# Latest

**URL:** https://discuss.elastic.co/latest.md?page=506

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 507

---

## [Filebeat Grok pattern for access log](https://discuss.elastic.co/t/filebeat-grok-pattern-for-access-log/345455)

<div class="topic-metadata">

**Author:** [@tucker](https://discuss.elastic.co/u/tucker)\
**Replies:** 5\
**Last updated:** [October 20, 2023, 6:52pm UTC](https://discuss.elastic.co/t/filebeat-grok-pattern-for-access-log/345455 "2023-10-20T18:52:15Z")

</div>

Hi, I have an access log for which I am trying to write a Grok pattern but in the filebeat log, I always see "Provided Grok expressions do not match field value:". The log entries look like: \[20/Oct/2023:09:52:33 +000…

---

## [Output syslog plugin \[Unable to load plugin\]](https://discuss.elastic.co/t/output-syslog-plugin-unable-to-load-plugin/344676)

<div class="topic-metadata">

**Author:** [@ans\_k](https://discuss.elastic.co/u/ans_k)\
**Replies:** 5\
**Last updated:** [October 20, 2023, 6:17pm UTC](https://discuss.elastic.co/t/output-syslog-plugin-unable-to-load-plugin/344676 "2023-10-20T18:17:05Z")

</div>

Hello, I followed this documentation : to install offline output syslog plugin in my machine, the plugin is successfully installed, but when i try to call syslog as output in my config file (logstash), i got "Unable …

---

## [DELETE index command returns varying JSON objects](https://discuss.elastic.co/t/delete-index-command-returns-varying-json-objects/345410)

<div class="topic-metadata">

**Author:** [@mrodent](https://discuss.elastic.co/u/mrodent)\
**Replies:** 1\
**Last updated:** [October 20, 2023, 6:03pm UTC](https://discuss.elastic.co/t/delete-index-command-returns-varying-json-objects/345410 "2023-10-20T18:03:02Z")

</div>

(ES 8.6.2, W10) In Insomnia, when I try to delete an non-existent index, using command DELETE and url https://localhost:9500/my\_test\_index, I always seem to get a JSON object like this: { "error": { "root\_cause": \[ …

---

## [Background Count (bg\_count) Remains Zero in Nested and Filtered significant\_terms Aggregation](https://discuss.elastic.co/t/background-count-bg-count-remains-zero-in-nested-and-filtered-significant-terms-aggregation/345413)

<div class="topic-metadata">

**Author:** [@Emporea](https://discuss.elastic.co/u/Emporea)\
**Replies:** 2\
**Last updated:** [October 20, 2023, 3:38pm UTC](https://discuss.elastic.co/t/background-count-bg-count-remains-zero-in-nested-and-filtered-significant-terms-aggregation/345413 "2023-10-20T15:38:20Z")

</div>

Hi everyone, I've recently started using the significant\_terms aggregation with a nested field in my index, and I've noticed that the results are very similar to those of a standard terms aggregation. This leads me to b…

---

## [Recuperer puis indexer des donnees via une api via logstash](https://discuss.elastic.co/t/recuperer-puis-indexer-des-donnees-via-une-api-via-logstash/345474)

<div class="topic-metadata">

**Author:** [@Phildefer](https://discuss.elastic.co/u/Phildefer)\
**Replies:** 0\
**Last updated:** [October 20, 2023, 3:37pm UTC](https://discuss.elastic.co/t/recuperer-puis-indexer-des-donnees-via-une-api-via-logstash/345474 "2023-10-20T15:37:42Z")

</div>

Bonjour, Je cherche à automatiser la récupération régulière (toutes les semaines) de données via une API. Les requêtes se présentent sous cette forme : V https://api.acleddata.com/{data}/{command}.csv Elles permetten…

---

## [An error occurred during rule execution: message: "Current rule execution has exceeded its allotted interval (5m) and has been stopped](https://discuss.elastic.co/t/an-error-occurred-during-rule-execution-message-current-rule-execution-has-exceeded-its-allotted-interval-5m-and-has-been-stopped/345434)

<div class="topic-metadata">

**Author:** [@galuh\_tirta](https://discuss.elastic.co/u/galuh_tirta)\
**Replies:** 1\
**Last updated:** [October 20, 2023, 2:57pm UTC](https://discuss.elastic.co/t/an-error-occurred-during-rule-execution-message-current-rule-execution-has-exceeded-its-allotted-interval-5m-and-has-been-stopped/345434 "2023-10-20T14:57:23Z")

</div>

hai everyone , what should i do to fix this An error occurred during rule execution: message: "Current rule execution has exceeded its allotted interval (5m) and has been stopped

---

## [Installing Logstash plugin while service is running](https://discuss.elastic.co/t/installing-logstash-plugin-while-service-is-running/345469)

<div class="topic-metadata">

**Author:** [@Samuele\_Lolli](https://discuss.elastic.co/u/Samuele_Lolli)\
**Replies:** 2\
**Last updated:** [October 20, 2023, 2:34pm UTC](https://discuss.elastic.co/t/installing-logstash-plugin-while-service-is-running/345469 "2023-10-20T14:34:14Z")

</div>

Hi everyone, just one quick question. I have on a linux server logstash running with systemctl. I need to try some new pipelines but i need to add a plugin. I can add a new plugin while the service is running? The plug…

---

## [Cannot generate enrollment token](https://discuss.elastic.co/t/cannot-generate-enrollment-token/345465)

<div class="topic-metadata">

**Author:** [@Diego667](https://discuss.elastic.co/u/Diego667)\
**Replies:** 1\
**Last updated:** [October 20, 2023, 2:25pm UTC](https://discuss.elastic.co/t/cannot-generate-enrollment-token/345465 "2023-10-20T14:25:03Z")

</div>

Hello, I'm using ELK 8.10. I have a working cluster composed by : 1 master + data node 1 data node Security layer has been configured manually using those documentation : TLS/SSL HTTP I did not entered any …

---

## [Java API for terms](https://discuss.elastic.co/t/java-api-for-terms/345461)

<div class="topic-metadata">

**Author:** [@mfrob](https://discuss.elastic.co/u/mfrob)\
**Replies:** 2\
**Last updated:** [October 20, 2023, 1:34pm UTC](https://discuss.elastic.co/t/java-api-for-terms/345461 "2023-10-20T13:34:02Z")

</div>

Hi, I hope someone finds this. I am very new to elasticsearch. Currently I have this code snippet in my java file to search based on customer identification card (IC) number. I am able to fetch and search based off just…

---

## [Use Environment Variables from Kubernetes Pod in Elastic Synthetics](https://discuss.elastic.co/t/use-environment-variables-from-kubernetes-pod-in-elastic-synthetics/345396)

<div class="topic-metadata">

**Author:** [@DougR](https://discuss.elastic.co/u/DougR)\
**Replies:** 9\
**Last updated:** [October 20, 2023, 1:27pm UTC](https://discuss.elastic.co/t/use-environment-variables-from-kubernetes-pod-in-elastic-synthetics/345396 "2023-10-20T13:27:28Z")

</div>

TL;DR Can I use local environment variables from my execution environment in my synthetics journeys (e.g., from the Kubernetes pod where the test runs), and if so, how? The Long Version I am using @elastic/synthetics-1.…

---

## [Elastic APM server Elastic search connection not able to establish](https://discuss.elastic.co/t/elastic-apm-server-elastic-search-connection-not-able-to-establish/345459)

<div class="topic-metadata">

**Author:** [@Rajat\_Gupta1](https://discuss.elastic.co/u/Rajat_Gupta1)\
**Replies:** 0\
**Last updated:** [October 20, 2023, 12:34pm UTC](https://discuss.elastic.co/t/elastic-apm-server-elastic-search-connection-not-able-to-establish/345459 "2023-10-20T12:34:21Z")

</div>

Hi All need Some help with existing elastic stack.I have used official helm charts for deployment of the elastic stack I have apm-server Elastic Search and Kibana to be deployed When I try to get health of Elastics…

---

## [How to change or replace the SSL Certificate used by Fleet Server](https://discuss.elastic.co/t/how-to-change-or-replace-the-ssl-certificate-used-by-fleet-server/344930)

<div class="topic-metadata">

**Author:** [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Replies:** 6\
**Last updated:** [October 20, 2023, 12:06pm UTC](https://discuss.elastic.co/t/how-to-change-or-replace-the-ssl-certificate-used-by-fleet-server/344930 "2023-10-20T12:06:57Z")

</div>

Hello, I'm looking for the steps that need to be done to change or replace the SSL Certificate for a existing Fleet Server and I could not find anything in the documentation. All documentation that I found is about how…

---

## [Managing Real-time and Batch Processing in Elasticsearch to Prevent Document Resurrection](https://discuss.elastic.co/t/managing-real-time-and-batch-processing-in-elasticsearch-to-prevent-document-resurrection/345452)

<div class="topic-metadata">

**Author:** [@taichi](https://discuss.elastic.co/u/taichi)\
**Replies:** 0\
**Last updated:** [October 20, 2023, 10:17am UTC](https://discuss.elastic.co/t/managing-real-time-and-batch-processing-in-elasticsearch-to-prevent-document-resurrection/345452 "2023-10-20T10:17:41Z")

</div>

Hello, I'm facing a challenge and need your expertise. In our system, we have a real-time process that adds or removes documents in an Elasticsearch index based on changes in an RDBMS. Alongside, we also have a batch pr…

---

## [Cloudflare logpush to http elastic agent](https://discuss.elastic.co/t/cloudflare-logpush-to-http-elastic-agent/344383)

<div class="topic-metadata">

**Author:** [@gyterpena](https://discuss.elastic.co/u/gyterpena)\
**Replies:** 1\
**Last updated:** [October 20, 2023, 9:44am UTC](https://discuss.elastic.co/t/cloudflare-logpush-to-http-elastic-agent/344383 "2023-10-20T09:44:03Z")

</div>

Hello I'm trying to set up logpush integration with CF. I have set up elastic agent per documentation and I'm trying to enable logpush on CF by API but I'm getting {"errors":\[{"code":1002,"message":"error validatin…

---

## [After Spring boot upgrade to 3.0.6 cannot see trace of requests in Transaction section in Kibana](https://discuss.elastic.co/t/after-spring-boot-upgrade-to-3-0-6-cannot-see-trace-of-requests-in-transaction-section-in-kibana/345123)

<div class="topic-metadata">

**Author:** [@anthonyvks](https://discuss.elastic.co/u/anthonyvks)\
**Replies:** 2\
**Last updated:** [October 20, 2023, 8:51am UTC](https://discuss.elastic.co/t/after-spring-boot-upgrade-to-3-0-6-cannot-see-trace-of-requests-in-transaction-section-in-kibana/345123 "2023-10-20T08:51:41Z")

</div>

After Spring boot upgrade to 3.0.6 cannot see trace of requests in Transaction section in Kibana. Before upgrading the Java Spring boot application to 3.0.6 and upgrading the Java to 17, the traces of requests was seen …

---

## [Are comments supported in the synonyms file?](https://discuss.elastic.co/t/are-comments-supported-in-the-synonyms-file/345442)

<div class="topic-metadata">

**Author:** [@peterge1998](https://discuss.elastic.co/u/peterge1998)\
**Replies:** 1\
**Last updated:** [October 20, 2023, 8:08am UTC](https://discuss.elastic.co/t/are-comments-supported-in-the-synonyms-file/345442 "2023-10-20T08:08:32Z")

</div>

We set up a new way to deploy the synonyms file to our elasticsearch hosts in our company using gitlab ci cd and ansible. Now we would like to include a comment into the synonyms file, some this like "Ansible managed, ed…

---

## [Is Elastic	Winlogbeat MSI still beta version?](https://discuss.elastic.co/t/is-elastic-winlogbeat-msi-still-beta-version/345437)

<div class="topic-metadata">

**Author:** [@Metaad](https://discuss.elastic.co/u/Metaad)\
**Replies:** 1\
**Last updated:** [October 20, 2023, 7:01am UTC](https://discuss.elastic.co/t/is-elastic-winlogbeat-msi-still-beta-version/345437 "2023-10-20T07:01:15Z")

</div>

Am downloading ElasticWinlogbeat from Download Winlogbeat | Ship Windows Event Logs | Elastic | Elastic The name of the .msi shows beta. Can anyone please confirm if its still version or just the name itself is beta. A…

---

## [Deleting Events From Frozen Data Tier](https://discuss.elastic.co/t/deleting-events-from-frozen-data-tier/345395)

<div class="topic-metadata">

**Author:** [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Replies:** 3\
**Last updated:** [October 20, 2023, 6:50am UTC](https://discuss.elastic.co/t/deleting-events-from-frozen-data-tier/345395 "2023-10-20T06:50:17Z")

</div>

Attempting to delete by query events in a frozen data tier index belonging to a data stream. I've tried targeting the specific index the events are in as well as the datastream name, but I get the following error: { …

---

## [Elasticsearch is processing incoming events/messages from Logstash in a non-sequential order](https://discuss.elastic.co/t/elasticsearch-is-processing-incoming-events-messages-from-logstash-in-a-non-sequential-order/345295)

<div class="topic-metadata">

**Author:** [@Aman\_Yadav1](https://discuss.elastic.co/u/Aman_Yadav1)\
**Replies:** 3\
**Last updated:** [October 20, 2023, 6:44am UTC](https://discuss.elastic.co/t/elasticsearch-is-processing-incoming-events-messages-from-logstash-in-a-non-sequential-order/345295 "2023-10-20T06:44:27Z")

</div>

We have a system that synchronises data from MongoDB to Elasticsearch . Here are the key components: MongoDB Source Connector: This component reads events from the MongoDB oplog and produces messages on a Kafka topic. L…

---

## [Error json parsing opensearch logs with logstash](https://discuss.elastic.co/t/error-json-parsing-opensearch-logs-with-logstash/345398)

<div class="topic-metadata">

**Author:** [@Xhar](https://discuss.elastic.co/u/Xhar)\
**Replies:** 3\
**Last updated:** [October 20, 2023, 6:44am UTC](https://discuss.elastic.co/t/error-json-parsing-opensearch-logs-with-logstash/345398 "2023-10-20T06:44:21Z")

</div>

Hello, i'm trying to parse suricata, logstash and opensearch logs with dictionary filter, here's part of my config input { file { path =\> "/opt/logs/opensearchTest/opensearch\_server.json" codec =\> "json" t…

---

## [What happens if index.store.type set as niofs when create index and change to default](https://discuss.elastic.co/t/what-happens-if-index-store-type-set-as-niofs-when-create-index-and-change-to-default/345427)

<div class="topic-metadata">

**Author:** [@jonathanjxsq](https://discuss.elastic.co/u/jonathanjxsq)\
**Replies:** 0\
**Last updated:** [October 20, 2023, 3:23am UTC](https://discuss.elastic.co/t/what-happens-if-index-store-type-set-as-niofs-when-create-index-and-change-to-default/345427 "2023-10-20T03:23:07Z")

</div>

I created index with index.store type as niofs. if I change the config to default, which type the system is really running with? Based on my test, it seems the system changed from niofs to default. I saw performance ben…

---

## [Shard numbers no longer equal (not even close) among cluster nodes](https://discuss.elastic.co/t/shard-numbers-no-longer-equal-not-even-close-among-cluster-nodes/345342)

<div class="topic-metadata">

**Author:** [@Hao\_Yellow](https://discuss.elastic.co/u/Hao_Yellow)\
**Replies:** 6\
**Last updated:** [October 20, 2023, 1:58am UTC](https://discuss.elastic.co/t/shard-numbers-no-longer-equal-not-even-close-among-cluster-nodes/345342 "2023-10-20T01:58:34Z")

</div>

Hello, I've been recently upgraded an Elasticsearch cluster, with 5 nodes, from version 7.3 to 7.17 then 8.9. As always, I've never disabled shard allocation and rebalancing, so until 7.17 it's observed, and as I unders…

---

## [How can i increment cursor by one for each run in httpjson](https://discuss.elastic.co/t/how-can-i-increment-cursor-by-one-for-each-run-in-httpjson/345421)

<div class="topic-metadata">

**Author:** [@German\_Bravo](https://discuss.elastic.co/u/German_Bravo)\
**Replies:** 0\
**Last updated:** [October 19, 2023, 10:16pm UTC](https://discuss.elastic.co/t/how-can-i-increment-cursor-by-one-for-each-run-in-httpjson/345421 "2023-10-19T22:16:54Z")

</div>

Hi im using the httpjson input module in filebeat and im trying to achieve the following without any luck In words: I need to fetch an API every 10s In the first run i need to set query param page = 0 In the following…

---

## [Sysmon/Sysmon64 not visible in metricbeats for sysmon version 15](https://discuss.elastic.co/t/sysmon-sysmon64-not-visible-in-metricbeats-for-sysmon-version-15/345308)

<div class="topic-metadata">

**Author:** [@shani\_angarkadu](https://discuss.elastic.co/u/shani_angarkadu)\
**Replies:** 5\
**Last updated:** [October 19, 2023, 8:29pm UTC](https://discuss.elastic.co/t/sysmon-sysmon64-not-visible-in-metricbeats-for-sysmon-version-15/345308 "2023-10-19T20:29:36Z")

</div>

Hi there, We are using the system module and metricsets process. I can see all the other CPU/memory metrics except the Sysmon. Sysmon is completely missing in the output. Here is my system.yml - module: system per…

---

## [Elasticsearch is returning less than the top K matches for a vector search](https://discuss.elastic.co/t/elasticsearch-is-returning-less-than-the-top-k-matches-for-a-vector-search/345207)

<div class="topic-metadata">

**Author:** [@sbruinsje](https://discuss.elastic.co/u/sbruinsje)\
**Replies:** 3\
**Last updated:** [October 19, 2023, 8:19pm UTC](https://discuss.elastic.co/t/elasticsearch-is-returning-less-than-the-top-k-matches-for-a-vector-search/345207 "2023-10-19T20:19:40Z")

</div>

I have a problem where elasticsearch doesn't return k matches for a knn search. It used to work before so I think something has changed between version 8.8.3 to 8.10.3. Perhaps a minimum score? I could not find it in the…

---

## [Elasticsearch process ended by code 137](https://discuss.elastic.co/t/elasticsearch-process-ended-by-code-137/345399)

<div class="topic-metadata">

**Author:** [@gustavoluza](https://discuss.elastic.co/u/gustavoluza)\
**Replies:** 7\
**Last updated:** [October 19, 2023, 7:09pm UTC](https://discuss.elastic.co/t/elasticsearch-process-ended-by-code-137/345399 "2023-10-19T19:09:10Z")

</div>

Hi, When checking the error message for the termination of the Elasticsearch process, it was indicating that the process was terminated due to error 137, when consulting I saw that it indicates excessive memory consumpt…

---

## [Connector Configuration](https://discuss.elastic.co/t/connector-configuration/345306)

<div class="topic-metadata">

**Author:** [@aisyaharifin](https://discuss.elastic.co/u/aisyaharifin)\
**Replies:** 1\
**Last updated:** [October 19, 2023, 6:39pm UTC](https://discuss.elastic.co/t/connector-configuration/345306 "2023-10-19T18:39:52Z")

</div>

Hi Elastic, I've been exploring the Connectors available in version 8.10 and have encountered a few questions regarding their configuration. After some exploration, it appears that there are different approaches for se…

---

## [Cluster to ingest 7TB of data daily](https://discuss.elastic.co/t/cluster-to-ingest-7tb-of-data-daily/345412)

<div class="topic-metadata">

**Author:** [@kaismax](https://discuss.elastic.co/u/kaismax)\
**Replies:** 1\
**Last updated:** [October 19, 2023, 6:41pm UTC](https://discuss.elastic.co/t/cluster-to-ingest-7tb-of-data-daily/345412 "2023-10-19T18:41:19Z")

</div>

The task at hand is to build a cluster that can ingest 7 terabytes daily, and Hold the data for 7 days in Hot phase, and 83 days in Cold phase, What is the best recommendation in a huge elasticsearch cluster? How many…

---

## [Elastic agent offline after upgrade from Fleet](https://discuss.elastic.co/t/elastic-agent-offline-after-upgrade-from-fleet/344973)

<div class="topic-metadata">

**Author:** [@DaddyYusk](https://discuss.elastic.co/u/DaddyYusk)\
**Replies:** 15\
**Last updated:** [October 19, 2023, 6:22pm UTC](https://discuss.elastic.co/t/elastic-agent-offline-after-upgrade-from-fleet/344973 "2023-10-19T18:22:20Z")

</div>

Hi, Because of the last vulnerabilities from this week affecting Elastic Suite, I've made an upgrade from 8.8.0 to 8.10.3 of all my Elastic Agent from Fleet. Now all the agents are Offline (and displaying the version a…

---

## [Question about how to proceed with the development of a metrics module for an integration](https://discuss.elastic.co/t/question-about-how-to-proceed-with-the-development-of-a-metrics-module-for-an-integration/345409)

<div class="topic-metadata">

**Author:** [@Sebastian\_Huettersen](https://discuss.elastic.co/u/Sebastian_Huettersen)\
**Replies:** 0\
**Last updated:** [October 19, 2023, 5:40pm UTC](https://discuss.elastic.co/t/question-about-how-to-proceed-with-the-development-of-a-metrics-module-for-an-integration/345409 "2023-10-19T17:40:48Z")

</div>

Hey everyone currently I am developing an Elastic Integration for openVPN. The normalization of the logs is no problem for me. But now I would like to have metrics as well and of course they should be nicely visualized i…

[Previous page](https://discuss.elastic.co/latest.md?page=505)

[Next page](https://discuss.elastic.co/latest.md?page=507)
