# Latest

**URL:** https://discuss.elastic.co/latest.md?page=497

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 498

---

## [Kibana cookies contain "--" characters in the SID which causes the user requests to get blocked in the azure WAF](https://discuss.elastic.co/t/kibana-cookies-contain-characters-in-the-sid-which-causes-the-user-requests-to-get-blocked-in-the-azure-waf/346087)

<div class="topic-metadata">

**Author:** [@sahadev\_d](https://discuss.elastic.co/u/sahadev_d)\
**Replies:** 0\
**Last updated:** [October 31, 2023, 5:45am UTC](https://discuss.elastic.co/t/kibana-cookies-contain-characters-in-the-sid-which-causes-the-user-requests-to-get-blocked-in-the-azure-waf/346087 "2023-10-31T05:45:08Z")

</div>

Hi Community, We are facing issue while using kibana using with URL, Whenever the user log-in to kibana with the RBAs user creds the user gets 403 error from the kibana servers. As we debugged the issue we came to know…

---

## [ElasticEndpoint authorization is automatically closed in FDA](https://discuss.elastic.co/t/elasticendpoint-authorization-is-automatically-closed-in-fda/345693)

<div class="topic-metadata">

**Author:** [@xqaiviwjxzw](https://discuss.elastic.co/u/xqaiviwjxzw)\
**Replies:** 2\
**Last updated:** [October 31, 2023, 3:42am UTC](https://discuss.elastic.co/t/elasticendpoint-authorization-is-automatically-closed-in-fda/345693 "2023-10-31T03:42:26Z")

</div>

After installing elastic agent versions 8.4.1 and 8.9.1, I have clicked and checked in FDA to authorize ElasticEndpoint. However, after running on the computer for a period of time, the authorization of ElasticEndpoint i…

---

## [ElasticSearch Fleet - Outdated Policy](https://discuss.elastic.co/t/elasticsearch-fleet-outdated-policy/346082)

<div class="topic-metadata">

**Author:** [@crypt0ace](https://discuss.elastic.co/u/crypt0ace)\
**Replies:** 0\
**Last updated:** [October 31, 2023, 3:37am UTC](https://discuss.elastic.co/t/elasticsearch-fleet-outdated-policy/346082 "2023-10-31T03:37:25Z")

</div>

Hello! I just added a Windows integration in my home lab in the Elasticsearch and I got this error Then when i view the integrations I can see Windows got added but I can also see this "Outdated Policy" with my agen…

---

## [Elastic data large exception (Data too large, data for \[http\_request\])](https://discuss.elastic.co/t/elastic-data-large-exception-data-too-large-data-for-http-request/345907)

<div class="topic-metadata">

**Author:** [@Rajesh123](https://discuss.elastic.co/u/Rajesh123)\
**Replies:** 2\
**Last updated:** [October 31, 2023, 12:25am UTC](https://discuss.elastic.co/t/elastic-data-large-exception-data-too-large-data-for-http-request/345907 "2023-10-31T00:25:14Z")

</div>

Hello, Could you please help on below issue . we getting this issue on Elastic and kibana. \`1e9fa016\]\[trial #34\] null during Elasticsearch operation (ElasticsearchStatusException\[Elasticsearch exception \[type=circuit\_b…

---

## [Data too large for response \[parent\]](https://discuss.elastic.co/t/data-too-large-for-response-parent/346048)

<div class="topic-metadata">

**Author:** [@uhlirradek95](https://discuss.elastic.co/u/uhlirradek95)\
**Replies:** 1\
**Last updated:** [October 31, 2023, 12:22am UTC](https://discuss.elastic.co/t/data-too-large-for-response-parent/346048 "2023-10-31T00:22:48Z")

</div>

Hi, could you please help me to understand following exception? Cluster configuration: 3 nodes each 6CPU, 32GB RAM, completely on SSD While making a search request, following exception occours: \[Invalid response ret…

---

## [TLS issue with Filebeat 8.10 an higher](https://discuss.elastic.co/t/tls-issue-with-filebeat-8-10-an-higher/345606)

<div class="topic-metadata">

**Author:** [@Somecallmesteve](https://discuss.elastic.co/u/Somecallmesteve)\
**Replies:** 20\
**Last updated:** [October 30, 2023, 9:54pm UTC](https://discuss.elastic.co/t/tls-issue-with-filebeat-8-10-an-higher/345606 "2023-10-30T21:54:40Z")

</div>

I started trying to upgrade some clients to Filebeat 8.10.3 and found that if I install 8.10.x I get the following error when connecting to a Logstash output using tsl : "...x509: cannot validate certificate for X.X.X.X…

---

## [Reference custom field in another custom field](https://discuss.elastic.co/t/reference-custom-field-in-another-custom-field/346066)

<div class="topic-metadata">

**Author:** [@patricio.devilla](https://discuss.elastic.co/u/patricio.devilla)\
**Replies:** 0\
**Last updated:** [October 30, 2023, 7:13pm UTC](https://discuss.elastic.co/t/reference-custom-field-in-another-custom-field/346066 "2023-10-30T19:13:27Z")

</div>

Is it possible to reference a custom field in another field? Creating custom field custom\_1 Creating custom field custom\_2 emit(doc\['custom\_1'\].value) I get the following error No field found for \[custom\_1\] in ma…

---

## [Elastic Web crawler extraction rule support for excluding css selectors with :not](https://discuss.elastic.co/t/elastic-web-crawler-extraction-rule-support-for-excluding-css-selectors-with-not/345391)

<div class="topic-metadata">

**Author:** [@sebastianboelling](https://discuss.elastic.co/u/sebastianboelling)\
**Replies:** 1\
**Last updated:** [October 30, 2023, 4:50pm UTC](https://discuss.elastic.co/t/elastic-web-crawler-extraction-rule-support-for-excluding-css-selectors-with-not/345391 "2023-10-30T16:50:58Z")

</div>

Hi, we are using the Elastic Web Crawler and we are trying to exclude content by using content extraction rules. based on CSS selectors. To be clear, we do not want to select content from DOM by an rule to an field, we…

---

## [Storage explorer UI in APM displays wrong "Total APM size"](https://discuss.elastic.co/t/storage-explorer-ui-in-apm-displays-wrong-total-apm-size/345933)

<div class="topic-metadata">

**Author:** [@vamshigottam](https://discuss.elastic.co/u/vamshigottam)\
**Replies:** 8\
**Last updated:** [October 30, 2023, 4:13pm UTC](https://discuss.elastic.co/t/storage-explorer-ui-in-apm-displays-wrong-total-apm-size/345933 "2023-10-30T16:13:36Z")

</div>

@Akhilesh\_Pokhariyal- apologies for tagging you directly. we are observing a strange issue in our APM environment with the Total APM size. we enabled APM for only handful of services on a single host and surprised to s…

---

## [Azure Functions APM not sending service.name in traces - bug in how service.name is overridden with null value](https://discuss.elastic.co/t/azure-functions-apm-not-sending-service-name-in-traces-bug-in-how-service-name-is-overridden-with-null-value/345943)

<div class="topic-metadata">

**Author:** [@andrisarkameru](https://discuss.elastic.co/u/andrisarkameru)\
**Replies:** 1\
**Last updated:** [October 30, 2023, 4:10pm UTC](https://discuss.elastic.co/t/azure-functions-apm-not-sending-service-name-in-traces-bug-in-how-service-name-is-overridden-with-null-value/345943 "2023-10-30T16:10:42Z")

</div>

APM Agent version dotnet apm agent Initially tested on: "Elastic.Apm.Azure.Functions" Version="1.25.0" NuGet package Later tried debugging on commit: d398ca0 by adding it locally to my project. Environment Windows A…

---

## [Custom Logs integration upgrade fails with invalid\_index\_template\_exception](https://discuss.elastic.co/t/custom-logs-integration-upgrade-fails-with-invalid-index-template-exception/346056)

<div class="topic-metadata">

**Author:** [@jmartin](https://discuss.elastic.co/u/jmartin)\
**Replies:** 0\
**Last updated:** [October 30, 2023, 3:53pm UTC](https://discuss.elastic.co/t/custom-logs-integration-upgrade-fails-with-invalid-index-template-exception/346056 "2023-10-30T15:53:07Z")

</div>

When trying to upgrade the custom logs integration, for fleet from version 2.0.0 to 2.3.0. Kibana gives the following error: invalid\_index\_template\_exception: index\_template \[logs-ERMP@custom\] invalid, cause \[Validati…

---

## [MySQL Connector cannot connect to Elasticsearch Docker Instance](https://discuss.elastic.co/t/mysql-connector-cannot-connect-to-elasticsearch-docker-instance/346043)

<div class="topic-metadata">

**Author:** [@James\_Cook1](https://discuss.elastic.co/u/James_Cook1)\
**Replies:** 1\
**Last updated:** [October 30, 2023, 3:38pm UTC](https://discuss.elastic.co/t/mysql-connector-cannot-connect-to-elasticsearch-docker-instance/346043 "2023-10-30T15:38:23Z")

</div>

Hello We are currently in the process of attempting to set up a locally running instance of Elasticsearch to connect to a MySQL database using Docker Containers but are unable to get this to work. We are following the …

---

## [Syslog severity and facility not set when upgrading version](https://discuss.elastic.co/t/syslog-severity-and-facility-not-set-when-upgrading-version/345695)

<div class="topic-metadata">

**Author:** [@Andrea\_De\_Pinto](https://discuss.elastic.co/u/Andrea_De_Pinto)\
**Replies:** 3\
**Last updated:** [October 30, 2023, 3:13pm UTC](https://discuss.elastic.co/t/syslog-severity-and-facility-not-set-when-upgrading-version/345695 "2023-10-30T15:13:31Z")

</div>

Hi, I did the migration from the version 6.8 to the 8.9 and I have a logstash pipeline that use the syslog to feed my elasticsearch. This is the configuration I have on the 6.8 : input { syslog { type =\> "sy…

---

## [Elastic APM- apm-agent-attach-cli.jar: Stop collecting metrics through apm cli](https://discuss.elastic.co/t/elastic-apm-apm-agent-attach-cli-jar-stop-collecting-metrics-through-apm-cli/345592)

<div class="topic-metadata">

**Author:** [@vamshigottam](https://discuss.elastic.co/u/vamshigottam)\
**Replies:** 9\
**Last updated:** [October 30, 2023, 3:01pm UTC](https://discuss.elastic.co/t/elastic-apm-apm-agent-attach-cli-jar-stop-collecting-metrics-through-apm-cli/345592 "2023-10-30T15:01:01Z")

</div>

We are capturing the application metrics with elastic APM agent using apm-agent-attach-cli.jar which attaches to the running JVM's without making any changes to the code or JVM startup. This is working fine without any …

---

## [How to handle unmapped fields](https://discuss.elastic.co/t/how-to-handle-unmapped-fields/345991)

<div class="topic-metadata">

**Author:** [@hta](https://discuss.elastic.co/u/hta)\
**Replies:** 4\
**Last updated:** [October 30, 2023, 2:35pm UTC](https://discuss.elastic.co/t/how-to-handle-unmapped-fields/345991 "2023-10-30T14:35:14Z")

</div>

filter { grok { id =\> "name school grok filter" match =\> { 'message' =\> '^.\*name=\\'%{WORD:student.name}\\'.\*school=\\'%{WORD:student.school}\\''} } } For example, with WORD:student.name I would like to create a…

---

## [Extract Exception Class](https://discuss.elastic.co/t/extract-exception-class/346046)

<div class="topic-metadata">

**Author:** [@hta](https://discuss.elastic.co/u/hta)\
**Replies:** 0\
**Last updated:** [October 30, 2023, 2:21pm UTC](https://discuss.elastic.co/t/extract-exception-class/346046 "2023-10-30T14:21:54Z")

</div>

Hello, what is the best way to extract the exception from the following log? I only need the exception class NullpointerException e.g. My attempt: %{TIMESTAMP\_ISO8601:log\_timestamp}.%{LOGLEVEL:log\_level}.\[%{GREEDYDATA:…

---

## [search profile breakdown](https://discuss.elastic.co/t/search-profile-breakdown/346041)

<div class="topic-metadata">

**Author:** [@getsolaris](https://discuss.elastic.co/u/getsolaris)\
**Replies:** 0\
**Last updated:** [October 30, 2023, 2:17pm UTC](https://discuss.elastic.co/t/search-profile-breakdown/346041 "2023-10-30T14:17:59Z")

</div>

hello, I'm using Elasticsearch's profile API to try and figure out what's taking so long. I currently have an index implemented with parent-child modeling. When I run a has\_child query, I am getting a high match in my…

---

## [How exlude particular index from ilm policy](https://discuss.elastic.co/t/how-exlude-particular-index-from-ilm-policy/345792)

<div class="topic-metadata">

**Author:** [@Ekta](https://discuss.elastic.co/u/Ekta)\
**Replies:** 4\
**Last updated:** [October 30, 2023, 2:15pm UTC](https://discuss.elastic.co/t/how-exlude-particular-index-from-ilm-policy/345792 "2023-10-30T14:15:55Z")

</div>

Hi, OS : 22.04 linux ES version: 7.17.0 I have created ilm policy like delete all indexes after 45 days. I am using \* in policy. but I want to exclude particular index pattern which is not deleted or ilm policy is not…

---

## [Ingesting data from MongoDB Atlas to Elastic App Search engine](https://discuss.elastic.co/t/ingesting-data-from-mongodb-atlas-to-elastic-app-search-engine/346019)

<div class="topic-metadata">

**Author:** [@Rustin\_Spencer](https://discuss.elastic.co/u/Rustin_Spencer)\
**Replies:** 1\
**Last updated:** [October 30, 2023, 1:57pm UTC](https://discuss.elastic.co/t/ingesting-data-from-mongodb-atlas-to-elastic-app-search-engine/346019 "2023-10-30T13:57:36Z")

</div>

Is there a tool to ingest data from MongoDB Atlas to App Search engine? Something like Firebase extensions? If there isn't any, what are some great practices to ingest the data?

---

## [Sync Postgresql and Elasticsearch using Filebeat](https://discuss.elastic.co/t/sync-postgresql-and-elasticsearch-using-filebeat/345576)

<div class="topic-metadata">

**Author:** [@tmslara.a](https://discuss.elastic.co/u/tmslara.a)\
**Replies:** 2\
**Last updated:** [October 30, 2023, 1:43pm UTC](https://discuss.elastic.co/t/sync-postgresql-and-elasticsearch-using-filebeat/345576 "2023-10-30T13:43:55Z")

</div>

Hi, I have a considerable amount of information in a Postgresql database. Registers are inserted on this database on demand. We are currently interested in syncronize this database and Elasticsearch in order to have the…

---

## [ELK | Logging | filter out specific ip's generated WARNs?](https://discuss.elastic.co/t/elk-logging-filter-out-specific-ips-generated-warns/346040)

<div class="topic-metadata">

**Author:** [@LucGasper](https://discuss.elastic.co/u/LucGasper)\
**Replies:** 0\
**Last updated:** [October 30, 2023, 1:33pm UTC](https://discuss.elastic.co/t/elk-logging-filter-out-specific-ips-generated-warns/346040 "2023-10-30T13:33:04Z")

</div>

Hi elk lovers, in our Company we are subjected daily to security penetration tests. All these tests are originated by a specific static ip. Our elasticsearch log is therefore filled up with WARNs, especially: ... \[2…

---

## [Windows Service Control Manager error with Elastic Agent](https://discuss.elastic.co/t/windows-service-control-manager-error-with-elastic-agent/346039)

<div class="topic-metadata">

**Author:** [@Bearloggs](https://discuss.elastic.co/u/Bearloggs)\
**Replies:** 0\
**Last updated:** [October 30, 2023, 1:21pm UTC](https://discuss.elastic.co/t/windows-service-control-manager-error-with-elastic-agent/346039 "2023-10-30T13:21:56Z")

</div>

Description When installing and running the Elastic Agent on a Windows 10 or Windows Server 2019 machine, I encounter Service Control Manager errors. The Elastic Agent seems to be functioning as expected on my Windows m…

---

## [Apache Logs Not Parsing with Filebeat Ingestion Pipeline](https://discuss.elastic.co/t/apache-logs-not-parsing-with-filebeat-ingestion-pipeline/345968)

<div class="topic-metadata">

**Author:** [@huzaifa224](https://discuss.elastic.co/u/huzaifa224)\
**Replies:** 3\
**Last updated:** [October 30, 2023, 12:37pm UTC](https://discuss.elastic.co/t/apache-logs-not-parsing-with-filebeat-ingestion-pipeline/345968 "2023-10-30T12:37:39Z")

</div>

I have installed Filebeat version 8.10.2 on an Ubuntu server and configured it to send Apache access and error logs to Logstash. While the logs are displayed in Kibana, they are not parsing through their default ingest p…

---

## [Elasticsearch node ram.percent at 100%](https://discuss.elastic.co/t/elasticsearch-node-ram-percent-at-100/346022)

<div class="topic-metadata">

**Author:** [@rahmathm1](https://discuss.elastic.co/u/rahmathm1)\
**Replies:** 1\
**Last updated:** [October 30, 2023, 10:57am UTC](https://discuss.elastic.co/t/elasticsearch-node-ram-percent-at-100/346022 "2023-10-30T10:57:33Z")

</div>

Hi, everyone, We have a 6x6 setup of ES deployed on Kubernetes. When we check node memory statistics, we can see that data nodes are using 100% of ram allocated to them. Below are the resource limits for data nodes: l…

---

## [Run painless script in cron like manner](https://discuss.elastic.co/t/run-painless-script-in-cron-like-manner/346017)

<div class="topic-metadata">

**Author:** [@Pawel\_Gorowicz](https://discuss.elastic.co/u/Pawel_Gorowicz)\
**Replies:** 0\
**Last updated:** [October 30, 2023, 10:01am UTC](https://discuss.elastic.co/t/run-painless-script-in-cron-like-manner/346017 "2023-10-30T10:01:36Z")

</div>

Hi All, I'm searching for an options to run a script in cron like manner. I need to run "\_update\_by\_query" with tiny painless script every few hours to fix some data inside the index. Is there any option to do that ?

---

## [Logstash RSS plugin failed to load after fresh install](https://discuss.elastic.co/t/logstash-rss-plugin-failed-to-load-after-fresh-install/345988)

<div class="topic-metadata">

**Author:** [@developerx](https://discuss.elastic.co/u/developerx)\
**Replies:** 2\
**Last updated:** [October 30, 2023, 9:15am UTC](https://discuss.elastic.co/t/logstash-rss-plugin-failed-to-load-after-fresh-install/345988 "2023-10-30T09:15:35Z")

</div>

Hello, i've an issue with a fresh logstash installation and logstash-input-rss plugin. when trying to test the configuration for a simple RSS reader for just 1 URL i got this error: \[DEBUG\] 2023-10-29 19:57:25.354 \[Con…

---

## [Concurrent Enrich Policy Execution](https://discuss.elastic.co/t/concurrent-enrich-policy-execution/346011)

<div class="topic-metadata">

**Author:** [@Akshey](https://discuss.elastic.co/u/Akshey)\
**Replies:** 0\
**Last updated:** [October 30, 2023, 8:32am UTC](https://discuss.elastic.co/t/concurrent-enrich-policy-execution/346011 "2023-10-30T08:32:36Z")

</div>

Hi Team, We've added an enrichment policy to join data among two indexes. The indexes are dynamic, hence we are running the execute policy query whenever there's an update in the source index. The problem is when there …

---

## [Problem with Template File Not Applying Correctly in Logstash](https://discuss.elastic.co/t/problem-with-template-file-not-applying-correctly-in-logstash/346006)

<div class="topic-metadata">

**Author:** [@inkweon7269](https://discuss.elastic.co/u/inkweon7269)\
**Replies:** 0\
**Last updated:** [October 30, 2023, 7:09am UTC](https://discuss.elastic.co/t/problem-with-template-file-not-applying-correctly-in-logstash/346006 "2023-10-30T07:09:06Z")

</div>

We are experiencing an issue with Logstash where the user\_dictionary\_rules, stopwords, and synonyms data are not being properly indexed based on the template file in an EC2 environment. When these data sets, specificall…

---

## [Why is the ssl\_key\_passphrase missing in the plugins-outputs-elasticsearch?](https://discuss.elastic.co/t/why-is-the-ssl-key-passphrase-missing-in-the-plugins-outputs-elasticsearch/345999)

<div class="topic-metadata">

**Author:** [@hengya\_liu](https://discuss.elastic.co/u/hengya_liu)\
**Replies:** 6\
**Last updated:** [October 30, 2023, 6:27am UTC](https://discuss.elastic.co/t/why-is-the-ssl-key-passphrase-missing-in-the-plugins-outputs-elasticsearch/345999 "2023-10-30T06:27:43Z")

</div>

Logstash 8.10 ssl\_key\_passphrase is Missing. If we set the SSL certificate, do we have to use the unencrypted key or use a keystore?

---

## [Index Created but No Document got written](https://discuss.elastic.co/t/index-created-but-no-document-got-written/346004)

<div class="topic-metadata">

**Author:** [@ivanchak](https://discuss.elastic.co/u/ivanchak)\
**Replies:** 0\
**Last updated:** [October 30, 2023, 4:57am UTC](https://discuss.elastic.co/t/index-created-but-no-document-got-written/346004 "2023-10-30T04:57:40Z")

</div>

Just set a more specific index template with a higher priority value than the more general one, and looking to apply this template instead of the general one. Then I removed related data stream (which wipes off all the r…

[Previous page](https://discuss.elastic.co/latest.md?page=496)

[Next page](https://discuss.elastic.co/latest.md?page=498)
