# Latest

**URL:** https://discuss.elastic.co/latest.md?page=517

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 518

---

## [Elasticsearch 7.17 index with alias - granting privileges best practice](https://discuss.elastic.co/t/elasticsearch-7-17-index-with-alias-granting-privileges-best-practice/344721)

<div class="topic-metadata">

**Author:** [@zvonimir](https://discuss.elastic.co/u/zvonimir)\
**Replies:** 0\
**Last updated:** [October 10, 2023, 9:35am UTC](https://discuss.elastic.co/t/elasticsearch-7-17-index-with-alias-granting-privileges-best-practice/344721 "2023-10-10T09:35:11Z")

</div>

Hi. What would be best practice for granting read security privileges on index with alias on Elasticsearch 7.17? Granting read privilege only on alias is deprecated but granting read privilege only on index isn't workin…

---

## [The problem when create HTTPS for elasticsearch](https://discuss.elastic.co/t/the-problem-when-create-https-for-elasticsearch/344708)

<div class="topic-metadata">

**Author:** [@Tai\_Nguyen\_Huu](https://discuss.elastic.co/u/Tai_Nguyen_Huu)\
**Replies:** 1\
**Last updated:** [October 10, 2023, 8:37am UTC](https://discuss.elastic.co/t/the-problem-when-create-https-for-elasticsearch/344708 "2023-10-10T08:37:25Z")

</div>

Hi guys, I am having the problem with setup HTTPS for elasticsearch stack. I created certifacate with private key with one certificate for every node with command elasticsearch-certutil http I am understanding that. I…

---

## [Whenever I restore from snapshot, I got Authentication Problem](https://discuss.elastic.co/t/whenever-i-restore-from-snapshot-i-got-authentication-problem/344707)

<div class="topic-metadata">

**Author:** [@Faker](https://discuss.elastic.co/u/Faker)\
**Replies:** 0\
**Last updated:** [October 10, 2023, 8:09am UTC](https://discuss.elastic.co/t/whenever-i-restore-from-snapshot-i-got-authentication-problem/344707 "2023-10-10T08:09:30Z")

</div>

Hello, thank you in advance. I'm trying to migrate my entire data from one ES to another ES. whenever i try to restore from snapshot, I am restoring an entire cluster so I followed instructions below. Restore an entir…

---

## [OIDC configuration - Role mapping](https://discuss.elastic.co/t/oidc-configuration-role-mapping/344705)

<div class="topic-metadata">

**Author:** [@Sherwin\_R](https://discuss.elastic.co/u/Sherwin_R)\
**Replies:** 0\
**Last updated:** [October 10, 2023, 7:59am UTC](https://discuss.elastic.co/t/oidc-configuration-role-mapping/344705 "2023-10-10T07:59:00Z")

</div>

I am trying to configure OIDC for signing into kibana. My OP provides a claim token after a successful authentication from which I am trying to map the value of a field called "roles" to kibana user roles. According to …

---

## [Unable to start elastic search -bound or publishing to a non-loopback address, enforcing bootstrap checks ERROR: \[1\] bootstrap checks failed \[1\]: max file descriptors \[4096\] for elasticsearch process is too low, increase to at least \[65535\]](https://discuss.elastic.co/t/unable-to-start-elastic-search-bound-or-publishing-to-a-non-loopback-address-enforcing-bootstrap-checks-error-1-bootstrap-checks-failed-1-max-file-descriptors-4096-for-elasticsearch-process-is-too-low-increase-to-at-least-65535/344696)

<div class="topic-metadata">

**Author:** [@ramyanamala013](https://discuss.elastic.co/u/ramyanamala013)\
**Replies:** 3\
**Last updated:** [October 10, 2023, 7:34am UTC](https://discuss.elastic.co/t/unable-to-start-elastic-search-bound-or-publishing-to-a-non-loopback-address-enforcing-bootstrap-checks-error-1-bootstrap-checks-failed-1-max-file-descriptors-4096-for-elasticsearch-process-is-too-low-increase-to-at-least-65535/344696 "2023-10-10T07:34:34Z")

</div>

Dear all, while starting Elasticsearch i'm getting below error please help \[2023-10-10T07:27:32,014\]\[INFO \]\[o.e.x.s.a.s.FileRolesStore\] \[visitor-es-node-1\] parsed \[0\] roles from file \[/opt/MBRL/Elastic/elasticsearch-6.…

---

## [Handle Error While upload csv file to Elasticsearch](https://discuss.elastic.co/t/handle-error-while-upload-csv-file-to-elasticsearch/344701)

<div class="topic-metadata">

**Author:** [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Replies:** 0\
**Last updated:** [October 10, 2023, 7:08am UTC](https://discuss.elastic.co/t/handle-error-while-upload-csv-file-to-elasticsearch/344701 "2023-10-10T07:08:44Z")

</div>

Hi Team, While uploading csv files to Elasticsearch through filebeat how to handle the records which are not processed. For Example the csv file contain 200 records and due to some reason 20 records not processed. So i…

---

## [Is there a way to add a custom tag to a Rally race?](https://discuss.elastic.co/t/is-there-a-way-to-add-a-custom-tag-to-a-rally-race/344134)

<div class="topic-metadata">

**Author:** [@rschirin](https://discuss.elastic.co/u/rschirin)\
**Replies:** 1\
**Last updated:** [October 10, 2023, 6:56am UTC](https://discuss.elastic.co/t/is-there-a-way-to-add-a-custom-tag-to-a-rally-race/344134 "2023-10-10T06:56:35Z")

</div>

Hey there, I was trying to use Rally to benchmark my clusters. Is there a way to add a tag to the race? I have a custom track and I want to modify only the races not the track.

---

## [EUI Simple navigation with Side Nav](https://discuss.elastic.co/t/eui-simple-navigation-with-side-nav/343141)

<div class="topic-metadata">

**Author:** [@tmp13](https://discuss.elastic.co/u/tmp13)\
**Replies:** 2\
**Last updated:** [October 10, 2023, 5:58am UTC](https://discuss.elastic.co/t/eui-simple-navigation-with-side-nav/343141 "2023-10-10T05:58:18Z")

</div>

Hi there. I have some question about Elastic UI. I try create simple form with some navigation Can i get some examples of usage Side Nav with change EuiPageBody? Something like when i switch betweeen config Users an…

---

## [Index doesn't show up in the dashboard although the status of the index is green](https://discuss.elastic.co/t/index-doesnt-show-up-in-the-dashboard-although-the-status-of-the-index-is-green/344604)

<div class="topic-metadata">

**Author:** [@Manula\_Manjitha](https://discuss.elastic.co/u/Manula_Manjitha)\
**Replies:** 4\
**Last updated:** [October 10, 2023, 5:02am UTC](https://discuss.elastic.co/t/index-doesnt-show-up-in-the-dashboard-although-the-status-of-the-index-is-green/344604 "2023-10-10T05:02:07Z")

</div>

I have setup a filebeat input as follows to read the logs from an application that we are running on the server. The name of the input is the filebeat-2023.10.277. filebeat.inputs: - type: log id: gateway-elk enabl…

---

## [Is @timestamp get value automatically from field timestamp?](https://discuss.elastic.co/t/is-timestamp-get-value-automatically-from-field-timestamp/343952)

<div class="topic-metadata">

**Author:** [@waitspring](https://discuss.elastic.co/u/waitspring)\
**Replies:** 4\
**Last updated:** [October 10, 2023, 3:16am UTC](https://discuss.elastic.co/t/is-timestamp-get-value-automatically-from-field-timestamp/343952 "2023-10-10T03:16:45Z")

</div>

When we use this configure: filter { grok { match =\> { "message" =\> \[ "(?\<timestamp\>%{YEAR}-%{MONTHNUM}-%{MONTHDAY} %{HOUR}:%{MINUTE}:%{SECOND}\\.\\d{3}) %{LOGLEVEL:level} \\\[%{DAT…

---

## [Ilm policy errors for indices](https://discuss.elastic.co/t/ilm-policy-errors-for-indices/344694)

<div class="topic-metadata">

**Author:** [@shailendra1](https://discuss.elastic.co/u/shailendra1)\
**Replies:** 0\
**Last updated:** [October 10, 2023, 2:40am UTC](https://discuss.elastic.co/t/ilm-policy-errors-for-indices/344694 "2023-10-10T02:40:58Z")

</div>

Hi All, duing the setup of my ILM policy for the indices , i am facing the errors illegal\_argument\_exception: setting \[index.lifecycle.rollover\_alias\] for index \[csec\_uat.test\] is empty or not defined. even after i h…

---

## [Date format increasing doesn't work](https://discuss.elastic.co/t/date-format-increasing-doesnt-work/343818)

<div class="topic-metadata">

**Author:** [@20wjsdudtj](https://discuss.elastic.co/u/20wjsdudtj)\
**Replies:** 1\
**Last updated:** [October 10, 2023, 12:48am UTC](https://discuss.elastic.co/t/date-format-increasing-doesnt-work/343818 "2023-10-10T00:48:03Z")

</div>

After assigning my ILM policy as follows: PUT /\_ilm/policy/my\_policy { "policy": { "phases": { "hot": { "actions": { "rollover": { "max\_size": "50gb", "max\_age": "30…

---

## [Path.repo is not being updated by elasticsearch.yml file](https://discuss.elastic.co/t/path-repo-is-not-being-updated-by-elasticsearch-yml-file/344441)

<div class="topic-metadata">

**Author:** [@Faker](https://discuss.elastic.co/u/Faker)\
**Replies:** 4\
**Last updated:** [October 10, 2023, 12:29am UTC](https://discuss.elastic.co/t/path-repo-is-not-being-updated-by-elasticsearch-yml-file/344441 "2023-10-10T00:29:57Z")

</div>

Hi, I'd like to thank you in advance for your reply. i am going through hard tasks. our team use ES 7.13.12 and wants to migrate (& upgrade) to docker ELK 8.10.2 according to ES document, i should go through 7.17.13 b…

---

## [What's the relationship between clients and CPU cores?](https://discuss.elastic.co/t/whats-the-relationship-between-clients-and-cpu-cores/344588)

<div class="topic-metadata">

**Author:** [@Dhineshkumar\_R](https://discuss.elastic.co/u/Dhineshkumar_R)\
**Replies:** 3\
**Last updated:** [October 9, 2023, 11:02pm UTC](https://discuss.elastic.co/t/whats-the-relationship-between-clients-and-cpu-cores/344588 "2023-10-09T23:02:15Z")

</div>

Hi Folks, I found that rally uses Actor model to generate load under the hood. From the documentation, I understand that target throughput is achieved with all clients together. However, I do not understand the way numb…

---

## [Documentation on in\_event and expect in Ruby filter test framework?](https://discuss.elastic.co/t/documentation-on-in-event-and-expect-in-ruby-filter-test-framework/344551)

<div class="topic-metadata">

**Author:** [@paolovalladolid](https://discuss.elastic.co/u/paolovalladolid)\
**Replies:** 6\
**Last updated:** [October 9, 2023, 9:32pm UTC](https://discuss.elastic.co/t/documentation-on-in-event-and-expect-in-ruby-filter-test-framework/344551 "2023-10-09T21:32:07Z")

</div>

I started working on a Ruby script to be called from my Logstash ruby filter. The official documentation mentions a test framework here There is an example test provided test "drop percentage 100%" do parameters do …

---

## [Elasticearch version\[8.6.2\] initialization error](https://discuss.elastic.co/t/elasticearch-version-8-6-2-initialization-error/344643)

<div class="topic-metadata">

**Author:** [@Daniel\_Schneider](https://discuss.elastic.co/u/Daniel_Schneider)\
**Replies:** 8\
**Last updated:** [October 9, 2023, 8:21pm UTC](https://discuss.elastic.co/t/elasticearch-version-8-6-2-initialization-error/344643 "2023-10-09T20:21:53Z")

</div>

Hi, When I'm trying to launch Elasticsearch server v 8.6.2 it fails with following error: \[2023-10-09T13:45:34,090\]\[INFO \]\[o.e.n.Node \] \[DANIELS-HRLP\] version\[8.6.2\], pid\[2188\], build\[zip/2d58d0f136141f03…

---

## [Generative AI for Search](https://discuss.elastic.co/t/generative-ai-for-search/344675)

<div class="topic-metadata">

**Author:** [@sivagurlinka](https://discuss.elastic.co/u/sivagurlinka)\
**Replies:** 2\
**Last updated:** [October 9, 2023, 7:31pm UTC](https://discuss.elastic.co/t/generative-ai-for-search/344675 "2023-10-09T19:31:28Z")

</div>

Hi, We are trying to understand Generative AI features/capabilities Elastic can offer. We are working on a semantic search use cases where we are aware of ELSER and Third party dense vector models. We would like to kno…

---

## [Elastic KNN search questions](https://discuss.elastic.co/t/elastic-knn-search-questions/344684)

<div class="topic-metadata">

**Author:** [@AdarshPrabhakara](https://discuss.elastic.co/u/AdarshPrabhakara)\
**Replies:** 2\
**Last updated:** [October 9, 2023, 7:14pm UTC](https://discuss.elastic.co/t/elastic-knn-search-questions/344684 "2023-10-09T19:14:12Z")

</div>

I am looking into using Elastic KNN search feature and from what I see this is how we query ES for KNN search. GET my-index/\_knn\_search { "knn": { "field": "image\_vector", "query\_vector": \[0.3, 0.1, 1.2\], …

---

## [Kibana not available after license expiration](https://discuss.elastic.co/t/kibana-not-available-after-license-expiration/344641)

<div class="topic-metadata">

**Author:** [@Andy0708](https://discuss.elastic.co/u/Andy0708)\
**Replies:** 4\
**Last updated:** [October 9, 2023, 7:12pm UTC](https://discuss.elastic.co/t/kibana-not-available-after-license-expiration/344641 "2023-10-09T19:12:00Z")

</div>

Hi, Within Kibana, I activated a 30 day trial license. To my surprise, I was "locked out" of Kibana when it expired, getting the "Kibana server is not ready yet" message. Kibana outputs the following: \[INFO \]\[savedobje…

---

## [Unable to start elastic search in linux server](https://discuss.elastic.co/t/unable-to-start-elastic-search-in-linux-server/344681)

<div class="topic-metadata">

**Author:** [@ramyanamala013](https://discuss.elastic.co/u/ramyanamala013)\
**Replies:** 1\
**Last updated:** [October 9, 2023, 6:06pm UTC](https://discuss.elastic.co/t/unable-to-start-elastic-search-in-linux-server/344681 "2023-10-09T18:06:47Z")

</div>

Unable to start Elasticsearch in linux server, kindly help Exception in thread "main" java.nio.file.AccessDeniedException: /opt/MBRL/Elastic/elasticsearch-6.5.0/config/jvm.options at sun.nio.fs.UnixException.translateT…

---

## [Troubleshoot Elastic Endpoint Unhealthy](https://discuss.elastic.co/t/troubleshoot-elastic-endpoint-unhealthy/344540)

<div class="topic-metadata">

**Author:** [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Replies:** 4\
**Last updated:** [October 9, 2023, 2:41pm UTC](https://discuss.elastic.co/t/troubleshoot-elastic-endpoint-unhealthy/344540 "2023-10-09T14:41:00Z")

</div>

Hello, We are doing a PoC with the Elastic Agent and one of our agent host in this scenario became UNHEALTHY after an upgrade. We have the following ingestion flow: Elastic Agent -\> HAProxy (passthrough) -\> Logstash -\>…

---

## [API Key Minimum Permissions for Querying Kibana Fleet Agents](https://discuss.elastic.co/t/api-key-minimum-permissions-for-querying-kibana-fleet-agents/344093)

<div class="topic-metadata">

**Author:** [@groth](https://discuss.elastic.co/u/groth)\
**Replies:** 2\
**Last updated:** [October 9, 2023, 4:09pm UTC](https://discuss.elastic.co/t/api-key-minimum-permissions-for-querying-kibana-fleet-agents/344093 "2023-10-09T16:09:31Z")

</div>

I'm on Elastic Cloud 8.9.1 using the Kibana Fleet APIs to pull agent information. In trying to figure out the minimum permissions needed for /api/fleet/agents, I have created a user account with a custom role with permis…

---

## [Filter records having count =0 in aggregation](https://discuss.elastic.co/t/filter-records-having-count-0-in-aggregation/344679)

<div class="topic-metadata">

**Author:** [@star42](https://discuss.elastic.co/u/star42)\
**Replies:** 0\
**Last updated:** [October 9, 2023, 3:24pm UTC](https://discuss.elastic.co/t/filter-records-having-count-0-in-aggregation/344679 "2023-10-09T15:24:30Z")

</div>

Hi, I have a requirement to fetch categories having zero count Query : GET /category-sale-\*/\_search?size=100&filter\_path=aggregations { "query": { "bool": { "filter": { "bool": { "must\_not": \[ { "bool": { "sh…

---

## [Auto profiler instrumentation is not working](https://discuss.elastic.co/t/auto-profiler-instrumentation-is-not-working/344672)

<div class="topic-metadata">

**Author:** [@Samiullah\_Shah](https://discuss.elastic.co/u/Samiullah_Shah)\
**Replies:** 0\
**Last updated:** [October 9, 2023, 2:15pm UTC](https://discuss.elastic.co/t/auto-profiler-instrumentation-is-not-working/344672 "2023-10-09T14:15:48Z")

</div>

Hi everyone, I have been using stand alone dotnet agent which working perfectly. I now i was trying to use third party tool dotnet auto instrumentation i followed the mentioned steps but my application is not sending …

---

## [How to parse multiple nested arrays](https://discuss.elastic.co/t/how-to-parse-multiple-nested-arrays/344671)

<div class="topic-metadata">

**Author:** [@Ankita\_Pachauri](https://discuss.elastic.co/u/Ankita_Pachauri)\
**Replies:** 0\
**Last updated:** [October 9, 2023, 2:14pm UTC](https://discuss.elastic.co/t/how-to-parse-multiple-nested-arrays/344671 "2023-10-09T14:14:05Z")

</div>

Hello everyone, I am trying to parse a json document using logstash version 8.3.3. The json document has multiple nested arrays, to flatten the document split is being used inside the filter. The issue is that the split…

---

## [create netflow filters in kibana dashboard](https://discuss.elastic.co/t/create-netflow-filters-in-kibana-dashboard/344666)

<div class="topic-metadata">

**Author:** [@Franciscofabion\_Nasc](https://discuss.elastic.co/u/Franciscofabion_Nasc)\
**Replies:** 0\
**Last updated:** [October 9, 2023, 2:11pm UTC](https://discuss.elastic.co/t/create-netflow-filters-in-kibana-dashboard/344666 "2023-10-09T14:11:36Z")

</div>

Hello, I'm new to elasticsearch, and I installed elasticsearch here at work with kibana and netflow. I would like to create a filter that would give me the following information: all destination ports originating from b…

---

## [How to filter \_search performed with text\_expansion](https://discuss.elastic.co/t/how-to-filter-search-performed-with-text-expansion/344646)

<div class="topic-metadata">

**Author:** [@sivagurlinka](https://discuss.elastic.co/u/sivagurlinka)\
**Replies:** 1\
**Last updated:** [October 9, 2023, 2:10pm UTC](https://discuss.elastic.co/t/how-to-filter-search-performed-with-text-expansion/344646 "2023-10-09T14:10:49Z")

</div>

I have an Elasticsearch index ingested with inference pipeline using ELSER. While performing the search I would like to filter and show all the URL's containing "/cn/" in it. (http://www.elastic.co/giude/cn/\*). How to a…

---

## [Fleet "CreateIndexRequest" constantly rollover indicies](https://discuss.elastic.co/t/fleet-createindexrequest-constantly-rollover-indicies/342604)

<div class="topic-metadata">

**Author:** [@Anabel](https://discuss.elastic.co/u/Anabel)\
**Replies:** 2\
**Last updated:** [October 9, 2023, 1:59pm UTC](https://discuss.elastic.co/t/fleet-createindexrequest-constantly-rollover-indicies/342604 "2023-10-09T13:59:27Z")

</div>

Hi everyone Elasticsearch was complaining that we've reached max amount of shards -- we've increased max\_shards\_per\_node from default 1000 to 2000 and later to 5000. and then we noticed hundreds of empty indices with …

---

## [Oracle to ElasticSearch using logstash](https://discuss.elastic.co/t/oracle-to-elasticsearch-using-logstash/344662)

<div class="topic-metadata">

**Author:** [@K\_Nguy\_n\_Kh\_c](https://discuss.elastic.co/u/K_Nguy_n_Kh_c)\
**Replies:** 0\
**Last updated:** [October 9, 2023, 1:38pm UTC](https://discuss.elastic.co/t/oracle-to-elasticsearch-using-logstash/344662 "2023-10-09T13:38:19Z")

</div>

Hi, i'm new to Elastic Stack and i try to push data from Oracle database to my Elasticsearch via Logstash but i'm stuck at this error Unable to configure plugins: (ArgumentError) Cannot determine timezone from nil my p…

---

## [Function\_score with several functions](https://discuss.elastic.co/t/function-score-with-several-functions/343786)

<div class="topic-metadata">

**Author:** [@MikeT1234](https://discuss.elastic.co/u/MikeT1234)\
**Replies:** 3\
**Last updated:** [October 9, 2023, 1:36pm UTC](https://discuss.elastic.co/t/function-score-with-several-functions/343786 "2023-10-09T13:36:03Z")

</div>

Could somebody point me to the right direction? :nerd\_face: I'm trying to search items and categorize / score them based on several criteria. function\_score seems to do all the right things except I it just returns tot…

[Previous page](https://discuss.elastic.co/latest.md?page=516)

[Next page](https://discuss.elastic.co/latest.md?page=518)
