# Latest

**URL:** https://discuss.elastic.co/latest.md?page=493

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 494

---

## [Take snapshot of only the global state and feature state in elasticsearch](https://discuss.elastic.co/t/take-snapshot-of-only-the-global-state-and-feature-state-in-elasticsearch/346352)

<div class="topic-metadata">

**Author:** [@nishant27](https://discuss.elastic.co/u/nishant27)\
**Replies:** 0\
**Last updated:** [November 3, 2023, 10:45am UTC](https://discuss.elastic.co/t/take-snapshot-of-only-the-global-state-and-feature-state-in-elasticsearch/346352 "2023-11-03T10:45:46Z")

</div>

I have created a policy in elasticsearch kibana for taking backup of only the "global state" and "feature state" of the cluster. But when i run the policy, it fails with "index\_not\_found\_exception". Is there any way to…

---

## [Elastic nodes started to give hardware error on esxi 8.01c servers](https://discuss.elastic.co/t/elastic-nodes-started-to-give-hardware-error-on-esxi-8-01c-servers/346208)

<div class="topic-metadata">

**Author:** [@cemkayar](https://discuss.elastic.co/u/cemkayar)\
**Replies:** 8\
**Last updated:** [November 3, 2023, 9:56am UTC](https://discuss.elastic.co/t/elastic-nodes-started-to-give-hardware-error-on-esxi-8-01c-servers/346208 "2023-11-03T09:56:09Z")

</div>

Hi, After upgrading ESXi servers from 7.0.3l to 8.0.1c some of the elastic clusters started to give hardware errors during index hash. If move the problematic elastics VMs to the old version of the esxi servers (7.0.3l …

---

## [After stopping elasticserver 8.x it is shown status deactivating](https://discuss.elastic.co/t/after-stopping-elasticserver-8-x-it-is-shown-status-deactivating/346329)

<div class="topic-metadata">

**Author:** [@subrahmanyam](https://discuss.elastic.co/u/subrahmanyam)\
**Replies:** 1\
**Last updated:** [November 3, 2023, 8:58am UTC](https://discuss.elastic.co/t/after-stopping-elasticserver-8-x-it-is-shown-status-deactivating/346329 "2023-11-03T08:58:01Z")

</div>

Loaded: loaded (/etc/systemd/system/Elasticsearch8.service; enabled; vendor preset: disabled) Active: deactivating (stop-sigterm) since Thu 2023-11-02 13:28:39 GMT; 16h ago Process: 2780103 ExecStop=/test/config/elasti…

---

## [Online monitoring log sending devices in logstash machine](https://discuss.elastic.co/t/online-monitoring-log-sending-devices-in-logstash-machine/346337)

<div class="topic-metadata">

**Author:** [@Mohsen\_R.Marandi](https://discuss.elastic.co/u/Mohsen_R.Marandi)\
**Replies:** 0\
**Last updated:** [November 3, 2023, 8:24am UTC](https://discuss.elastic.co/t/online-monitoring-log-sending-devices-in-logstash-machine/346337 "2023-11-03T08:24:36Z")

</div>

Hi every one I have set up logstash on a large scale network. Is there a way to online monitor log sending devices? Tanks

---

## [Issues with collecting Dependabot alerts using GitHub integration](https://discuss.elastic.co/t/issues-with-collecting-dependabot-alerts-using-github-integration/346277)

<div class="topic-metadata">

**Author:** [@bil15](https://discuss.elastic.co/u/bil15)\
**Replies:** 7\
**Last updated:** [November 3, 2023, 8:16am UTC](https://discuss.elastic.co/t/issues-with-collecting-dependabot-alerts-using-github-integration/346277 "2023-11-03T08:16:24Z")

</div>

Hello! I'm trying to ingest Dependabot alerts from a GitHub organization to Elastic but I'm encountering some issues. The most interesting part is that I use the same PAT and input parameters (organization, tag set, et…

---

## [Filebeat not reached to Kafka but Metricbeat reached](https://discuss.elastic.co/t/filebeat-not-reached-to-kafka-but-metricbeat-reached/346335)

<div class="topic-metadata">

**Author:** [@jongpchubb](https://discuss.elastic.co/u/jongpchubb)\
**Replies:** 1\
**Last updated:** [November 3, 2023, 8:02am UTC](https://discuss.elastic.co/t/filebeat-not-reached-to-kafka-but-metricbeat-reached/346335 "2023-11-03T08:02:46Z")

</div>

I'm using Filebeat and Metricbeat version 8.9 on Redhat. Metricbeat has no any problem that can send a log to Kafka and shown on OpenSearch to be a dashboard. But Filebeat has no any error in the log that can connect and…

---

## [Delay in first SPAN in some transactions](https://discuss.elastic.co/t/delay-in-first-span-in-some-transactions/346333)

<div class="topic-metadata">

**Author:** [@sheugen](https://discuss.elastic.co/u/sheugen)\
**Replies:** 0\
**Last updated:** [November 3, 2023, 7:29am UTC](https://discuss.elastic.co/t/delay-in-first-span-in-some-transactions/346333 "2023-11-03T07:29:34Z")

</div>

Kibana version: v8.10.2 Elasticsearch version: v8.10.2 APM Server version:v8.10.2 APM Agent language and version: PHP v1.10.0 Original install method (e.g. download page, yum, deb, from source, etc.) and version: Ins…

---

## [Logstash Stuck Indexing Pipeline and throwing Error - warning: already initialized constant Manticore::Client::HttpPost](https://discuss.elastic.co/t/logstash-stuck-indexing-pipeline-and-throwing-error-warning-already-initialized-constant-manticore-httppost/345948)

<div class="topic-metadata">

**Author:** [@mnasim1](https://discuss.elastic.co/u/mnasim1)\
**Replies:** 5\
**Last updated:** [November 3, 2023, 5:52am UTC](https://discuss.elastic.co/t/logstash-stuck-indexing-pipeline-and-throwing-error-warning-already-initialized-constant-manticore-httppost/345948 "2023-11-03T05:52:57Z")

</div>

Logstash was running fine and successfully reading data from the Postgres Database for indexing. However, it suddenly started throwing the following errors, causing the indexing pipeline to become stuck: logstash-8.6.2…

---

## [Logstash 8.10.4 breaking changes](https://discuss.elastic.co/t/logstash-8-10-4-breaking-changes/346312)

<div class="topic-metadata">

**Author:** [@ranjini](https://discuss.elastic.co/u/ranjini)\
**Replies:** 9\
**Last updated:** [November 3, 2023, 4:55am UTC](https://discuss.elastic.co/t/logstash-8-10-4-breaking-changes/346312 "2023-11-03T04:55:19Z")

</div>

"status"=\>400, "error"=\>{"type"=\>"mapper\_parsing\_exception", "reason"=\>"failed to parse field \[host\] of type \[text\] in document with id 'xxxxxxx'. added this to resolve the above mutate { rename =\> { "\[host\]" =\> …

---

## [Nested JSON in CSV](https://discuss.elastic.co/t/nested-json-in-csv/346310)

<div class="topic-metadata">

**Author:** [@Cal](https://discuss.elastic.co/u/Cal)\
**Replies:** 1\
**Last updated:** [November 3, 2023, 4:54am UTC](https://discuss.elastic.co/t/nested-json-in-csv/346310 "2023-11-03T04:54:39Z")

</div>

I have a CSV file with 1500 rows of data. I am wanting to optimize how I have certain data and nest it in Elastic. Here's an example: Name, Location, Age, Favorite Colors Bob, USA, 32, Orange, Pink Jane, USA, 28, Gr…

---

## [Coordinating Nodes High Circuit Breaker Tripped Counts](https://discuss.elastic.co/t/coordinating-nodes-high-circuit-breaker-tripped-counts/344161)

<div class="topic-metadata">

**Author:** [@BenB196](https://discuss.elastic.co/u/BenB196)\
**Replies:** 11\
**Last updated:** [November 3, 2023, 2:37am UTC](https://discuss.elastic.co/t/coordinating-nodes-high-circuit-breaker-tripped-counts/344161 "2023-11-03T02:37:24Z")

</div>

Hi All, I'm curious if anyone has any ideas on an issue I'm seeing. I have a cluster of 33 nodes, 3 of these nodes are coordinating only nodes that handle all requests. I've been noticing that these coordinating nodes…

---

## [Manually Add node to cluster Elasticsearch 8.6](https://discuss.elastic.co/t/manually-add-node-to-cluster-elasticsearch-8-6/346322)

<div class="topic-metadata">

**Author:** [@syifelastic](https://discuss.elastic.co/u/syifelastic)\
**Replies:** 4\
**Last updated:** [November 3, 2023, 1:52am UTC](https://discuss.elastic.co/t/manually-add-node-to-cluster-elasticsearch-8-6/346322 "2023-11-03T01:52:51Z")

</div>

Hello. I have a 3 node Elasticsearch cluster. I originally set up the 3 nodes with an enrollment token. However, I later changed from http keystore to a certificate/key configuration in the yml. This breaks the enrollme…

---

## [APM visualizations on a custom dashboard (v7.17)](https://discuss.elastic.co/t/apm-visualizations-on-a-custom-dashboard-v7-17/346323)

<div class="topic-metadata">

**Author:** [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Replies:** 1\
**Last updated:** [November 3, 2023, 1:15am UTC](https://discuss.elastic.co/t/apm-visualizations-on-a-custom-dashboard-v7-17/346323 "2023-11-03T01:15:16Z")

</div>

Hi, im trying to reproduce this APM visualizations in the Observability section of kibana, on a custom dashboard without success this is what i have in TSVB how can i convert the values to percentaje like in the f…

---

## [Http.p12 structure and use of keytool](https://discuss.elastic.co/t/http-p12-structure-and-use-of-keytool/346325)

<div class="topic-metadata">

**Author:** [@ken33](https://discuss.elastic.co/u/ken33)\
**Replies:** 0\
**Last updated:** [November 2, 2023, 11:04pm UTC](https://discuss.elastic.co/t/http-p12-structure-and-use-of-keytool/346325 "2023-11-02T23:04:35Z")

</div>

Hi, In elasticsearch, I can execute : /usr/share/elasticsearch/jdk/bin/keytool -list -keystore http.p12.orig Enter keystore password: Keystore type: PKCS12 Keystore provider: SUN Your keystore contains 2 entries h…

---

## [Creating a Tag Cloud](https://discuss.elastic.co/t/creating-a-tag-cloud/346289)

<div class="topic-metadata">

**Author:** [@vils](https://discuss.elastic.co/u/vils)\
**Replies:** 3\
**Last updated:** [November 2, 2023, 8:55pm UTC](https://discuss.elastic.co/t/creating-a-tag-cloud/346289 "2023-11-02T20:55:35Z")

</div>

Hello all, I have a field that displays feedback. I was hoping to create a tag cloud of the most popular words from the feedback, to get a feel of what customers are saying. Does anyone know how I could do this?

---

## [Index Object structure](https://discuss.elastic.co/t/index-object-structure/346156)

<div class="topic-metadata">

**Author:** [@volkerfrank](https://discuss.elastic.co/u/volkerfrank)\
**Replies:** 3\
**Last updated:** [November 2, 2023, 6:36pm UTC](https://discuss.elastic.co/t/index-object-structure/346156 "2023-11-02T18:36:29Z")

</div>

Hi, how can I index a document with this fields to an index? .. "gitlab": { "path": "/api/v4/jobs/request", "method": "POST", …

---

## [ElastiSearch consuming above 90% RAM memory continuously](https://discuss.elastic.co/t/elastisearch-consuming-above-90-ram-memory-continuously/345812)

<div class="topic-metadata">

**Author:** [@Rajesh123](https://discuss.elastic.co/u/Rajesh123)\
**Replies:** 3\
**Last updated:** [November 2, 2023, 6:31pm UTC](https://discuss.elastic.co/t/elastisearch-consuming-above-90-ram-memory-continuously/345812 "2023-11-02T18:31:11Z")

</div>

Hello, Elastic Search continuously occupying above 90% . Total RAM : 108 GB JVM: 32 GB ( 28Gb used out of 32GB) Single Node Elastic search. Could you please suggest/help how to reduce the RAM usage. Thanks in adva…

---

## [Logstash multiline charset =\> "UTF-8"](https://discuss.elastic.co/t/logstash-multiline-charset-utf-8/346146)

<div class="topic-metadata">

**Author:** [@ranjini](https://discuss.elastic.co/u/ranjini)\
**Replies:** 4\
**Last updated:** [November 2, 2023, 5:14pm UTC](https://discuss.elastic.co/t/logstash-multiline-charset-utf-8/346146 "2023-11-02T17:14:56Z")

</div>

\[2023-10-31T12:01:11,534\]\[WARN \]\[logstash.codecs.multiline\]\[main\]\[a029b778777f02de25308ca25697ff60da99dc3bc13beaf4e1c2d010740b27d8\] Received an event that has a different character encoding than you configured. {:text=\>"…

---

## [If there is an error log in an application, how to send log files onto elastic search](https://discuss.elastic.co/t/if-there-is-an-error-log-in-an-application-how-to-send-log-files-onto-elastic-search/345906)

<div class="topic-metadata">

**Author:** [@jt2023](https://discuss.elastic.co/u/jt2023)\
**Replies:** 21\
**Last updated:** [November 2, 2023, 4:01pm UTC](https://discuss.elastic.co/t/if-there-is-an-error-log-in-an-application-how-to-send-log-files-onto-elastic-search/345906 "2023-11-02T16:01:42Z")

</div>

if there is an error log in an application, how to send log files onto Elasticsearch

---

## [Elasticsearch vm.max\_map\_count error in docker image on MacOS 14](https://discuss.elastic.co/t/elasticsearch-vm-max-map-count-error-in-docker-image-on-macos-14/346285)

<div class="topic-metadata">

**Author:** [@timofeyp](https://discuss.elastic.co/u/timofeyp)\
**Replies:** 1\
**Last updated:** [November 2, 2023, 3:54pm UTC](https://discuss.elastic.co/t/elasticsearch-vm-max-map-count-error-in-docker-image-on-macos-14/346285 "2023-11-02T15:54:29Z")

</div>

Hello! I have the "vm.max\_map\_count \[65530\] is too low, increase to at least \[262144\]" error while elastic container starting on Docker 4.25, MacOS 14 and ARM core. Here is my container props: image: elasticsearch…

---

## [Elastic Architecture review](https://discuss.elastic.co/t/elastic-architecture-review/345987)

<div class="topic-metadata">

**Author:** [@ksrawat88](https://discuss.elastic.co/u/ksrawat88)\
**Replies:** 3\
**Last updated:** [November 2, 2023, 3:24pm UTC](https://discuss.elastic.co/t/elastic-architecture-review/345987 "2023-11-02T15:24:03Z")

</div>

We are planning to deploy elastic stack for logging and monitoring as SIEM, we want to start from open source version (community version) and if we see value we would upgrade to enterprise version with full security feat…

---

## [How can you know that a logstash input query has finished](https://discuss.elastic.co/t/how-can-you-know-that-a-logstash-input-query-has-finished/346173)

<div class="topic-metadata">

**Author:** [@dimitris\_sb](https://discuss.elastic.co/u/dimitris_sb)\
**Replies:** 1\
**Last updated:** [November 2, 2023, 3:22pm UTC](https://discuss.elastic.co/t/how-can-you-know-that-a-logstash-input-query-has-finished/346173 "2023-11-02T15:22:31Z")

</div>

Hi All, If you deploy a logstash pipeline using the input plugin with a query, how could you know that ingesting data has been completed to decommission it? Thank you in advance for your insight

---

## [Elasticsearch 8.10.2 synonyms not working](https://discuss.elastic.co/t/elasticsearch-8-10-2-synonyms-not-working/346303)

<div class="topic-metadata">

**Author:** [@smritibhandari91](https://discuss.elastic.co/u/smritibhandari91)\
**Replies:** 0\
**Last updated:** [November 2, 2023, 3:16pm UTC](https://discuss.elastic.co/t/elasticsearch-8-10-2-synonyms-not-working/346303 "2023-11-02T15:16:53Z")

</div>

We have deployed Elasticsearch 8.10.2 via ECK. The deployment is successful, however, we are facing below two issues: Index creation failing with IOException while reading synonyms\_path\_path. Synonym path has been succ…

---

## [Comparision between Elastic Observability Stack and Grafana Stack](https://discuss.elastic.co/t/comparision-between-elastic-observability-stack-and-grafana-stack/346191)

<div class="topic-metadata">

**Author:** [@phucnv282](https://discuss.elastic.co/u/phucnv282)\
**Replies:** 1\
**Last updated:** [November 2, 2023, 3:17pm UTC](https://discuss.elastic.co/t/comparision-between-elastic-observability-stack-and-grafana-stack/346191 "2023-11-02T15:17:04Z")

</div>

Hi all, Currently, I wanna install the Observability features on our K8s Infrastructure. When surveyed about the suitable solutions for that I wonder what is the difference, the pros and cons, use-cases,... of the Elas…

---

## [Elastic APM instrumentation vs OpenTelemetry instrumentation](https://discuss.elastic.co/t/elastic-apm-instrumentation-vs-opentelemetry-instrumentation/344785)

<div class="topic-metadata">

**Author:** [@deastr](https://discuss.elastic.co/u/deastr)\
**Replies:** 1\
**Last updated:** [November 2, 2023, 3:00pm UTC](https://discuss.elastic.co/t/elastic-apm-instrumentation-vs-opentelemetry-instrumentation/344785 "2023-11-02T15:00:50Z")

</div>

I'm trying OpenTelemetry client with Elastic APM to log into Elastic APM server. There are several instrumentations that exists both in OTEL client and Elastic APM client, for example AspNetCoreInstrumentation. Do these …

---

## [Data not updating on kibana](https://discuss.elastic.co/t/data-not-updating-on-kibana/346297)

<div class="topic-metadata">

**Author:** [@IJ\_Oma](https://discuss.elastic.co/u/IJ_Oma)\
**Replies:** 1\
**Last updated:** [November 2, 2023, 2:55pm UTC](https://discuss.elastic.co/t/data-not-updating-on-kibana/346297 "2023-11-02T14:55:22Z")

</div>

Hello all, Data stopped flowing from the database jbdc through logstash to kibana across all indices. Is anyone else having same issue? For about more than a week now, data updates on kibana via logstash has been very s…

---

## [What is logstash instance?](https://discuss.elastic.co/t/what-is-logstash-instance/345357)

<div class="topic-metadata">

**Author:** [@Nghia\_D\_ng](https://discuss.elastic.co/u/Nghia_D_ng)\
**Replies:** 10\
**Last updated:** [November 2, 2023, 2:50pm UTC](https://discuss.elastic.co/t/what-is-logstash-instance/345357 "2023-11-02T14:50:49Z")

</div>

I want to know what a logstash instance is? Is it a self-generated .conf file? Which command should I use to check which instances are running?

---

## [Multiline pattern for covering all inconsistencies](https://discuss.elastic.co/t/multiline-pattern-for-covering-all-inconsistencies/346162)

<div class="topic-metadata">

**Author:** [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Replies:** 6\
**Last updated:** [November 2, 2023, 2:46pm UTC](https://discuss.elastic.co/t/multiline-pattern-for-covering-all-inconsistencies/346162 "2023-11-02T14:46:00Z")

</div>

Hello All, The application log generates messages which include various lines (not the same number every time). It also contains messages in XML form and various other kind. Is there a way I could define a multiline.p…

---

## [Bare metall - replace old hot allocators (SSD)](https://discuss.elastic.co/t/bare-metall-replace-old-hot-allocators-ssd/346293)

<div class="topic-metadata">

**Author:** [@jojsf](https://discuss.elastic.co/u/jojsf)\
**Replies:** 1\
**Last updated:** [November 2, 2023, 2:28pm UTC](https://discuss.elastic.co/t/bare-metall-replace-old-hot-allocators-ssd/346293 "2023-11-02T14:28:58Z")

</div>

Hi, We are in a need of order new servers for our installation. I am wondering about hot and warm allocators and the type of SSD. In the \[Hardware prerequisites | Elastic Cloud Enterprise Reference \[3.6\] | Elastic\](Ha…

---

## [Data view in Kibana with the latest timestamp version of a datastream](https://discuss.elastic.co/t/data-view-in-kibana-with-the-latest-timestamp-version-of-a-datastream/345177)

<div class="topic-metadata">

**Author:** [@Mubolio](https://discuss.elastic.co/u/Mubolio)\
**Replies:** 11\
**Last updated:** [November 2, 2023, 1:34pm UTC](https://discuss.elastic.co/t/data-view-in-kibana-with-the-latest-timestamp-version-of-a-datastream/345177 "2023-11-02T13:34:41Z")

</div>

Hello, I have a datastream that it is often being updated, for some graphs I use the full data stream for visualizations, for example, doing histograms with the @timestamp field. But for other cases I would like to do g…

[Previous page](https://discuss.elastic.co/latest.md?page=492)

[Next page](https://discuss.elastic.co/latest.md?page=494)
