch deployed as pod and iam trying to check the status with a curl command i used https curl --cacert /root/http\_ca.crt -u elastic:$ELASTIC\_PASSWORD protocol://…

---

## [How to Display Trending Posts](https://discuss.elastic.co/t/how-to-display-trending-posts/347898)

<div class="topic-metadata">

**Author:** [@aisyaharifin](https://discuss.elastic.co/u/aisyaharifin)\
**Replies:** 3\
**Last updated:** [November 30, 2023, 9:40am UTC](https://discuss.elastic.co/t/how-to-display-trending-posts/347898 "2023-11-30T09:40:06Z")

</div>

Hello Elastic, I have this requirement where my user would like to display the top trending post, can refer image below : I showed them that we do have analytics based on the queries, but to specifically shown the t…

---

## [ERROR: java.lang.NoClassDefFoundError: co/elastic/apm/api/ElasticApm](https://discuss.elastic.co/t/error-java-lang-noclassdeffounderror-co-elastic-apm-api-elasticapm/348263)

<div class="topic-metadata">

**Author:** [@miguel.longo](https://discuss.elastic.co/u/miguel.longo)\
**Replies:** 1\
**Last updated:** [November 30, 2023, 8:37am UTC](https://discuss.elastic.co/t/error-java-lang-noclassdeffounderror-co-elastic-apm-api-elasticapm/348263 "2023-11-30T08:37:38Z")

</div>

Kibana version: 8.6.2 Elasticsearch version: 8.6.2 APM Server version: 8.6.2 APM Agent language and version: 1.43.0 Original install method (e.g. download page, yum, deb, from source, etc.) and version: Docker stack …

---

## [Reg: Logstash JVM OOM](https://discuss.elastic.co/t/reg-logstash-jvm-oom/348041)

<div class="topic-metadata">

**Author:** [@Thumati](https://discuss.elastic.co/u/Thumati)\
**Replies:** 5\
**Last updated:** [November 30, 2023, 7:36am UTC](https://discuss.elastic.co/t/reg-logstash-jvm-oom/348041 "2023-11-30T07:36:46Z")

</div>

Hi Logstash version is 8.4.3 . Logstash settings are done in below way cpu - 1000m, limits - 7 gi, request - 6 gi ,JVM is 67 %. From the metrics of CPU and memory we can see the memory is not even reaching the 3.5 GI …

---

## [Plugin server cannot accept body with get request from plugin ui](https://discuss.elastic.co/t/plugin-server-cannot-accept-body-with-get-request-from-plugin-ui/347721)

<div class="topic-metadata">

**Author:** [@Sheereen](https://discuss.elastic.co/u/Sheereen)\
**Replies:** 6\
**Last updated:** [November 30, 2023, 6:45am UTC](https://discuss.elastic.co/t/plugin-server-cannot-accept-body-with-get-request-from-plugin-ui/347721 "2023-11-30T06:45:37Z")

</div>

Hi, I am developing a custom external plugin in React, on Kibana 8.8.1. When I give a GET request from plugin ui to server, with a body; the body is still always undefined, even if I validate it with the basic schema. …

---

## [Elastics/kibana coonect with IBM ace server thru the APM server](https://discuss.elastic.co/t/elastics-kibana-coonect-with-ibm-ace-server-thru-the-apm-server/348289)

<div class="topic-metadata">

**Author:** [@kasunpurnima](https://discuss.elastic.co/u/kasunpurnima)\
**Replies:** 0\
**Last updated:** [November 30, 2023, 5:55am UTC](https://discuss.elastic.co/t/elastics-kibana-coonect-with-ibm-ace-server-thru-the-apm-server/348289 "2023-11-30T05:55:40Z")

</div>

Hi is there anyone is connect elastc with IBM aces server ?

---

## [Problem in Embedding iframe](https://discuss.elastic.co/t/problem-in-embedding-iframe/348116)

<div class="topic-metadata">

**Author:** [@Saksham\_Kawatra](https://discuss.elastic.co/u/Saksham_Kawatra)\
**Replies:** 4\
**Last updated:** [November 30, 2023, 5:09am UTC](https://discuss.elastic.co/t/problem-in-embedding-iframe/348116 "2023-11-30T05:09:00Z")

</div>

Hey everyone. I have been encountering a problem while trying to embed iframe of my dashboard into my application. Whenever i try to add credentials on the login page and press enter, the login page appears again, and …

---

## [Elasticsearch statefulset deployment failed with 8.11.1 image version](https://discuss.elastic.co/t/elasticsearch-statefulset-deployment-failed-with-8-11-1-image-version/348286)

<div class="topic-metadata">

**Author:** [@Subhajit](https://discuss.elastic.co/u/Subhajit)\
**Replies:** 0\
**Last updated:** [November 30, 2023, 4:53am UTC](https://discuss.elastic.co/t/elasticsearch-statefulset-deployment-failed-with-8-11-1-image-version/348286 "2023-11-30T04:53:31Z")

</div>

Hello Team, currently I am facing this below error while deploying latest \[elasticsearch:8.11.1\] image with elasticsearch statefulset helm chart. 2023-11-27T17:50:15.202018883Z {"@timestamp":"2023-11-27T17:50:15.200Z",…

---

## [AWS EC2 metrics integration not getting all values](https://discuss.elastic.co/t/aws-ec2-metrics-integration-not-getting-all-values/348278)

<div class="topic-metadata">

**Author:** [@eleong](https://discuss.elastic.co/u/eleong)\
**Replies:** 0\
**Last updated:** [November 29, 2023, 10:29pm UTC](https://discuss.elastic.co/t/aws-ec2-metrics-integration-not-getting-all-values/348278 "2023-11-29T22:29:17Z")

</div>

Hi, I am using Elastic 8.9.2. I'm trying to grab EC2 metrics via Elastic Agent integration (not using metricbeat for some reason). The integration is done, but for some reason, it is not getting all the values. The con…

---

## [Fuzz and stemmer](https://discuss.elastic.co/t/fuzz-and-stemmer/348277)

<div class="topic-metadata">

**Author:** [@staix](https://discuss.elastic.co/u/staix)\
**Replies:** 0\
**Last updated:** [November 29, 2023, 9:59pm UTC](https://discuss.elastic.co/t/fuzz-and-stemmer/348277 "2023-11-29T21:59:36Z")

</div>

Hello. if there is a mistake in the word, then when using fuzz, is it possible to somehow launch a stemmer after fuzz

---

## [How to disable querying ALL fields by default](https://discuss.elastic.co/t/how-to-disable-querying-all-fields-by-default/348249)

<div class="topic-metadata">

**Author:** [@Matt\_McGovern](https://discuss.elastic.co/u/Matt_McGovern)\
**Replies:** 6\
**Last updated:** [November 29, 2023, 7:47pm UTC](https://discuss.elastic.co/t/how-to-disable-querying-all-fields-by-default/348249 "2023-11-29T19:47:58Z")

</div>

We have some users that are killing our performance because they're not putting a field in their Discover searches...rather they are just putting a single value only so elasticsearch has to search through everything. Th…

---

## [.Net APM Traces Incomplete When Deployed](https://discuss.elastic.co/t/net-apm-traces-incomplete-when-deployed/348185)

<div class="topic-metadata">

**Author:** [@skaaks](https://discuss.elastic.co/u/skaaks)\
**Replies:** 3\
**Last updated:** [November 29, 2023, 6:47pm UTC](https://discuss.elastic.co/t/net-apm-traces-incomplete-when-deployed/348185 "2023-11-29T18:47:56Z")

</div>

Kibana version: 7.17..0 Elasticsearch version: 7.17.0 APM Server version: 7.17.15 APM Agent language and version: .Net Core 6.0 Browser version: Chrome 119.0.6045.160 Original install method (e.g. download page, yum…

---

## [Unable to see the Reporting option under Analytics in the Kibana Privileges](https://discuss.elastic.co/t/unable-to-see-the-reporting-option-under-analytics-in-the-kibana-privileges/348269)

<div class="topic-metadata">

**Author:** [@nmurilo](https://discuss.elastic.co/u/nmurilo)\
**Replies:** 3\
**Last updated:** [November 29, 2023, 6:35pm UTC](https://discuss.elastic.co/t/unable-to-see-the-reporting-option-under-analytics-in-the-kibana-privileges/348269 "2023-11-29T18:35:34Z")

</div>

I'm running a cloud Elastic/Kibana with an Enterprise license. But unable to see the reporting sub-feature option under Analytics session in the kibana privileges tab. Checked all documentation, but I didn't find what …

---

## [URL template in data view now working](https://discuss.elastic.co/t/url-template-in-data-view-now-working/346773)

<div class="topic-metadata">

**Author:** [@mathur7vidit](https://discuss.elastic.co/u/mathur7vidit)\
**Replies:** 4\
**Last updated:** [November 29, 2023, 5:32pm UTC](https://discuss.elastic.co/t/url-template-in-data-view-now-working/346773 "2023-11-29T17:32:22Z")

</div>

Hi All, I am getting 1 field which basically is going to showcase service now ticket no. now i want to map that field as a URL and i am trying to achieve it using URL template in that field. however, its not working at …

---

## [Active Alerts Showing for Unenrolled Agents](https://discuss.elastic.co/t/active-alerts-showing-for-unenrolled-agents/347060)

<div class="topic-metadata">

**Author:** [@DougR](https://discuss.elastic.co/u/DougR)\
**Replies:** 4\
**Last updated:** [November 29, 2023, 5:20pm UTC](https://discuss.elastic.co/t/active-alerts-showing-for-unenrolled-agents/347060 "2023-11-29T17:20:52Z")

</div>

We are using Elastic Cloud 8.11.0. I have active alerts showing for agents which have been unenrolled from Fleet and are showing in Fleet as unenrolled. How can I remove these alerts?

[Previous page](https://discuss.elastic.co/latest.md?page=467)

[Next page](https://discuss.elastic.co/latest.md?page=469)
