# Latest

**URL:** https://discuss.elastic.co/latest.md?page=522

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 523

---

## [It is not possible exclude specific mount point from metricbeat measurement](https://discuss.elastic.co/t/it-is-not-possible-exclude-specific-mount-point-from-metricbeat-measurement/344378)

<div class="topic-metadata">

**Author:** [@LadaDvorak](https://discuss.elastic.co/u/LadaDvorak)\
**Replies:** 0\
**Last updated:** [October 4, 2023, 10:33am UTC](https://discuss.elastic.co/t/it-is-not-possible-exclude-specific-mount-point-from-metricbeat-measurement/344378 "2023-10-04T10:33:22Z")

</div>

I use metricbeat on linux server to detect free disk space on disk. My metricbeat.yml is set like this: processors: -drop\_event.when.regexp: system.filesystem.mount\_point: ‘^ / (sys | cgroup | proc | run | n…

---

## [Duplicated Google Workspace log entries by Filebeat](https://discuss.elastic.co/t/duplicated-google-workspace-log-entries-by-filebeat/344374)

<div class="topic-metadata">

**Author:** [@rlevitsky](https://discuss.elastic.co/u/rlevitsky)\
**Replies:** 0\
**Last updated:** [October 4, 2023, 10:06am UTC](https://discuss.elastic.co/t/duplicated-google-workspace-log-entries-by-filebeat/344374 "2023-10-04T10:06:34Z")

</div>

Couple weeks ago, we’ve noticed that some Google Workspace logs received by Filebeat got duplicated. I’ve searched the internet for possible cause and find one similar issue here at Elastic Discuss, Google Workspace mod…

---

## [Optimizing Elasticsearch Cluster Setup: Merging Logs Across Two Node](https://discuss.elastic.co/t/optimizing-elasticsearch-cluster-setup-merging-logs-across-two-node/344371)

<div class="topic-metadata">

**Author:** [@Priyaansh\_Dwivedi](https://discuss.elastic.co/u/Priyaansh_Dwivedi)\
**Replies:** 0\
**Last updated:** [October 4, 2023, 9:57am UTC](https://discuss.elastic.co/t/optimizing-elasticsearch-cluster-setup-merging-logs-across-two-node/344371 "2023-10-04T09:57:08Z")

</div>

"I have always valued the support of this community, and I find myself in need of assistance once again. Here's the situation: I currently have Elasticsearch installed on VM1, but I'm facing disk space issues, and the cl…

---

## [Es/search\] Missing \[X-Elastic-Product\] header](https://discuss.elastic.co/t/es-search-missing-x-elastic-product-header/344366)

<div class="topic-metadata">

**Author:** [@matt4589](https://discuss.elastic.co/u/matt4589)\
**Replies:** 2\
**Last updated:** [October 4, 2023, 9:56am UTC](https://discuss.elastic.co/t/es-search-missing-x-elastic-product-header/344366 "2023-10-04T09:56:24Z")

</div>

I'm using Java API Client 8.5.3 against elasticsearch 7.12.0 I'm gettinf this error when doing a search: co.elastic.clients.transport.TransportException: \[es/search\] Missing \[X-Elastic-Product\] header. Please check th…

---

## [Unexpected Behavior of OR Match Query With Synonym Graph](https://discuss.elastic.co/t/unexpected-behavior-of-or-match-query-with-synonym-graph/344320)

<div class="topic-metadata">

**Author:** [@MilanGatyas](https://discuss.elastic.co/u/MilanGatyas)\
**Replies:** 3\
**Last updated:** [October 4, 2023, 9:45am UTC](https://discuss.elastic.co/t/unexpected-behavior-of-or-match-query-with-synonym-graph/344320 "2023-10-04T09:45:03Z")

</div>

I don't know if the following behavior is intended or not. See the following example of index definition and documents: PUT /test { "settings": { "analysis": { "filter": { "syn": { "syn…

---

## [The use of \`size\` and \`from\` parameter in a \`knn\` search](https://discuss.elastic.co/t/the-use-of-size-and-from-parameter-in-a-knn-search/343962)

<div class="topic-metadata">

**Author:** [@sbruinsje](https://discuss.elastic.co/u/sbruinsje)\
**Replies:** 4\
**Last updated:** [October 4, 2023, 8:13am UTC](https://discuss.elastic.co/t/the-use-of-size-and-from-parameter-in-a-knn-search/343962 "2023-10-04T08:13:24Z")

</div>

When doing a knn search there is a parameter k which specifies the number of best matching documents to return (approximately). You can also use the size parameter to determine the number of documents to return. Is there…

---

## [Wildcard-like search on synonym authorizer](https://discuss.elastic.co/t/wildcard-like-search-on-synonym-authorizer/344363)

<div class="topic-metadata">

**Author:** [@mkalaaji](https://discuss.elastic.co/u/mkalaaji)\
**Replies:** 0\
**Last updated:** [October 4, 2023, 7:44am UTC](https://discuss.elastic.co/t/wildcard-like-search-on-synonym-authorizer/344363 "2023-10-04T07:44:44Z")

</div>

Currently facing an issue with synonyms and using Elasticsearch managed service not self hosted elasticsearch I have created a synonym file and created an authorizer that utilizes this synonym file in a filter PUT /sto…

---

## [From Python to Rust](https://discuss.elastic.co/t/from-python-to-rust/344329)

<div class="topic-metadata">

**Author:** [@FrederickFrance](https://discuss.elastic.co/u/FrederickFrance)\
**Replies:** 2\
**Last updated:** [October 4, 2023, 7:34am UTC](https://discuss.elastic.co/t/from-python-to-rust/344329 "2023-10-04T07:34:56Z")

</div>

Hi all, I'm a newbie with Python and Elasticsearch. I'm trying to create a client from host, username and password. With Python, the original code is: Elasticsearch( hosts=hosts, http\_auth=(es…

---

## [Fuzziness on multiple fields and match a particular field elastic search query](https://discuss.elastic.co/t/fuzziness-on-multiple-fields-and-match-a-particular-field-elastic-search-query/344361)

<div class="topic-metadata">

**Author:** [@uma\_parvathy](https://discuss.elastic.co/u/uma_parvathy)\
**Replies:** 0\
**Last updated:** [October 4, 2023, 7:32am UTC](https://discuss.elastic.co/t/fuzziness-on-multiple-fields-and-match-a-particular-field-elastic-search-query/344361 "2023-10-04T07:32:12Z")

</div>

Hi All, My requirement is to get the response for a specific word which can be appear anywhere in the document and it should belongs the user's account id. i've to use date range query like last 3 hours or 24 hours doc…

---

## [Web crawler DNS name resolution failed while validating domain](https://discuss.elastic.co/t/web-crawler-dns-name-resolution-failed-while-validating-domain/344356)

<div class="topic-metadata">

**Author:** [@sivagurlinka](https://discuss.elastic.co/u/sivagurlinka)\
**Replies:** 1\
**Last updated:** [October 4, 2023, 7:22am UTC](https://discuss.elastic.co/t/web-crawler-dns-name-resolution-failed-while-validating-domain/344356 "2023-10-04T07:22:07Z")

</div>

While trying to validate the domain we are getting "DNS name resolution failed. No suitable addresses found!" and we are able to access URL from browser. we have standalone Elasticsearch running on windows and Enterpri…

---

## [Is BulkIngester (replacement of 'Bulk Processor') in elasticsearch java api thread safe?](https://discuss.elastic.co/t/is-bulkingester-replacement-of-bulk-processor-in-elasticsearch-java-api-thread-safe/344285)

<div class="topic-metadata">

**Author:** [@Irfanulla](https://discuss.elastic.co/u/Irfanulla)\
**Replies:** 2\
**Last updated:** [October 4, 2023, 7:12am UTC](https://discuss.elastic.co/t/is-bulkingester-replacement-of-bulk-processor-in-elasticsearch-java-api-thread-safe/344285 "2023-10-04T07:12:35Z")

</div>

Use case: I have multiple kafka listeners for various topics. Each topic Listener will run in multiple threads (using spring's 'ConcurrentKafkaListenerContainer'). Listeners will be performing Update/Insert operations on…

---

## [Logs are not ingesting to elasticsearch](https://discuss.elastic.co/t/logs-are-not-ingesting-to-elasticsearch/344355)

<div class="topic-metadata">

**Author:** [@rahul\_sirugudi](https://discuss.elastic.co/u/rahul_sirugudi)\
**Replies:** 0\
**Last updated:** [October 4, 2023, 4:40am UTC](https://discuss.elastic.co/t/logs-are-not-ingesting-to-elasticsearch/344355 "2023-10-04T04:40:27Z")

</div>

This was my set up earlier. filebeat =\> logstash (SQS-PUSH) =\> logstash (SQS-PULL) =\> elasticsearch. The above approach seems very costlier to us because of (SQS API) calls. Hence we replaced kafka (standalone). fileb…

---

## [Elastic dev tool has different total hits number than discover query search](https://discuss.elastic.co/t/elastic-dev-tool-has-different-total-hits-number-than-discover-query-search/344275)

<div class="topic-metadata">

**Author:** [@JasonREC](https://discuss.elastic.co/u/JasonREC)\
**Replies:** 9\
**Last updated:** [October 4, 2023, 2:22am UTC](https://discuss.elastic.co/t/elastic-dev-tool-has-different-total-hits-number-than-discover-query-search/344275 "2023-10-04T02:22:53Z")

</div>

Hi, I have the same query and with the same filter. But the dev tool and discover give me different total hit counts ..I wonder what is the reason to that? and which is the accurate one

---

## [Restoring indexes that have missing shards from snapshot](https://discuss.elastic.co/t/restoring-indexes-that-have-missing-shards-from-snapshot/344265)

<div class="topic-metadata">

**Author:** [@Russell\_Fulton](https://discuss.elastic.co/u/Russell_Fulton)\
**Replies:** 3\
**Last updated:** [October 4, 2023, 2:11am UTC](https://discuss.elastic.co/t/restoring-indexes-that-have-missing-shards-from-snapshot/344265 "2023-10-04T02:11:43Z")

</div>

I had a cluster node restart while another the cluster was still recovering from another node crashing which resulted in some indexes with missing shards. None of the affected indexes are currently being written and I h…

---

## [Elastic Defend Degraded - Configure Network Events](https://discuss.elastic.co/t/elastic-defend-degraded-configure-network-events/344297)

<div class="topic-metadata">

**Author:** [@GKre](https://discuss.elastic.co/u/GKre)\
**Replies:** 3\
**Last updated:** [October 4, 2023, 12:39am UTC](https://discuss.elastic.co/t/elastic-defend-degraded-configure-network-events/344297 "2023-10-04T00:39:24Z")

</div>

Hi there, i rolled out elastic defend to my kali linux vm. On this machine the Agend is degraded with Elastic Defend showing a problem "configure network events". {"@timestamp":"2023-09-30T10:41:44.190134275Z","agent"…

---

## [How to enable "Continue as Guest" on Kibana?](https://discuss.elastic.co/t/how-to-enable-continue-as-guest-on-kibana/343713)

<div class="topic-metadata">

**Author:** [@Ong](https://discuss.elastic.co/u/Ong)\
**Replies:** 4\
**Last updated:** [October 4, 2023, 12:05am UTC](https://discuss.elastic.co/t/how-to-enable-continue-as-guest-on-kibana/343713 "2023-10-04T00:05:37Z")

</div>

I would like to enable "Continue as Guest" on Kibana and have followed the elastic docs but it did not work. My setup is a Kibana container running on Kubernetes that connects to a backend Elasticsearch. Kibana can star…

---

## [I want to have date filter in my embed kibana dashbard which i have one external web page](https://discuss.elastic.co/t/i-want-to-have-date-filter-in-my-embed-kibana-dashbard-which-i-have-one-external-web-page/344171)

<div class="topic-metadata">

**Author:** [@Jyoti\_Pandey](https://discuss.elastic.co/u/Jyoti_Pandey)\
**Replies:** 3\
**Last updated:** [October 3, 2023, 11:44pm UTC](https://discuss.elastic.co/t/i-want-to-have-date-filter-in-my-embed-kibana-dashbard-which-i-have-one-external-web-page/344171 "2023-10-03T23:44:01Z")

</div>

i am using the library for the date filter which is already present on my web page I want my date filter date should have to reflect to result of the Kibana dashboard as per the date range

---

## [Do Time series data streams (TSDS) store non-numeric/non-dimension logs efficiently?](https://discuss.elastic.co/t/do-time-series-data-streams-tsds-store-non-numeric-non-dimension-logs-efficiently/344352)

<div class="topic-metadata">

**Author:** [@micheal\_riff](https://discuss.elastic.co/u/micheal_riff)\
**Replies:** 0\
**Last updated:** [October 3, 2023, 10:40pm UTC](https://discuss.elastic.co/t/do-time-series-data-streams-tsds-store-non-numeric-non-dimension-logs-efficiently/344352 "2023-10-03T22:40:07Z")

</div>

Hi, I have a few questions about time series data streams (TSDS). I've tried looking through the documentation but am still confused on a few small things :slightly\_smiling\_face: I was wondering if fields that are not …

---

## [Mariadb-java-client-3.2.0.jar never found](https://discuss.elastic.co/t/mariadb-java-client-3-2-0-jar-never-found/344350)

<div class="topic-metadata">

**Author:** [@loekvankooten](https://discuss.elastic.co/u/loekvankooten)\
**Replies:** 2\
**Last updated:** [October 3, 2023, 10:00pm UTC](https://discuss.elastic.co/t/mariadb-java-client-3-2-0-jar-never-found/344350 "2023-10-03T22:00:39Z")

</div>

I'm on Windows 11. Elastic Search is in D:\\ES. Logstash is in D:\\LS. In D:\\LS is ls.conf: input { jdbc { jdbc\_driver\_library =\> "D:/LS/mariadb-java-client-3.2.0.jar" jdbc\_driver\_class =\> "org.mariadb.jdbc.Dri…

---

## [Using an index per Board in my application (need help with the Architeture of my elastic search cluster)](https://discuss.elastic.co/t/using-an-index-per-board-in-my-application-need-help-with-the-architeture-of-my-elastic-search-cluster/344340)

<div class="topic-metadata">

**Author:** [@Goalfy\_Services](https://discuss.elastic.co/u/Goalfy_Services)\
**Replies:** 0\
**Last updated:** [October 3, 2023, 7:14pm UTC](https://discuss.elastic.co/t/using-an-index-per-board-in-my-application-need-help-with-the-architeture-of-my-elastic-search-cluster/344340 "2023-10-03T19:14:48Z")

</div>

Good evening, I'm been using Elastic Search for a while and I need some help with my arch design, basically I'm using Elasticsearch for storgin dynamic forms which can have an (n) amount of fields, these forms are stored…

---

## [Elasticsearch performance testing](https://discuss.elastic.co/t/elasticsearch-performance-testing/344335)

<div class="topic-metadata">

**Author:** [@jaykb77](https://discuss.elastic.co/u/jaykb77)\
**Replies:** 0\
**Last updated:** [October 3, 2023, 6:10pm UTC](https://discuss.elastic.co/t/elasticsearch-performance-testing/344335 "2023-10-03T18:10:58Z")

</div>

Hi all, We are trying to come up with performance tests, stress tests etc to calculate throughput and identify bottlenecks in our elasticsearch cluster. We are using elasticsearch exporter to export metrics from the clu…

---

## [Problem updating field via SDK GO](https://discuss.elastic.co/t/problem-updating-field-via-sdk-go/344326)

<div class="topic-metadata">

**Author:** [@Wiliam\_Joaquim](https://discuss.elastic.co/u/Wiliam_Joaquim)\
**Replies:** 0\
**Last updated:** [October 3, 2023, 3:48pm UTC](https://discuss.elastic.co/t/problem-updating-field-via-sdk-go/344326 "2023-10-03T15:48:02Z")

</div>

I'm using the Go SDK to update data in Elasticsearch, but strangely, via the SDK it doesn't update a specific field, via the http client it works correctly sometimes: POST test/type1/123/\_update { "doc": { "asset…

---

## [Using script processor in elastic-agent integration](https://discuss.elastic.co/t/using-script-processor-in-elastic-agent-integration/342632)

<div class="topic-metadata">

**Author:** [@aaszxc](https://discuss.elastic.co/u/aaszxc)\
**Replies:** 1\
**Last updated:** [October 3, 2023, 3:44pm UTC](https://discuss.elastic.co/t/using-script-processor-in-elastic-agent-integration/342632 "2023-10-03T15:44:52Z")

</div>

Need your help. I don't like that using kubernetes integration in elastic-agents we have one event\_dataset for all logs: kubernetes.container\_logs I would like to split it into several. In filebeat this can be done with…

---

## [Unknown certifications?](https://discuss.elastic.co/t/unknown-certifications/344325)

<div class="topic-metadata">

**Author:** [@Daniel\_Calisto](https://discuss.elastic.co/u/Daniel_Calisto)\
**Replies:** 1\
**Last updated:** [October 3, 2023, 3:35pm UTC](https://discuss.elastic.co/t/unknown-certifications/344325 "2023-10-03T15:35:30Z")

</div>

Hi, a client is asking for this certifications, but it seems that they are not part of yours certifications: -Elasticsearch advanced data modeling. -Elasticsearch Developer. Googling I found this document that seems l…

---

## [Customize filebeat connections](https://discuss.elastic.co/t/customize-filebeat-connections/344239)

<div class="topic-metadata">

**Author:** [@yvangarc](https://discuss.elastic.co/u/yvangarc)\
**Replies:** 7\
**Last updated:** [October 3, 2023, 3:28pm UTC](https://discuss.elastic.co/t/customize-filebeat-connections/344239 "2023-10-03T15:28:51Z")

</div>

Hello, We have been given a logstash endpoint, which goes against 2 replicas running on an infra of k8s. What we see is that there is no control of the logstash pod to which we connect, and that many times our clients e…

---

## [Problem when create index template](https://discuss.elastic.co/t/problem-when-create-index-template/344302)

<div class="topic-metadata">

**Author:** [@Joker\_Thanh](https://discuss.elastic.co/u/Joker_Thanh)\
**Replies:** 5\
**Last updated:** [October 3, 2023, 2:04pm UTC](https://discuss.elastic.co/t/problem-when-create-index-template/344302 "2023-10-03T14:04:38Z")

</div>

i have seen problem when create index template based endpoint /\_index/c1s-template { "error" : { "root\_cause" : \[ { "type" : "illegal\_argument\_exception", "reason" : "IOException while readin…

---

## [Trying to query on length of the nested field](https://discuss.elastic.co/t/trying-to-query-on-length-of-the-nested-field/343853)

<div class="topic-metadata">

**Author:** [@Anand\_Konagala](https://discuss.elastic.co/u/Anand_Konagala)\
**Replies:** 7\
**Last updated:** [October 3, 2023, 1:41pm UTC](https://discuss.elastic.co/t/trying-to-query-on-length-of-the-nested-field/343853 "2023-10-03T13:41:07Z")

</div>

Hi, i have a mapping for an index of field resume.profile.locations, which is an nested field Here, I need to perform a scripting query... I am getting error call no mapping for that field but, I gave a mapping for …

---

## [Can't delete index template](https://discuss.elastic.co/t/cant-delete-index-template/344310)

<div class="topic-metadata">

**Author:** [@toddcarv](https://discuss.elastic.co/u/toddcarv)\
**Replies:** 3\
**Last updated:** [October 3, 2023, 1:18pm UTC](https://discuss.elastic.co/t/cant-delete-index-template/344310 "2023-10-03T13:18:43Z")

</div>

Using Kibana 8.8.1 and ES 8.8.1 I deleted an index template as follows and it was acknowledged: DELETE /\_index\_template/my\_template However, when I run the following the template is still there: GET /\_cat/templates?v …

---

## [Getting No mapping Error](https://discuss.elastic.co/t/getting-no-mapping-error/344283)

<div class="topic-metadata">

**Author:** [@Anand\_Konagala](https://discuss.elastic.co/u/Anand_Konagala)\
**Replies:** 1\
**Last updated:** [October 3, 2023, 12:20pm UTC](https://discuss.elastic.co/t/getting-no-mapping-error/344283 "2023-10-03T12:20:26Z")

</div>

Hii, I tried a lot of queries.. but, Its not works.. It through an error.. Can anyone try this Here is my mapping, PUT array\_sort { "mappings": { "properties": { "Skills": { "type": "nested", …

---

## [AWS S3 repository for snapshot/restore in elasticsearch](https://discuss.elastic.co/t/aws-s3-repository-for-snapshot-restore-in-elasticsearch/342503)

<div class="topic-metadata">

**Author:** [@HiteshSingh](https://discuss.elastic.co/u/HiteshSingh)\
**Replies:** 7\
**Last updated:** [October 3, 2023, 11:24am UTC](https://discuss.elastic.co/t/aws-s3-repository-for-snapshot-restore-in-elasticsearch/342503 "2023-10-03T11:24:49Z")

</div>

I want to use AWS S3 bucket for Elasticsearch snapshot/restore of indices. I have read the official doc but I am unable to understand what all properties will be needed in my elasticsearch.yml file to connect to my S3 b…

[Previous page](https://discuss.elastic.co/latest.md?page=521)

[Next page](https://discuss.elastic.co/latest.md?page=523)
