# Latest

**URL:** https://discuss.elastic.co/latest.md?page=469

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 470

---

## [Search Filter API (js client) filter on field type array](https://discuss.elastic.co/t/search-filter-api-js-client-filter-on-field-type-array/348192)

<div class="topic-metadata">

**Author:** [@Rustin\_Spencer](https://discuss.elastic.co/u/Rustin_Spencer)\
**Replies:** 1\
**Last updated:** [November 29, 2023, 5:12pm UTC](https://discuss.elastic.co/t/search-filter-api-js-client-filter-on-field-type-array/348192 "2023-11-29T17:12:32Z")

</div>

I want to filter if the value contains in the array, not-contains and array contains all of the value given. How would I build the filter options in these cases?

---

## [Elastic Native Connector Troubles](https://discuss.elastic.co/t/elastic-native-connector-troubles/348247)

<div class="topic-metadata">

**Author:** [@George3](https://discuss.elastic.co/u/George3)\
**Replies:** 1\
**Last updated:** [November 29, 2023, 4:40pm UTC](https://discuss.elastic.co/t/elastic-native-connector-troubles/348247 "2023-11-29T16:40:28Z")

</div>

Hi all We've been struggling to get either of the Workplace search SharePoint Online connector or the SharePoint native connector working. We started with Workplace search and were advised by Elastic support to pivot t…

---

## [How can we deploy, start and ingest pipeline for ELSER2?](https://discuss.elastic.co/t/how-can-we-deploy-start-and-ingest-pipeline-for-elser2/348251)

<div class="topic-metadata">

**Author:** [@Rakesh\_Nayak](https://discuss.elastic.co/u/Rakesh_Nayak)\
**Replies:** 1\
**Last updated:** [November 29, 2023, 3:53pm UTC](https://discuss.elastic.co/t/how-can-we-deploy-start-and-ingest-pipeline-for-elser2/348251 "2023-11-29T15:53:55Z")

</div>

Hello Team, We are exploring using ELSER2 and we have migrated ourselves to use elastic 8.11.1. We have done the POC of the deploy/start of the elser model and created an ingest pipeline through Kibanna. But we need to …

---

## [Metricbeat - Can't see linked indices](https://discuss.elastic.co/t/metricbeat-cant-see-linked-indices/348166)

<div class="topic-metadata">

**Author:** [@Swathi12](https://discuss.elastic.co/u/Swathi12)\
**Replies:** 3\
**Last updated:** [November 29, 2023, 3:42pm UTC](https://discuss.elastic.co/t/metricbeat-cant-see-linked-indices/348166 "2023-11-29T15:42:28Z")

</div>

Hi together, after an issue with metricbeat i have to re-configure everything again. i deployed on my kuberentes cluster metricbeat-7.17.8. In Kibana i can't see any linked indices but logs tells me no error 2023-1…

---

## [Data Analysis with Kibana - Machine Learning](https://discuss.elastic.co/t/data-analysis-with-kibana-machine-learning/346315)

<div class="topic-metadata">

**Author:** [@Jordan\_Santander](https://discuss.elastic.co/u/Jordan_Santander)\
**Replies:** 1\
**Last updated:** [November 29, 2023, 3:31pm UTC](https://discuss.elastic.co/t/data-analysis-with-kibana-machine-learning/346315 "2023-11-29T15:31:01Z")

</div>

Course: Data Analysis with Kibana Version: 7.15 Question: Hello, In the lab environment I don't have the options to use machine learning, it only allows me to access data visualizer, so I can't do the machine learning …

---

## [Delete indices after 180 days](https://discuss.elastic.co/t/delete-indices-after-180-days/348148)

<div class="topic-metadata">

**Author:** [@secsec](https://discuss.elastic.co/u/secsec)\
**Replies:** 2\
**Last updated:** [November 29, 2023, 3:25pm UTC](https://discuss.elastic.co/t/delete-indices-after-180-days/348148 "2023-11-29T15:25:11Z")

</div>

Hello, i have create new ILM policy PUT \_ilm/policy/delete-logs-after-6months { "policy": { "phases": { "delete": { "min\_age": "180d", "actions": { "delete": {} } } …

---

## [.NET Core - DefaultMappingFor\<T\> hits multiple indexes](https://discuss.elastic.co/t/net-core-defaultmappingfor-t-hits-multiple-indexes/348250)

<div class="topic-metadata">

**Author:** [@kruegeba](https://discuss.elastic.co/u/kruegeba)\
**Replies:** 0\
**Last updated:** [November 29, 2023, 3:22pm UTC](https://discuss.elastic.co/t/net-core-defaultmappingfor-t-hits-multiple-indexes/348250 "2023-11-29T15:22:46Z")

</div>

We are using the Elastic.Clients.Elasticsearch 8.1 package in our .NET Core application. We are trying to set up the ability to use a single Elastic client, and hit different indexes based on the model type. We have the …

---

## [Fetch multiples traces with a common id](https://discuss.elastic.co/t/fetch-multiples-traces-with-a-common-id/348202)

<div class="topic-metadata">

**Author:** [@casteillet](https://discuss.elastic.co/u/casteillet)\
**Replies:** 1\
**Last updated:** [November 29, 2023, 3:15pm UTC](https://discuss.elastic.co/t/fetch-multiples-traces-with-a-common-id/348202 "2023-11-29T15:15:58Z")

</div>

Hi, I'm new with the Elasticsearch web interface. I'm trying to display player session results on the dashboard. I have three dropdown filters, with difficulty, level selected and name of the player (actor). During a s…

---

## [Elasticsearch's Docuements count dosen't match the exact number of input log lines](https://discuss.elastic.co/t/elasticsearchs-docuements-count-dosent-match-the-exact-number-of-input-log-lines/348217)

<div class="topic-metadata">

**Author:** [@Dokh\_Ahmed](https://discuss.elastic.co/u/Dokh_Ahmed)\
**Replies:** 9\
**Last updated:** [November 29, 2023, 3:01pm UTC](https://discuss.elastic.co/t/elasticsearchs-docuements-count-dosent-match-the-exact-number-of-input-log-lines/348217 "2023-11-29T15:01:30Z")

</div>

have a log file containing 2044 lines, but after indexing into Elasticsearch using Logstash, I find only 2043 documents. I suspect that an empty line in the log file might have been skipped by Logstash during indexing. I…

---

## [ML Anomaly Detection count of Processed Records](https://discuss.elastic.co/t/ml-anomaly-detection-count-of-processed-records/348234)

<div class="topic-metadata">

**Author:** [@marmai16](https://discuss.elastic.co/u/marmai16)\
**Replies:** 0\
**Last updated:** [November 29, 2023, 1:27pm UTC](https://discuss.elastic.co/t/ml-anomaly-detection-count-of-processed-records/348234 "2023-11-29T13:27:31Z")

</div>

Hello everyone, i deployed several anomaly detection jobs with different query\_delay parameters to evaluate which one fits best without losing documents or being to much behind real-time. What's interesting here is tha…

---

## [Compatibility: Filebeat 8.x with Elasticsearch 7.17](https://discuss.elastic.co/t/compatibility-filebeat-8-x-with-elasticsearch-7-17/348238)

<div class="topic-metadata">

**Author:** [@yago82](https://discuss.elastic.co/u/yago82)\
**Replies:** 0\
**Last updated:** [November 29, 2023, 2:18pm UTC](https://discuss.elastic.co/t/compatibility-filebeat-8-x-with-elasticsearch-7-17/348238 "2023-11-29T14:18:04Z")

</div>

Dear Community, I seek guidance regarding a scenario where we aim to use a plugin developed for Filebeat version 8.10.x, which is intended to send data to Elasticsearch 7.17. Considering the potential compatibility chal…

---

## [LogStash returns an error in connection with VMWare](https://discuss.elastic.co/t/logstash-returns-an-error-in-connection-with-vmware/347340)

<div class="topic-metadata">

**Author:** [@heisenberg93](https://discuss.elastic.co/u/heisenberg93)\
**Replies:** 3\
**Last updated:** [November 29, 2023, 2:09pm UTC](https://discuss.elastic.co/t/logstash-returns-an-error-in-connection-with-vmware/347340 "2023-11-29T14:09:14Z")

</div>

Hi, I set the forwarding configuration in a vCenter server to the port of my Elastic server where Logstash is running and set port 9300. Now my Logstash config for this looks like this: input { tcp { …

---

## [Is Apache HttpClient 5.x supported?](https://discuss.elastic.co/t/is-apache-httpclient-5-x-supported/348235)

<div class="topic-metadata">

**Author:** [@johngregg](https://discuss.elastic.co/u/johngregg)\
**Replies:** 1\
**Last updated:** [November 29, 2023, 1:47pm UTC](https://discuss.elastic.co/t/is-apache-httpclient-5-x-supported/348235 "2023-11-29T13:47:59Z")

</div>

I'm using java agent 1.42.0. Is Apache HttpClient 5.x supported? The docs say 4.3+. With debug enabled, I see messages like: 2023-11-29 07:29:20,399 \[main\] DEBUG co.elastic.apm.agent.bci.ElasticApmAgent - Applying i…

---

## [LDAP Elasticsearch](https://discuss.elastic.co/t/ldap-elasticsearch/348205)

<div class="topic-metadata">

**Author:** [@Manal\_A](https://discuss.elastic.co/u/Manal_A)\
**Replies:** 2\
**Last updated:** [November 29, 2023, 12:22pm UTC](https://discuss.elastic.co/t/ldap-elasticsearch/348205 "2023-11-29T12:22:33Z")

</div>

Hello , I want to know how to connect Elasticsearch to an external LDAP, and if I am in a cluster that contains multiple nodes, do I need to configure LDAP on all Elasticsearch nodes or just one of them (and wich one :…

---

## [Updating entities indexed by Hibernate Search](https://discuss.elastic.co/t/updating-entities-indexed-by-hibernate-search/348207)

<div class="topic-metadata">

**Author:** [@Muhammad\_namjas](https://discuss.elastic.co/u/Muhammad_namjas)\
**Replies:** 0\
**Last updated:** [November 29, 2023, 9:25am UTC](https://discuss.elastic.co/t/updating-entities-indexed-by-hibernate-search/348207 "2023-11-29T09:25:38Z")

</div>

I created a new entity connected to Hibernate Elastic Search and indexed it. Upon retrieving the indexed data, I noticed that updating the entity using the student ID resulted in deleting the existing data and re-inserti…

---

## [Json filter not parsing AWS WAF Logs](https://discuss.elastic.co/t/json-filter-not-parsing-aws-waf-logs/347639)

<div class="topic-metadata">

**Author:** [@laale1](https://discuss.elastic.co/u/laale1)\
**Replies:** 5\
**Last updated:** [November 29, 2023, 11:45am UTC](https://discuss.elastic.co/t/json-filter-not-parsing-aws-waf-logs/347639 "2023-11-29T11:45:34Z")

</div>

Hello Community, I having issue with parsing AWS Waf logs using Logstash filter plugin, here is the breakdown I'm pulling logs from AWS using kinesis input and the I'm filtering the log message using :- filter { jso…

---

## [Kibana custom branding](https://discuss.elastic.co/t/kibana-custom-branding/348194)

<div class="topic-metadata">

**Author:** [@Rutuja\_More](https://discuss.elastic.co/u/Rutuja_More)\
**Replies:** 1\
**Last updated:** [November 29, 2023, 11:35am UTC](https://discuss.elastic.co/t/kibana-custom-branding/348194 "2023-11-29T11:35:45Z")

</div>

Does the custom branding feature of the elastic enterprise version , allow us to change the "Welcome to elastic" part of kibana login page to something like " Welcome to xyz"??? If yes then how?????

---

## [ERROR co.elastic.apm.agent.bci.IndyBootstrap - Advice threw an exception, this should never happen! java.lang.NoSuchMethodError](https://discuss.elastic.co/t/error-co-elastic-apm-agent-bci-indybootstrap-advice-threw-an-exception-this-should-never-happen-java-lang-nosuchmethoderror/348150)

<div class="topic-metadata">

**Author:** [@miguel.longo](https://discuss.elastic.co/u/miguel.longo)\
**Replies:** 4\
**Last updated:** [November 29, 2023, 11:28am UTC](https://discuss.elastic.co/t/error-co-elastic-apm-agent-bci-indybootstrap-advice-threw-an-exception-this-should-never-happen-java-lang-nosuchmethoderror/348150 "2023-11-29T11:28:09Z")

</div>

Kibana version: 8.6.2 Elasticsearch version: 8.6.2 APM Server version: 8.6.2 APM Agent language and version: java/1.43.0 Original install method (e.g. download page, yum, deb, from source, etc.) and version: Docker s…

---

## [Elastic SIEM Detections](https://discuss.elastic.co/t/elastic-siem-detections/348212)

<div class="topic-metadata">

**Author:** [@The\_BlueishSky](https://discuss.elastic.co/u/The_BlueishSky)\
**Replies:** 2\
**Last updated:** [November 29, 2023, 11:24am UTC](https://discuss.elastic.co/t/elastic-siem-detections/348212 "2023-11-29T11:24:23Z")

</div>

How to manage Rule exemptions in Elastic SIEM, We have 1000+ alerts in elastic and we would like to understand how do we manage the whitelisting on each detections. Ex- we make some exemption on any rule, how do we maint…

---

## [FSCrawler, custom Tika parser](https://discuss.elastic.co/t/fscrawler-custom-tika-parser/348219)

<div class="topic-metadata">

**Author:** [@Eldar\_Madyarov](https://discuss.elastic.co/u/Eldar_Madyarov)\
**Replies:** 0\
**Last updated:** [November 29, 2023, 11:06am UTC](https://discuss.elastic.co/t/fscrawler-custom-tika-parser/348219 "2023-11-29T11:06:17Z")

</div>

I have created a custom Tika Parser, added a new type to custom-mimetypes.xml, built a jar. Then a put this jar to FSCrawler lib directory. But still FSCrawler doesn't see my Parser and using EmptyParser... What did I …

---

## [Search requests still get rejected at the same number of queued requests despite having increased \`queue\_size\`](https://discuss.elastic.co/t/search-requests-still-get-rejected-at-the-same-number-of-queued-requests-despite-having-increased-queue-size/346716)

<div class="topic-metadata">

**Author:** [@JvSPV](https://discuss.elastic.co/u/JvSPV)\
**Replies:** 1\
**Last updated:** [November 29, 2023, 10:43am UTC](https://discuss.elastic.co/t/search-requests-still-get-rejected-at-the-same-number-of-queued-requests-despite-having-increased-queue-size/346716 "2023-11-29T10:43:06Z")

</div>

We have a cluster of five nodes. For a lot of processing, our system sends search requests to Elasticsearch 7.17 in bursts, which fill up its queue\_size and Elasticsearch will start rejecting requests. However, our syst…

---

## [Elastic-agent AWS cloudtrail integration fails](https://discuss.elastic.co/t/elastic-agent-aws-cloudtrail-integration-fails/348161)

<div class="topic-metadata">

**Author:** [@Merdesz](https://discuss.elastic.co/u/Merdesz)\
**Replies:** 2\
**Last updated:** [November 29, 2023, 9:35am UTC](https://discuss.elastic.co/t/elastic-agent-aws-cloudtrail-integration-fails/348161 "2023-11-29T09:35:43Z")

</div>

Trying to set up Elastic-agent with the AWS cloudtrail integration, but it always fails to connect: \[elastic\_agent.filebeat\]\[error\] Input 'aws-s3' failed with: failed to initialize s3 poller: failed to get AWS region fo…

---

## [Upgrade Elasticsearch 8.6.0 into new environment](https://discuss.elastic.co/t/upgrade-elasticsearch-8-6-0-into-new-environment/348002)

<div class="topic-metadata">

**Author:** [@Septianingrum.17](https://discuss.elastic.co/u/Septianingrum.17)\
**Replies:** 3\
**Last updated:** [November 29, 2023, 9:26am UTC](https://discuss.elastic.co/t/upgrade-elasticsearch-8-6-0-into-new-environment/348002 "2023-11-29T09:26:18Z")

</div>

Hi All, currently I have elasticsearch version 8.6.0 with 2 elasticsearch nodes, 1 kibana node, 1 fleet server and 1 logstash node with each installed on RHEL 7.9 OS. I want to upgrade ELK to version 8.10 but in the new…

---

## [ELK Compatibility with Red Hat Java 8](https://discuss.elastic.co/t/elk-compatibility-with-red-hat-java-8/348198)

<div class="topic-metadata">

**Author:** [@swarali\_vartak](https://discuss.elastic.co/u/swarali_vartak)\
**Replies:** 1\
**Last updated:** [November 29, 2023, 8:22am UTC](https://discuss.elastic.co/t/elk-compatibility-with-red-hat-java-8/348198 "2023-11-29T08:22:50Z")

</div>

Hi, Current version of ELK Setup is 7.11.x Migrating OS from Oracle Java to Red Hat Java 8. Is elasticsearch 7.11 compatible with Red Hat java 8 ? Awaiting response. Thank you.

---

## [Frequent "No snapshot information" on default client- Azure repository](https://discuss.elastic.co/t/frequent-no-snapshot-information-on-default-client-azure-repository/348195)

<div class="topic-metadata">

**Author:** [@Anushree](https://discuss.elastic.co/u/Anushree)\
**Replies:** 0\
**Last updated:** [November 29, 2023, 6:48am UTC](https://discuss.elastic.co/t/frequent-no-snapshot-information-on-default-client-azure-repository/348195 "2023-11-29T06:48:31Z")

</div>

We are consistently encountering the "No snapshot information" message on the 'default' client for the 'Azure' repository type, even though snapshots exist in Azure containers. Despite the repository connection verificat…

---

## [Rollover Indexes Using ILM](https://discuss.elastic.co/t/rollover-indexes-using-ilm/348190)

<div class="topic-metadata">

**Author:** [@krish1](https://discuss.elastic.co/u/krish1)\
**Replies:** 1\
**Last updated:** [November 29, 2023, 5:51am UTC](https://discuss.elastic.co/t/rollover-indexes-using-ilm/348190 "2023-11-29T05:51:05Z")

</div>

I am currently using ES version 7.17.0 and trying out rollover indexes using the ILM. I have read through the documentation and my use case is to rollover my ES index every Monday midnight once a week i.e, rollover by ag…

---

## [APM agent suddenly stopped sending data to APM server](https://discuss.elastic.co/t/apm-agent-suddenly-stopped-sending-data-to-apm-server/345544)

<div class="topic-metadata">

**Author:** [@surya\_dadi\_dhamarake](https://discuss.elastic.co/u/surya_dadi_dhamarake)\
**Replies:** 12\
**Last updated:** [November 29, 2023, 4:53am UTC](https://discuss.elastic.co/t/apm-agent-suddenly-stopped-sending-data-to-apm-server/345544 "2023-11-29T04:53:54Z")

</div>

Hi Team, I have deployed elastic cloud deployment along with APM server and integrations server. My Deployment version : 8.9.0 Kibana and integration servers with: 1GB RAM, up to 8.4vCPU I have integrated APM agent w…

---

## [Multiple Anonymous Access in Kibana](https://discuss.elastic.co/t/multiple-anonymous-access-in-kibana/348111)

<div class="topic-metadata">

**Author:** [@Saksham\_Kawatra](https://discuss.elastic.co/u/Saksham_Kawatra)\
**Replies:** 2\
**Last updated:** [November 29, 2023, 4:41am UTC](https://discuss.elastic.co/t/multiple-anonymous-access-in-kibana/348111 "2023-11-29T04:41:07Z")

</div>

Suppose i have got 5 customers for whom i have to make dashboards via Kibana. I make the dashboards for each respective user. Now i want such that each user is able to access their respective dashboard anonymously. I was…

---

## [Restoring a single index for a datastream cheatsheet](https://discuss.elastic.co/t/restoring-a-single-index-for-a-datastream-cheatsheet/348180)

<div class="topic-metadata">

**Author:** [@seanziee](https://discuss.elastic.co/u/seanziee)\
**Replies:** 0\
**Last updated:** [November 28, 2023, 9:52pm UTC](https://discuss.elastic.co/t/restoring-a-single-index-for-a-datastream-cheatsheet/348180 "2023-11-28T21:52:22Z")

</div>

I feel like it took me a long time to figure this out and it may be helpful for others. These are the sets of commands that I send when I need to get back an index that already got deleted by ILM but I want to see the da…

---

## [How can I change the timezone on Kibana?](https://discuss.elastic.co/t/how-can-i-change-the-timezone-on-kibana/348172)

<div class="topic-metadata">

**Author:** [@SamuelSMendes](https://discuss.elastic.co/u/SamuelSMendes)\
**Replies:** 2\
**Last updated:** [November 28, 2023, 7:08pm UTC](https://discuss.elastic.co/t/how-can-i-change-the-timezone-on-kibana/348172 "2023-11-28T19:08:18Z")

</div>

I've noticed that my Kibana has a 3hours difference with my actual time. I've been looking into similar cases but so far changing the timezone in the Advanced Settings hasn't worked yet. What other ways could I try to ac…

[Previous page](https://discuss.elastic.co/latest.md?page=468)

[Next page](https://discuss.elastic.co/latest.md?page=470)
