# Latest

**URL:** https://discuss.elastic.co/latest.md?page=492

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 493

---

## [Where can we find those user tutorials mentioned on the badges?](https://discuss.elastic.co/t/where-can-we-find-those-user-tutorials-mentioned-on-the-badges/346432)

<div class="topic-metadata">

**Author:** [@bunste](https://discuss.elastic.co/u/bunste)\
**Replies:** 4\
**Last updated:** [November 5, 2023, 1:42pm UTC](https://discuss.elastic.co/t/where-can-we-find-those-user-tutorials-mentioned-on-the-badges/346432 "2023-11-05T13:42:56Z")

</div>

In the badge overview you can see that there seems to be a new user tutorial ("Certified" badge) and an advanced user tutorial ("Licensed" badge). But where can we find these tutorials? I have not been able to find them…

---

## [Edit static lookup with API](https://discuss.elastic.co/t/edit-static-lookup-with-api/346111)

<div class="topic-metadata">

**Author:** [@cyberzlo](https://discuss.elastic.co/u/cyberzlo)\
**Replies:** 1\
**Last updated:** [November 5, 2023, 10:24am UTC](https://discuss.elastic.co/t/edit-static-lookup-with-api/346111 "2023-11-05T10:24:11Z")

</div>

I have the following problem. I have an X field in every document, but not in every document I have a Y field. I would like the information from field Y to appear in place of field X. Specifically, it is about the occurr…

---

## [Import Pretrained Model to Elasticsearch Cluster](https://discuss.elastic.co/t/import-pretrained-model-to-elasticsearch-cluster/346440)

<div class="topic-metadata">

**Author:** [@Khanh\_Dao\_Minh](https://discuss.elastic.co/u/Khanh_Dao_Minh)\
**Replies:** 1\
**Last updated:** [November 5, 2023, 3:09am UTC](https://discuss.elastic.co/t/import-pretrained-model-to-elasticsearch-cluster/346440 "2023-11-05T03:09:09Z")

</div>

Hello everyone. I have a question about import sentence-transformer model to elasticsearch cluster. When I run the python script below, I see only 1 node has allocated my mode, but I want to allocate my model in 2 nodes …

---

## [This error seems to be related to mapping issues in Elasticsearch, below error found in logstash](https://discuss.elastic.co/t/this-error-seems-to-be-related-to-mapping-issues-in-elasticsearch-below-error-found-in-logstash/346414)

<div class="topic-metadata">

**Author:** [@Sreecharanhope](https://discuss.elastic.co/u/Sreecharanhope)\
**Replies:** 4\
**Last updated:** [November 5, 2023, 2:38am UTC](https://discuss.elastic.co/t/this-error-seems-to-be-related-to-mapping-issues-in-elasticsearch-below-error-found-in-logstash/346414 "2023-11-05T02:38:14Z")

</div>

2023-11-04T10:33:48,353\]\[WARN \]\[logstash.outputs.elasticsearch\]\[main\] Could not index event to Elasticsearch. {:status=\>400, :action=\>\["index", {:\_id=\>nil, :\_index=\>"staging-2023.11.04", :\_type=\>"\_doc", :routing=\>nil}, …

---

## [How to create a document where the \_id has spaces (Dev Tools)](https://discuss.elastic.co/t/how-to-create-a-document-where-the-id-has-spaces-dev-tools/346404)

<div class="topic-metadata">

**Author:** [@thadc](https://discuss.elastic.co/u/thadc)\
**Replies:** 9\
**Last updated:** [November 4, 2023, 10:08pm UTC](https://discuss.elastic.co/t/how-to-create-a-document-where-the-id-has-spaces-dev-tools/346404 "2023-11-04T22:08:45Z")

</div>

I am attempting to create a document in an index where \_id has spaces. I get a parsing exception in Dev Tools. Here is the start of POST statement: POST /label-expression/\_doc/(AB\_123 | CD\_123) I must have the spaces, …

---

## [Query for the fields which is non empty](https://discuss.elastic.co/t/query-for-the-fields-which-is-non-empty/345764)

<div class="topic-metadata">

**Author:** [@Manasa4](https://discuss.elastic.co/u/Manasa4)\
**Replies:** 5\
**Last updated:** [November 4, 2023, 6:27pm UTC](https://discuss.elastic.co/t/query-for-the-fields-which-is-non-empty/345764 "2023-11-04T18:27:32Z")

</div>

Hi Team, I'm reaching out query that I have, I want a query which returns the field with any random value inside it and filter out the empty records. For eg: In my case, I have a FileContent.content field and it has va…

---

## [This error seems to be related to mapping issues in Elasticsearch, ](https://discuss.elastic.co/t/this-error-seems-to-be-related-to-mapping-issues-in-elasticsearch/346427)

<div class="topic-metadata">

**Author:** [@jamesjames](https://discuss.elastic.co/u/jamesjames)\
**Replies:** 2\
**Last updated:** [November 4, 2023, 4:06pm UTC](https://discuss.elastic.co/t/this-error-seems-to-be-related-to-mapping-issues-in-elasticsearch/346427 "2023-11-04T16:06:29Z")

</div>

2023-11-04T10:33:48,353\]\[WARN \]\[logstash.outputs.elasticsearch\]\[main\] Could not index event to Elasticsearch. {:status=\>400, :action=\>\["index", {:\_id=\>nil, :\_index=\>"staging-2023.11.04", :\_type=\>"\_doc", :routing=\>nil}, …

---

## [What happened to the .Net client?](https://discuss.elastic.co/t/what-happened-to-the-net-client/346068)

<div class="topic-metadata">

**Author:** [@Eric\_Paul](https://discuss.elastic.co/u/Eric_Paul)\
**Replies:** 2\
**Last updated:** [November 4, 2023, 2:21pm UTC](https://discuss.elastic.co/t/what-happened-to-the-net-client/346068 "2023-11-04T14:21:45Z")

</div>

OK it's been a bit since I coded against elasticsearch. Now it looks like there is a new client to replace nest. But the documentation is severely lacking. I don't see any examples of code except for the most basic stuff…

---

## [Kibana Plugin](https://discuss.elastic.co/t/kibana-plugin/346245)

<div class="topic-metadata">

**Author:** [@Srini-99](https://discuss.elastic.co/u/Srini-99)\
**Replies:** 1\
**Last updated:** [November 4, 2023, 12:49pm UTC](https://discuss.elastic.co/t/kibana-plugin/346245 "2023-11-04T12:49:09Z")

</div>

Hi! I wanted to create a custom plugin to add on to kibana. since i had Elasticsearch and kibana already set up and running, i started my plugin development in the 'plugin' of kibana. (system - win11) when i start kib…

---

## [Extract JSON log from JSON](https://discuss.elastic.co/t/extract-json-log-from-json/346353)

<div class="topic-metadata">

**Author:** [@AlarleCKe](https://discuss.elastic.co/u/AlarleCKe)\
**Replies:** 2\
**Last updated:** [November 4, 2023, 11:33am UTC](https://discuss.elastic.co/t/extract-json-log-from-json/346353 "2023-11-04T11:33:26Z")

</div>

Hi everyone, I´m trying to create an index based on a script output. The script itself creates an NDJSON like: {"packages/current\_version":"3.7.3-2+deb10u5","packages/candidate\_version":"3.7.3-2+deb10u6","packages/prio…

---

## [Elasticsearch vector](https://discuss.elastic.co/t/elasticsearch-vector/346425)

<div class="topic-metadata">

**Author:** [@zhl19911203](https://discuss.elastic.co/u/zhl19911203)\
**Replies:** 0\
**Last updated:** [November 4, 2023, 11:00am UTC](https://discuss.elastic.co/t/elasticsearch-vector/346425 "2023-11-04T11:00:48Z")

</div>

Is there an official example of how to add, delete, modify, and check vector data in Elasticsearch8.10.2 version? Using Elasticsearch Java client operations

---

## [Why filebeat cannot start and stop after a few second](https://discuss.elastic.co/t/why-filebeat-cannot-start-and-stop-after-a-few-second/346406)

<div class="topic-metadata">

**Author:** [@baber1223](https://discuss.elastic.co/u/baber1223)\
**Replies:** 2\
**Last updated:** [November 4, 2023, 5:22am UTC](https://discuss.elastic.co/t/why-filebeat-cannot-start-and-stop-after-a-few-second/346406 "2023-11-04T05:22:03Z")

</div>

My elasticsearch version = 8.10.4 filebeat version : 8.7 I cannot install latest version of filebeat on my redhat 6.4 . Now when start filebeat . it is stopping after a few second . and this is my filebeat log : ta…

---

## [Logstash http\_pollar Rest API push more than 1000 records](https://discuss.elastic.co/t/logstash-http-pollar-rest-api-push-more-than-1000-records/346374)

<div class="topic-metadata">

**Author:** [@puneetsharma2](https://discuss.elastic.co/u/puneetsharma2)\
**Replies:** 12\
**Last updated:** [November 3, 2023, 6:35pm UTC](https://discuss.elastic.co/t/logstash-http-pollar-rest-api-push-more-than-1000-records/346374 "2023-11-03T18:35:20Z")

</div>

Logstash http\_pollar Rest API push more than 1000 records As we are using HTTP\_POLLAR to execute the rest API and push the response in elastic index in one go. But default only 1000 records are pushing in elastic. How …

---

## [Show only time with out date](https://discuss.elastic.co/t/show-only-time-with-out-date/345059)

<div class="topic-metadata">

**Author:** [@naveed786.shaik](https://discuss.elastic.co/u/naveed786.shaik)\
**Replies:** 7\
**Last updated:** [November 3, 2023, 11:10pm UTC](https://discuss.elastic.co/t/show-only-time-with-out-date/345059 "2023-11-03T23:10:49Z")

</div>

Hi All, Need a help with Kibana dashboard , I could see the customization for date and time, in version 8.6.0 of the dashboard. I am trying to get indexed data with only time where need to exclude date. Please suggest …

---

## [Unable to load pipelines arraycopy: length -1 is negative](https://discuss.elastic.co/t/unable-to-load-pipelines-arraycopy-length-1-is-negative/346407)

<div class="topic-metadata">

**Author:** [@emi\_rose](https://discuss.elastic.co/u/emi_rose)\
**Replies:** 0\
**Last updated:** [November 3, 2023, 8:55pm UTC](https://discuss.elastic.co/t/unable-to-load-pipelines-arraycopy-length-1-is-negative/346407 "2023-11-03T20:55:42Z")

</div>

Hi there, I noticed one of my ingest pipelines didn't appear to be working, and when I went to look at the ingest pipelines, this error message popped up. I haven't been able to find this error anywhere else on any foru…

---

## [Certificate signed by unknown authority](https://discuss.elastic.co/t/certificate-signed-by-unknown-authority/346348)

<div class="topic-metadata">

**Author:** [@baber1223](https://discuss.elastic.co/u/baber1223)\
**Replies:** 6\
**Last updated:** [November 3, 2023, 8:12pm UTC](https://discuss.elastic.co/t/certificate-signed-by-unknown-authority/346348 "2023-11-03T20:12:00Z")

</div>

This is my filebeat.yml file but when I want to check it shows error : filebeat test output elasticsearch: https://172.10.110.29:9200... parse url... OK connection... parse host... OK dns lookup... OK addresses: …

---

## [High cpu for new data nodes for several days?](https://discuss.elastic.co/t/high-cpu-for-new-data-nodes-for-several-days/346400)

<div class="topic-metadata">

**Author:** [@linkerc](https://discuss.elastic.co/u/linkerc)\
**Replies:** 0\
**Last updated:** [November 3, 2023, 7:22pm UTC](https://discuss.elastic.co/t/high-cpu-for-new-data-nodes-for-several-days/346400 "2023-11-03T19:22:55Z")

</div>

Has anybody experienced this? Or is this normal? After adding 6 new data nodes, the high CPU (bouncing off 100%) often persisted for several days (around 5 days). The shards are balanced within a day of new node addit…

---

## [Accessing Aggregation buckets to get the \`key\` value and \`\_doc\` values](https://discuss.elastic.co/t/accessing-aggregation-buckets-to-get-the-key-value-and-doc-values/346391)

<div class="topic-metadata">

**Author:** [@Santosh\_mandyajayara](https://discuss.elastic.co/u/Santosh_mandyajayara)\
**Replies:** 0\
**Last updated:** [November 3, 2023, 5:12pm UTC](https://discuss.elastic.co/t/accessing-aggregation-buckets-to-get-the-key-value-and-doc-values/346391 "2023-11-03T17:12:50Z")

</div>

We were using the Rest High Level Client before and below was the usage to access the aggregation buckets from the SearchResponse ParsedStringTerms aggregation1 = searchResponse.getAggregations().get(AGGREGATION1.name…

---

## [Deleting indices older than 30 days with policy problem](https://discuss.elastic.co/t/deleting-indices-older-than-30-days-with-policy-problem/346388)

<div class="topic-metadata">

**Author:** [@Mark\_S](https://discuss.elastic.co/u/Mark_S)\
**Replies:** 0\
**Last updated:** [November 3, 2023, 4:51pm UTC](https://discuss.elastic.co/t/deleting-indices-older-than-30-days-with-policy-problem/346388 "2023-11-03T16:51:25Z")

</div>

I am using an application that creates daily indices, using legacy index template. Two types of indices are created: jaeger-spans-date and jaeger-services-date (where date is the date produced). Using the kibana UI, I c…

---

## [Elastic Agent Disk Queue](https://discuss.elastic.co/t/elastic-agent-disk-queue/346382)

<div class="topic-metadata">

**Author:** [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Replies:** 0\
**Last updated:** [November 3, 2023, 3:42pm UTC](https://discuss.elastic.co/t/elastic-agent-disk-queue/346382 "2023-11-03T15:42:03Z")

</div>

Does Elastic Agent support disk queue? How do you configure it?

---

## [API Key for Kibana Reporting](https://discuss.elastic.co/t/api-key-for-kibana-reporting/345662)

<div class="topic-metadata">

**Author:** [@DougR](https://discuss.elastic.co/u/DougR)\
**Replies:** 8\
**Last updated:** [November 3, 2023, 2:27pm UTC](https://discuss.elastic.co/t/api-key-for-kibana-reporting/345662 "2023-11-03T14:27:54Z")

</div>

I need to generate an API key which will allow a user to generate a report in Kibana and then download it, once it's generated. What permissions do I need to set? I haven't been able to determine this from the docs. Thx…

---

## [Logstash + S3 Input plugin with High Availability](https://discuss.elastic.co/t/logstash-s3-input-plugin-with-high-availability/346370)

<div class="topic-metadata">

**Author:** [@Pedro\_Baldanta](https://discuss.elastic.co/u/Pedro_Baldanta)\
**Replies:** 1\
**Last updated:** [November 3, 2023, 2:01pm UTC](https://discuss.elastic.co/t/logstash-s3-input-plugin-with-high-availability/346370 "2023-11-03T14:01:38Z")

</div>

Hi all: I need to implement high availability of Logstash reading log files from S3. Is there any way to implement HA via scaleout without duplicating the events? Each VM is going to store until which file has read, s…

---

## [Fleet with own artifact registry fails cause of external GPG validation](https://discuss.elastic.co/t/fleet-with-own-artifact-registry-fails-cause-of-external-gpg-validation/345904)

<div class="topic-metadata">

**Author:** [@xtruthx](https://discuss.elastic.co/u/xtruthx)\
**Replies:** 5\
**Last updated:** [November 3, 2023, 1:51pm UTC](https://discuss.elastic.co/t/fleet-with-own-artifact-registry-fails-cause-of-external-gpg-validation/345904 "2023-11-03T13:51:42Z")

</div>

I have in an environment as described here Air Gapped Env artifacts hosted my own artifact registry. This is also cleanly queried during upgrade see log. However, a GPG validation is attempted externally. But why? Wher…

---

## [How do we customize the login page in latest version 8.10.2](https://discuss.elastic.co/t/how-do-we-customize-the-login-page-in-latest-version-8-10-2/346359)

<div class="topic-metadata">

**Author:** [@Abj\_Ins](https://discuss.elastic.co/u/Abj_Ins)\
**Replies:** 1\
**Last updated:** [November 3, 2023, 12:57pm UTC](https://discuss.elastic.co/t/how-do-we-customize-the-login-page-in-latest-version-8-10-2/346359 "2023-11-03T12:57:08Z")

</div>

Hi Team, How do we customize the login page in latest version of ELK 8.10.2 Observed that when compared to previous versions (8.5.2) here we find many changes in folder structure also. Requesting team to provide solut…

---

## [Visualize logs from two Suricata filebeat modules in one dashboard](https://discuss.elastic.co/t/visualize-logs-from-two-suricata-filebeat-modules-in-one-dashboard/346306)

<div class="topic-metadata">

**Author:** [@edpuig97](https://discuss.elastic.co/u/edpuig97)\
**Replies:** 1\
**Last updated:** [November 3, 2023, 12:35pm UTC](https://discuss.elastic.co/t/visualize-logs-from-two-suricata-filebeat-modules-in-one-dashboard/346306 "2023-11-03T12:35:21Z")

</div>

Hi, I'm using Filebeat's suricata module from two suricata hosts, when I setup those, only the last of them is showed in the Kibana dashboards. Is any way to show both of them? Thanks in advance.

---

## [Additional Elastic Agent Integrations needed](https://discuss.elastic.co/t/additional-elastic-agent-integrations-needed/346308)

<div class="topic-metadata">

**Author:** [@dwortmann](https://discuss.elastic.co/u/dwortmann)\
**Replies:** 2\
**Last updated:** [November 3, 2023, 12:09pm UTC](https://discuss.elastic.co/t/additional-elastic-agent-integrations-needed/346308 "2023-11-03T12:09:51Z")

</div>

We are current users of Elastic stack and are using FileBeat modules to assist with parsing of data. We have begun to review the Elastic Agent and have found there are several additional integrations that are available …

---

## [How to search these kind of texts without Synonyms](https://discuss.elastic.co/t/how-to-search-these-kind-of-texts-without-synonyms/346362)

<div class="topic-metadata">

**Author:** [@Anand\_Konagala](https://discuss.elastic.co/u/Anand_Konagala)\
**Replies:** 0\
**Last updated:** [November 3, 2023, 11:55am UTC](https://discuss.elastic.co/t/how-to-search-these-kind-of-texts-without-synonyms/346362 "2023-11-03T11:55:42Z")

</div>

Hi, When I search with this query, { "match":{ "company":{ "query":"walmart" } } …

---

## [User for filebeat](https://discuss.elastic.co/t/user-for-filebeat/346361)

<div class="topic-metadata">

**Author:** [@hta](https://discuss.elastic.co/u/hta)\
**Replies:** 0\
**Last updated:** [November 3, 2023, 11:38am UTC](https://discuss.elastic.co/t/user-for-filebeat/346361 "2023-11-03T11:38:41Z")

</div>

How can I create a user for filebeat via the console? The user would of course have to be able to send logs over. I get the following message in the logs: "this action is granted by the cluster privileges \[monitor, manag…

---

## [ECK | Filebeat | Kubernetes Logs are missing / no field data](https://discuss.elastic.co/t/eck-filebeat-kubernetes-logs-are-missing-no-field-data/346360)

<div class="topic-metadata">

**Author:** [@TimK](https://discuss.elastic.co/u/TimK)\
**Replies:** 0\
**Last updated:** [November 3, 2023, 11:34am UTC](https://discuss.elastic.co/t/eck-filebeat-kubernetes-logs-are-missing-no-field-data/346360 "2023-11-03T11:34:46Z")

</div>

Hi there! We recently deployed the Elastic Cloud on Kubernetes for a Kubernetes Cluster in Azure. Our goal is to collect the log information from the pods. I applied the following Filebeat YAML from the Doc (with the …

---

## [\[Filebeat\] Filebeat with K8S autodicover using hints keeps refreshing all pod config every 10s](https://discuss.elastic.co/t/filebeat-filebeat-with-k8s-autodicover-using-hints-keeps-refreshing-all-pod-config-every-10s/346339)

<div class="topic-metadata">

**Author:** [@Lebvanih](https://discuss.elastic.co/u/Lebvanih)\
**Replies:** 1\
**Last updated:** [November 3, 2023, 10:56am UTC](https://discuss.elastic.co/t/filebeat-filebeat-with-k8s-autodicover-using-hints-keeps-refreshing-all-pod-config-every-10s/346339 "2023-11-03T10:56:40Z")

</div>

Hello, We noticed this issue quite long ago (High CPU Usage on some filebeat instances), but we finally had time to dig a bit more on a more recent version of filebeat too (8.10.1). From what we recently noticed, out l…

[Previous page](https://discuss.elastic.co/latest.md?page=491)

[Next page](https://discuss.elastic.co/latest.md?page=493)
