# Latest

**URL:** https://discuss.elastic.co/latest.md?page=520

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 521

---

## [Migration from OpenSearch1.1 to Elasticsearch7.18 using logstash](https://discuss.elastic.co/t/migration-from-opensearch1-1-to-elasticsearch7-18-using-logstash/343535)

<div class="topic-metadata">

**Author:** [@gaurav\_jain](https://discuss.elastic.co/u/gaurav_jain)\
**Replies:** 12\
**Last updated:** [October 5, 2023, 9:19pm UTC](https://discuss.elastic.co/t/migration-from-opensearch1-1-to-elasticsearch7-18-using-logstash/343535 "2023-10-05T21:19:25Z")

</div>

Hi Experts, I am trying to migrate my Opensearch cluster version 1.1 to elastic cloud 7.18. I have created a logstash pipeline for the same who's configuration looks like this : input { opensearch { hosts …

---

## [How to display node hostname in Kibana stack monitoring?](https://discuss.elastic.co/t/how-to-display-node-hostname-in-kibana-stack-monitoring/344504)

<div class="topic-metadata">

**Author:** [@Jignesh\_Soni](https://discuss.elastic.co/u/Jignesh_Soni)\
**Replies:** 1\
**Last updated:** [October 5, 2023, 8:10pm UTC](https://discuss.elastic.co/t/how-to-display-node-hostname-in-kibana-stack-monitoring/344504 "2023-10-05T20:10:03Z")

</div>

Hi All, Hostname is set in Elasticsearch and Kibana configurations , but still Kibana stack monitoring is showing only IP address of nodes. Is there any way to show host name also of nodes in stack monitoring in Kibana…

---

## [@Timestamp is not matching event timestamp \_dateparsefailure](https://discuss.elastic.co/t/timestamp-is-not-matching-event-timestamp-dateparsefailure/344506)

<div class="topic-metadata">

**Author:** [@Cara410](https://discuss.elastic.co/u/Cara410)\
**Replies:** 2\
**Last updated:** [October 5, 2023, 8:01pm UTC](https://discuss.elastic.co/t/timestamp-is-not-matching-event-timestamp-dateparsefailure/344506 "2023-10-05T20:01:48Z")

</div>

Hello All, I am having filebeat send data through logstash and I have been unable to get the @timestamp to match the event time. I get a \_dateparsefailure tag in Kibana. Everything else is ingesting as intended. I have …

---

## [Using Elasticsearch Completion Suggester for large text search](https://discuss.elastic.co/t/using-elasticsearch-completion-suggester-for-large-text-search/344507)

<div class="topic-metadata">

**Author:** [@TomTom](https://discuss.elastic.co/u/TomTom)\
**Replies:** 0\
**Last updated:** [October 5, 2023, 7:55pm UTC](https://discuss.elastic.co/t/using-elasticsearch-completion-suggester-for-large-text-search/344507 "2023-10-05T19:55:52Z")

</div>

Is it possible to use the Completion Suggester feature for Elasticsearch to find content as text is typed, similar to Elasticsearch's Discuss? For example, I have articles in my knowledge base that have a title and cont…

---

## [Query an Elasticsearch index for one field, all documents in last 24 hours?](https://discuss.elastic.co/t/query-an-elasticsearch-index-for-one-field-all-documents-in-last-24-hours/344493)

<div class="topic-metadata">

**Author:** [@Meme-ento](https://discuss.elastic.co/u/Meme-ento)\
**Replies:** 1\
**Last updated:** [October 5, 2023, 7:40pm UTC](https://discuss.elastic.co/t/query-an-elasticsearch-index-for-one-field-all-documents-in-last-24-hours/344493 "2023-10-05T19:40:16Z")

</div>

Hi There. I'm trying to make a simple get request to my elk index. I have the right credentials, hostname, index name, etc. my ELK version is 6.8.6 But for what I'm trying to get I cannot figure out how to construct …

---

## [Elastic Common Schema support for Opensearch](https://discuss.elastic.co/t/elastic-common-schema-support-for-opensearch/344452)

<div class="topic-metadata">

**Author:** [@q3uxlyn](https://discuss.elastic.co/u/q3uxlyn)\
**Replies:** 3\
**Last updated:** [October 5, 2023, 7:22pm UTC](https://discuss.elastic.co/t/elastic-common-schema-support-for-opensearch/344452 "2023-10-05T19:22:19Z")

</div>

Hello! Have you plans about adding OpenSearch support to Elastic Common Schema? Cause of OpenSearch has different field types than Elasticsearch we can't easily use ECS. I want to be able to keep the schemas up to date…

---

## [Run time fields in Kibana VIsualizations](https://discuss.elastic.co/t/run-time-fields-in-kibana-visualizations/343567)

<div class="topic-metadata">

**Author:** [@JeremyP](https://discuss.elastic.co/u/JeremyP)\
**Replies:** 9\
**Last updated:** [October 5, 2023, 3:43pm UTC](https://discuss.elastic.co/t/run-time-fields-in-kibana-visualizations/343567 "2023-10-05T15:43:35Z")

</div>

Hello, I have a couple of run time fields defined in the index mappings which calculates the difference between two time stamps in days. It works fine, and I can see the data in Kibana discover. However, if I attempt t…

---

## [ABAC / Custom Realm / Extend JWT authentication](https://discuss.elastic.co/t/abac-custom-realm-extend-jwt-authentication/344500)

<div class="topic-metadata">

**Author:** [@SvenHa](https://discuss.elastic.co/u/SvenHa)\
**Replies:** 0\
**Last updated:** [October 5, 2023, 3:36pm UTC](https://discuss.elastic.co/t/abac-custom-realm-extend-jwt-authentication/344500 "2023-10-05T15:36:34Z")

</div>

Hello, Currently, I'm trying to evaluate the best solution for a customer project. Some facts about the project environment: User authentication with OIDC/JWT is available. It is not possible to extend the JWT with c…

---

## [Kibana error: security\_exception: \[security\_exception\] Reason: unable to authenticate with provided credentials and anonymous access is not allowed for this request](https://discuss.elastic.co/t/kibana-error-security-exception-security-exception-reason-unable-to-authenticate-with-provided-credentials-and-anonymous-access-is-not-allowed-for-this-request/344243)

<div class="topic-metadata">

**Author:** [@PodarcisMuralis](https://discuss.elastic.co/u/PodarcisMuralis)\
**Replies:** 1\
**Last updated:** [October 5, 2023, 3:26pm UTC](https://discuss.elastic.co/t/kibana-error-security-exception-security-exception-reason-unable-to-authenticate-with-provided-credentials-and-anonymous-access-is-not-allowed-for-this-request/344243 "2023-10-05T15:26:00Z")

</div>

Hi. I upgraded the Kibana from 7.17 to 8.5.3 and got some corrupt indices. then I used these instructions and deleted .kibana and . monitoring indices. Resolve Migration Failures But I also deleted .security\_7. This …

---

## [Logstash Metrics unavailable on Kibana Stack Monitoring UI](https://discuss.elastic.co/t/logstash-metrics-unavailable-on-kibana-stack-monitoring-ui/343328)

<div class="topic-metadata">

**Author:** [@gsekar](https://discuss.elastic.co/u/gsekar)\
**Replies:** 8\
**Last updated:** [October 5, 2023, 3:01pm UTC](https://discuss.elastic.co/t/logstash-metrics-unavailable-on-kibana-stack-monitoring-ui/343328 "2023-10-05T15:01:56Z")

</div>

Hi all Have installed metricbeat to monitor Logstash Nodes. The data stream - .monitoring-logstash-8-mb does get created and am seeing the data in the discover tab. But in the Stack Monitoring page for some reason the d…

---

## [Kibana Error - Error while updating search session x: Saved object x conflict](https://discuss.elastic.co/t/kibana-error-error-while-updating-search-session-x-saved-object-x-conflict/343783)

<div class="topic-metadata">

**Author:** [@PodarcisMuralis](https://discuss.elastic.co/u/PodarcisMuralis)\
**Replies:** 1\
**Last updated:** [October 5, 2023, 2:56pm UTC](https://discuss.elastic.co/t/kibana-error-error-while-updating-search-session-x-saved-object-x-conflict/343783 "2023-10-05T14:56:31Z")

</div>

Hello. I am using Kibana 8.5.3 and getting this error continuously. Error while updating search session b4100d1f-dfea-4ba9-8873-070219cbfe5f: Saved object \[search-session/b4100d1f-dfea-4ba9-8873-070219cbfe5f\] conflict…

---

## [Kibana fleet error - Failed to fetch latest version of synthetics from registry: Error connecting to package registry: request to URL failed, reason: connect ENETUNREACH xx.xxx.xxx.xxx:xxx - Local (0.0.0.0:0)](https://discuss.elastic.co/t/kibana-fleet-error-failed-to-fetch-latest-version-of-synthetics-from-registry-error-connecting-to-package-registry-request-to-url-failed-reason-connect-enetunreach-xx-xxx-xxx-xxx-xxx-local-0-0-0-0-0/344498)

<div class="topic-metadata">

**Author:** [@PodarcisMuralis](https://discuss.elastic.co/u/PodarcisMuralis)\
**Replies:** 0\
**Last updated:** [October 5, 2023, 2:43pm UTC](https://discuss.elastic.co/t/kibana-fleet-error-failed-to-fetch-latest-version-of-synthetics-from-registry-error-connecting-to-package-registry-request-to-url-failed-reason-connect-enetunreach-xx-xxx-xxx-xxx-xxx-local-0-0-0-0-0/344498 "2023-10-05T14:43:55Z")

</div>

Hi. I am using Kibana 8.5.3 and everytime I start Kibana with "sudo systemctl start kibana" or restart, I get this error once. Failed to fetch latest version of synthetics from registry: Error connecting to package reg…

---

## [bulkIndex() or saveAll()?](https://discuss.elastic.co/t/bulkindex-or-saveall/344487)

<div class="topic-metadata">

**Author:** [@Cemre\_Senyuva](https://discuss.elastic.co/u/Cemre_Senyuva)\
**Replies:** 0\
**Last updated:** [October 5, 2023, 1:24pm UTC](https://discuss.elastic.co/t/bulkindex-or-saveall/344487 "2023-10-05T13:24:19Z")

</div>

Which one is faster method to save/index in elasticsearch bulkIndex() or saveAll()?

---

## [Elasticsearch SCCM Windows deployment](https://discuss.elastic.co/t/elasticsearch-sccm-windows-deployment/344497)

<div class="topic-metadata">

**Author:** [@Waldfried](https://discuss.elastic.co/u/Waldfried)\
**Replies:** 0\
**Last updated:** [October 5, 2023, 2:24pm UTC](https://discuss.elastic.co/t/elasticsearch-sccm-windows-deployment/344497 "2023-10-05T14:24:20Z")

</div>

Hi everyone, i'm having problems deploying Elasticsearch via SCCM. During execution the setup tries to create a symlink which is working as long as i install it with a administrative user account. As soon as the setup …

---

## [Kibana errors after changing encryptionKey - Failed to decrypt "apiKey" attribute: Unsupported state or unable to authenticate data](https://discuss.elastic.co/t/kibana-errors-after-changing-encryptionkey-failed-to-decrypt-apikey-attribute-unsupported-state-or-unable-to-authenticate-data/344492)

<div class="topic-metadata">

**Author:** [@PodarcisMuralis](https://discuss.elastic.co/u/PodarcisMuralis)\
**Replies:** 1\
**Last updated:** [October 5, 2023, 2:21pm UTC](https://discuss.elastic.co/t/kibana-errors-after-changing-encryptionkey-failed-to-decrypt-apikey-attribute-unsupported-state-or-unable-to-authenticate-data/344492 "2023-10-05T14:21:07Z")

</div>

I use elasticstack 8.5.3 and have 2 Logstash, 5 ELS and 1 Kibana nodes. I was cleaning the older kibana system indices ( upgraded from 7.17.7) and deleted .security\_7 index also and had to create all built in users agai…

---

## [Elasticsearch jvm memory outbursts above settings causing oom-kill](https://discuss.elastic.co/t/elasticsearch-jvm-memory-outbursts-above-settings-causing-oom-kill/344490)

<div class="topic-metadata">

**Author:** [@Guillaume\_Soustrade](https://discuss.elastic.co/u/Guillaume_Soustrade)\
**Replies:** 0\
**Last updated:** [October 5, 2023, 1:49pm UTC](https://discuss.elastic.co/t/elasticsearch-jvm-memory-outbursts-above-settings-causing-oom-kill/344490 "2023-10-05T13:49:55Z")

</div>

Dear Elasticsearch connoisseurs, We have a repeating issue in our clusters of nodes suddenly exiting due to the java process being oom-killed. Let's take the example of this falling node : 94.3 Go of RAM 8 CPUs SWAP …

---

## [Elastic-Agent takes up too much disk space](https://discuss.elastic.co/t/elastic-agent-takes-up-too-much-disk-space/344429)

<div class="topic-metadata">

**Author:** [@swtrux](https://discuss.elastic.co/u/swtrux)\
**Replies:** 3\
**Last updated:** [October 5, 2023, 1:32pm UTC](https://discuss.elastic.co/t/elastic-agent-takes-up-too-much-disk-space/344429 "2023-10-05T13:32:50Z")

</div>

The size of elastic-agent continues to increase with every version: 8.8 1.7G 8.7 1.4G 8.6 1.2G 8.5 415M 1.7GB for this package size is way too big. We are looking at moving to elastic-agent but can't have over 2000 …

---

## [Getting error after adding filebeat](https://discuss.elastic.co/t/getting-error-after-adding-filebeat/344481)

<div class="topic-metadata">

**Author:** [@2328943\_dc](https://discuss.elastic.co/u/2328943_dc)\
**Replies:** 0\
**Last updated:** [October 5, 2023, 12:56pm UTC](https://discuss.elastic.co/t/getting-error-after-adding-filebeat/344481 "2023-10-05T12:56:24Z")

</div>

Dear Team, We are getting error as below after adding new log files through filebeat ,we have increased our heap size up to 30 g ,and total memory is 62 gb present now on server , \[ERROR\]\[o.e.x.c.a.AsyncTaskIndexServic…

---

## [Does Elastic accept combined JSON with flatten keys](https://discuss.elastic.co/t/does-elastic-accept-combined-json-with-flatten-keys/344373)

<div class="topic-metadata">

**Author:** [@ddoroshenko](https://discuss.elastic.co/u/ddoroshenko)\
**Replies:** 1\
**Last updated:** [October 4, 2023, 12:06pm UTC](https://discuss.elastic.co/t/does-elastic-accept-combined-json-with-flatten-keys/344373 "2023-10-04T12:06:17Z")

</div>

Hi, is it possible to send to ES messages in combined JSON format { "a": { "b": { "c.d.e.f": "value" } } } or it ends with error like can't merge a non object mapping with an object mapping?

---

## [Best practice for TDocument class reference to pass to Java's ElasticsearchClient methods?](https://discuss.elastic.co/t/best-practice-for-tdocument-class-reference-to-pass-to-javas-elasticsearchclient-methods/344473)

<div class="topic-metadata">

**Author:** [@ilgrosso](https://discuss.elastic.co/u/ilgrosso)\
**Replies:** 2\
**Last updated:** [October 5, 2023, 12:14pm UTC](https://discuss.elastic.co/t/best-practice-for-tdocument-class-reference-to-pass-to-javas-elasticsearchclient-methods/344473 "2023-10-05T12:14:45Z")

</div>

Hi, I am using the latest Java REST API client and wondering what Class\<TDocument\> reference I should be passing to the search() method in case of no object domain model is being used. At present I am using a bare Map.…

---

## [GC time monitoring with apm java agent and machine learning](https://discuss.elastic.co/t/gc-time-monitoring-with-apm-java-agent-and-machine-learning/344393)

<div class="topic-metadata">

**Author:** [@Gaston\_Beltramelli](https://discuss.elastic.co/u/Gaston_Beltramelli)\
**Replies:** 5\
**Last updated:** [October 5, 2023, 12:12pm UTC](https://discuss.elastic.co/t/gc-time-monitoring-with-apm-java-agent-and-machine-learning/344393 "2023-10-05T12:12:58Z")

</div>

Hello Community, I hope this message finds you well. I have been working with Elastic APM to monitor the performance of my Java application, and I'm particularly interested in tracking the time spend in Garbage Collecto…

---

## [How do we write painless script for scripted fields](https://discuss.elastic.co/t/how-do-we-write-painless-script-for-scripted-fields/344467)

<div class="topic-metadata">

**Author:** [@Abj\_Ins](https://discuss.elastic.co/u/Abj_Ins)\
**Replies:** 1\
**Last updated:** [October 5, 2023, 11:49am UTC](https://discuss.elastic.co/t/how-do-we-write-painless-script-for-scripted-fields/344467 "2023-10-05T11:49:06Z")

</div>

Hi Team, am trying to write painless script for the below scenario.. i have department numbers like 1100,1200,1300... so, instead of department numbers am expecting short name as IND, USA, UK....by using scripted fiel…

---

## [How to change an index mapping in Elastic search](https://discuss.elastic.co/t/how-to-change-an-index-mapping-in-elastic-search/344456)

<div class="topic-metadata">

**Author:** [@Francesco66](https://discuss.elastic.co/u/Francesco66)\
**Replies:** 4\
**Last updated:** [October 5, 2023, 11:47am UTC](https://discuss.elastic.co/t/how-to-change-an-index-mapping-in-elastic-search/344456 "2023-10-05T11:47:11Z")

</div>

Hello, I am ingesting the following document into Elasticsearch via Logstash: \[xxxx@yyyy ~\]# curl -k http://my\_es\_hostname:9200/cdp-zos-syslog-console-plex75-20231005/\_search?pretty { "took" : 564, "timed\_out" : fal…

---

## [Filebeat 7.17.6 automatically populates event.module and service.type fields?](https://discuss.elastic.co/t/filebeat-7-17-6-automatically-populates-event-module-and-service-type-fields/344474)

<div class="topic-metadata">

**Author:** [@andreycha](https://discuss.elastic.co/u/andreycha)\
**Replies:** 0\
**Last updated:** [October 5, 2023, 11:34am UTC](https://discuss.elastic.co/t/filebeat-7-17-6-automatically-populates-event-module-and-service-type-fields/344474 "2023-10-05T11:34:33Z")

</div>

Hi, I'm facing weird behaviour of Filebeat for which I couldn't find any explanation in the docs. So we write application logs into files in ECS format using Elastic.CommonSchema.Serilog package. All log entries have po…

---

## [Optimal way to handle log with multiple format?](https://discuss.elastic.co/t/optimal-way-to-handle-log-with-multiple-format/344470)

<div class="topic-metadata">

**Author:** [@Tanin\_Imanothai](https://discuss.elastic.co/u/Tanin_Imanothai)\
**Replies:** 0\
**Last updated:** [October 5, 2023, 10:33am UTC](https://discuss.elastic.co/t/optimal-way-to-handle-log-with-multiple-format/344470 "2023-10-05T10:33:57Z")

</div>

I try to parse this dataset: https://github.com/logpai/loghub/tree/master/Android using logstash. I have tried using grok filter but some parts of the log contains multiple templates. example of log: 03-17 16:13:38.81…

---

## [Search api problem with filter geolocation field](https://discuss.elastic.co/t/search-api-problem-with-filter-geolocation-field/344468)

<div class="topic-metadata">

**Author:** [@Apiwat\_Jaisak](https://discuss.elastic.co/u/Apiwat_Jaisak)\
**Replies:** 1\
**Last updated:** [October 5, 2023, 10:11am UTC](https://discuss.elastic.co/t/search-api-problem-with-filter-geolocation-field/344468 "2023-10-05T10:11:23Z")

</div>

{ "query": "", "page": { "size": 5, "current": 1 }, "sort": { "write\_date": "asc" }, "filters": { "all": \[ { "map\_location": { …

---

## [503 error from Kibana while running Filebeat setup](https://discuss.elastic.co/t/503-error-from-kibana-while-running-filebeat-setup/344435)

<div class="topic-metadata">

**Author:** [@nspeaks](https://discuss.elastic.co/u/nspeaks)\
**Replies:** 1\
**Last updated:** [October 5, 2023, 9:54am UTC](https://discuss.elastic.co/t/503-error-from-kibana-while-running-filebeat-setup/344435 "2023-10-05T09:54:52Z")

</div>

I am trying to run the command filebeat setup -e and this is the error I get {"log.level":"info","@timestamp":"2023-10-05T02:55:42.666Z","log.origin":{"file.name":"instance/beat.go","file.line":783},"message":"Home pa…

---

## [View SAML Users](https://discuss.elastic.co/t/view-saml-users/344462)

<div class="topic-metadata">

**Author:** [@lehu](https://discuss.elastic.co/u/lehu)\
**Replies:** 0\
**Last updated:** [October 5, 2023, 9:20am UTC](https://discuss.elastic.co/t/view-saml-users/344462 "2023-10-05T09:20:13Z")

</div>

Hi, does anybody know why I can't see users that login with SAML even though I am an admin? It is necessary to view all users to change their roles otherwise all SAML users have the same role, which I dont want... Any su…

---

## [Watcher filter Latency\_info](https://discuss.elastic.co/t/watcher-filter-latency-info/344458)

<div class="topic-metadata">

**Author:** [@Aitor\_MtzAm](https://discuss.elastic.co/u/Aitor_MtzAm)\
**Replies:** 0\
**Last updated:** [October 5, 2023, 8:52am UTC](https://discuss.elastic.co/t/watcher-filter-latency-info/344458 "2023-10-05T08:52:34Z")

</div>

I need the watcher to differentiate between 2 values of the same field: Within the latency\_info field in the task "Integration" I need to differentiate whether the result field is "-" or "200". "latency\_info": \[ { "t…

---

## [Salesforce input logstash - add filter](https://discuss.elastic.co/t/salesforce-input-logstash-add-filter/344217)

<div class="topic-metadata">

**Author:** [@Samuele\_Lolli](https://discuss.elastic.co/u/Samuele_Lolli)\
**Replies:** 4\
**Last updated:** [October 5, 2023, 8:17am UTC](https://discuss.elastic.co/t/salesforce-input-logstash-add-filter/344217 "2023-10-05T08:17:50Z")

</div>

I have a input configuration like that and i wonder if is possible to filter document like with a query or something like that. salesforce{ use\_test\_sandbox =\> true client\_id =\> '' client…

[Previous page](https://discuss.elastic.co/latest.md?page=519)

[Next page](https://discuss.elastic.co/latest.md?page=521)
