# Latest

**URL:** https://discuss.elastic.co/latest.md?page=521

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 522

---

## [Salesforce input logstash - add filter](https://discuss.elastic.co/t/salesforce-input-logstash-add-filter/344217)

<div class="topic-metadata">

**Author:** [@Samuele\_Lolli](https://discuss.elastic.co/u/Samuele_Lolli)\
**Replies:** 4\
**Last updated:** [October 5, 2023, 8:17am UTC](https://discuss.elastic.co/t/salesforce-input-logstash-add-filter/344217 "2023-10-05T08:17:50Z")

</div>

I have a input configuration like that and i wonder if is possible to filter document like with a query or something like that. salesforce{ use\_test\_sandbox =\> true client\_id =\> '' client…

---

## [Error with net/smtp in Logstash (Docker)](https://discuss.elastic.co/t/error-with-net-smtp-in-logstash-docker/344312)

<div class="topic-metadata">

**Author:** [@Samuele\_Lolli](https://discuss.elastic.co/u/Samuele_Lolli)\
**Replies:** 2\
**Last updated:** [October 5, 2023, 8:08am UTC](https://discuss.elastic.co/t/error-with-net-smtp-in-logstash-docker/344312 "2023-10-05T08:08:47Z")

</div>

Hi everyone, im having some issue with docker and logstash. I have the following error: 2023-10-03 14:46:24 warning: thread "\[main\]-pipeline-manager" terminated with exception (report\_on\_exception is true): 2023-10-03 …

---

## [Why does cluster.routing.allocation.exclude.\_ip only work as a transient, not persistent setting?](https://discuss.elastic.co/t/why-does-cluster-routing-allocation-exclude-ip-only-work-as-a-transient-not-persistent-setting/344419)

<div class="topic-metadata">

**Author:** [@Jamshid](https://discuss.elastic.co/u/Jamshid)\
**Replies:** 3\
**Last updated:** [October 5, 2023, 7:12am UTC](https://discuss.elastic.co/t/why-does-cluster-routing-allocation-exclude-ip-only-work-as-a-transient-not-persistent-setting/344419 "2023-10-05T07:12:47Z")

</div>

Just a sanity check... trying to remove a node by setting cluster.routing.allocation.exclude.\_ip does not seem to have any effect if it's a persistent setting. Tested with elasticesarch 7.17.13 on a 3-node cluster. When …

---

## [Lot of delay in logs parsing at kibana GUI](https://discuss.elastic.co/t/lot-of-delay-in-logs-parsing-at-kibana-gui/344449)

<div class="topic-metadata">

**Author:** [@syedsyed](https://discuss.elastic.co/u/syedsyed)\
**Replies:** 0\
**Last updated:** [October 5, 2023, 7:01am UTC](https://discuss.elastic.co/t/lot-of-delay-in-logs-parsing-at-kibana-gui/344449 "2023-10-05T07:01:33Z")

</div>

I have Elasticsearch and kibana installed and i have integrated the fleet server into it, enrolled the elastic agent with sonicwall integration into it, but i am facing lot of delay of about one and half day, mostly the …

---

## [Max items on runtime fields](https://discuss.elastic.co/t/max-items-on-runtime-fields/344307)

<div class="topic-metadata">

**Author:** [@lipig](https://discuss.elastic.co/u/lipig)\
**Replies:** 1\
**Last updated:** [October 5, 2023, 6:16am UTC](https://discuss.elastic.co/t/max-items-on-runtime-fields/344307 "2023-10-05T06:16:31Z")

</div>

Hi Elastic people, A curiosity... I emit more than 100 values ​​in the runtime fields, and I saw in the forum that 100 was the maximum. I saw this thread from 2021 and wanted to ask if there have been any updates. Th…

---

## [Elastic system indices migration issue while upgrade](https://discuss.elastic.co/t/elastic-system-indices-migration-issue-while-upgrade/344434)

<div class="topic-metadata">

**Author:** [@Harper\_S1](https://discuss.elastic.co/u/Harper_S1)\
**Replies:** 1\
**Last updated:** [October 5, 2023, 6:10am UTC](https://discuss.elastic.co/t/elastic-system-indices-migration-issue-while-upgrade/344434 "2023-10-05T06:10:48Z")

</div>

Hi, I am upgrading elastic from 6.8 to 7.17.0 and then 8.x.x. From version 6.8 to 7.17 migration was fine but while preparing to migrate from version 7.17 to 8.x.x upgrade assistant is not able to migrate this one(Task…

---

## [Filebeat cisco ios Parsing delimeter error](https://discuss.elastic.co/t/filebeat-cisco-ios-parsing-delimeter-error/344432)

<div class="topic-metadata">

**Author:** [@lee.clemens](https://discuss.elastic.co/u/lee.clemens)\
**Replies:** 0\
**Last updated:** [October 4, 2023, 10:00pm UTC](https://discuss.elastic.co/t/filebeat-cisco-ios-parsing-delimeter-error/344432 "2023-10-04T22:00:10Z")

</div>

Hello, I'm seeing this runtime error being logged parsing deny logs from IOS: GoError: could not find beginning delimiter: list in remaining: F0/0: fman\_fp\_image: list ACL\_Inbound denied udp 127.0.0.1(51052) -\> 127.0.…

---

## [Master node in ECK with differente IP between pod and elasticsearch](https://discuss.elastic.co/t/master-node-in-eck-with-differente-ip-between-pod-and-elasticsearch/344431)

<div class="topic-metadata">

**Author:** [@dudds22](https://discuss.elastic.co/u/dudds22)\
**Replies:** 0\
**Last updated:** [October 4, 2023, 8:34pm UTC](https://discuss.elastic.co/t/master-node-in-eck-with-differente-ip-between-pod-and-elasticsearch/344431 "2023-10-04T20:34:06Z")

</div>

Hi, Today we faced a strange situation and really want to share with you in order to try to obtain more infos about what can be happened. Context: We have a elasticsearch cluster and we need to send slowlogs to Datado…

---

## [Slef-host elasticsearch with azure ad sso SAML](https://discuss.elastic.co/t/slef-host-elasticsearch-with-azure-ad-sso-saml/344423)

<div class="topic-metadata">

**Author:** [@Yue\_CHEN](https://discuss.elastic.co/u/Yue_CHEN)\
**Replies:** 3\
**Last updated:** [October 4, 2023, 9:09pm UTC](https://discuss.elastic.co/t/slef-host-elasticsearch-with-azure-ad-sso-saml/344423 "2023-10-04T21:09:38Z")

</div>

Hello, Recently created a self-host Elasticsearch and Kibana version 8.10 in Azure VM. Both working fine now. Like to get Azure AD SSO enable when user open kibana. But did not see a good document for how to set it up.…

---

## [Elastic query takes over 1 minute due to time spent in "HighlightPhase"](https://discuss.elastic.co/t/elastic-query-takes-over-1-minute-due-to-time-spent-in-highlightphase/344344)

<div class="topic-metadata">

**Author:** [@David\_Avant](https://discuss.elastic.co/u/David_Avant)\
**Replies:** 5\
**Last updated:** [October 4, 2023, 7:26pm UTC](https://discuss.elastic.co/t/elastic-query-takes-over-1-minute-due-to-time-spent-in-highlightphase/344344 "2023-10-04T19:26:59Z")

</div>

Some elastic queries are slow, taking more than a minute to execute. The query input is simple: just a single, numeric account identifier (i.e. "123456789"). The query takes 68 seconds to execute and returns 6 hits. T…

---

## [File not found when attempting to index](https://discuss.elastic.co/t/file-not-found-when-attempting-to-index/344353)

<div class="topic-metadata">

**Author:** [@Ahriss](https://discuss.elastic.co/u/Ahriss)\
**Replies:** 2\
**Last updated:** [October 4, 2023, 7:23pm UTC](https://discuss.elastic.co/t/file-not-found-when-attempting-to-index/344353 "2023-10-04T19:23:12Z")

</div>

Hello. I'm building a simple elasticsearch/PHP application, and I got a very weird error. I can search on it just fine, though I need to build pagination for it still, but when I attempt to index something, I simply get …

---

## [Connector with postgresql not connect](https://discuss.elastic.co/t/connector-with-postgresql-not-connect/344196)

<div class="topic-metadata">

**Author:** [@irianvillalba](https://discuss.elastic.co/u/irianvillalba)\
**Replies:** 9\
**Last updated:** [October 4, 2023, 7:21pm UTC](https://discuss.elastic.co/t/connector-with-postgresql-not-connect/344196 "2023-10-04T19:21:08Z")

</div>

I'm having a problem with the postgresql connector, it's the first time I've tried to use it. I installed the entire elk suite in a container, I uploaded elastic, kibana, apm-server and enterprise-search, all properly in…

---

## [Filebeat auth.oauth2 error appeared on Google workspace config](https://discuss.elastic.co/t/filebeat-auth-oauth2-error-appeared-on-google-workspace-config/344421)

<div class="topic-metadata">

**Author:** [@Umor](https://discuss.elastic.co/u/Umor)\
**Replies:** 0\
**Last updated:** [October 4, 2023, 6:25pm UTC](https://discuss.elastic.co/t/filebeat-auth-oauth2-error-appeared-on-google-workspace-config/344421 "2023-10-04T18:25:50Z")

</div>

Greetings, I am using the Google Workspace module, and while running Filebeat the Google logs show and after a couple of minutes this error appeared {"log.level":"error","@timestamp":"2023-10-04T23:21:34.745+0500","log…

---

## [Send syslog to Filebeat server](https://discuss.elastic.co/t/send-syslog-to-filebeat-server/343987)

<div class="topic-metadata">

**Author:** [@msylvestre](https://discuss.elastic.co/u/msylvestre)\
**Replies:** 27\
**Last updated:** [October 4, 2023, 7:06pm UTC](https://discuss.elastic.co/t/send-syslog-to-filebeat-server/343987 "2023-10-04T19:06:22Z")

</div>

Greetings, I'm trying to send my Cisco Switches logs to my Filebeat server but for some reason it's not working. I can see that the Filebeat receives the logs, but it doesn't ship them to elastic afterwards. I tried usi…

---

## [ERROR: Skipping security auto configuration because it appears that the node is not starting up for the first time. The node might already be part of a cluster and this auto setup utility is designed to configure Security for new clusters only., with exit](https://discuss.elastic.co/t/error-skipping-security-auto-configuration-because-it-appears-that-the-node-is-not-starting-up-for-the-first-time-the-node-might-already-be-part-of-a-cluster-and-this-auto-setup-utility-is-designed-to-configure-security-for-new-clusters-only-with-exit/344422)

<div class="topic-metadata">

**Author:** [@nav\_11](https://discuss.elastic.co/u/nav_11)\
**Replies:** 0\
**Last updated:** [October 4, 2023, 6:29pm UTC](https://discuss.elastic.co/t/error-skipping-security-auto-configuration-because-it-appears-that-the-node-is-not-starting-up-for-the-first-time-the-node-might-already-be-part-of-a-cluster-and-this-auto-setup-utility-is-designed-to-configure-security-for-new-clusters-only-with-exit/344422 "2023-10-04T18:29:24Z")

</div>

Getting below error while adding the node. I am following the MACOS setup guide below. Command: bin/elasticsearch --enrollment-token ERROR: Skipping security auto configuration because it appears that the node is no…

---

## [Import Objects API for Rules/Connectors](https://discuss.elastic.co/t/import-objects-api-for-rules-connectors/344409)

<div class="topic-metadata">

**Author:** [@ameindel](https://discuss.elastic.co/u/ameindel)\
**Replies:** 1\
**Last updated:** [October 4, 2023, 5:38pm UTC](https://discuss.elastic.co/t/import-objects-api-for-rules-connectors/344409 "2023-10-04T17:38:36Z")

</div>

Hello, Elastic! I'm currently using a curl command to push an Alert Rule. Currently the rule gets created but is created in a 'disabled' state (see warnings.message): { "successCount": 1, "success": true, "warnin…

---

## [Getting index rate](https://discuss.elastic.co/t/getting-index-rate/344381)

<div class="topic-metadata">

**Author:** [@avnere](https://discuss.elastic.co/u/avnere)\
**Replies:** 1\
**Last updated:** [October 4, 2023, 3:56pm UTC](https://discuss.elastic.co/t/getting-index-rate/344381 "2023-10-04T15:56:49Z")

</div>

Hi, I am looking a way to monitor index rate not through Kibana. Is there any RestAPI command that provide the current index rate? Is there alternative way? Thanks...

---

## [ECK Filebeat processor add\_kubernetes\_metadata does not add fields with kube metadata](https://discuss.elastic.co/t/eck-filebeat-processor-add-kubernetes-metadata-does-not-add-fields-with-kube-metadata/344322)

<div class="topic-metadata">

**Author:** [@AlekseyD](https://discuss.elastic.co/u/AlekseyD)\
**Replies:** 2\
**Last updated:** [October 4, 2023, 3:30pm UTC](https://discuss.elastic.co/t/eck-filebeat-processor-add-kubernetes-metadata-does-not-add-fields-with-kube-metadata/344322 "2023-10-04T15:30:30Z")

</div>

Kubernetes: 1.24.3 Kibana: 8.10.2 Elastic: 8.10.2 Filebeat: 8.10.2 Fresh install via ECK 2.9.0 The processor "add\_kubernetesmetadata" does not add kubernetes metadata fields to elasticsearch, the filebeat log does n…

---

## [Issue in restoring an Elastic Snapshot](https://discuss.elastic.co/t/issue-in-restoring-an-elastic-snapshot/343329)

<div class="topic-metadata">

**Author:** [@girolamo](https://discuss.elastic.co/u/girolamo)\
**Replies:** 7\
**Last updated:** [October 4, 2023, 3:08pm UTC](https://discuss.elastic.co/t/issue-in-restoring-an-elastic-snapshot/343329 "2023-10-04T15:08:18Z")

</div>

Hello there, I'm having issues restoring an elasticsearch snapshot. I've tried: POST \_snapshot/snapshot\_repo/snap-EIHidJXeQWuHpnGfzR04Uw/\_restore { "indices": "target\_indicies" } but I've got: { "error" : { "ro…

---

## [APM RUM on flutter app](https://discuss.elastic.co/t/apm-rum-on-flutter-app/344368)

<div class="topic-metadata">

**Author:** [@Klauck](https://discuss.elastic.co/u/Klauck)\
**Replies:** 1\
**Last updated:** [October 4, 2023, 2:56pm UTC](https://discuss.elastic.co/t/apm-rum-on-flutter-app/344368 "2023-10-04T14:56:18Z")

</div>

Hi, I'm wondering if there is a possibility to use real user monitoring in an flutter app? Is there any package or howto available? Best Martin

---

## [Full-text queries with date filter](https://discuss.elastic.co/t/full-text-queries-with-date-filter/344391)

<div class="topic-metadata">

**Author:** [@combbbbinator](https://discuss.elastic.co/u/combbbbinator)\
**Replies:** 3\
**Last updated:** [October 4, 2023, 2:17pm UTC](https://discuss.elastic.co/t/full-text-queries-with-date-filter/344391 "2023-10-04T14:17:51Z")

</div>

Hello. I'm trying to understand whether it is possible to make a full-text request and specify a time filter in the request, for example, for the last 15 minutes? A request that I would like to improve : { "query": { …

---

## [Could not communicate with the node on any of the addresses from the enrollment token. All of \[10.89.3.8:9200\] were attempted., with exit code 69](https://discuss.elastic.co/t/could-not-communicate-with-the-node-on-any-of-the-addresses-from-the-enrollment-token-all-of-10-89-3-8-9200-were-attempted-with-exit-code-69/344398)

<div class="topic-metadata">

**Author:** [@uli67](https://discuss.elastic.co/u/uli67)\
**Replies:** 0\
**Last updated:** [October 4, 2023, 2:06pm UTC](https://discuss.elastic.co/t/could-not-communicate-with-the-node-on-any-of-the-addresses-from-the-enrollment-token-all-of-10-89-3-8-9200-were-attempted-with-exit-code-69/344398 "2023-10-04T14:06:41Z")

</div>

Hi fellows, I need our help. When I try to run my elasticsearch container like this: \`docker run -e "ENROLLMENT\_TOKEN= eyJ2ZXIiOiI4LjEwLjIiLCJhZHIiOlsiMTAuODkuMy44OjkyMDAiXSwiZmdyIjoiZjAwYjJjMjYyMmRiOTQ4NDU4ZmI3NjRhZ…

---

## [Elasticsearch spark runtime dependencies](https://discuss.elastic.co/t/elasticsearch-spark-runtime-dependencies/344341)

<div class="topic-metadata">

**Author:** [@krezno](https://discuss.elastic.co/u/krezno)\
**Replies:** 1\
**Last updated:** [October 4, 2023, 1:00pm UTC](https://discuss.elastic.co/t/elasticsearch-spark-runtime-dependencies/344341 "2023-10-04T13:00:22Z")

</div>

Hello, I have sucessfuly managed to use elasticsearch-spark with both pyspark and scala spark by simply adding the jar to the classpath. I have noticed that the jar has some runtime dependencies such as protobuf-java an…

---

## [Auto deletion of all indices](https://discuss.elastic.co/t/auto-deletion-of-all-indices/344382)

<div class="topic-metadata">

**Author:** [@sujata\_g](https://discuss.elastic.co/u/sujata_g)\
**Replies:** 1\
**Last updated:** [October 4, 2023, 12:36pm UTC](https://discuss.elastic.co/t/auto-deletion-of-all-indices/344382 "2023-10-04T12:36:01Z")

</div>

Hi, i am using Elasticsearch and kibana which are running on docker container(Elasticsearch version is 7.12.0) and all my indices are getting deleted automatically every month and i have not applied any policies and ever…

---

## [Port 80 is already in use. Another instance of Kibana may be running](https://discuss.elastic.co/t/port-80-is-already-in-use-another-instance-of-kibana-may-be-running/343939)

<div class="topic-metadata">

**Author:** [@Nghia\_D\_ng](https://discuss.elastic.co/u/Nghia_D_ng)\
**Replies:** 11\
**Last updated:** [October 4, 2023, 12:35pm UTC](https://discuss.elastic.co/t/port-80-is-already-in-use-another-instance-of-kibana-may-be-running/343939 "2023-10-04T12:35:11Z")

</div>

Hi team, I'm having problems with kibana Currently I have kibana configured with port 80 and displaying the web interface normally. But when I change to kibana's default port, I get an error and no longer display the w…

---

## [Knn versus match scores](https://discuss.elastic.co/t/knn-versus-match-scores/344386)

<div class="topic-metadata">

**Author:** [@sbruinsje](https://discuss.elastic.co/u/sbruinsje)\
**Replies:** 0\
**Last updated:** [October 4, 2023, 12:22pm UTC](https://discuss.elastic.co/t/knn-versus-match-scores/344386 "2023-10-04T12:22:13Z")

</div>

When doing a hybrid search using a query and a knn clause using the \_search api, the combined document score is the sum of both scores. What I am unable to find in the docs is how the knn and match scores relate? Are the…

---

## [Elasticsearch on K8s VS Vm](https://discuss.elastic.co/t/elasticsearch-on-k8s-vs-vm/344384)

<div class="topic-metadata">

**Author:** [@avnere](https://discuss.elastic.co/u/avnere)\
**Replies:** 0\
**Last updated:** [October 4, 2023, 12:09pm UTC](https://discuss.elastic.co/t/elasticsearch-on-k8s-vs-vm/344384 "2023-10-04T12:09:15Z")

</div>

Hi, On production which approach is preferred? Installing elastic on K8s or Vm? Is there any difference\\limitation? Thanks...

---

## [Move from High Level REST client to Java API Client](https://discuss.elastic.co/t/move-from-high-level-rest-client-to-java-api-client/344304)

<div class="topic-metadata">

**Author:** [@matt4589](https://discuss.elastic.co/u/matt4589)\
**Replies:** 4\
**Last updated:** [October 4, 2023, 12:03pm UTC](https://discuss.elastic.co/t/move-from-high-level-rest-client-to-java-api-client/344304 "2023-10-04T12:03:00Z")

</div>

I have to move from High Level REST client to Java API Client I would like to show one method I have to replace and learn from that . This is old method: public List\<Map\<String, Object\>\> getPublicFilters() { Search…

---

## [Migrating Saved Objects from Kibana 5.5 to 8.1](https://discuss.elastic.co/t/migrating-saved-objects-from-kibana-5-5-to-8-1/344117)

<div class="topic-metadata">

**Author:** [@Divyanshu\_Raj](https://discuss.elastic.co/u/Divyanshu_Raj)\
**Replies:** 6\
**Last updated:** [October 4, 2023, 11:51am UTC](https://discuss.elastic.co/t/migrating-saved-objects-from-kibana-5-5-to-8-1/344117 "2023-10-04T11:51:40Z")

</div>

Hello Community, we are trying to export our saved objects ( visualizations, dashboards ..) from Kibana 5.5 to Kibana 8.1. The challenge is that exported saved objects from Kibana are in .json format and the expected f…

---

## [elasticsearch.UnsupportedProductError: The client noticed that the server is not Elasticsearch and we do not support this unknown product](https://discuss.elastic.co/t/elasticsearch-unsupportedproducterror-the-client-noticed-that-the-server-is-not-elasticsearch-and-we-do-not-support-this-unknown-product/344379)

<div class="topic-metadata">

**Author:** [@Arshdeep\_Singh](https://discuss.elastic.co/u/Arshdeep_Singh)\
**Replies:** 2\
**Last updated:** [October 4, 2023, 11:15am UTC](https://discuss.elastic.co/t/elasticsearch-unsupportedproducterror-the-client-noticed-that-the-server-is-not-elasticsearch-and-we-do-not-support-this-unknown-product/344379 "2023-10-04T11:15:22Z")

</div>

Here I'm trying to create a full sync between Django's database and Elastic Search. While running the command "python manage.py search\_index --create -f", I'm getting the error: ERROR: Traceback (most recent call last)…

[Previous page](https://discuss.elastic.co/latest.md?page=520)

[Next page](https://discuss.elastic.co/latest.md?page=522)
