# Latest

**URL:** https://discuss.elastic.co/latest.md?page=473

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 474

---

## [Grouping logs into sessions](https://discuss.elastic.co/t/grouping-logs-into-sessions/347934)

<div class="topic-metadata">

**Author:** [@Dor-Alter](https://discuss.elastic.co/u/Dor-Alter)\
**Replies:** 7\
**Last updated:** [November 24, 2023, 3:35pm UTC](https://discuss.elastic.co/t/grouping-logs-into-sessions/347934 "2023-11-24T15:35:24Z")

</div>

My entries in Elasticsearch are logs of different event. I am trying to group the logs into sessions of users based on an attribute of the logs. Each log has action attribute, everytime there is the action "session\_start…

---

## [Backup Of Index In Elasticsearch](https://discuss.elastic.co/t/backup-of-index-in-elasticsearch/347834)

<div class="topic-metadata">

**Author:** [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Replies:** 4\
**Last updated:** [November 24, 2023, 3:27pm UTC](https://discuss.elastic.co/t/backup-of-index-in-elasticsearch/347834 "2023-11-24T15:27:27Z")

</div>

Hi Team, I had a requirement where Elasticsearch is running as a container. I need to take backup of the one of the index and need to restore in Elasticsearch cluster which is running on VM. There is no Kibana configure…

---

## ["No JVMs were found" in JVM tab after APM upgrade from 1.38 to 1.43](https://discuss.elastic.co/t/no-jvms-were-found-in-jvm-tab-after-apm-upgrade-from-1-38-to-1-43/346537)

<div class="topic-metadata">

**Author:** [@jandry](https://discuss.elastic.co/u/jandry)\
**Replies:** 23\
**Last updated:** [November 24, 2023, 3:25pm UTC](https://discuss.elastic.co/t/no-jvms-were-found-in-jvm-tab-after-apm-upgrade-from-1-38-to-1-43/346537 "2023-11-24T15:25:36Z")

</div>

Kibana version: 7.16.3 APM Jva agent version: 1.43 Hi, For my previous ticket we did an upgrade of our apm agent from 1.38 to 1.43 and only that We now have the transaction correctly but we lost the JVM tab But w…

---

## [Add value to a previously indexed field with logstash](https://discuss.elastic.co/t/add-value-to-a-previously-indexed-field-with-logstash/347940)

<div class="topic-metadata">

**Author:** [@elk-user-0001](https://discuss.elastic.co/u/elk-user-0001)\
**Replies:** 0\
**Last updated:** [November 24, 2023, 3:25pm UTC](https://discuss.elastic.co/t/add-value-to-a-previously-indexed-field-with-logstash/347940 "2023-11-24T15:25:21Z")

</div>

Hello! I have a pipeline that has many inputs ( 19 ) and I use the update on the output using a document\_id to avoid duplicates and the elasticsearch filter and update the values. Is it possible to add the value of a f…

---

## [Max suggested index sizes / document amount etc](https://discuss.elastic.co/t/max-suggested-index-sizes-document-amount-etc/347937)

<div class="topic-metadata">

**Author:** [@elk1985](https://discuss.elastic.co/u/elk1985)\
**Replies:** 2\
**Last updated:** [November 24, 2023, 2:56pm UTC](https://discuss.elastic.co/t/max-suggested-index-sizes-document-amount-etc/347937 "2023-11-24T14:56:57Z")

</div>

Hello. My cluster is reaching 2000 opened shards. I have two data nodes now. I don't want to add another data node and scale up the cluster. I'm thinking more like changing indexing strategy. Currently logstash is cre…

---

## [logstash-output-elasticsearch fails with Permission denied](https://discuss.elastic.co/t/logstash-output-elasticsearch-fails-with-permission-denied/347787)

<div class="topic-metadata">

**Author:** [@mirceastoian](https://discuss.elastic.co/u/mirceastoian)\
**Replies:** 18\
**Last updated:** [November 24, 2023, 2:46pm UTC](https://discuss.elastic.co/t/logstash-output-elasticsearch-fails-with-permission-denied/347787 "2023-11-24T14:46:15Z")

</div>

Logstash information: Logstash version: 7.17.9 Logstash installation source: deb How is Logstash being run: systemd How was the Logstash Plugin installed: sudo /usr/share/logstash/bin/logstash-plugin install logstash-o…

---

## [Datafeed has been retrieving no data for a while](https://discuss.elastic.co/t/datafeed-has-been-retrieving-no-data-for-a-while/347924)

<div class="topic-metadata">

**Author:** [@marmai16](https://discuss.elastic.co/u/marmai16)\
**Replies:** 2\
**Last updated:** [November 24, 2023, 12:30pm UTC](https://discuss.elastic.co/t/datafeed-has-been-retrieving-no-data-for-a-while/347924 "2023-11-24T12:30:53Z")

</div>

Hello everybody, i just created some anomaly detection jobs, however new records are not processed after the lookback was performed. New data is available in the source index the jobs are working on. If i reset the jo…

---

## [Cannot upgrade APM integration after setting "traces-apm.traces-default\_policy" in stackConfigPolicy](https://discuss.elastic.co/t/cannot-upgrade-apm-integration-after-setting-traces-apm-traces-default-policy-in-stackconfigpolicy/347913)

<div class="topic-metadata">

**Author:** [@GeorgeGkinis](https://discuss.elastic.co/u/GeorgeGkinis)\
**Replies:** 1\
**Last updated:** [November 24, 2023, 11:42am UTC](https://discuss.elastic.co/t/cannot-upgrade-apm-integration-after-setting-traces-apm-traces-default-policy-in-stackconfigpolicy/347913 "2023-11-24T11:42:44Z")

</div>

We had disk running full because the "traces-apm.traces-default\_policy" did not specify a delete fase. To make sure the delete fase will be there in the future we defined the traces-apm.traces-default\_policy in our stac…

---

## [How best to Denormalize a SQL schema](https://discuss.elastic.co/t/how-best-to-denormalize-a-sql-schema/347922)

<div class="topic-metadata">

**Author:** [@cylon86](https://discuss.elastic.co/u/cylon86)\
**Replies:** 0\
**Last updated:** [November 24, 2023, 11:21am UTC](https://discuss.elastic.co/t/how-best-to-denormalize-a-sql-schema/347922 "2023-11-24T11:21:41Z")

</div>

Hi all, I'm building a new Index for a use case and I'm wondering what would be the best mapping to structure this index. I have no problem building this with SQL tables, links and joins; but I struggle finding the goo…

---

## [Json parse error](https://discuss.elastic.co/t/json-parse-error/347919)

<div class="topic-metadata">

**Author:** [@Belbo\_belbo](https://discuss.elastic.co/u/Belbo_belbo)\
**Replies:** 0\
**Last updated:** [November 24, 2023, 10:51am UTC](https://discuss.elastic.co/t/json-parse-error/347919 "2023-11-24T10:51:31Z")

</div>

I'm trying, via a busybox pod, to generate a json that sends it to filebeat which in turn sends it to logstash but I have this problem: at \[Source: (byte\[\])"Hello, World!"; line: 1, column: 7\]\>} \[2023-11-24T10:41:27,44…

---

## [Problem with Search-time Synonyms](https://discuss.elastic.co/t/problem-with-search-time-synonyms/347654)

<div class="topic-metadata">

**Author:** [@elleWajexi](https://discuss.elastic.co/u/elleWajexi)\
**Replies:** 7\
**Last updated:** [November 24, 2023, 10:38am UTC](https://discuss.elastic.co/t/problem-with-search-time-synonyms/347654 "2023-11-24T10:38:07Z")

</div>

I have an index with synonyms : "index": { "analysis": { "analyzer": { "index\_analyzer": { "tokenizer": "standard", "filter": \[ "lowercase", "my\_stemmer" \] }…

---

## [Elasticsearch .Net v8.x client use for bulk indexing raw JSON data](https://discuss.elastic.co/t/elasticsearch-net-v8-x-client-use-for-bulk-indexing-raw-json-data/347914)

<div class="topic-metadata">

**Author:** [@askids](https://discuss.elastic.co/u/askids)\
**Replies:** 0\
**Last updated:** [November 24, 2023, 10:19am UTC](https://discuss.elastic.co/t/elasticsearch-net-v8-x-client-use-for-bulk-indexing-raw-json-data/347914 "2023-11-24T10:19:58Z")

</div>

hi, I am using .Net 6.0, running Elastic.Client 8.x connecting to 7.17 ES, which will be shortly upgraded to 8.4. I want to know how do I perform bulk indexing of raw json data? I could see some example under Java clien…

---

## [Elasticsearch Classic Plugin Development Documents](https://discuss.elastic.co/t/elasticsearch-classic-plugin-development-documents/347912)

<div class="topic-metadata">

**Author:** [@Zeus101](https://discuss.elastic.co/u/Zeus101)\
**Replies:** 0\
**Last updated:** [November 24, 2023, 9:17am UTC](https://discuss.elastic.co/t/elasticsearch-classic-plugin-development-documents/347912 "2023-11-24T09:17:57Z")

</div>

I have been trying to develop plugins for Elasticsearch, but was unable to as I couldn't find a proper documentation for the same. I have been using to cookiecutters' sample template to play around this but a proper docu…

---

## [Logstash is processing old documents](https://discuss.elastic.co/t/logstash-is-processing-old-documents/347678)

<div class="topic-metadata">

**Author:** [@Cruz](https://discuss.elastic.co/u/Cruz)\
**Replies:** 3\
**Last updated:** [November 24, 2023, 9:12am UTC](https://discuss.elastic.co/t/logstash-is-processing-old-documents/347678 "2023-11-24T09:12:38Z")

</div>

When I restart the logstash service, the old documents are coming out. I tried to stopping the filebeat service where the logs are coming from and I deleted the old documents. But when I restart the logstash service the…

---

## [400 response on /intake/v2/events after elastic-agent 8.11.x upgrade](https://discuss.elastic.co/t/400-response-on-intake-v2-events-after-elastic-agent-8-11-x-upgrade/347103)

<div class="topic-metadata">

**Author:** [@viktorbard](https://discuss.elastic.co/u/viktorbard)\
**Replies:** 2\
**Last updated:** [November 24, 2023, 8:56am UTC](https://discuss.elastic.co/t/400-response-on-intake-v2-events-after-elastic-agent-8-11-x-upgrade/347103 "2023-11-24T08:56:14Z")

</div>

Hello Elastic team! I'm having issues with apm java agent after upgrading elasic-agent acting as APM server to 8.11.x. See specs below. Kibana version: 8.11.1 Elasticsearch version: 8.11.1 APM Server version: 8.11.1 …

---

## [What does "\_ignored" tag mean in hits](https://discuss.elastic.co/t/what-does-ignored-tag-mean-in-hits/344300)

<div class="topic-metadata">

**Author:** [@Aiswarya\_S](https://discuss.elastic.co/u/Aiswarya_S)\
**Replies:** 2\
**Last updated:** [November 24, 2023, 7:19am UTC](https://discuss.elastic.co/t/what-does-ignored-tag-mean-in-hits/344300 "2023-11-24T07:19:49Z")

</div>

In my Elastic search pulled data, I am getting an ignored tag in the hits but yet the data is coming correctly... so what does that ignored tag mean? { "took": 9, "timed\_out": false, "\_shards": { "total": 1, …

---

## [Vault Logging using Elasticsearch](https://discuss.elastic.co/t/vault-logging-using-elasticsearch/347897)

<div class="topic-metadata">

**Author:** [@VijayIQA](https://discuss.elastic.co/u/VijayIQA)\
**Replies:** 0\
**Last updated:** [November 24, 2023, 5:17am UTC](https://discuss.elastic.co/t/vault-logging-using-elasticsearch/347897 "2023-11-24T05:17:42Z")

</div>

Hi team, As per elastic docs at vault audit enable socket address=${ELASTIC\_AGENT\_IP}:9007 socket\_type=tcp In the place of ELASTIC\_AGENT\_IP I placed Elasticsearch IP and port as 9200 in this case getting an error as …

---

## [Elasticsearch CPU usage](https://discuss.elastic.co/t/elasticsearch-cpu-usage/347689)

<div class="topic-metadata">

**Author:** [@VijayIQA](https://discuss.elastic.co/u/VijayIQA)\
**Replies:** 4\
**Last updated:** [November 24, 2023, 3:10am UTC](https://discuss.elastic.co/t/elasticsearch-cpu-usage/347689 "2023-11-24T03:10:17Z")

</div>

Hi Team, Cluster monitoring by Kibana stack monitoring in that able to get all parameters but not getting CPU usages of the nodes.

---

## [How to use LruRedux cache in ruby filter](https://discuss.elastic.co/t/how-to-use-lruredux-cache-in-ruby-filter/347893)

<div class="topic-metadata">

**Author:** [@Chen\_Wei](https://discuss.elastic.co/u/Chen_Wei)\
**Replies:** 0\
**Last updated:** [November 24, 2023, 2:44am UTC](https://discuss.elastic.co/t/how-to-use-lruredux-cache-in-ruby-filter/347893 "2023-11-24T02:44:03Z")

</div>

Somehow we have some logs having duplicated events, we want to dedup the events using fingerprint and LRU cache in the logstash pipeline, So I write a ruby file require "lru\_redux" def register(params) limit = para…

---

## [Encryption of saved logs](https://discuss.elastic.co/t/encryption-of-saved-logs/347612)

<div class="topic-metadata">

**Author:** [@Hamada](https://discuss.elastic.co/u/Hamada)\
**Replies:** 5\
**Last updated:** [November 24, 2023, 1:08am UTC](https://discuss.elastic.co/t/encryption-of-saved-logs/347612 "2023-11-24T01:08:57Z")

</div>

I am using Elastic 8.1 in a Windows environment, How do you implement encryption of saved logs?

---

## [Index has disappeared](https://discuss.elastic.co/t/index-has-disappeared/347889)

<div class="topic-metadata">

**Author:** [@juancamiloll](https://discuss.elastic.co/u/juancamiloll)\
**Replies:** 5\
**Last updated:** [November 23, 2023, 10:47pm UTC](https://discuss.elastic.co/t/index-has-disappeared/347889 "2023-11-23T22:47:53Z")

</div>

Hello I have several sources that ELK processes, as you know from /etc/logstash/conf.d a .conf file is created for each of the sources to be processed either by GROK or CSV, I don't know if there is another way. One of…

---

## [Time fields show different time](https://discuss.elastic.co/t/time-fields-show-different-time/346651)

<div class="topic-metadata">

**Author:** [@juancamiloll](https://discuss.elastic.co/u/juancamiloll)\
**Replies:** 8\
**Last updated:** [November 23, 2023, 10:25pm UTC](https://discuss.elastic.co/t/time-fields-show-different-time/346651 "2023-11-23T22:25:01Z")

</div>

Hello again, I find a new problem where in the logs of a Paloalto I see that the "ReceivedTime" field and the "column103" field show a different time. I would appreciate your help input { file { path =\> "…

---

## [Logstash Multiline and line codec differences](https://discuss.elastic.co/t/logstash-multiline-and-line-codec-differences/347466)

<div class="topic-metadata">

**Author:** [@randomnamegenerator](https://discuss.elastic.co/u/randomnamegenerator)\
**Replies:** 6\
**Last updated:** [November 23, 2023, 7:42pm UTC](https://discuss.elastic.co/t/logstash-multiline-and-line-codec-differences/347466 "2023-11-23T19:42:09Z")

</div>

Hello All, We have application logs coming in from a number of different hosts (shipped with filebeat) and have obvserved a mixing of datastreams for one of the log types. We changed the logstash input.config from vers…

---

## [How to namespace indexes - Automatic not Manual](https://discuss.elastic.co/t/how-to-namespace-indexes-automatic-not-manual/347886)

<div class="topic-metadata">

**Author:** [@Alexander\_Mills](https://discuss.elastic.co/u/Alexander_Mills)\
**Replies:** 1\
**Last updated:** [November 23, 2023, 7:33pm UTC](https://discuss.elastic.co/t/how-to-namespace-indexes-automatic-not-manual/347886 "2023-11-23T19:33:31Z")

</div>

Mongo has namespacing via different databases on the same db server RabbitMQ has namespacing via different exhanges How can I automatically namespace indices with Elastic without manually namespacing keys with prod-x…

---

## [Setting Up Logstash In Docker-Compose For Bulk Ingest Of CSV Files In Local Machine](https://discuss.elastic.co/t/setting-up-logstash-in-docker-compose-for-bulk-ingest-of-csv-files-in-local-machine/346916)

<div class="topic-metadata">

**Author:** [@Ethan777100](https://discuss.elastic.co/u/Ethan777100)\
**Replies:** 112\
**Last updated:** [November 23, 2023, 5:55pm UTC](https://discuss.elastic.co/t/setting-up-logstash-in-docker-compose-for-bulk-ingest-of-csv-files-in-local-machine/346916 "2023-11-23T17:55:14Z")

</div>

CONTINUATION FROM kibana-8-11-0-failed-to-start-exit-code-1 My use case is to bulk ingest csv files into Elasticsearch. Understand i need Logstash to do it. Not sure how to start. Should I be using a default or cus…

---

## [Kubernetes Heartbeat autodiscover not working](https://discuss.elastic.co/t/kubernetes-heartbeat-autodiscover-not-working/347867)

<div class="topic-metadata">

**Author:** [@Paul\_B](https://discuss.elastic.co/u/Paul_B)\
**Replies:** 5\
**Last updated:** [November 23, 2023, 6:41pm UTC](https://discuss.elastic.co/t/kubernetes-heartbeat-autodiscover-not-working/347867 "2023-11-23T18:41:49Z")

</div>

Hi all, I've used the Kubernetes manifest file from this part of the documentation - Running Heartbeat on Kubernetes | Heartbeat Reference \[8.11\] | Elastic The deployment is working and the standalone monitors I've cre…

---

## [OpenTelemetry Agent cannot connect to Elastic APM in Fleet](https://discuss.elastic.co/t/opentelemetry-agent-cannot-connect-to-elastic-apm-in-fleet/347781)

<div class="topic-metadata">

**Author:** [@mmarinov](https://discuss.elastic.co/u/mmarinov)\
**Replies:** 5\
**Last updated:** [November 23, 2023, 6:23pm UTC](https://discuss.elastic.co/t/opentelemetry-agent-cannot-connect-to-elastic-apm-in-fleet/347781 "2023-11-23T18:23:24Z")

</div>

Kibana version: 8.11.1 Elasticsearch version: 8.11.1 APM Server version: 8.11.1 APM Agent language and version: opentelemetry-javaagent.jar 1.32.0 Browser version: not relevant Original install method (e.g. download…

---

## [Duplicate logs in Logstash](https://discuss.elastic.co/t/duplicate-logs-in-logstash/347630)

<div class="topic-metadata">

**Author:** [@marcowiskhy](https://discuss.elastic.co/u/marcowiskhy)\
**Replies:** 8\
**Last updated:** [November 23, 2023, 6:15pm UTC](https://discuss.elastic.co/t/duplicate-logs-in-logstash/347630 "2023-11-23T18:15:47Z")

</div>

I collect VPN logs through Logstash and index them in Elasticsearch, but I'm having the following problem: For each unique VPN connection (represented by TunnelID), there should be only one tunnel-up event and one tunne…

---

## [The Output Isolator Pattern: Inquiry regarding downstream pipeline failures](https://discuss.elastic.co/t/the-output-isolator-pattern-inquiry-regarding-downstream-pipeline-failures/347878)

<div class="topic-metadata">

**Author:** [@Kihyun\_Hwang](https://discuss.elastic.co/u/Kihyun_Hwang)\
**Replies:** 2\
**Last updated:** [November 23, 2023, 5:14pm UTC](https://discuss.elastic.co/t/the-output-isolator-pattern-inquiry-regarding-downstream-pipeline-failures/347878 "2023-11-23T17:14:12Z")

</div>

I have applied the Output Isolator pattern to send logs to two ES clusters. However, as mentioned in the reference: "If any of the persistent queues of the downstream pipelines (in the example above, buffered-es and bu…

---

## [Cannot login to kibana afer activating SE-LINUX](https://discuss.elastic.co/t/cannot-login-to-kibana-afer-activating-se-linux/347882)

<div class="topic-metadata">

**Author:** [@uli67](https://discuss.elastic.co/u/uli67)\
**Replies:** 0\
**Last updated:** [November 23, 2023, 4:49pm UTC](https://discuss.elastic.co/t/cannot-login-to-kibana-afer-activating-se-linux/347882 "2023-11-23T16:49:10Z")

</div>

Hello, I am running docker.elastic.co/elasticsearch/elasticsearch:8.11.0 eswrapper docker.elastic.co/beats/elastic-agent:8.11.0 7 days ago Up 3 minutes 0.0.0.0:8220-\>8220/tcp…

[Previous page](https://discuss.elastic.co/latest.md?page=472)

[Next page](https://discuss.elastic.co/latest.md?page=474)
