# Latest

**URL:** https://discuss.elastic.co/latest.md?page=523

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 524

---

## [Change the location of an existing snapshot repository](https://discuss.elastic.co/t/change-the-location-of-an-existing-snapshot-repository/344200)

<div class="topic-metadata">

**Author:** [@Russell\_Fulton](https://discuss.elastic.co/u/Russell_Fulton)\
**Replies:** 7\
**Last updated:** [October 3, 2023, 9:40am UTC](https://discuss.elastic.co/t/change-the-location-of-an-existing-snapshot-repository/344200 "2023-10-03T09:40:45Z")

</div>

I need to change the location of the repository: but when I do I get this error: we had to move the mountpoint for the shared disk...

---

## [EBS disk type for High traffic Elasticsearch Cluster](https://discuss.elastic.co/t/ebs-disk-type-for-high-traffic-elasticsearch-cluster/344244)

<div class="topic-metadata">

**Author:** [@SiorMeir](https://discuss.elastic.co/u/SiorMeir)\
**Replies:** 3\
**Last updated:** [October 3, 2023, 9:31am UTC](https://discuss.elastic.co/t/ebs-disk-type-for-high-traffic-elasticsearch-cluster/344244 "2023-10-03T09:31:15Z")

</div>

We encountered a dilemma during the setup of a new cluster of ES version 8 with Elastic Cloud for Kubernetes (EKS) operator on AWS with Elastic Block Storage (EBS) as the data hosting service. EBS offers different speci…

---

## [Looking for confirmation: we cannot use the watcher to 'just' generate reports](https://discuss.elastic.co/t/looking-for-confirmation-we-cannot-use-the-watcher-to-just-generate-reports/343728)

<div class="topic-metadata">

**Author:** [@mpjjonker](https://discuss.elastic.co/u/mpjjonker)\
**Replies:** 1\
**Last updated:** [October 3, 2023, 9:19am UTC](https://discuss.elastic.co/t/looking-for-confirmation-we-cannot-use-the-watcher-to-just-generate-reports/343728 "2023-10-03T09:19:12Z")

</div>

My use case is to schedule reporting but NOT to e-mail them as attachment. On this page, there is an option to call the API using a script, of course we can do this, but than we have to find a scheduling solution outsi…

---

## [Setting min=max in ngram tokenizers](https://discuss.elastic.co/t/setting-min-max-in-ngram-tokenizers/344218)

<div class="topic-metadata">

**Author:** [@cawoodm](https://discuss.elastic.co/u/cawoodm)\
**Replies:** 5\
**Last updated:** [October 3, 2023, 9:09am UTC](https://discuss.elastic.co/t/setting-min-max-in-ngram-tokenizers/344218 "2023-10-03T09:09:05Z")

</div>

The docs suggest setting min=max on ngrams - but this results in a very poor search experience. Assuming 3,3 and searching for "rough" you will never find "trough". Only if you search "tro", "rou" or any other 3 characte…

---

## [How to sory array type field using the length](https://discuss.elastic.co/t/how-to-sory-array-type-field-using-the-length/344210)

<div class="topic-metadata">

**Author:** [@Anand\_Konagala](https://discuss.elastic.co/u/Anand_Konagala)\
**Replies:** 7\
**Last updated:** [October 3, 2023, 8:59am UTC](https://discuss.elastic.co/t/how-to-sory-array-type-field-using-the-length/344210 "2023-10-03T08:59:59Z")

</div>

Hi, I want to create an index having with one array field.. Then, how can I give mapping for that array field which is available to sort using the length of that array. One more thing that it supports that the array hav…

---

## [How to embed kibana dashboard in html code?](https://discuss.elastic.co/t/how-to-embed-kibana-dashboard-in-html-code/343748)

<div class="topic-metadata">

**Author:** [@Jyoti\_Pandey](https://discuss.elastic.co/u/Jyoti_Pandey)\
**Replies:** 11\
**Last updated:** [October 3, 2023, 8:56am UTC](https://discuss.elastic.co/t/how-to-embed-kibana-dashboard-in-html-code/343748 "2023-10-03T08:56:29Z")

</div>

i paste the iframe code in any external site, kibana login page appears when i enter my username and password the login page just gets reloaded and asks for the username and password again. the same process is repeating …

---

## [Elasticsearch span\_multi query rewrite parameter getting same result for top\_terms\_n top\_terms\_boost\_n and top\_terms\_blended\_freqs\_n?](https://discuss.elastic.co/t/elasticsearch-span-multi-query-rewrite-parameter-getting-same-result-for-top-terms-n-top-terms-boost-n-and-top-terms-blended-freqs-n/344295)

<div class="topic-metadata">

**Author:** [@Naman\_Mahor](https://discuss.elastic.co/u/Naman_Mahor)\
**Replies:** 0\
**Last updated:** [October 3, 2023, 8:34am UTC](https://discuss.elastic.co/t/elasticsearch-span-multi-query-rewrite-parameter-getting-same-result-for-top-terms-n-top-terms-boost-n-and-top-terms-blended-freqs-n/344295 "2023-10-03T08:34:01Z")

</div>

I m trying below query with "explain": true on million of articles. but top\_terms, top\_terms\_boost and top\_terms\_blended\_freqs returning me the same result. "query": { "span\_multi": { "match": { "pref…

---

## [Port configured for logstash does not turn up (5044)](https://discuss.elastic.co/t/port-configured-for-logstash-does-not-turn-up-5044/344213)

<div class="topic-metadata">

**Author:** [@Manula\_Manjitha](https://discuss.elastic.co/u/Manula_Manjitha)\
**Replies:** 13\
**Last updated:** [October 3, 2023, 8:11am UTC](https://discuss.elastic.co/t/port-configured-for-logstash-does-not-turn-up-5044/344213 "2023-10-03T08:11:14Z")

</div>

I have configured a logstash on my server and the configurations in /etc/logstash/conf.d/beats.conf file are as follows. input { beats { port =\> 5044 host =\> "192.168.14.189" } } filter { if \[type\] =="sy…

---

## [Getting the facets info using search API facets](https://discuss.elastic.co/t/getting-the-facets-info-using-search-api-facets/344289)

<div class="topic-metadata">

**Author:** [@Aswanth\_Parambath](https://discuss.elastic.co/u/Aswanth_Parambath)\
**Replies:** 0\
**Last updated:** [October 3, 2023, 7:35am UTC](https://discuss.elastic.co/t/getting-the-facets-info-using-search-api-facets/344289 "2023-10-03T07:35:41Z")

</div>

I have data in the format { field1:"data", field2 :{ innerField1 : "data2", innerField2: "data3" } } i want to implement the facets with search AP…

---

## [Kibana discover chart section not showing correct time](https://discuss.elastic.co/t/kibana-discover-chart-section-not-showing-correct-time/344201)

<div class="topic-metadata">

**Author:** [@Geeboy](https://discuss.elastic.co/u/Geeboy)\
**Replies:** 4\
**Last updated:** [October 3, 2023, 7:04am UTC](https://discuss.elastic.co/t/kibana-discover-chart-section-not-showing-correct-time/344201 "2023-10-03T07:04:38Z")

</div>

good day, my script in the backend/source server is running hourly. The behavior of my script will run every hour to capture the previous hour count. my concern is this discover chart (green bar) why it is showing 0800 …

---

## [Can't create API role for Gitlab Advanced Search](https://discuss.elastic.co/t/cant-create-api-role-for-gitlab-advanced-search/344131)

<div class="topic-metadata">

**Author:** [@Oscar\_Yerpes](https://discuss.elastic.co/u/Oscar_Yerpes)\
**Replies:** 2\
**Last updated:** [October 3, 2023, 5:42am UTC](https://discuss.elastic.co/t/cant-create-api-role-for-gitlab-advanced-search/344131 "2023-10-03T05:42:54Z")

</div>

Hi all, As a part of enabling Gitlab Advanced Search using Elastic as a backend, I need to create a role in Elastic. Elastic API returns this error message when doing GET or POST actions: GET \_security/role { "error…

---

## [Little bit confused on min\_age parameter in ilm](https://discuss.elastic.co/t/little-bit-confused-on-min-age-parameter-in-ilm/299049)

<div class="topic-metadata">

**Author:** [@gokulnath112](https://discuss.elastic.co/u/gokulnath112)\
**Replies:** 4\
**Last updated:** [October 3, 2023, 4:12am UTC](https://discuss.elastic.co/t/little-bit-confused-on-min-age-parameter-in-ilm/299049 "2023-10-03T04:12:36Z")

</div>

Greetings...! Im currently using below ilm policy for my project. I just want to know the life span of an index. PUT \_ilm/policy/hot\_warm\_delete { "policy": { "phases": { "hot": { "min\_age": "0ms", "actions": { "…

---

## [Logstash Upgrade and 8.10.1 net snmp error](https://discuss.elastic.co/t/logstash-upgrade-and-8-10-1-net-snmp-error/343307)

<div class="topic-metadata">

**Author:** [@VamPikmin](https://discuss.elastic.co/u/VamPikmin)\
**Replies:** 6\
**Last updated:** [October 3, 2023, 1:39am UTC](https://discuss.elastic.co/t/logstash-upgrade-and-8-10-1-net-snmp-error/343307 "2023-10-03T01:39:51Z")

</div>

After the upgrade logstash doesn't start Any else experience this? Thank you! org.jruby.exceptions.LoadError: (LoadError) no such file to load -- net/smtp at org.jruby.RubyKernel.require(org/jruby/RubyKernel.java:1057)…

---

## [Unable to add APM Integration](https://discuss.elastic.co/t/unable-to-add-apm-integration/344255)

<div class="topic-metadata">

**Author:** [@jwalker](https://discuss.elastic.co/u/jwalker)\
**Replies:** 10\
**Last updated:** [October 3, 2023, 12:29am UTC](https://discuss.elastic.co/t/unable-to-add-apm-integration/344255 "2023-10-03T00:29:12Z")

</div>

Hello, I am following the quick start guide for Elastic APM for version 7.17. Everything went well until I got to Step 3: 'Add the APM integration'. The first instruction is "In Kibana, select Add integrations \> Elastic …

---

## [Turn on Anonymous access](https://discuss.elastic.co/t/turn-on-anonymous-access/343822)

<div class="topic-metadata">

**Author:** [@gabrielpicagevicz](https://discuss.elastic.co/u/gabrielpicagevicz)\
**Replies:** 4\
**Last updated:** [October 3, 2023, 12:19am UTC](https://discuss.elastic.co/t/turn-on-anonymous-access/343822 "2023-10-03T00:19:46Z")

</div>

I currently have version 8.9.1 of Kibana (basic license) installed on my machine. I created an anonymous user with full access to testing I've added the following to Elasticsearch.yml xpack.security.authc: anonymous:…

---

## [What are the use cases of EQL in elasticsearch?](https://discuss.elastic.co/t/what-are-the-use-cases-of-eql-in-elasticsearch/343554)

<div class="topic-metadata">

**Author:** [@jaimika\_kosambia](https://discuss.elastic.co/u/jaimika_kosambia)\
**Replies:** 2\
**Last updated:** [October 2, 2023, 9:56pm UTC](https://discuss.elastic.co/t/what-are-the-use-cases-of-eql-in-elasticsearch/343554 "2023-10-02T21:56:53Z")

</div>

What are the use cases of EQL in elasticsearch , Please explain with example ?

---

## [Can we Pin Column in Lens Table Visualization?](https://discuss.elastic.co/t/can-we-pin-column-in-lens-table-visualization/343534)

<div class="topic-metadata">

**Author:** [@ArpithaS](https://discuss.elastic.co/u/ArpithaS)\
**Replies:** 1\
**Last updated:** [October 2, 2023, 9:50pm UTC](https://discuss.elastic.co/t/can-we-pin-column-in-lens-table-visualization/343534 "2023-10-02T21:50:40Z")

</div>

i have created a table viz using Lens . Can i hide only the column headings in kibana version 7.14? and Pin the first column ?

---

## [No modules or inputs enabled - GCP vpcflow](https://discuss.elastic.co/t/no-modules-or-inputs-enabled-gcp-vpcflow/344246)

<div class="topic-metadata">

**Author:** [@rschirin](https://discuss.elastic.co/u/rschirin)\
**Replies:** 7\
**Last updated:** [October 2, 2023, 9:21pm UTC](https://discuss.elastic.co/t/no-modules-or-inputs-enabled-gcp-vpcflow/344246 "2023-10-02T21:21:54Z")

</div>

hey there, I am really confused about the correct configuration of Filebeat v8.8.1 GCP module. I need to enable the vpcflow module, so I configured the gcp.yml file in this way: - module: gcp vpcflow: enabled: t…

---

## [Elasticsearch 8.9.1 indexing bottleneck on i3.2xlarge and d3.2xlarge nodes in EKS using ECK](https://discuss.elastic.co/t/elasticsearch-8-9-1-indexing-bottleneck-on-i3-2xlarge-and-d3-2xlarge-nodes-in-eks-using-eck/342001)

<div class="topic-metadata">

**Author:** [@Chris\_Austin](https://discuss.elastic.co/u/Chris_Austin)\
**Replies:** 10\
**Last updated:** [October 2, 2023, 8:09pm UTC](https://discuss.elastic.co/t/elasticsearch-8-9-1-indexing-bottleneck-on-i3-2xlarge-and-d3-2xlarge-nodes-in-eks-using-eck/342001 "2023-10-02T20:09:08Z")

</div>

Last May I asked a similar question about performance in 7.17.10, but ran out of things to try and the discussion was auto-closed due to inactivity. I'll avoid repeating the same context info from that post (the initial …

---

## [Error adding a 4th node to existing ES cluster](https://discuss.elastic.co/t/error-adding-a-4th-node-to-existing-es-cluster/344252)

<div class="topic-metadata">

**Author:** [@Bolmar](https://discuss.elastic.co/u/Bolmar)\
**Replies:** 0\
**Last updated:** [October 2, 2023, 6:02pm UTC](https://discuss.elastic.co/t/error-adding-a-4th-node-to-existing-es-cluster/344252 "2023-10-02T18:02:51Z")

</div>

ERROR: Skipping security auto configuration because this node is configured to bootstrap or to join a multi-node cluster, which is not supported. Steps for joining 4th node (First approach): Extract ES software (elast…

---

## [Multiple TCP output plugins in Logstash](https://discuss.elastic.co/t/multiple-tcp-output-plugins-in-logstash/344204)

<div class="topic-metadata">

**Author:** [@Mano](https://discuss.elastic.co/u/Mano)\
**Replies:** 2\
**Last updated:** [October 2, 2023, 3:37pm UTC](https://discuss.elastic.co/t/multiple-tcp-output-plugins-in-logstash/344204 "2023-10-02T15:37:07Z")

</div>

Hi, I am planning to send logs to 2 different servers over TCP. My output section looks looks something like, output { tcp { host =\> "XX.X.XXX.XXX" #ip address of server 1 m…

---

## [Connecting metricbeat to elasticsearch using ssl connection](https://discuss.elastic.co/t/connecting-metricbeat-to-elasticsearch-using-ssl-connection/344121)

<div class="topic-metadata">

**Author:** [@website](https://discuss.elastic.co/u/website)\
**Replies:** 5\
**Last updated:** [October 2, 2023, 2:42pm UTC](https://discuss.elastic.co/t/connecting-metricbeat-to-elasticsearch-using-ssl-connection/344121 "2023-10-02T14:42:36Z")

</div>

Good afternoon, can you help with connecting metricbeat to elasticsearch wazuh The file /etc/elasticsearch/elasticsearch.yml looks like this: network.host: 0.0.0.0 node.name: elasticsearch cluster.initial\_master\_nodes:…

---

## [Unable to authenticate user \[kibana\_system\]](https://discuss.elastic.co/t/unable-to-authenticate-user-kibana-system/344192)

<div class="topic-metadata">

**Author:** [@MdRashid](https://discuss.elastic.co/u/MdRashid)\
**Replies:** 8\
**Last updated:** [October 2, 2023, 2:41pm UTC](https://discuss.elastic.co/t/unable-to-authenticate-user-kibana-system/344192 "2023-10-02T14:41:53Z")

</div>

Hi, Error "type":"log","@timestamp":"2023-10-01T18:33:17+00:00","tags":\["info","plugins-service"\],"pid":1219,"message":"Plugin \\"metricsEntities\\" is disabled."} {"type":"log","@timestamp":"2023-10-01T18:33:17+00:00","…

---

## [Migrating HLRC IndexLifecycleClient to ES:8.8.1](https://discuss.elastic.co/t/migrating-hlrc-indexlifecycleclient-to-es-8-8-1/344236)

<div class="topic-metadata">

**Author:** [@UP2711](https://discuss.elastic.co/u/UP2711)\
**Replies:** 0\
**Last updated:** [October 2, 2023, 2:38pm UTC](https://discuss.elastic.co/t/migrating-hlrc-indexlifecycleclient-to-es-8-8-1/344236 "2023-10-02T14:38:31Z")

</div>

I'm in the process of migrating from Elasticsearch version 7.17.0 to version 8.8.1. In my existing code, I'm using the High-Level Rest Client (HLRC) to manage Index Lifecycle Policies. However, in Elasticsearch version 8…

---

## [Elastic search key, password encryption](https://discuss.elastic.co/t/elastic-search-key-password-encryption/344230)

<div class="topic-metadata">

**Author:** [@Keremcan\_Seker](https://discuss.elastic.co/u/Keremcan_Seker)\
**Replies:** 1\
**Last updated:** [October 2, 2023, 2:32pm UTC](https://discuss.elastic.co/t/elastic-search-key-password-encryption/344230 "2023-10-02T14:32:15Z")

</div>

is it possible to use a encrypted key between client and elasticsearch? i know the question is not very clear because i have little knowledge about the topic. What i need is a encryption system between the people who s…

---

## [Unable to login to kibana with superuser privilege (stuck at completing setup)](https://discuss.elastic.co/t/unable-to-login-to-kibana-with-superuser-privilege-stuck-at-completing-setup/344234)

<div class="topic-metadata">

**Author:** [@poiler22](https://discuss.elastic.co/u/poiler22)\
**Replies:** 0\
**Last updated:** [October 2, 2023, 2:30pm UTC](https://discuss.elastic.co/t/unable-to-login-to-kibana-with-superuser-privilege-stuck-at-completing-setup/344234 "2023-10-02T14:30:47Z")

</div>

I have encountered the problem that Kibana stuck completing setup when I launch it with user super123 When I looked at the log, I found that there's an error stating that Blockquote \[ERROR\]\[savedobjects-service\] \[.kib…

---

## [Wildcard queries \_index field](https://discuss.elastic.co/t/wildcard-queries-index-field/344232)

<div class="topic-metadata">

**Author:** [@frens](https://discuss.elastic.co/u/frens)\
**Replies:** 1\
**Last updated:** [October 2, 2023, 2:28pm UTC](https://discuss.elastic.co/t/wildcard-queries-index-field/344232 "2023-10-02T14:28:05Z")

</div>

We've just upgraded ES from 7.12.0 to 7.17.13 and since then we seem to be unable to run wildcard queries on the \_index field. Is this expected? Is this something we can work around? We have index patterns in Kibana wit…

---

## [Date math questions](https://discuss.elastic.co/t/date-math-questions/344228)

<div class="topic-metadata">

**Author:** [@Thomas\_Barrier](https://discuss.elastic.co/u/Thomas_Barrier)\
**Replies:** 0\
**Last updated:** [October 2, 2023, 2:10pm UTC](https://discuss.elastic.co/t/date-math-questions/344228 "2023-10-02T14:10:21Z")

</div>

Hello everyone, I'm currently working on Kibana 7.17 and could use a little help customising Time filter quick ranges in Kibana's advanced settings. I would like to automatically track my Dashboards from 9am every morn…

---

## [Output syslog plugin](https://discuss.elastic.co/t/output-syslog-plugin/344219)

<div class="topic-metadata">

**Author:** [@Manal\_A](https://discuss.elastic.co/u/Manal_A)\
**Replies:** 2\
**Last updated:** [October 2, 2023, 12:35pm UTC](https://discuss.elastic.co/t/output-syslog-plugin/344219 "2023-10-02T12:35:09Z")

</div>

I'm trying to install output syslog plugin in my virtual machine where there is no network, i didn't find the package in the official elastic website to download it, i found this link to upload it : logstash-output-syslo…

---

## [Distinguishing hybrid search results](https://discuss.elastic.co/t/distinguishing-hybrid-search-results/344086)

<div class="topic-metadata">

**Author:** [@Gabor\_Gergely](https://discuss.elastic.co/u/Gabor_Gergely)\
**Replies:** 2\
**Last updated:** [October 2, 2023, 12:14pm UTC](https://discuss.elastic.co/t/distinguishing-hybrid-search-results/344086 "2023-10-02T12:14:18Z")

</div>

Hi Folks, I perform hybrid search by providing both the knn and a query, like the example in the Elasticsearch Guide: POST image-index/\_search { "query": { "match": { "title": { "query": "mountain l…

[Previous page](https://discuss.elastic.co/latest.md?page=522)

[Next page](https://discuss.elastic.co/latest.md?page=524)
