# Latest

**URL:** https://discuss.elastic.co/latest.md?page=576

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 577

---

## [ElasticsearchException connection refused](https://discuss.elastic.co/t/elasticsearchexception-connection-refused/340567)

<div class="topic-metadata">

**Author:** [@Hanane1](https://discuss.elastic.co/u/Hanane1)\
**Replies:** 0\
**Last updated:** [August 10, 2023, 1:42pm UTC](https://discuss.elastic.co/t/elasticsearchexception-connection-refused/340567 "2023-08-10T13:42:10Z")

</div>

Hello, I have this error when I try to search for something using elasticsearch Caused by: org.springframework.data.elasticsearch.UncategorizedElasticsearchException: java.util.concurrent.ExecutionException: java.net.C…

---

## [ES performance improvement after restarting ES instance?](https://discuss.elastic.co/t/es-performance-improvement-after-restarting-es-instance/340564)

<div class="topic-metadata">

**Author:** [@hyt](https://discuss.elastic.co/u/hyt)\
**Replies:** 0\
**Last updated:** [August 10, 2023, 1:29pm UTC](https://discuss.elastic.co/t/es-performance-improvement-after-restarting-es-instance/340564 "2023-08-10T13:29:12Z")

</div>

I encountered a strange phenomenon where the Elasticsearch instance performed better after restarting it during performance testing with esrally. i don't know why? esrally ：v2.6.0 （official http\_logs track） es : v7.17.…

---

## [Job fails injecting dataframe with variables in index name](https://discuss.elastic.co/t/job-fails-injecting-dataframe-with-variables-in-index-name/340370)

<div class="topic-metadata">

**Author:** [@Joachim\_Rodrigues](https://discuss.elastic.co/u/Joachim_Rodrigues)\
**Replies:** 1\
**Last updated:** [August 10, 2023, 1:08pm UTC](https://discuss.elastic.co/t/job-fails-injecting-dataframe-with-variables-in-index-name/340370 "2023-08-10T13:08:57Z")

</div>

Hello I have this code that injects a dataframe to an elastic cluster 7.9.3 myDataframe.saveToEs("customer-{year}.{month}") But i'm getting this error : User class threw exception: java.lang.Exception: Error(s) durin…

---

## [Please share your wisdom: Passing Elastic key/value pairs instead of log statements?](https://discuss.elastic.co/t/please-share-your-wisdom-passing-elastic-key-value-pairs-instead-of-log-statements/340489)

<div class="topic-metadata">

**Author:** [@McJava1967](https://discuss.elastic.co/u/McJava1967)\
**Replies:** 2\
**Last updated:** [August 10, 2023, 12:57pm UTC](https://discuss.elastic.co/t/please-share-your-wisdom-passing-elastic-key-value-pairs-instead-of-log-statements/340489 "2023-08-10T12:57:38Z")

</div>

Hi all. I'm looking for some very general advice. I know ELK started as a way to make sense of log statements, like: "We shipped 12 yellow rubber duckies to France". It will pick out "yellow", "rubber" and "duckies",…

---

## [Open Search Contexts Not Closed After Expiration](https://discuss.elastic.co/t/open-search-contexts-not-closed-after-expiration/340557)

<div class="topic-metadata">

**Author:** [@Jaeger\_Jochimsen](https://discuss.elastic.co/u/Jaeger_Jochimsen)\
**Replies:** 0\
**Last updated:** [August 10, 2023, 12:25pm UTC](https://discuss.elastic.co/t/open-search-contexts-not-closed-after-expiration/340557 "2023-08-10T12:25:54Z")

</div>

We recently had a sudden surge in open search contexts as a result of initiating many scrolls without iterating on them or closing them explicitly. Even though scroll time to live was set to 2 min we continued to have to…

---

## [WARN messages in elsasticsearch.log CFF/OTF](https://discuss.elastic.co/t/warn-messages-in-elsasticsearch-log-cff-otf/340547)

<div class="topic-metadata">

**Author:** [@shayshy](https://discuss.elastic.co/u/shayshy)\
**Replies:** 3\
**Last updated:** [August 10, 2023, 12:22pm UTC](https://discuss.elastic.co/t/warn-messages-in-elsasticsearch-log-cff-otf/340547 "2023-08-10T12:22:21Z")

</div>

I have lots of WARN Messages in elasticsearch.log org.apache.pdfbox.pdmodel.font.PDCIDFontType2 WARNING: Found CFF/OTF but expected embedded TTF fount Generic3-Regular and also POI does not currently support template…

---

## [AWS target group health check configuration for application load balancer](https://discuss.elastic.co/t/aws-target-group-health-check-configuration-for-application-load-balancer/340553)

<div class="topic-metadata">

**Author:** [@akansha](https://discuss.elastic.co/u/akansha)\
**Replies:** 0\
**Last updated:** [August 10, 2023, 11:35am UTC](https://discuss.elastic.co/t/aws-target-group-health-check-configuration-for-application-load-balancer/340553 "2023-08-10T11:35:34Z")

</div>

I need to expose kibana through application load balancer , i have created one but the problem is health check for target group is failing , what should I do to resolve this?

---

## [Queries regarding reindexing](https://discuss.elastic.co/t/queries-regarding-reindexing/340517)

<div class="topic-metadata">

**Author:** [@ANUBHAV\_GUPTA](https://discuss.elastic.co/u/ANUBHAV_GUPTA)\
**Replies:** 3\
**Last updated:** [August 10, 2023, 10:17am UTC](https://discuss.elastic.co/t/queries-regarding-reindexing/340517 "2023-08-10T10:17:11Z")

</div>

Hi there, I want to get some clarity on the reindexing API and how does it work. After talking to an ES developer I understood few points on the high level. But still I am having a doubt with the below question:- If …

---

## [Discovery service as endpoint provider not recognised](https://discuss.elastic.co/t/discovery-service-as-endpoint-provider-not-recognised/340512)

<div class="topic-metadata">

**Author:** [@nealder](https://discuss.elastic.co/u/nealder)\
**Replies:** 3\
**Last updated:** [August 10, 2023, 10:14am UTC](https://discuss.elastic.co/t/discovery-service-as-endpoint-provider-not-recognised/340512 "2023-08-10T10:14:52Z")

</div>

Hi Everyone, I have submitted a bug ticket on github, but I got redirected here. Here is the ticket. In short I found that the 'discovery.zen.ping.unicast.host' could resolve IP addresses of nodes in my cluster via dis…

---

## [The commercial usage of ELK stack in Russia today](https://discuss.elastic.co/t/the-commercial-usage-of-elk-stack-in-russia-today/340545)

<div class="topic-metadata">

**Author:** [@Abbey\_Monk](https://discuss.elastic.co/u/Abbey_Monk)\
**Replies:** 0\
**Last updated:** [August 10, 2023, 10:12am UTC](https://discuss.elastic.co/t/the-commercial-usage-of-elk-stack-in-russia-today/340545 "2023-08-10T10:12:39Z")

</div>

Hi, guys! Could we use ELK for free in Russia for the commercial purposes today? Thank you for your assistance.

---

## [I use elk in docker , i open xpack secuirty ,but when i restart by docker ,there some error log](https://discuss.elastic.co/t/i-use-elk-in-docker-i-open-xpack-secuirty-but-when-i-restart-by-docker-there-some-error-log/340544)

<div class="topic-metadata">

**Author:** [@yichitgo](https://discuss.elastic.co/u/yichitgo)\
**Replies:** 0\
**Last updated:** [August 10, 2023, 10:11am UTC](https://discuss.elastic.co/t/i-use-elk-in-docker-i-open-xpack-secuirty-but-when-i-restart-by-docker-there-some-error-log/340544 "2023-08-10T10:11:45Z")

</div>

aiting for Elasticsearch cluster to respond (1/30) logstash started. Starting Kibana5 \[ OK \] touch: cannot touch '/var/log/elasticsearch/{"error":{"root\_cause":\[{"…

---

## [The issue of data corruption in Logstash's Netflow plugin under high data concurrency](https://discuss.elastic.co/t/the-issue-of-data-corruption-in-logstashs-netflow-plugin-under-high-data-concurrency/340541)

<div class="topic-metadata">

**Author:** [@chenlx594](https://discuss.elastic.co/u/chenlx594)\
**Replies:** 0\
**Last updated:** [August 10, 2023, 10:02am UTC](https://discuss.elastic.co/t/the-issue-of-data-corruption-in-logstashs-netflow-plugin-under-high-data-concurrency/340541 "2023-08-10T10:02:38Z")

</div>

The Logstash Netflow plugin encounters a problem of misinterpreted fields like first\_switched , last\_switched , and bytes under a netflow data copy rate of 0.4 Gbps. How can this issue be resolved?

---

## [Getting 403 denied to elastic.co](https://discuss.elastic.co/t/getting-403-denied-to-elastic-co/339534)

<div class="topic-metadata">

**Author:** [@AlexandrK](https://discuss.elastic.co/u/AlexandrK)\
**Replies:** 3\
**Last updated:** [August 10, 2023, 9:58am UTC](https://discuss.elastic.co/t/getting-403-denied-to-elastic-co/339534 "2023-08-10T09:58:32Z")

</div>

Hello! My company's IP address was blocked by mistake. I wrote in a topic that deals with this problem, but the last unlock activity there was on May 1st. I don't know where to write to get my address unblocked Please …

---

## [Auditbeat authentications log](https://discuss.elastic.co/t/auditbeat-authentications-log/340535)

<div class="topic-metadata">

**Author:** [@lliadan](https://discuss.elastic.co/u/lliadan)\
**Replies:** 0\
**Last updated:** [August 10, 2023, 9:40am UTC](https://discuss.elastic.co/t/auditbeat-authentications-log/340535 "2023-08-10T09:40:34Z")

</div>

Hello ! I'm trying to receive the authentication faillure and success from my devices but i'm having few complications.. From my windows devices, it's ok, i'm able to receive log out / in / failled , with winlogbeat b…

---

## [I get this error in Logstash coming even when the pipeline is working just fine. What could it be?](https://discuss.elastic.co/t/i-get-this-error-in-logstash-coming-even-when-the-pipeline-is-working-just-fine-what-could-it-be/340531)

<div class="topic-metadata">

**Author:** [@SamuelSMendes](https://discuss.elastic.co/u/SamuelSMendes)\
**Replies:** 0\
**Last updated:** [August 10, 2023, 9:16am UTC](https://discuss.elastic.co/t/i-get-this-error-in-logstash-coming-even-when-the-pipeline-is-working-just-fine-what-could-it-be/340531 "2023-08-10T09:16:47Z")

</div>

\[2023-08-10T06:10:02,974\]\[ERROR\]\[logstash.licensechecker.licensereader\] Unable to retrieve license information from license server {:message=\>"No Available connections"} \[2023-08-10T06:10:06,662\]\[INFO \]\[logstash.license…

---

## [Elasticsearch Composite Aggregation Orderby in Java Client 8.8.2](https://discuss.elastic.co/t/elasticsearch-composite-aggregation-orderby-in-java-client-8-8-2/340514)

<div class="topic-metadata">

**Author:** [@tcpeiris](https://discuss.elastic.co/u/tcpeiris)\
**Replies:** 5\
**Last updated:** [August 10, 2023, 9:11am UTC](https://discuss.elastic.co/t/elasticsearch-composite-aggregation-orderby-in-java-client-8-8-2/340514 "2023-08-10T09:11:23Z")

</div>

I'm getting a parse exception when I add order to CompositeAggregationSource. Map\<String, CompositeAggregationSource\> cas = new HashMap\<\>(); List\<NamedValue\<SortOrder\>\> orderby = new ArrayList\<\>(); orderby.add(NamedVal…

---

## [Isolate a node](https://discuss.elastic.co/t/isolate-a-node/340528)

<div class="topic-metadata">

**Author:** [@Manal\_A](https://discuss.elastic.co/u/Manal_A)\
**Replies:** 1\
**Last updated:** [August 10, 2023, 9:01am UTC](https://discuss.elastic.co/t/isolate-a-node/340528 "2023-08-10T09:01:53Z")

</div>

How can we isolate a node that serves both as a master and data node from a cluster?

---

## [Source missing in filebeat logs](https://discuss.elastic.co/t/source-missing-in-filebeat-logs/340291)

<div class="topic-metadata">

**Author:** [@vaibhav.ubale](https://discuss.elastic.co/u/vaibhav.ubale)\
**Replies:** 5\
**Last updated:** [August 10, 2023, 8:51am UTC](https://discuss.elastic.co/t/source-missing-in-filebeat-logs/340291 "2023-08-10T08:51:34Z")

</div>

Hi Team , I have set up the filebeat to send the custom logs to Elasticsearch cluster, But there is "Source" missing on logs when I see them in Filebeat. I am using filebeat-8.7.0-1.x86\_64 for sending the logs. is …

---

## [Chaining queries with rally](https://discuss.elastic.co/t/chaining-queries-with-rally/340525)

<div class="topic-metadata">

**Author:** [@Gustavo\_Llermaly](https://discuss.elastic.co/u/Gustavo_Llermaly)\
**Replies:** 0\
**Last updated:** [August 10, 2023, 8:22am UTC](https://discuss.elastic.co/t/chaining-queries-with-rally/340525 "2023-08-10T08:22:08Z")

</div>

Hi , What's the best practice to benchmark an application side joins scenario? Meaning running an initial query with "collapse" to group by some id, take all the ids from the response and run a second "terms" query? W…

---

## [Multiterms on multi index](https://discuss.elastic.co/t/multiterms-on-multi-index/340519)

<div class="topic-metadata">

**Author:** [@Suresh\_Ghatuwa](https://discuss.elastic.co/u/Suresh_Ghatuwa)\
**Replies:** 0\
**Last updated:** [August 10, 2023, 7:47am UTC](https://discuss.elastic.co/t/multiterms-on-multi-index/340519 "2023-08-10T07:47:46Z")

</div>

Currently I am testing on ES Multi Terms feature. Please find the sample data with indices. PUT multi\_terms\_test1 { "settings": { "number\_of\_shards": 1, "number\_of\_replicas": 0 } } PUT multi\_terms\_test1/\_ma…

---

## [Elasticsearch: 'x\_content\_parse\_exception' \[template\] unknown field \[lifecycle\]](https://discuss.elastic.co/t/elasticsearch-x-content-parse-exception-template-unknown-field-lifecycle/340009)

<div class="topic-metadata">

**Author:** [@anton3](https://discuss.elastic.co/u/anton3)\
**Replies:** 6\
**Last updated:** [August 10, 2023, 7:45am UTC](https://discuss.elastic.co/t/elasticsearch-x-content-parse-exception-template-unknown-field-lifecycle/340009 "2023-08-10T07:45:15Z")

</div>

I have elk stack deployed from deviantony/docker-elk version 8.9 . every component is 8.9 And i'm trying to create lifecycle with retention policy for my datastream as mentioned in official documentetion PUT \_index\_te…

---

## [Curl: (77) Problem with the SSL CA cert (path? access rights?)](https://discuss.elastic.co/t/curl-77-problem-with-the-ssl-ca-cert-path-access-rights/338761)

<div class="topic-metadata">

**Author:** [@PodarcisMuralis](https://discuss.elastic.co/u/PodarcisMuralis)\
**Replies:** 4\
**Last updated:** [August 10, 2023, 7:39am UTC](https://discuss.elastic.co/t/curl-77-problem-with-the-ssl-ca-cert-path-access-rights/338761 "2023-08-10T07:39:34Z")

</div>

Hi, I use a shell script to send curl to elasticsearch. But I got this error: curl: (77) Problem with the SSL CA cert (path? access rights?) My curl is like: RESPONSE=$(curl -v -s -w "%{http\_code}" -o /dev/null -XDEL…

---

## [Overriding timestamp in logstash](https://discuss.elastic.co/t/overriding-timestamp-in-logstash/340515)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 0\
**Last updated:** [August 10, 2023, 7:26am UTC](https://discuss.elastic.co/t/overriding-timestamp-in-logstash/340515 "2023-08-10T07:26:03Z")

</div>

Hi on logstash need to override timestamp, here is the scenario input file, output as http. here is the string must be send via “http output”: mymeasure,tag=mytag field="myfield" 1689682934 FYI: this part "1689682934…

---

## [Elasticsearch not getting data from filter after index migration](https://discuss.elastic.co/t/elasticsearch-not-getting-data-from-filter-after-index-migration/340467)

<div class="topic-metadata">

**Author:** [@cosskay](https://discuss.elastic.co/u/cosskay)\
**Replies:** 2\
**Last updated:** [August 10, 2023, 6:17am UTC](https://discuss.elastic.co/t/elasticsearch-not-getting-data-from-filter-after-index-migration/340467 "2023-08-10T06:17:23Z")

</div>

after moving an index from one cluster to another, the index does not search for data by filter. The number of Lucene docs is the same in both indexes. All indices Health (green) . Index cloned from VM in openshift . Ela…

---

## [Scripted Fields not showing up in visualizations](https://discuss.elastic.co/t/scripted-fields-not-showing-up-in-visualizations/340417)

<div class="topic-metadata">

**Author:** [@thomas.kelly](https://discuss.elastic.co/u/thomas.kelly)\
**Replies:** 3\
**Last updated:** [August 10, 2023, 6:16am UTC](https://discuss.elastic.co/t/scripted-fields-not-showing-up-in-visualizations/340417 "2023-08-10T06:16:57Z")

</div>

Hi, I am attempting to create a dashboard based off a scripted field. The scripted field is a pretty simple boolean evaluation, and I tested the expression using the preview results feature. The visualization I am attemp…

---

## [This node doesn't appear to be auto-configured for security. Expected configuration is missing from elasticsearch.yml](https://discuss.elastic.co/t/this-node-doesnt-appear-to-be-auto-configured-for-security-expected-configuration-is-missing-from-elasticsearch-yml/339649)

<div class="topic-metadata">

**Author:** [@KunwarAkanksha](https://discuss.elastic.co/u/KunwarAkanksha)\
**Replies:** 2\
**Last updated:** [August 10, 2023, 4:14am UTC](https://discuss.elastic.co/t/this-node-doesnt-appear-to-be-auto-configured-for-security-expected-configuration-is-missing-from-elasticsearch-yml/339649 "2023-08-10T04:14:28Z")

</div>

Kindly Help, While the Elasticsearch is with the default elasticsearch.yml it is giving such error /usr/share/elasticsearch/bin/elasticsearch-reconfigure-node --enrollment-token Generates all the necessary security c…

---

## [Failed to pull data from Salesforce into logstash](https://discuss.elastic.co/t/failed-to-pull-data-from-salesforce-into-logstash/340503)

<div class="topic-metadata">

**Author:** [@Lazaro\_O\_Farrill](https://discuss.elastic.co/u/Lazaro_O_Farrill)\
**Replies:** 0\
**Last updated:** [August 10, 2023, 3:44am UTC](https://discuss.elastic.co/t/failed-to-pull-data-from-salesforce-into-logstash/340503 "2023-08-10T03:44:35Z")

</div>

I am trying to pull my data from my Salesforce sandbox into logstash, and I am getting the following error. Does anyone have any idea what it might mean? I have tested the credentials directly through the API endpoints a…

---

## [After I uncomment xpack.security.enabled: true line in elasticsearch.service Failed to start Elasticsearch](https://discuss.elastic.co/t/after-i-uncomment-xpack-security-enabled-true-line-in-elasticsearch-service-failed-to-start-elasticsearch/339661)

<div class="topic-metadata">

**Author:** [@janitha\_ilangage](https://discuss.elastic.co/u/janitha_ilangage)\
**Replies:** 2\
**Last updated:** [August 10, 2023, 3:43am UTC](https://discuss.elastic.co/t/after-i-uncomment-xpack-security-enabled-true-line-in-elasticsearch-service-failed-to-start-elasticsearch/339661 "2023-08-10T03:43:16Z")

</div>

After I uncomment xpack.security.enabled: true line in elasticsearch.service Failed to start Elasticsearch. root@kibana:~# systemctl status elasticsearch.service ● elasticsearch.service - Elasticsearch Loaded: load…

---

## [Java APM1.41.0 JVM used is Zero](https://discuss.elastic.co/t/java-apm1-41-0-jvm-used-is-zero/340218)

<div class="topic-metadata">

**Author:** [@zt9788](https://discuss.elastic.co/u/zt9788)\
**Replies:** 7\
**Last updated:** [August 10, 2023, 2:00am UTC](https://discuss.elastic.co/t/java-apm1-41-0-jvm-used-is-zero/340218 "2023-08-10T02:00:08Z")

</div>

1.38.0 can catch the jvm used Programs typically use around 200-300M of heap memory Non-Heap memory is 260~320M in 1.38.0 befor JDK: JDK17.0.8 Kibana version: 7.13.2 Elasticsearch version: 7.13.2 APM Serv…

---

## [ECE docker containers stopped and no logs](https://discuss.elastic.co/t/ece-docker-containers-stopped-and-no-logs/340502)

<div class="topic-metadata">

**Author:** [@shani\_angarkadu](https://discuss.elastic.co/u/shani_angarkadu)\
**Replies:** 0\
**Last updated:** [August 10, 2023, 1:53am UTC](https://discuss.elastic.co/t/ece-docker-containers-stopped-and-no-logs/340502 "2023-08-10T01:53:57Z")

</div>

Hi there, Our ECE is hosted on-premises within Docker containers. Unfortunately, all beat runners on each host are currently offline, and we lack visibility into the health status of the Docker containers, both in serve…

[Previous page](https://discuss.elastic.co/latest.md?page=575)

[Next page](https://discuss.elastic.co/latest.md?page=577)
