# Latest

**URL:** https://discuss.elastic.co/latest.md?page=490

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 491

---

## [Getting 401 first time and able to login in same session in second attempt](https://discuss.elastic.co/t/getting-401-first-time-and-able-to-login-in-same-session-in-second-attempt/346524)

<div class="topic-metadata">

**Author:** [@amitkumar.gupta](https://discuss.elastic.co/u/amitkumar.gupta)\
**Replies:** 3\
**Last updated:** [November 7, 2023, 11:42am UTC](https://discuss.elastic.co/t/getting-401-first-time-and-able-to-login-in-same-session-in-second-attempt/346524 "2023-11-07T11:42:53Z")

</div>

I am implementing SSO with elastic/Kibana. and using Wso2 credential to login. When i login first time, i see 401, below is the curl i can copy from browser. curl 'http://server1.local:5601/api/security/oidc/callback?c…

---

## [APM dotnet core agent - disable logging](https://discuss.elastic.co/t/apm-dotnet-core-agent-disable-logging/346542)

<div class="topic-metadata">

**Author:** [@shlomys](https://discuss.elastic.co/u/shlomys)\
**Replies:** 4\
**Last updated:** [November 7, 2023, 10:21am UTC](https://discuss.elastic.co/t/apm-dotnet-core-agent-disable-logging/346542 "2023-11-07T10:21:38Z")

</div>

Hi, I am using elastic apm Elastic.Apm.NetCoreAll version 1.25.0. Tried every possible way to disable the logs: ElasticApm:LogLevel=None Logging:LogLevel:Elastic.Apm=None environment variable .... Nothing seems to wo…

---

## [Filebeat 7.10.2 : logging Configurations logging.files.rotateeverybytes not working](https://discuss.elastic.co/t/filebeat-7-10-2-logging-configurations-logging-files-rotateeverybytes-not-working/346611)

<div class="topic-metadata">

**Author:** [@epadmav](https://discuss.elastic.co/u/epadmav)\
**Replies:** 0\
**Last updated:** [November 7, 2023, 9:45am UTC](https://discuss.elastic.co/t/filebeat-7-10-2-logging-configurations-logging-files-rotateeverybytes-not-working/346611 "2023-11-07T09:45:15Z")

</div>

Hello All, I am trying to rotate the logs generated by filebeat process by setting maximum file size of 1MB by configuring logging.files.rotateeverybytes: 1048576 but logs files are getting generated more than 10 MB and…

---

## [Supporting Exact Search while obeying punctuations using ES](https://discuss.elastic.co/t/supporting-exact-search-while-obeying-punctuations-using-es/346604)

<div class="topic-metadata">

**Author:** [@prakharchaube](https://discuss.elastic.co/u/prakharchaube)\
**Replies:** 0\
**Last updated:** [November 7, 2023, 9:22am UTC](https://discuss.elastic.co/t/supporting-exact-search-while-obeying-punctuations-using-es/346604 "2023-11-07T09:22:36Z")

</div>

Hi folks, I am new to ES and was stuck at something so seeking help! I have a search requirement where I need to get results for "Exact Matches". Consider it similar to Google's double quote search but only on content…

---

## [In kibana under oberservabilty /uptime/monitor uptime setting need to configure with installation](https://discuss.elastic.co/t/in-kibana-under-oberservabilty-uptime-monitor-uptime-setting-need-to-configure-with-installation/344698)

<div class="topic-metadata">

**Author:** [@Monika1](https://discuss.elastic.co/u/Monika1)\
**Replies:** 2\
**Last updated:** [November 7, 2023, 8:54am UTC](https://discuss.elastic.co/t/in-kibana-under-oberservabilty-uptime-monitor-uptime-setting-need-to-configure-with-installation/344698 "2023-11-07T08:54:06Z")

</div>

Hi, In Kibana uptime setting need to add new indices in uptime indices and need to set alert connector as well not from UI Thanks

---

## [What's the equivalent of NEST TermRangeQuery in the new ES 8.x client?](https://discuss.elastic.co/t/whats-the-equivalent-of-nest-termrangequery-in-the-new-es-8-x-client/346538)

<div class="topic-metadata">

**Author:** [@yansklyarenko](https://discuss.elastic.co/u/yansklyarenko)\
**Replies:** 2\
**Last updated:** [November 7, 2023, 8:50am UTC](https://discuss.elastic.co/t/whats-the-equivalent-of-nest-termrangequery-in-the-new-es-8-x-client/346538 "2023-11-07T08:50:48Z")

</div>

The NEST client for ES 7 has TermRangeQuery class, which covers the case when the rage query is used with Text and Keyword fields. However, I can't find the equivalent in the new ES 8.x client. There's a class called Ra…

---

## [APM server healthcheck returning empty response](https://discuss.elastic.co/t/apm-server-healthcheck-returning-empty-response/346547)

<div class="topic-metadata">

**Author:** [@senyam08](https://discuss.elastic.co/u/senyam08)\
**Replies:** 2\
**Last updated:** [November 7, 2023, 8:47am UTC](https://discuss.elastic.co/t/apm-server-healthcheck-returning-empty-response/346547 "2023-11-07T08:47:20Z")

</div>

We are using elactic stack 8.10.1 and APM server is running in standalone mode with kubernetes operator Not getting json output from apm-server for healthcheck endpoint. metrics are getting into apm-server without issue…

---

## [\_ingest.timestamp does not match my local time](https://discuss.elastic.co/t/ingest-timestamp-does-not-match-my-local-time/346600)

<div class="topic-metadata">

**Author:** [@JasonREC](https://discuss.elastic.co/u/JasonREC)\
**Replies:** 3\
**Last updated:** [November 7, 2023, 8:15am UTC](https://discuss.elastic.co/t/ingest-timestamp-does-not-match-my-local-time/346600 "2023-11-07T08:15:47Z")

</div>

I am currently in GMT+8 time zone, I have created this pipeline so that when indexing new document, the new document is created with a timestamp PUT \_ingest/pipeline/add-current-time { "processors": \[ { "se…

---

## [I'm working on new community beat](https://discuss.elastic.co/t/im-working-on-new-community-beat/346190)

<div class="topic-metadata">

**Author:** [@zeynepyz](https://discuss.elastic.co/u/zeynepyz)\
**Replies:** 7\
**Last updated:** [November 7, 2023, 8:12am UTC](https://discuss.elastic.co/t/im-working-on-new-community-beat/346190 "2023-11-07T08:12:35Z")

</div>

Hello, i'm working on new project that collecting metrics from k6 via restAPI and indexes them then sending them to elasticsearch by beats. I just wonder if anyone working on this?

---

## [Change path.data in elasticsearh cluster node](https://discuss.elastic.co/t/change-path-data-in-elasticsearh-cluster-node/346596)

<div class="topic-metadata">

**Author:** [@Frances\_Chu](https://discuss.elastic.co/u/Frances_Chu)\
**Replies:** 0\
**Last updated:** [November 7, 2023, 7:07am UTC](https://discuss.elastic.co/t/change-path-data-in-elasticsearh-cluster-node/346596 "2023-11-07T07:07:26Z")

</div>

May I got 3 node elasticsearch cluster. Is it possible to change the path.data If yes. What is the recommended procedure?

---

## [Extend the size of ElasticSearch path.data](https://discuss.elastic.co/t/extend-the-size-of-elasticsearch-path-data/346595)

<div class="topic-metadata">

**Author:** [@Frances\_Chu](https://discuss.elastic.co/u/Frances_Chu)\
**Replies:** 0\
**Last updated:** [November 7, 2023, 7:04am UTC](https://discuss.elastic.co/t/extend-the-size-of-elasticsearch-path-data/346595 "2023-11-07T07:04:00Z")

</div>

I got a elasticsearch cluster with 3 nodes. Each node got a path.data (size 5T) Which is a virtual harddisk. I would like to know is it possible to enlarge the disk storage by extend the virtual disk to 10T. If it is …

---

## [Kibana Timeseries or Area chart to split chart on two fileds value](https://discuss.elastic.co/t/kibana-timeseries-or-area-chart-to-split-chart-on-two-fileds-value/346497)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 1\
**Last updated:** [November 7, 2023, 3:43am UTC](https://discuss.elastic.co/t/kibana-timeseries-or-area-chart-to-split-chart-on-two-fileds-value/346497 "2023-11-07T03:43:07Z")

</div>

Hello All, I have a requirement for below data and not sure which visual could achieve the requirement properly.Ideal requirement is of Timeseries using TSVB or someother visual also fine.Plz let know if this is possibl…

---

## [Elastic ILM Filebeat](https://discuss.elastic.co/t/elastic-ilm-filebeat/345716)

<div class="topic-metadata">

**Author:** [@lehu](https://discuss.elastic.co/u/lehu)\
**Replies:** 4\
**Last updated:** [November 7, 2023, 5:37am UTC](https://discuss.elastic.co/t/elastic-ilm-filebeat/345716 "2023-11-07T05:37:40Z")

</div>

Hi, so I created a working lifecycle policy and I want it to apply it to the indices that are daily created by filebeat. But my filebeat configuration uses setup.template.name and setup.template.pattern and I dont want …

---

## [Duplicates logs are available on running the query for same time](https://discuss.elastic.co/t/duplicates-logs-are-available-on-running-the-query-for-same-time/346586)

<div class="topic-metadata">

**Author:** [@Ayushi\_bhardwaj](https://discuss.elastic.co/u/Ayushi_bhardwaj)\
**Replies:** 1\
**Last updated:** [November 7, 2023, 5:32am UTC](https://discuss.elastic.co/t/duplicates-logs-are-available-on-running-the-query-for-same-time/346586 "2023-11-07T05:32:03Z")

</div>

Duplicates logs are available on running the query for same time (now-1m) We are running the query for last now-1m based upon our use case however we seeing duplicates getting generated in Output. Please help with the p…

---

## [Curl ssl error to elasticsearch server via filebeat](https://discuss.elastic.co/t/curl-ssl-error-to-elasticsearch-server-via-filebeat/346420)

<div class="topic-metadata">

**Author:** [@baber1223](https://discuss.elastic.co/u/baber1223)\
**Replies:** 2\
**Last updated:** [November 7, 2023, 4:52am UTC](https://discuss.elastic.co/t/curl-ssl-error-to-elasticsearch-server-via-filebeat/346420 "2023-11-07T04:52:57Z")

</div>

This is my filebeat output test : filebeat test output elasticsearch: https://172.10.110.29:9200... parse url... OK connection... parse host... OK dns lookup... OK addresses: 172.10.110.29 dial up..…

---

## [How to catch an exception for "Authentication using apikey failed - api key is expired"](https://discuss.elastic.co/t/how-to-catch-an-exception-for-authentication-using-apikey-failed-api-key-is-expired/346158)

<div class="topic-metadata">

**Author:** [@Jim\_Song](https://discuss.elastic.co/u/Jim_Song)\
**Replies:** 1\
**Last updated:** [November 7, 2023, 4:48am UTC](https://discuss.elastic.co/t/how-to-catch-an-exception-for-authentication-using-apikey-failed-api-key-is-expired/346158 "2023-11-07T04:48:54Z")

</div>

I am using client lib to perform a search operation. The API key used for constructing an ElasticsearchClient expired. How can I catch this specific type of "API Key expired" error, so that I can handle it, e.g. creating…

---

## [Elastic SQL CLI Error](https://discuss.elastic.co/t/elastic-sql-cli-error/345905)

<div class="topic-metadata">

**Author:** [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Replies:** 6\
**Last updated:** [November 7, 2023, 4:46am UTC](https://discuss.elastic.co/t/elastic-sql-cli-error/345905 "2023-11-07T04:46:29Z")

</div>

HI Team, I am able to connect to Elastic sql CLI but while querying the index data getting below error. Could you please help me on this. sql\> select \* from employee; Communication error \[Cannot POST address http://1…

---

## [Use search or scroll for large dataset which needs aggregations](https://discuss.elastic.co/t/use-search-or-scroll-for-large-dataset-which-needs-aggregations/346578)

<div class="topic-metadata">

**Author:** [@nboisnea1](https://discuss.elastic.co/u/nboisnea1)\
**Replies:** 0\
**Last updated:** [November 6, 2023, 10:45pm UTC](https://discuss.elastic.co/t/use-search-or-scroll-for-large-dataset-which-needs-aggregations/346578 "2023-11-06T22:45:38Z")

</div>

Hi! I'm new to Elasticsearch and I have a particular use case for which I don't know if I should use a basic search or a scroll search. I have an index in which I periodically save a copy of JSON documents. Each JSON do…

---

## [Configure Remote Clusters](https://discuss.elastic.co/t/configure-remote-clusters/346571)

<div class="topic-metadata">

**Author:** [@biancoda](https://discuss.elastic.co/u/biancoda)\
**Replies:** 0\
**Last updated:** [November 6, 2023, 9:18pm UTC](https://discuss.elastic.co/t/configure-remote-clusters/346571 "2023-11-06T21:18:17Z")

</div>

So, I'm trying to configure the remote cluster connections. But I believe I'm missing something. I'm following this instructions: Remote clusters | Elastic Cloud on Kubernetes \[2.9\] | Elastic I have 2 different ES cl…

---

## [Connection reset by peer](https://discuss.elastic.co/t/connection-reset-by-peer/346570)

<div class="topic-metadata">

**Author:** [@milindyedge](https://discuss.elastic.co/u/milindyedge)\
**Replies:** 0\
**Last updated:** [November 6, 2023, 8:58pm UTC](https://discuss.elastic.co/t/connection-reset-by-peer/346570 "2023-11-06T20:58:22Z")

</div>

We are using Elasticsearch cloud version. We are connecting to Elasticsearch cloud using Elasticsearch java api client. However, we are getting "IOException : connection reset by peer" error randomly. It seems this error…

---

## [My Elasticsearch experiences freezing 3 to 4 times a day](https://discuss.elastic.co/t/my-elasticsearch-experiences-freezing-3-to-4-times-a-day/346438)

<div class="topic-metadata">

**Author:** [@ihatecrypto](https://discuss.elastic.co/u/ihatecrypto)\
**Replies:** 9\
**Last updated:** [November 6, 2023, 8:39pm UTC](https://discuss.elastic.co/t/my-elasticsearch-experiences-freezing-3-to-4-times-a-day/346438 "2023-11-06T20:39:49Z")

</div>

Hello everyone, I'm currently facing an issue that's not well defined. . The freezing periods last approximately 30 to 60 seconds. During these periods, I'm unable to query it using Kibana or the Nodejs client. I've…

---

## [Variables and subfields](https://discuss.elastic.co/t/variables-and-subfields/346554)

<div class="topic-metadata">

**Author:** [@B-Rad](https://discuss.elastic.co/u/B-Rad)\
**Replies:** 0\
**Last updated:** [November 6, 2023, 7:01pm UTC](https://discuss.elastic.co/t/variables-and-subfields/346554 "2023-11-06T19:01:16Z")

</div>

When working with alerts and using variables in the connectors, is if possible to only use a subset of the data in my notifications? For example, the field name is details, but this field looks to contain its own json d…

---

## [Sorting when scoring documents with child function\_score](https://discuss.elastic.co/t/sorting-when-scoring-documents-with-child-function-score/346551)

<div class="topic-metadata">

**Author:** [@AngX](https://discuss.elastic.co/u/AngX)\
**Replies:** 0\
**Last updated:** [November 6, 2023, 6:28pm UTC](https://discuss.elastic.co/t/sorting-when-scoring-documents-with-child-function-score/346551 "2023-11-06T18:28:45Z")

</div>

Hi all, Running into a tricky requirement when it comes to sorting in search so would appreciate getting some thoughts or advice on the matter We have two collections of documents set with a join. The child documents h…

---

## [Plugin \[analysis-icu\] was built for Elasticsearch version 8.5.0 but version 8.9.1 is running](https://discuss.elastic.co/t/plugin-analysis-icu-was-built-for-elasticsearch-version-8-5-0-but-version-8-9-1-is-running/346062)

<div class="topic-metadata">

**Author:** [@lanz](https://discuss.elastic.co/u/lanz)\
**Replies:** 5\
**Last updated:** [November 6, 2023, 5:26pm UTC](https://discuss.elastic.co/t/plugin-analysis-icu-was-built-for-elasticsearch-version-8-5-0-but-version-8-9-1-is-running/346062 "2023-11-06T17:26:15Z")

</div>

Hello, I am trying to upgrade the ELK from 8.5.0 to 8.9.1 version, Once installed 8.9.1 version, I need to install the analysis-icu\] plug-in . Therefore I have followed the steps of this link ICU analysis plugin | Elas…

---

## [App Search - sort by nested object array field with filter](https://discuss.elastic.co/t/app-search-sort-by-nested-object-array-field-with-filter/346475)

<div class="topic-metadata">

**Author:** [@Pradeep\_Renukaiah](https://discuss.elastic.co/u/Pradeep_Renukaiah)\
**Replies:** 4\
**Last updated:** [November 6, 2023, 4:56pm UTC](https://discuss.elastic.co/t/app-search-sort-by-nested-object-array-field-with-filter/346475 "2023-11-06T16:56:16Z")

</div>

I am using App Search to fetch the results from index. When I have a root level fields, I can easily able to sort the documents. However, recently there is requirement to sort based on the nested object field and nested …

---

## [Server-client search architecture with PIT in ElasticSearch](https://discuss.elastic.co/t/server-client-search-architecture-with-pit-in-elasticsearch/346545)

<div class="topic-metadata">

**Author:** [@forceson](https://discuss.elastic.co/u/forceson)\
**Replies:** 0\
**Last updated:** [November 6, 2023, 4:41pm UTC](https://discuss.elastic.co/t/server-client-search-architecture-with-pit-in-elasticsearch/346545 "2023-11-06T16:41:58Z")

</div>

I want to use search\_after and PIT to provide consistent search results. The guide documentation suggests that PITs should be generated in the background and utilized after each search, rather than after every search. M…

---

## [SNMP with Logstash (Pipeline Error)](https://discuss.elastic.co/t/snmp-with-logstash-pipeline-error/346533)

<div class="topic-metadata">

**Author:** [@Funkster](https://discuss.elastic.co/u/Funkster)\
**Replies:** 2\
**Last updated:** [November 6, 2023, 4:03pm UTC](https://discuss.elastic.co/t/snmp-with-logstash-pipeline-error/346533 "2023-11-06T16:03:19Z")

</div>

Hello, I am trying to get SNMP-Loggin to work whithin ELK in Logstash and I get the following Error: root@vm-kibana:~# /usr/share/logstash/bin/logstash -f /etc/logstash/conf.d/logstash-snmp.conf --path.settings=/etc/lo…

---

## [Need assist with Painless scripting](https://discuss.elastic.co/t/need-assist-with-painless-scripting/345116)

<div class="topic-metadata">

**Author:** [@KristjanH](https://discuss.elastic.co/u/KristjanH)\
**Replies:** 3\
**Last updated:** [November 6, 2023, 3:58pm UTC](https://discuss.elastic.co/t/need-assist-with-painless-scripting/345116 "2023-11-06T15:58:25Z")

</div>

I'm trying to make a script that sorts text that contains text + numbers in numbering order. Example, we have the the data: "Box 1", "Box 2", "Box 3", "Box 10", "Box 20" By using normal alphabetical ordering then it w…

---

## [Multiple Pipelines with condition](https://discuss.elastic.co/t/multiple-pipelines-with-condition/346405)

<div class="topic-metadata">

**Author:** [@Manasa4](https://discuss.elastic.co/u/Manasa4)\
**Replies:** 4\
**Last updated:** [November 6, 2023, 3:44pm UTC](https://discuss.elastic.co/t/multiple-pipelines-with-condition/346405 "2023-11-06T15:44:20Z")

</div>

Hi Team, I have been trying to add a condition on my multi processor pipeline. { "4modelprocessor\_peopleagg": { "processors": \[ { "pipeline": { "name": "ner\_pipeline\_peopleagg" } }, { "pipeline": { "name": "e…

---

## [Spring controller hiden behind DispatcherServlet#do\*](https://discuss.elastic.co/t/spring-controller-hiden-behind-dispatcherservlet-do/345548)

<div class="topic-metadata">

**Author:** [@jandry](https://discuss.elastic.co/u/jandry)\
**Replies:** 4\
**Last updated:** [November 6, 2023, 3:05pm UTC](https://discuss.elastic.co/t/spring-controller-hiden-behind-dispatcherservlet-do/345548 "2023-11-06T15:05:00Z")

</div>

Kibana version: 7.16.3 I got exctly the same issue as Remove spring DispatcherServlet from transactions - #18 by ethranes See screenshot I'm using Spring Boot 3.0.x with agent elastic-apm-agent-1.36.0.jar I tried …

[Previous page](https://discuss.elastic.co/latest.md?page=489)

[Next page](https://discuss.elastic.co/latest.md?page=491)
