# Latest

**URL:** https://discuss.elastic.co/latest.md?page=528

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 529

---

## [How to create finger print ingest pipeline for nested field?](https://discuss.elastic.co/t/how-to-create-finger-print-ingest-pipeline-for-nested-field/343845)

<div class="topic-metadata">

**Author:** [@mhsankar](https://discuss.elastic.co/u/mhsankar)\
**Replies:** 2\
**Last updated:** [September 27, 2023, 9:23am UTC](https://discuss.elastic.co/t/how-to-create-finger-print-ingest-pipeline-for-nested-field/343845 "2023-09-27T09:23:58Z")

</div>

Hi every body. I have a mapping with nested field. I want to identify a finger print for every rows in nested field . how can create this ingest pipeline? I\`m using Elasticsearch v 7.17.7 my mapping: PUT test-neste…

---

## [Performance is low when using cluster mode](https://discuss.elastic.co/t/performance-is-low-when-using-cluster-mode/343964)

<div class="topic-metadata">

**Author:** [@AndreWanga](https://discuss.elastic.co/u/AndreWanga)\
**Replies:** 0\
**Last updated:** [September 27, 2023, 9:23am UTC](https://discuss.elastic.co/t/performance-is-low-when-using-cluster-mode/343964 "2023-09-27T09:23:12Z")

</div>

Elasticsearch Version 7.4.0 Java Version from official docker image OS Version from official docker image Problem Description I have set up an Elasticsearch cluster using the official Elasticsearch image. I have confi…

---

## [ElasticSearch Cluster with two Nodes](https://discuss.elastic.co/t/elasticsearch-cluster-with-two-nodes/343874)

<div class="topic-metadata">

**Author:** [@Priyaansh\_Dwivedi](https://discuss.elastic.co/u/Priyaansh_Dwivedi)\
**Replies:** 2\
**Last updated:** [September 27, 2023, 8:37am UTC](https://discuss.elastic.co/t/elasticsearch-cluster-with-two-nodes/343874 "2023-09-27T08:37:15Z")

</div>

I've always appreciated the support of this community, and I hope it can assist me once more. Here's the situation: I currently have Elasticsearch installed on my VM1, but I've encountered disk space issues, and the clus…

---

## [Getting one of index in red and did rolling restart of elastic cluster but still in red](https://discuss.elastic.co/t/getting-one-of-index-in-red-and-did-rolling-restart-of-elastic-cluster-but-still-in-red/343957)

<div class="topic-metadata">

**Author:** [@Jeet\_Lal\_Bhatrai](https://discuss.elastic.co/u/Jeet_Lal_Bhatrai)\
**Replies:** 0\
**Last updated:** [September 27, 2023, 8:27am UTC](https://discuss.elastic.co/t/getting-one-of-index-in-red-and-did-rolling-restart-of-elastic-cluster-but-still-in-red/343957 "2023-09-27T08:27:54Z")

</div>

Getting one of index in red and did rolling restart of elastic cluster but still in red

---

## [ECK apm server failed to to index event (security\_exception): action \[indices:admin/auto\_create\]](https://discuss.elastic.co/t/eck-apm-server-failed-to-to-index-event-security-exception-action-indices-admin-auto-create/343741)

<div class="topic-metadata">

**Author:** [@jijil](https://discuss.elastic.co/u/jijil)\
**Replies:** 6\
**Last updated:** [September 26, 2023, 9:19am UTC](https://discuss.elastic.co/t/eck-apm-server-failed-to-to-index-event-security-exception-action-indices-admin-auto-create/343741 "2023-09-26T09:19:41Z")

</div>

Kibana version:8.5.3 Elasticsearch version:8.5.3 APM Server version:8.5.3 I used the below code for ECK APM apiVersion: apm.k8s.elastic.co/v1 kind: ApmServer metadata: name: apm-server-stg spec: version: 8.5.3 …

---

## [Tutorial elastic search full text query search engine](https://discuss.elastic.co/t/tutorial-elastic-search-full-text-query-search-engine/343929)

<div class="topic-metadata">

**Author:** [@cmansilla](https://discuss.elastic.co/u/cmansilla)\
**Replies:** 1\
**Last updated:** [September 27, 2023, 5:36am UTC](https://discuss.elastic.co/t/tutorial-elastic-search-full-text-query-search-engine/343929 "2023-09-27T05:36:23Z")

</div>

Hi im looking for tutorial about build a search engine (proof of concept in windows or centos) with Elasticsearch, any idea where i can start?, we have about 500k files (html, word and pdf files) for start, we was search…

---

## [How can I fix this to suggest phrases after say, three characters have been entered?](https://discuss.elastic.co/t/how-can-i-fix-this-to-suggest-phrases-after-say-three-characters-have-been-entered/343755)

<div class="topic-metadata">

**Author:** [@Bhavyagc](https://discuss.elastic.co/u/Bhavyagc)\
**Replies:** 7\
**Last updated:** [September 27, 2023, 4:34am UTC](https://discuss.elastic.co/t/how-can-i-fix-this-to-suggest-phrases-after-say-three-characters-have-been-entered/343755 "2023-09-27T04:34:30Z")

</div>

My query { "suggest": { "text" : "Tes", "simple\_phrase" : { "phrase" : { "field" : "Active\_Substance\_mstr.trigram", "size" : 1, "max\_errors" : 6, "direct\_generator" : \[ { "field" : "Active\_Substan…

---

## [Please suggest best mechanism to sync from Mongo db to elastic search in kubernetes (on prem)?](https://discuss.elastic.co/t/please-suggest-best-mechanism-to-sync-from-mongo-db-to-elastic-search-in-kubernetes-on-prem/343937)

<div class="topic-metadata">

**Author:** [@siva\_k](https://discuss.elastic.co/u/siva_k)\
**Replies:** 1\
**Last updated:** [September 27, 2023, 4:22am UTC](https://discuss.elastic.co/t/please-suggest-best-mechanism-to-sync-from-mongo-db-to-elastic-search-in-kubernetes-on-prem/343937 "2023-09-27T04:22:33Z")

</div>

Please suggest best mechanism to sync from Mongo db to Elasticsearch in kubernetes (on prem)? Thank you

---

## [How to replace fleet tls cert when expired?](https://discuss.elastic.co/t/how-to-replace-fleet-tls-cert-when-expired/343941)

<div class="topic-metadata">

**Author:** [@chengye233](https://discuss.elastic.co/u/chengye233)\
**Replies:** 0\
**Last updated:** [September 27, 2023, 2:11am UTC](https://discuss.elastic.co/t/how-to-replace-fleet-tls-cert-when-expired/343941 "2023-09-27T02:11:58Z")

</div>

Hi, I'm using fleet -server with tls cert. Recently, the cert will be expired and I need to replace a new one. All elastic-stack version is 8.4 Last year, I used this command to install: sudo elastic-agent-8.4.3-linux…

---

## [\[indices:admin/flush\[s\]\[r\]\] is unauthorized for user \[user\] with effective roles \[grant\_kibana\_system\_indices,superuser\] on restricted indices \[my-restricted-index\], this action is granted by the index privileges \[maintenance,manage,all\]](https://discuss.elastic.co/t/indices-admin-flush-s-r-is-unauthorized-for-user-user-with-effective-roles-grant-kibana-system-indices-superuser-on-restricted-indices-my-restricted-index-this-action-is-granted-by-the-index-privileges-maintenance-manage-all/343629)

<div class="topic-metadata">

**Author:** [@emi\_rose](https://discuss.elastic.co/u/emi_rose)\
**Replies:** 2\
**Last updated:** [September 26, 2023, 11:32pm UTC](https://discuss.elastic.co/t/indices-admin-flush-s-r-is-unauthorized-for-user-user-with-effective-roles-grant-kibana-system-indices-superuser-on-restricted-indices-my-restricted-index-this-action-is-granted-by-the-index-privileges-maintenance-manage-all/343629 "2023-09-26T23:32:53Z")

</div>

Continuing the discussion from Action \[indices:admin/flush\[s\]\] is unauthorized for user \[admin\] with roles \[superuser\] on restricted indices \[.kibana\_task\_manager\_7.17.5\_001\], this action is granted by the index privileg…

---

## [Elastic connectors release version download error](https://discuss.elastic.co/t/elastic-connectors-release-version-download-error/343933)

<div class="topic-metadata">

**Author:** [@siva\_k](https://discuss.elastic.co/u/siva_k)\
**Replies:** 0\
**Last updated:** [September 26, 2023, 9:45pm UTC](https://discuss.elastic.co/t/elastic-connectors-release-version-download-error/343933 "2023-09-26T21:45:42Z")

</div>

Hi, May I know how to get the elastic connector release version (I can successfully download and install snap shot version but getting an error during the release version) ? container\_name: els\_connector image: docker…

---

## [Mysql slow log](https://discuss.elastic.co/t/mysql-slow-log/343917)

<div class="topic-metadata">

**Author:** [@danmed](https://discuss.elastic.co/u/danmed)\
**Replies:** 1\
**Last updated:** [September 26, 2023, 8:28pm UTC](https://discuss.elastic.co/t/mysql-slow-log/343917 "2023-09-26T20:28:54Z")

</div>

Hi all, I am not able to successfully parse Mysql's slow log using logstash. The log file: # Time: 2018-02-27T09:20:14.122543Z # User@Host: user\[user\] @ \[nnn.nnn.nnn.nn\] Id: 148 # Query\_time: 10.275441 Lock\_time: …

---

## [Term query by \_id very slow (30s+) occasionally](https://discuss.elastic.co/t/term-query-by-id-very-slow-30s-occasionally/343305)

<div class="topic-metadata">

**Author:** [@May\_Zeng](https://discuss.elastic.co/u/May_Zeng)\
**Replies:** 20\
**Last updated:** [September 26, 2023, 8:10pm UTC](https://discuss.elastic.co/t/term-query-by-id-very-slow-30s-occasionally/343305 "2023-09-26T20:10:48Z")

</div>

Mapping: { "dynamic": "strict", "\_source": { "enabled": false }, "properties": { "data": { "type": "binary", "doc\_values": false, "store": true } } } Query: {"query":{ "bool" …

---

## [Easy way to parse flattened data type?](https://discuss.elastic.co/t/easy-way-to-parse-flattened-data-type/343926)

<div class="topic-metadata">

**Author:** [@elasticnub](https://discuss.elastic.co/u/elasticnub)\
**Replies:** 0\
**Last updated:** [September 26, 2023, 7:59pm UTC](https://discuss.elastic.co/t/easy-way-to-parse-flattened-data-type/343926 "2023-09-26T19:59:21Z")

</div>

While I understand the reasoning behind the flattened data type, is there an easy way to split key value pairs out as their own field to use with dashboards / aggregations etc. IE - m365\_defender.event.activity.objects …

---

## [How to close co.elastic.clients.elasticsearch.ElasticsearchClient](https://discuss.elastic.co/t/how-to-close-co-elastic-clients-elasticsearch-elasticsearchclient/343922)

<div class="topic-metadata">

**Author:** [@toddcarv](https://discuss.elastic.co/u/toddcarv)\
**Replies:** 2\
**Last updated:** [September 26, 2023, 7:55pm UTC](https://discuss.elastic.co/t/how-to-close-co-elastic-clients-elasticsearch-elasticsearchclient/343922 "2023-09-26T19:55:55Z")

</div>

The HLRC client had a .close() method. Can anyone tell me the correct way to close the new client? Thanks.

---

## [What field shows sign-in due to app or hardware token?](https://discuss.elastic.co/t/what-field-shows-sign-in-due-to-app-or-hardware-token/343925)

<div class="topic-metadata">

**Author:** [@BabyElkUser](https://discuss.elastic.co/u/BabyElkUser)\
**Replies:** 0\
**Last updated:** [September 26, 2023, 7:49pm UTC](https://discuss.elastic.co/t/what-field-shows-sign-in-due-to-app-or-hardware-token/343925 "2023-09-26T19:49:16Z")

</div>

I'm in Filebeat and am hoping that someone can please help me find the field that holds the information as to whether someone is signing in with an app, like the MFA app, or with a hardware token. This is getting me all…

---

## [Elasticsearch index has multiple document ids](https://discuss.elastic.co/t/elasticsearch-index-has-multiple-document-ids/343923)

<div class="topic-metadata">

**Author:** [@PodarcisMuralis](https://discuss.elastic.co/u/PodarcisMuralis)\
**Replies:** 1\
**Last updated:** [September 26, 2023, 7:36pm UTC](https://discuss.elastic.co/t/elasticsearch-index-has-multiple-document-ids/343923 "2023-09-26T19:36:59Z")

</div>

Hi. I am using Logstash / Elasticsearch (8.5.3) and am indexing json data. In logstash I use http input plugin, filter plugins and elasticsearch output. Currently the auto generated @version field in logstash filter i…

---

## [Not eligible for data streams because config contains one or more settings that are not compatible with data streams: {"index"=\>"logstash-%{+YYYY.MM.dd}"}](https://discuss.elastic.co/t/not-eligible-for-data-streams-because-config-contains-one-or-more-settings-that-are-not-compatible-with-data-streams-index-logstash-yyyy-mm-dd/343803)

<div class="topic-metadata">

**Author:** [@Dinoo](https://discuss.elastic.co/u/Dinoo)\
**Replies:** 7\
**Last updated:** [September 26, 2023, 7:13pm UTC](https://discuss.elastic.co/t/not-eligible-for-data-streams-because-config-contains-one-or-more-settings-that-are-not-compatible-with-data-streams-index-logstash-yyyy-mm-dd/343803 "2023-09-26T19:13:13Z")

</div>

Hi, I am working on the ELK stack using Docker compose. I am following this tutorial: Getting started with the Elastic Stack and Docker-Compose | Elastic Blog. Everything works except Logstash. When I run docker-compose …

---

## [Elastic agent dropwizard configuration](https://discuss.elastic.co/t/elastic-agent-dropwizard-configuration/343920)

<div class="topic-metadata">

**Author:** [@umesh2020](https://discuss.elastic.co/u/umesh2020)\
**Replies:** 0\
**Last updated:** [September 26, 2023, 6:48pm UTC](https://discuss.elastic.co/t/elastic-agent-dropwizard-configuration/343920 "2023-09-26T18:48:37Z")

</div>

Does elastic agent support dropwizard configuration ? I couldn't find any documentation on how to enable dropwizard configuration using elastic agent. I am running elastic agent in kubernetes, and would like to know ho…

---

## [Downgrade from ES 8.10.1 TO 8.9.2](https://discuss.elastic.co/t/downgrade-from-es-8-10-1-to-8-9-2/343919)

<div class="topic-metadata">

**Author:** [@balakr](https://discuss.elastic.co/u/balakr)\
**Replies:** 3\
**Last updated:** [September 26, 2023, 6:22pm UTC](https://discuss.elastic.co/t/downgrade-from-es-8-10-1-to-8-9-2/343919 "2023-09-26T18:22:49Z")

</div>

I would like to upgrade my ES to 8.10.1, i want to have the option to downgrade if tests fails. i did my search and did not find any breaking change between 8.9 to 8.10, wanted to confirm is downgrade is possible. ex., …

---

## [Question for storage types for hot nodes on Elastic Cloud](https://discuss.elastic.co/t/question-for-storage-types-for-hot-nodes-on-elastic-cloud/343790)

<div class="topic-metadata">

**Author:** [@Ray\_Zhang](https://discuss.elastic.co/u/Ray_Zhang)\
**Replies:** 2\
**Last updated:** [September 26, 2023, 5:42pm UTC](https://discuss.elastic.co/t/question-for-storage-types-for-hot-nodes-on-elastic-cloud/343790 "2023-09-26T17:42:49Z")

</div>

I was checking the fact sheets for " Elasticsearch Service GCP default provider instance configurations" on elastic website and noticed that the storage type is "NVME" for the hot nodes instead of "Zonal SSD Persistent D…

---

## [Restrict nested data in result of search](https://discuss.elastic.co/t/restrict-nested-data-in-result-of-search/343918)

<div class="topic-metadata">

**Author:** [@TomTom](https://discuss.elastic.co/u/TomTom)\
**Replies:** 0\
**Last updated:** [September 26, 2023, 5:38pm UTC](https://discuss.elastic.co/t/restrict-nested-data-in-result-of-search/343918 "2023-09-26T17:38:21Z")

</div>

I have a index that stores tasks to do, in it there is a user id, task id and inside there is nested data that is used to store a timer that the user started and finished working on a task. I have a script that I used i…

---

## [Indexing Subtitles and Maintaining Timestamps](https://discuss.elastic.co/t/indexing-subtitles-and-maintaining-timestamps/343708)

<div class="topic-metadata">

**Author:** [@ADarkDividedGem](https://discuss.elastic.co/u/ADarkDividedGem)\
**Replies:** 7\
**Last updated:** [September 26, 2023, 5:32pm UTC](https://discuss.elastic.co/t/indexing-subtitles-and-maintaining-timestamps/343708 "2023-09-26T17:32:00Z")

</div>

I am wanting to index subtitles and also maintain the timestamp data. My initial thought was to make each line of text a document with the start and end timestamps stored as fields for that document. For example the fol…

---

## [Error when querying Elasticsearch from Logstash](https://discuss.elastic.co/t/error-when-querying-elasticsearch-from-logstash/343907)

<div class="topic-metadata">

**Author:** [@subash](https://discuss.elastic.co/u/subash)\
**Replies:** 0\
**Last updated:** [September 26, 2023, 3:19pm UTC](https://discuss.elastic.co/t/error-when-querying-elasticsearch-from-logstash/343907 "2023-09-26T15:19:17Z")

</div>

I'm using Elasticsearch input plugin in logstash to query the Elastic data. But I'm getting the below error Ignoring clear\_scroll exception {:message=\>"\[404\] {\\"succeeded\\":true,\\"num\_freed\\":0}", :exception=\>Elasticsea…

---

## [Email action message](https://discuss.elastic.co/t/email-action-message/343910)

<div class="topic-metadata">

**Author:** [@ramiwashere](https://discuss.elastic.co/u/ramiwashere)\
**Replies:** 0\
**Last updated:** [September 26, 2023, 3:55pm UTC](https://discuss.elastic.co/t/email-action-message/343910 "2023-09-26T15:55:52Z")

</div>

Hello, I have an alert using rule from security section. My aim is to gather some information into the mail alert from the alert: In my example, I would like to take the username & the ip: {{#context.hits}} Username:…

---

## [Trace Search](https://discuss.elastic.co/t/trace-search/343908)

<div class="topic-metadata">

**Author:** [@techtuga](https://discuss.elastic.co/u/techtuga)\
**Replies:** 0\
**Last updated:** [September 26, 2023, 3:26pm UTC](https://discuss.elastic.co/t/trace-search/343908 "2023-09-26T15:26:37Z")

</div>

Hi there, We are getting application feeds from an opentelemetry/java 1.23.1 agent, trough Otel Collector 0.82.0 to APM 8.9.1 Server, the feeds are arriving fine into the APM index: Anyway when trying to to filter u…

---

## [Discovery in multi node cluster using docker compose](https://discuss.elastic.co/t/discovery-in-multi-node-cluster-using-docker-compose/343199)

<div class="topic-metadata">

**Author:** [@JoyceBabu](https://discuss.elastic.co/u/JoyceBabu)\
**Replies:** 2\
**Last updated:** [September 26, 2023, 3:21pm UTC](https://discuss.elastic.co/t/discovery-in-multi-node-cluster-using-docker-compose/343199 "2023-09-26T15:21:38Z")

</div>

I am trying to create a three node ElasticSEarch cluster following the tutorial When I set cluster.initial\_master\_nodes to es1,es2,es3, I am getting the warning this node is locked into cluster UUID \[lUWf3vbtRcarnQX…

---

## [How to add persistent data to filebeat](https://discuss.elastic.co/t/how-to-add-persistent-data-to-filebeat/341981)

<div class="topic-metadata">

**Author:** [@A\_Mightiev](https://discuss.elastic.co/u/A_Mightiev)\
**Replies:** 4\
**Last updated:** [September 26, 2023, 2:55pm UTC](https://discuss.elastic.co/t/how-to-add-persistent-data-to-filebeat/341981 "2023-09-26T14:55:15Z")

</div>

I have some log files that only in the first line it will display the version of the file, but I want to use that version everywhere in the log. is there a way I can store that data and use it for the rest of the file? …

---

## [Can't connect to autonomoous oracledb cloud](https://discuss.elastic.co/t/cant-connect-to-autonomoous-oracledb-cloud/343081)

<div class="topic-metadata">

**Author:** [@A\_Mightiev](https://discuss.elastic.co/u/A_Mightiev)\
**Replies:** 1\
**Last updated:** [September 26, 2023, 2:54pm UTC](https://discuss.elastic.co/t/cant-connect-to-autonomoous-oracledb-cloud/343081 "2023-09-26T14:54:13Z")

</div>

Hi I can't connect to an oracle db in oracle cloud, it gives me an error Got minus one from a read call. I've been trying many things in the discussions but nothing seems to work for me: this is my input: input{ j…

---

## [Packetbeat MongoDB in Windows Server doesn't work](https://discuss.elastic.co/t/packetbeat-mongodb-in-windows-server-doesnt-work/343903)

<div class="topic-metadata">

**Author:** [@A\_Mightiev](https://discuss.elastic.co/u/A_Mightiev)\
**Replies:** 0\
**Last updated:** [September 26, 2023, 2:53pm UTC](https://discuss.elastic.co/t/packetbeat-mongodb-in-windows-server-doesnt-work/343903 "2023-09-26T14:53:30Z")

</div>

Hi I'm trying to monitor mongodb connections using packetbeat, doing it locally on my mongodb works fine: this is my configuration: packetbeat.interfaces: - device: \\Device\\NPF\_{422A5385-8A2F-46AB-8B71-2C94764B14FA} …

[Previous page](https://discuss.elastic.co/latest.md?page=527)

[Next page](https://discuss.elastic.co/latest.md?page=529)
