# Latest

**URL:** https://discuss.elastic.co/latest.md?page=566

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 567

---

## [Coerce seems not working](https://discuss.elastic.co/t/coerce-seems-not-working/341019)

<div class="topic-metadata">

**Author:** [@Jan\_Vavra](https://discuss.elastic.co/u/Jan_Vavra)\
**Replies:** 2\
**Last updated:** [August 22, 2023, 7:33am UTC](https://discuss.elastic.co/t/coerce-seems-not-working/341019 "2023-08-22T07:33:54Z")

</div>

I am constructing datetime from directory structure, eg. 2023\\08\\17\\15\\08 represent files stored at 2023-08-17 15:08. I have this logstash.conf that parses each directory name into variables and hours and minutes are opt…

---

## [Index creating through logstash and show on kibana index pattern](https://discuss.elastic.co/t/index-creating-through-logstash-and-show-on-kibana-index-pattern/340972)

<div class="topic-metadata">

**Author:** [@bharti](https://discuss.elastic.co/u/bharti)\
**Replies:** 5\
**Last updated:** [August 22, 2023, 7:05am UTC](https://discuss.elastic.co/t/index-creating-through-logstash-and-show-on-kibana-index-pattern/340972 "2023-08-22T07:05:35Z")

</div>

Hello , I need a help on configuration of logstash output section....i want to create an index and fetch some particular logs on that index...whenever am creating a new index it is not showing on kibana output { if "…

---

## [Failed to retrieve password hash for reserved user \[elastic\]](https://discuss.elastic.co/t/failed-to-retrieve-password-hash-for-reserved-user-elastic/341330)

<div class="topic-metadata">

**Author:** [@nairobi](https://discuss.elastic.co/u/nairobi)\
**Replies:** 0\
**Last updated:** [August 22, 2023, 7:03am UTC](https://discuss.elastic.co/t/failed-to-retrieve-password-hash-for-reserved-user-elastic/341330 "2023-08-22T07:03:20Z")

</div>

I upgraded elasticsearch cluster 7.17 to 8.9 version. I used "yum update elasticsearch" command to upgrade. It is upgraded successfully. But when i try to start elasticsearch, it couldn't start. How can i solve it? e…

---

## [Answers | Practice Exam: Elastic Certified Observability Engineer](https://discuss.elastic.co/t/answers-practice-exam-elastic-certified-observability-engineer/341265)

<div class="topic-metadata">

**Author:** [@AmitKakkad](https://discuss.elastic.co/u/AmitKakkad)\
**Replies:** 1\
**Last updated:** [August 22, 2023, 6:53am UTC](https://discuss.elastic.co/t/answers-practice-exam-elastic-certified-observability-engineer/341265 "2023-08-22T06:53:15Z")

</div>

Course: Elastic Certified Observability Engineer Version: 7.9 Question: Why are there no solutions to this Practice Exam? There were solutions for the "Elastic Certified Analyst Practice Exam". Some of the questions n…

---

## [UDP-input Receiving an encoding value �](https://discuss.elastic.co/t/udp-input-receiving-an-encoding-value/341199)

<div class="topic-metadata">

**Author:** [@aurangzeb99](https://discuss.elastic.co/u/aurangzeb99)\
**Replies:** 7\
**Last updated:** [August 22, 2023, 6:36am UTC](https://discuss.elastic.co/t/udp-input-receiving-an-encoding-value/341199 "2023-08-22T06:36:03Z")

</div>

Hi I am using logstash udp input and in elasticsearch field event.original have true values. but in a document field.DeviceCapabilities value is "�" and for field.PoleCapabilities is empty. fieldname: event.original Va…

---

## [Elasticsearch cluster certs configuration](https://discuss.elastic.co/t/elasticsearch-cluster-certs-configuration/341320)

<div class="topic-metadata">

**Author:** [@ANUBHAV\_GUPTA](https://discuss.elastic.co/u/ANUBHAV_GUPTA)\
**Replies:** 0\
**Last updated:** [August 22, 2023, 5:18am UTC](https://discuss.elastic.co/t/elasticsearch-cluster-certs-configuration/341320 "2023-08-22T05:18:10Z")

</div>

Hey there, I am trying to run ES cluster of let's say 3 nodes. I am using volume mount in docker to mount my self signed certificates. And here is the command I am using:- sudo docker run -it --privileged -p 9200:92…

---

## [AFTER changed DATA STREAM INDEX template, index stay 225b,](https://discuss.elastic.co/t/after-changed-data-stream-index-template-index-stay-225b/341293)

<div class="topic-metadata">

**Author:** [@cLaYYs](https://discuss.elastic.co/u/cLaYYs)\
**Replies:** 1\
**Last updated:** [August 22, 2023, 4:54am UTC](https://discuss.elastic.co/t/after-changed-data-stream-index-template-index-stay-225b/341293 "2023-08-22T04:54:20Z")

</div>

Hi All, We use custom UDP integration(fleet managed integration) to collect Linux auth logs. We set the default pipeline for auth logs which is \[logs-system.auth-default\]. We did parse the data as we expected. This dat…

---

## [Geo fields at root?](https://discuss.elastic.co/t/geo-fields-at-root/341307)

<div class="topic-metadata">

**Author:** [@rsk0](https://discuss.elastic.co/u/rsk0)\
**Replies:** 1\
**Last updated:** [August 22, 2023, 12:58am UTC](https://discuss.elastic.co/t/geo-fields-at-root/341307 "2023-08-22T00:58:17Z")

</div>

ECS geo docs say: The geo fields are expected to be nested at: client.geo destination.geo host.geo server.geo ... Note also that the geo fields are not expected to be used directly at the root of the events. I was …

---

## [A good place for "state of being a canary" field](https://discuss.elastic.co/t/a-good-place-for-state-of-being-a-canary-field/340690)

<div class="topic-metadata">

**Author:** [@rsk0](https://discuss.elastic.co/u/rsk0)\
**Replies:** 5\
**Last updated:** [August 21, 2023, 11:21pm UTC](https://discuss.elastic.co/t/a-good-place-for-state-of-being-a-canary-field/340690 "2023-08-21T23:21:14Z")

</div>

Where do you think is a good place to indicate that a log message is from a canary? orchestration.\* doesn't seem appropriate. Maybe something in the upcoming node field set? (Where do I find information about that?) I…

---

## [How to specify ILM policies in Elastic agent policy config?](https://discuss.elastic.co/t/how-to-specify-ilm-policies-in-elastic-agent-policy-config/341296)

<div class="topic-metadata">

**Author:** [@Craig\_Rodrigues](https://discuss.elastic.co/u/Craig_Rodrigues)\
**Replies:** 5\
**Last updated:** [August 21, 2023, 10:48pm UTC](https://discuss.elastic.co/t/how-to-specify-ilm-policies-in-elastic-agent-policy-config/341296 "2023-08-21T22:48:50Z")

</div>

I have about 2000 Elastic agents (version 8.9.0) connected to a system with 3 Fleet servers (version 8.9.0). We have about 20 different agent policies, because the various Elastic agents are sending slightly different …

---

## [Update indices replica set in Elasticsearch cluster](https://discuss.elastic.co/t/update-indices-replica-set-in-elasticsearch-cluster/341149)

<div class="topic-metadata">

**Author:** [@ahmed.emad](https://discuss.elastic.co/u/ahmed.emad)\
**Replies:** 1\
**Last updated:** [August 21, 2023, 10:32pm UTC](https://discuss.elastic.co/t/update-indices-replica-set-in-elasticsearch-cluster/341149 "2023-08-21T22:32:59Z")

</div>

Hello, I would like to update the number of replicas for newly creating indices to be 5 automatically, so i used the below curl curl -XPUT -k -u elastic:password 'https://192.168.x.x:9200/\_index\_template/my\_template' -…

---

## [Docker image "elastic-connectors:8.9.1.0" for ARM64 architecture?](https://discuss.elastic.co/t/docker-image-elastic-connectors-8-9-1-0-for-arm64-architecture/341302)

<div class="topic-metadata">

**Author:** [@lenny1](https://discuss.elastic.co/u/lenny1)\
**Replies:** 0\
**Last updated:** [August 21, 2023, 9:16pm UTC](https://discuss.elastic.co/t/docker-image-elastic-connectors-8-9-1-0-for-arm64-architecture/341302 "2023-08-21T21:16:09Z")

</div>

Hello, I want to deploy the Enterprise Search MySQL connector docker image on an ARM64 architecture host. Is there a ARM64 docker image for: "enterprise-search/elastic-connectors:8.9.1.0" ? Best regards, Martin

---

## [Pinned Filters Passed Through Dashboard URL Are Not Applied](https://discuss.elastic.co/t/pinned-filters-passed-through-dashboard-url-are-not-applied/340162)

<div class="topic-metadata">

**Author:** [@kevfar](https://discuss.elastic.co/u/kevfar)\
**Replies:** 3\
**Last updated:** [August 21, 2023, 8:41pm UTC](https://discuss.elastic.co/t/pinned-filters-passed-through-dashboard-url-are-not-applied/340162 "2023-08-21T20:41:20Z")

</div>

Hello! I recently posted a question regarding this issue, but unfortunately the topic was closed before I got around to responding to the first reply. I am working for a company that utilizes Kibana dashboards to view cl…

---

## [Replica count 3 for .security-7](https://discuss.elastic.co/t/replica-count-3-for-security-7/341274)

<div class="topic-metadata">

**Author:** [@data\_smith](https://discuss.elastic.co/u/data_smith)\
**Replies:** 1\
**Last updated:** [August 21, 2023, 7:27pm UTC](https://discuss.elastic.co/t/replica-count-3-for-security-7/341274 "2023-08-21T19:27:06Z")

</div>

I'm trying to set the replica count for .security-7 to 3 so that if 2 nodes go down it's still ok. But it seems superuser can't update it. What's the best path forward for this situation. The docs don't really answer …

---

## [Changing to Service type of LoadBalancer from ClusterIP on ECK Operator Breaks](https://discuss.elastic.co/t/changing-to-service-type-of-loadbalancer-from-clusterip-on-eck-operator-breaks/341276)

<div class="topic-metadata">

**Author:** [@bigjoe21](https://discuss.elastic.co/u/bigjoe21)\
**Replies:** 1\
**Last updated:** [August 21, 2023, 6:04pm UTC](https://discuss.elastic.co/t/changing-to-service-type-of-loadbalancer-from-clusterip-on-eck-operator-breaks/341276 "2023-08-21T18:04:29Z")

</div>

I went through the quickstart and successfully deployed elasticsearch and kibana on EKS using the ECK operator. I then followed the directions in the docs to allow public access. However, the ECK Operator keeps throwing…

---

## [Data is being shown sometimes without access](https://discuss.elastic.co/t/data-is-being-shown-sometimes-without-access/340968)

<div class="topic-metadata">

**Author:** [@Amol\_Gaitonde1](https://discuss.elastic.co/u/Amol_Gaitonde1)\
**Replies:** 2\
**Last updated:** [August 21, 2023, 5:57pm UTC](https://discuss.elastic.co/t/data-is-being-shown-sometimes-without-access/340968 "2023-08-21T17:57:39Z")

</div>

We are on elastic version 8.8.1, build\_flavor is default and build\_type is docker. We have created an user test\_user with role role\_1 which has access to index\_1 and no other index. We are noticing a security issue that…

---

## [Elastic defend certificate error on windows when connecting to ES](https://discuss.elastic.co/t/elastic-defend-certificate-error-on-windows-when-connecting-to-es/341161)

<div class="topic-metadata">

**Author:** [@pushou](https://discuss.elastic.co/u/pushou)\
**Replies:** 2\
**Last updated:** [August 21, 2023, 5:53pm UTC](https://discuss.elastic.co/t/elastic-defend-certificate-error-on-windows-when-connecting-to-es/341161 "2023-08-21T17:53:34Z")

</div>

Elastic agent is working and was registered with ca.crt file path on windows 2019 server. Elastic defend integration failed to connect to ES with this message:"Elasticsearch connection failure" Looking at logs give me …

---

## [Filebeat Intermittently Hanging with Increasing Memory Cache while Processing High-Traffic Nginx Accesslog](https://discuss.elastic.co/t/filebeat-intermittently-hanging-with-increasing-memory-cache-while-processing-high-traffic-nginx-accesslog/339335)

<div class="topic-metadata">

**Author:** [@ryoni88](https://discuss.elastic.co/u/ryoni88)\
**Replies:** 5\
**Last updated:** [August 21, 2023, 5:07pm UTC](https://discuss.elastic.co/t/filebeat-intermittently-hanging-with-increasing-memory-cache-while-processing-high-traffic-nginx-accesslog/339335 "2023-08-21T17:07:09Z")

</div>

Hello, I have set up a process using Filebeat to send a high traffic Nginx accesslog to Logstash. However, Filebeat intermittently hangs, with a consistent pattern of increasing memory cache. Both Filebeat and Nginx ar…

---

## [Create a rule or alert to monitor when its not receiving logs by 24 hours?](https://discuss.elastic.co/t/create-a-rule-or-alert-to-monitor-when-its-not-receiving-logs-by-24-hours/340932)

<div class="topic-metadata">

**Author:** [@lucasyuki](https://discuss.elastic.co/u/lucasyuki)\
**Replies:** 1\
**Last updated:** [August 21, 2023, 5:00pm UTC](https://discuss.elastic.co/t/create-a-rule-or-alert-to-monitor-when-its-not-receiving-logs-by-24-hours/340932 "2023-08-21T17:00:37Z")

</div>

Hi, I've been trying to check how to create this type of rule in the forum and I saw that other people have the same problem

---

## [Difference between Elasticsearch Security and Watcher Setting in Elasticsearch](https://discuss.elastic.co/t/difference-between-elasticsearch-security-and-watcher-setting-in-elasticsearch/341173)

<div class="topic-metadata">

**Author:** [@ANUBHAV\_GUPTA](https://discuss.elastic.co/u/ANUBHAV_GUPTA)\
**Replies:** 20\
**Last updated:** [August 21, 2023, 4:59pm UTC](https://discuss.elastic.co/t/difference-between-elasticsearch-security-and-watcher-setting-in-elasticsearch/341173 "2023-08-21T16:59:38Z")

</div>

Hi there, I am looking to set security on http and transport layer. But I am confused in what to use between the following: xpack.security.transport.ssl.verification\_mode=certificate xpack.transport.ssl.verification\_…

---

## [Null value in field type with nested](https://discuss.elastic.co/t/null-value-in-field-type-with-nested/341278)

<div class="topic-metadata">

**Author:** [@Murilo\_Livorato](https://discuss.elastic.co/u/Murilo_Livorato)\
**Replies:** 0\
**Last updated:** [August 21, 2023, 4:18pm UTC](https://discuss.elastic.co/t/null-value-in-field-type-with-nested/341278 "2023-08-21T16:18:24Z")

</div>

I have a filed , that if has value , it has ID and TITLE . so , wold be like this - category: { id: 2, title: 'monitor' } but can be like this as well category: NULL So I did like this the mapping - "category":…

---

## [Cannot change log format with pipeline config file, pipeline config file is not getting read](https://discuss.elastic.co/t/cannot-change-log-format-with-pipeline-config-file-pipeline-config-file-is-not-getting-read/340081)

<div class="topic-metadata">

**Author:** [@Jenkins-Jobs](https://discuss.elastic.co/u/Jenkins-Jobs)\
**Replies:** 7\
**Last updated:** [August 21, 2023, 4:04pm UTC](https://discuss.elastic.co/t/cannot-change-log-format-with-pipeline-config-file-pipeline-config-file-is-not-getting-read/340081 "2023-08-21T16:04:30Z")

</div>

Greetings, First time posting here, elasticsearch 8.9 rhel 7 I am getting logs from jenkins jobs using logstash plugin with no issues the only mime type that seems to work is "application/json" If i try any other t…

---

## [Watcher API - ACK with Action Conditions](https://discuss.elastic.co/t/watcher-api-ack-with-action-conditions/341277)

<div class="topic-metadata">

**Author:** [@Charles614](https://discuss.elastic.co/u/Charles614)\
**Replies:** 0\
**Last updated:** [August 21, 2023, 3:59pm UTC](https://discuss.elastic.co/t/watcher-api-ack-with-action-conditions/341277 "2023-08-21T15:59:54Z")

</div>

Hello all, I have been building a Watcher that has a transform and then any number of actions dependent upon user input. I want to make it to where a user can ACK a specific action in order to allow throttling. The way…

---

## [Manually import the logs generated by APM into the ES index](https://discuss.elastic.co/t/manually-import-the-logs-generated-by-apm-into-the-es-index/341275)

<div class="topic-metadata">

**Author:** [@seth\_qiang](https://discuss.elastic.co/u/seth_qiang)\
**Replies:** 0\
**Last updated:** [August 21, 2023, 3:39pm UTC](https://discuss.elastic.co/t/manually-import-the-logs-generated-by-apm-into-the-es-index/341275 "2023-08-21T15:39:51Z")

</div>

Hello everyone. I recently encountered a scenario when using apm-server: how to process the json log file output by apm-server through python and then manually import it into es to correspond to different index data, for…

---

## [Can I use hints based autodiscovery with Docker Swarm secrets?](https://discuss.elastic.co/t/can-i-use-hints-based-autodiscovery-with-docker-swarm-secrets/340497)

<div class="topic-metadata">

**Author:** [@jerrac](https://discuss.elastic.co/u/jerrac)\
**Replies:** 1\
**Last updated:** [August 21, 2023, 3:21pm UTC](https://discuss.elastic.co/t/can-i-use-hints-based-autodiscovery-with-docker-swarm-secrets/340497 "2023-08-21T15:21:54Z")

</div>

Per Securely manage credentials while monitoring Kubernetes workloads with autodiscovery | Elastic Blog it is possible to use Kubernetes secrets with hints based autodiscovery. Can I do the same with Docker Swarm secret…

---

## [RSS feed for new Elasticsearch versions](https://discuss.elastic.co/t/rss-feed-for-new-elasticsearch-versions/341272)

<div class="topic-metadata">

**Author:** [@jaketw47](https://discuss.elastic.co/u/jaketw47)\
**Replies:** 0\
**Last updated:** [August 21, 2023, 3:13pm UTC](https://discuss.elastic.co/t/rss-feed-for-new-elasticsearch-versions/341272 "2023-08-21T15:13:25Z")

</div>

Our company watches a small number of release-only RSS feeds so that we can be quickly notified when new versions of software we depend on are released (at least ones that still require manual upgrades). The Elastic Blog…

---

## [Can we trigger alert to end user filter from log message](https://discuss.elastic.co/t/can-we-trigger-alert-to-end-user-filter-from-log-message/341030)

<div class="topic-metadata">

**Author:** [@SumitSingh](https://discuss.elastic.co/u/SumitSingh)\
**Replies:** 1\
**Last updated:** [August 21, 2023, 2:56pm UTC](https://discuss.elastic.co/t/can-we-trigger-alert-to-end-user-filter-from-log-message/341030 "2023-08-21T14:56:27Z")

</div>

Hi, I want to send alert to user whose name in log message field. For example a user tried to access a project but he is not authorized, in this case log captured (access is forbidden for user: 'xyx') in message field. …

---

## [Should I disable scroll time if I don't explicitly use scroll in any search or index operation?](https://discuss.elastic.co/t/should-i-disable-scroll-time-if-i-dont-explicitly-use-scroll-in-any-search-or-index-operation/341158)

<div class="topic-metadata">

**Author:** [@arifd](https://discuss.elastic.co/u/arifd)\
**Replies:** 1\
**Last updated:** [August 21, 2023, 2:39pm UTC](https://discuss.elastic.co/t/should-i-disable-scroll-time-if-i-dont-explicitly-use-scroll-in-any-search-or-index-operation/341158 "2023-08-21T14:39:40Z")

</div>

Hello! So I am not (as far as I am aware) using the Scroll API, and yet I was able to get the "Trying to create too many scroll contexts. Must be less than or equal to: \[500\]" error. From searching around, I am under t…

---

## [Two custom analyzers with the same synonym filter - why no match](https://discuss.elastic.co/t/two-custom-analyzers-with-the-same-synonym-filter-why-no-match/341264)

<div class="topic-metadata">

**Author:** [@Lukas\_Cern](https://discuss.elastic.co/u/Lukas_Cern)\
**Replies:** 0\
**Last updated:** [August 21, 2023, 2:17pm UTC](https://discuss.elastic.co/t/two-custom-analyzers-with-the-same-synonym-filter-why-no-match/341264 "2023-08-21T14:17:23Z")

</div>

I have index with two fields. Each field uses different custom analyzer. Each of those analyzers use the same synonym filter. When querying with bool + should + match on both fields, it matches no document. I dont under…

---

## [ERROR : "Authentication to realm file1 failed - Password authentication failed for elastic" after updgrading my kubernetes cluster](https://discuss.elastic.co/t/error-authentication-to-realm-file1-failed-password-authentication-failed-for-elastic-after-updgrading-my-kubernetes-cluster/341260)

<div class="topic-metadata">

**Author:** [@khaled\_belgacem](https://discuss.elastic.co/u/khaled_belgacem)\
**Replies:** 0\
**Last updated:** [August 21, 2023, 2:08pm UTC](https://discuss.elastic.co/t/error-authentication-to-realm-file1-failed-password-authentication-failed-for-elastic-after-updgrading-my-kubernetes-cluster/341260 "2023-08-21T14:08:49Z")

</div>

hello everyone, a few days ago my kubernetes cluster certificates expired (on prem) so i upgraded my kubernetes version to get them renewed, before the upgrade i was using ECK for about a year, had multiple elastic clus…

[Previous page](https://discuss.elastic.co/latest.md?page=565)

[Next page](https://discuss.elastic.co/latest.md?page=567)
