# Latest

**URL:** https://discuss.elastic.co/latest.md?page=498

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 499

---

## [Configure Elastic agent to collect AWS RDS SLOW logs loaded in S3](https://discuss.elastic.co/t/configure-elastic-agent-to-collect-aws-rds-slow-logs-loaded-in-s3/346003)

<div class="topic-metadata">

**Author:** [@douglas0923](https://discuss.elastic.co/u/douglas0923)\
**Replies:** 0\
**Last updated:** [October 30, 2023, 4:54am UTC](https://discuss.elastic.co/t/configure-elastic-agent-to-collect-aws-rds-slow-logs-loaded-in-s3/346003 "2023-10-30T04:54:21Z")

</div>

Hi there Is there a way to configure the Elastic Agent to directly read the slow logs from the S3 bucket instead of the local file path? Additionally, I feel that configuring this through Kibana's Fleet GUI might be ch…

---

## [Synonym search latency](https://discuss.elastic.co/t/synonym-search-latency/346001)

<div class="topic-metadata">

**Author:** [@vanduong](https://discuss.elastic.co/u/vanduong)\
**Replies:** 0\
**Last updated:** [October 30, 2023, 3:51am UTC](https://discuss.elastic.co/t/synonym-search-latency/346001 "2023-10-30T03:51:00Z")

</div>

I recently utilized synonyms in an Elasticsearch context. After reading a blog that discusses the advantages of applying synonyms at search time as opposed to index time, I began to wonder if using synonyms at search tim…

---

## [\[Packetbeat\] packet loss for mysql queries](https://discuss.elastic.co/t/packetbeat-packet-loss-for-mysql-queries/345857)

<div class="topic-metadata">

**Author:** [@lenovore](https://discuss.elastic.co/u/lenovore)\
**Replies:** 2\
**Last updated:** [October 30, 2023, 2:23am UTC](https://discuss.elastic.co/t/packetbeat-packet-loss-for-mysql-queries/345857 "2023-10-30T02:23:21Z")

</div>

Version: packetbeat-8.10.4、packetbeat-7.10.2 Operating System: ubuntu20.04 #18471 #20890 Three years have passed, and the problem of packet loss in MySQL queries remains unresolved. sql: use dba\_backup; select \* fr…

---

## [How to configure prometheus ssl host with metricbeat?](https://discuss.elastic.co/t/how-to-configure-prometheus-ssl-host-with-metricbeat/345997)

<div class="topic-metadata">

**Author:** [@pooh97](https://discuss.elastic.co/u/pooh97)\
**Replies:** 0\
**Last updated:** [October 30, 2023, 2:05am UTC](https://discuss.elastic.co/t/how-to-configure-prometheus-ssl-host-with-metricbeat/345997 "2023-10-30T02:05:07Z")

</div>

This is my first time on elasticsearch. I have to get metrics from prometheus hosts with ssl. I'll describe my develop environment in advance. I'm using metricbeat 8.8.2 on A Server. But I want to scrap Prometheus fe…

---

## [Index data storage into a cluster](https://discuss.elastic.co/t/index-data-storage-into-a-cluster/344298)

<div class="topic-metadata">

**Author:** [@MattzGB](https://discuss.elastic.co/u/MattzGB)\
**Replies:** 3\
**Last updated:** [October 29, 2023, 11:07pm UTC](https://discuss.elastic.co/t/index-data-storage-into-a-cluster/344298 "2023-10-29T23:07:13Z")

</div>

I have an elasticsearch cluster with 3 nodes where the elasticsearch service is installed on each node. When I check the cluster health and the index on each node, I can see that the cluster is green and that the 25GB i…

---

## [Prioritizing Indices for Search Speed](https://discuss.elastic.co/t/prioritizing-indices-for-search-speed/345973)

<div class="topic-metadata">

**Author:** [@maorethians](https://discuss.elastic.co/u/maorethians)\
**Replies:** 2\
**Last updated:** [October 29, 2023, 10:09pm UTC](https://discuss.elastic.co/t/prioritizing-indices-for-search-speed/345973 "2023-10-29T22:09:48Z")

</div>

We have an Elasticsearch instance, containing 100s of indices in it with different, statically-defined mappings. Is there a way to prioritize some of them for read/write operations not to be affected by low-priority ones…

---

## [Question about discuss.elastic.co](https://discuss.elastic.co/t/question-about-discuss-elastic-co/345984)

<div class="topic-metadata">

**Author:** [@Roman\_Kagan](https://discuss.elastic.co/u/Roman_Kagan)\
**Replies:** 2\
**Last updated:** [October 29, 2023, 5:32pm UTC](https://discuss.elastic.co/t/question-about-discuss-elastic-co/345984 "2023-10-29T17:32:20Z")

</div>

Hello: I was trying to ask a question on discuss.elastic.co and I see that I cannot do that anymore. Not sure why. Maybe you could find out why I am blacklisted there.

---

## [How to activate sysmon event ID 3](https://discuss.elastic.co/t/how-to-activate-sysmon-event-id-3/345977)

<div class="topic-metadata">

**Author:** [@yassinebad](https://discuss.elastic.co/u/yassinebad)\
**Replies:** 1\
**Last updated:** [October 29, 2023, 3:51pm UTC](https://discuss.elastic.co/t/how-to-activate-sysmon-event-id-3/345977 "2023-10-29T15:51:26Z")

</div>

Hey everyone, I am sending my logs from a windows node using winlogbeat and sysmon64 to my ELK stack. While in discover panel in kibana I can see my logs with different events ID of sysmon, but I have noticed that the …

---

## [Logstash create many zero document indexes](https://discuss.elastic.co/t/logstash-create-many-zero-document-indexes/345522)

<div class="topic-metadata">

**Author:** [@Amzath\_Khan](https://discuss.elastic.co/u/Amzath_Khan)\
**Replies:** 3\
**Last updated:** [October 29, 2023, 12:28pm UTC](https://discuss.elastic.co/t/logstash-create-many-zero-document-indexes/345522 "2023-10-29T12:28:25Z")

</div>

I'm sending data from a Microsoft SQL Server database into elasticsearch using logstash 8.x. It functions well. However, logstash multiplies indexes with no documents and raises the shared. It takes over an hour to reach…

---

## [HAYSTACK\_CONNECTIONS](https://discuss.elastic.co/t/haystack-connections/345829)

<div class="topic-metadata">

**Author:** [@sdarwin](https://discuss.elastic.co/u/sdarwin)\
**Replies:** 3\
**Last updated:** [October 29, 2023, 11:49am UTC](https://discuss.elastic.co/t/haystack-connections/345829 "2023-10-29T11:49:29Z")

</div>

Hi, Not sure which category to post this in. Django Haystack GitHub - django-haystack/django-haystack: Modular search for Django supports Elasticsearch as a backend search engine. The connection is specified this way: H…

---

## [Elastic 8.10.3 failed to establish trust with server at \[\<unknown host\>\]; the server provided a certificate with subject name](https://discuss.elastic.co/t/elastic-8-10-3-failed-to-establish-trust-with-server-at-unknown-host-the-server-provided-a-certificate-with-subject-name/345656)

<div class="topic-metadata">

**Author:** [@efrainMZ](https://discuss.elastic.co/u/efrainMZ)\
**Replies:** 8\
**Last updated:** [October 29, 2023, 11:21am UTC](https://discuss.elastic.co/t/elastic-8-10-3-failed-to-establish-trust-with-server-at-unknown-host-the-server-provided-a-certificate-with-subject-name/345656 "2023-10-29T11:21:41Z")

</div>

Hello good morning! I am trying to create an elastic cluster in version 8.10.3 but when starting the coordinator role I get the following error: \[ithrtc3aen1elk1-coordinator-1\] failed to establish trust with server at …

---

## [Can not connect Logstash to Elasticsearch](https://discuss.elastic.co/t/can-not-connect-logstash-to-elasticsearch/345867)

<div class="topic-metadata">

**Author:** [@liaotoca](https://discuss.elastic.co/u/liaotoca)\
**Replies:** 1\
**Last updated:** [October 29, 2023, 11:15am UTC](https://discuss.elastic.co/t/can-not-connect-logstash-to-elasticsearch/345867 "2023-10-29T11:15:16Z")

</div>

I follow the instructions here Secure your connection to Elasticsearch | Logstash Reference \[8.10\] | Elastic but if I did not put the username/password, logstash reported 401, if I put in the user name /password, the sta…

---

## [Master Node cant connect](https://discuss.elastic.co/t/master-node-cant-connect/345899)

<div class="topic-metadata">

**Author:** [@Nerd0](https://discuss.elastic.co/u/Nerd0)\
**Replies:** 1\
**Last updated:** [October 29, 2023, 11:11am UTC](https://discuss.elastic.co/t/master-node-cant-connect/345899 "2023-10-29T11:11:27Z")

</div>

Hi, I have a problem caused by: sun.security.validator.ValidatorException: PKIX path validation failed: java.security.cert.CertPathValidatorException: Path does not chain with any of the trust anchors I configured 3 nod…

---

## [How to restore .security index from snapshot](https://discuss.elastic.co/t/how-to-restore-security-index-from-snapshot/344959)

<div class="topic-metadata">

**Author:** [@dna01](https://discuss.elastic.co/u/dna01)\
**Replies:** 6\
**Last updated:** [October 29, 2023, 11:06am UTC](https://discuss.elastic.co/t/how-to-restore-security-index-from-snapshot/344959 "2023-10-29T11:06:56Z")

</div>

what is the recommended approach to restore .security index from snapshot? the index needs to be closed to be restored, but once it is closed, users cannot login anymore. and the whole database stuck since it cannot lo…

---

## [Logs don't show up on kibana](https://discuss.elastic.co/t/logs-dont-show-up-on-kibana/345930)

<div class="topic-metadata">

**Author:** [@yassinebad](https://discuss.elastic.co/u/yassinebad)\
**Replies:** 8\
**Last updated:** [October 29, 2023, 11:06am UTC](https://discuss.elastic.co/t/logs-dont-show-up-on-kibana/345930 "2023-10-29T11:06:23Z")

</div>

Hey I am using winlogbeat on my windows machine with sysmon64. my winlogbeat.yml file is configured correctly. I have checked with the config command. once I run ./winlogbeat.exe setup -e ! my index and dashboards get …

---

## [Logstash cvs plugin not sending data to index](https://discuss.elastic.co/t/logstash-cvs-plugin-not-sending-data-to-index/345924)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 3\
**Last updated:** [October 29, 2023, 7:36am UTC](https://discuss.elastic.co/t/logstash-cvs-plugin-not-sending-data-to-index/345924 "2023-10-29T07:36:29Z")

</div>

Hello All, I have csv files under one folder in windows system and need to send the data in elastic index using logstash. I'm not sure why data is not showing in index,though index getting created. Need key and value a…

---

## [LogStash::Error: Don't know how to handle \`Java::JavaLang::IllegalStateException\` for \`PipelineAction::Create\<main\>\`](https://discuss.elastic.co/t/logstash-dont-know-how-to-handle-java-illegalstateexception-for-pipelineaction-create-main/345882)

<div class="topic-metadata">

**Author:** [@fae](https://discuss.elastic.co/u/fae)\
**Replies:** 6\
**Last updated:** [October 29, 2023, 6:53am UTC](https://discuss.elastic.co/t/logstash-dont-know-how-to-handle-java-illegalstateexception-for-pipelineaction-create-main/345882 "2023-10-29T06:53:11Z")

</div>

Need help troubleshooting logstash java issue, it was working fine until a while ago when it started throwing up this error below: systemctl status logstash -l ● logstash.service - Logstash service (ELK stack). Loade…

---

## [Restore snapshot with curl](https://discuss.elastic.co/t/restore-snapshot-with-curl/345961)

<div class="topic-metadata">

**Author:** [@cyberzlo](https://discuss.elastic.co/u/cyberzlo)\
**Replies:** 2\
**Last updated:** [October 28, 2023, 5:49pm UTC](https://discuss.elastic.co/t/restore-snapshot-with-curl/345961 "2023-10-28T17:49:04Z")

</div>

Hi, I have snapshot of indexes pattern .\*, now after Kibana problems due power off I have to restore .kibana\* indexes to fix my problems. How can I do it with curl (as Kibana doesn't work)?

---

## [I have the same problem](https://discuss.elastic.co/t/i-have-the-same-problem/345963)

<div class="topic-metadata">

**Author:** [@1337](https://discuss.elastic.co/u/1337)\
**Replies:** 2\
**Last updated:** [October 28, 2023, 1:54pm UTC](https://discuss.elastic.co/t/i-have-the-same-problem/345963 "2023-10-28T13:54:04Z")

</div>

Continuing the discussion from How to re-run cluster with different cluster uuid:

---

## [Get all ids with Python](https://discuss.elastic.co/t/get-all-ids-with-python/344689)

<div class="topic-metadata">

**Author:** [@marc.schwarzschild](https://discuss.elastic.co/u/marc.schwarzschild)\
**Replies:** 1\
**Last updated:** [October 27, 2023, 9:51pm UTC](https://discuss.elastic.co/t/get-all-ids-with-python/344689 "2023-10-27T21:51:21Z")

</div>

Hi, I'd like to use the elastic\_enterprise\_search.AppSearch package to get all our document ids. I have tried many things and always hit the 10k result limit. I understand that "scrolling" may be the solution but have…

---

## [Error: Switching kibana port failed The current kibana port configured in kibana.yml is 80, changing it to 5601 gives an error](https://discuss.elastic.co/t/error-switching-kibana-port-failed-the-current-kibana-port-configured-in-kibana-yml-is-80-changing-it-to-5601-gives-an-error/344516)

<div class="topic-metadata">

**Author:** [@Nghia\_D\_ng](https://discuss.elastic.co/u/Nghia_D_ng)\
**Replies:** 2\
**Last updated:** [October 27, 2023, 9:30pm UTC](https://discuss.elastic.co/t/error-switching-kibana-port-failed-the-current-kibana-port-configured-in-kibana-yml-is-80-changing-it-to-5601-gives-an-error/344516 "2023-10-27T21:30:26Z")

</div>

Sep 27 10:42:13 Kibana kibana\[1250331\]: {"type":"log","@timestamp":"2023-09-27T03:42:13Z","tags":\["error","plugins","reporting","validations"\],"pid":1250331,"message":"The Reporting plugin encountered issues launching Ch…

---

## [Java APM agent crashes JVM Corretto 17 on AWS EB Linux 2023](https://discuss.elastic.co/t/java-apm-agent-crashes-jvm-corretto-17-on-aws-eb-linux-2023/345956)

<div class="topic-metadata">

**Author:** [@Daniele\_Renda](https://discuss.elastic.co/u/Daniele_Renda)\
**Replies:** 0\
**Last updated:** [October 27, 2023, 8:42pm UTC](https://discuss.elastic.co/t/java-apm-agent-crashes-jvm-corretto-17-on-aws-eb-linux-2023/345956 "2023-10-27T20:42:12Z")

</div>

Hi, I hope I'm not wrong posting here this problem. It seems that a recurrent JVM crash that happens lately in our AWS ES cluster depends on ES APM agent. I filed an issue here Probably the bug in on the JVM but I thi…

---

## [Why doesn't elser\_model\_1 generate the Vectors during index?](https://discuss.elastic.co/t/why-doesnt-elser-model-1-generate-the-vectors-during-index/345920)

<div class="topic-metadata">

**Author:** [@mbastarache](https://discuss.elastic.co/u/mbastarache)\
**Replies:** 3\
**Last updated:** [October 27, 2023, 8:29pm UTC](https://discuss.elastic.co/t/why-doesnt-elser-model-1-generate-the-vectors-during-index/345920 "2023-10-27T20:29:46Z")

</div>

No matter what I try, I don't get any errors during indexing, but when I search, the ml\_title and ml\_description fields are not in the results. When I look at the mappings, they are there with the correct configurations…

---

## [Fields option using NEST](https://discuss.elastic.co/t/fields-option-using-nest/345954)

<div class="topic-metadata">

**Author:** [@xef](https://discuss.elastic.co/u/xef)\
**Replies:** 0\
**Last updated:** [October 27, 2023, 8:28pm UTC](https://discuss.elastic.co/t/fields-option-using-nest/345954 "2023-10-27T20:28:23Z")

</div>

When using the Fieds options just to get a selection of fileds using the NEST client library and setting the Source(false), the Hits object's fields property is null. How are we supposed to get access to the values retur…

---

## [How to access the "fields" field in the Elasticsearch query rule](https://discuss.elastic.co/t/how-to-access-the-fields-field-in-the-elasticsearch-query-rule/345951)

<div class="topic-metadata">

**Author:** [@MG989836](https://discuss.elastic.co/u/MG989836)\
**Replies:** 1\
**Last updated:** [October 27, 2023, 8:17pm UTC](https://discuss.elastic.co/t/how-to-access-the-fields-field-in-the-elasticsearch-query-rule/345951 "2023-10-27T20:17:06Z")

</div>

I am using Elastic & Kibana version 8.7.1 I created a runtime\_mappings field called "eventTime". I can see this runtime field and its value in the Kibana Discover page. PUT /logs-parkingInfo/\_mapping { "dynamic": "ru…

---

## [Add Runtime field to change Mapping of a Field](https://discuss.elastic.co/t/add-runtime-field-to-change-mapping-of-a-field/345373)

<div class="topic-metadata">

**Author:** [@Samuele\_Lolli](https://discuss.elastic.co/u/Samuele_Lolli)\
**Replies:** 2\
**Last updated:** [October 27, 2023, 8:17pm UTC](https://discuss.elastic.co/t/add-runtime-field-to-change-mapping-of-a-field/345373 "2023-10-27T20:17:04Z")

</div>

Hi everyone! I need to change the mapping of a current field because is currentry a text field and i need to be a keyword. The field path is event.userDefined.headerId The currentry mapping has some dynamic templates: …

---

## [Filter nested field in aggregation if value isn't indexed or is null](https://discuss.elastic.co/t/filter-nested-field-in-aggregation-if-value-isnt-indexed-or-is-null/345949)

<div class="topic-metadata">

**Author:** [@Raphael\_Fidelis](https://discuss.elastic.co/u/Raphael_Fidelis)\
**Replies:** 0\
**Last updated:** [October 27, 2023, 6:55pm UTC](https://discuss.elastic.co/t/filter-nested-field-in-aggregation-if-value-isnt-indexed-or-is-null/345949 "2023-10-27T18:55:44Z")

</div>

Hello, I have been stuck on an issue regarding my aggregation. I have a mapping similar to as the following: { "product":{ "aliases":{}, "mappings":{ "properties":{ "characteristics…

---

## [Multi match query is not matching numbers](https://discuss.elastic.co/t/multi-match-query-is-not-matching-numbers/344969)

<div class="topic-metadata">

**Author:** [@uma\_parvathy](https://discuss.elastic.co/u/uma_parvathy)\
**Replies:** 1\
**Last updated:** [October 27, 2023, 6:28pm UTC](https://discuss.elastic.co/t/multi-match-query-is-not-matching-numbers/344969 "2023-10-27T18:28:51Z")

</div>

Hi all, My requirement is to get a Elasticsearch response wherever the user typed query matches in the index. ( basically i'm working on search API with elasticsearch). so i've used multi match query with fuzziness aut…

---

## [Data Harmonization](https://discuss.elastic.co/t/data-harmonization/345872)

<div class="topic-metadata">

**Author:** [@aisyaharifin](https://discuss.elastic.co/u/aisyaharifin)\
**Replies:** 1\
**Last updated:** [October 27, 2023, 6:25pm UTC](https://discuss.elastic.co/t/data-harmonization/345872 "2023-10-27T18:25:03Z")

</div>

Hello Elastic, I want to ask do Elastic can do Data Harmonization? It means that it could group multiple data source, that have the same terms of material and group into one Harmonization Code. For instance, below ima…

---

## [Split message in Logstash does not display complete message](https://discuss.elastic.co/t/split-message-in-logstash-does-not-display-complete-message/345936)

<div class="topic-metadata">

**Author:** [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Replies:** 4\
**Last updated:** [October 27, 2023, 5:59pm UTC](https://discuss.elastic.co/t/split-message-in-logstash-does-not-display-complete-message/345936 "2023-10-27T17:59:42Z")

</div>

Hi All, The stdout log of an application is tokenized with a delimiter ~|~. There are a total of 5 delimiters. An excerpt from log is as below: 2023-10-27 11:03:41,294~|~INFO~|~host.com~|~com.controller.LoginControll…

[Previous page](https://discuss.elastic.co/latest.md?page=497)

[Next page](https://discuss.elastic.co/latest.md?page=499)
