# Latest

**URL:** https://discuss.elastic.co/latest.md?page=585

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 586

---

## [Fleet Self Sign Certficiate in Certificate Chain](https://discuss.elastic.co/t/fleet-self-sign-certficiate-in-certificate-chain/339949)

<div class="topic-metadata">

**Author:** [@amarcelq](https://discuss.elastic.co/u/amarcelq)\
**Replies:** 0\
**Last updated:** [August 2, 2023, 2:19pm UTC](https://discuss.elastic.co/t/fleet-self-sign-certficiate-in-certificate-chain/339949 "2023-08-02T14:19:22Z")

</div>

Hi, unfortunatly I encounter the following error. I don't have any clue which certificate is needed to be added. request to https://epr.elastic.co/categories?kibana.version=8.9.0 failed, reason: self signed certificate…

---

## [How to filter out strings starting with any from a list of strings](https://discuss.elastic.co/t/how-to-filter-out-strings-starting-with-any-from-a-list-of-strings/339948)

<div class="topic-metadata">

**Author:** [@michael\_c\_michael](https://discuss.elastic.co/u/michael_c_michael)\
**Replies:** 0\
**Last updated:** [August 2, 2023, 2:18pm UTC](https://discuss.elastic.co/t/how-to-filter-out-strings-starting-with-any-from-a-list-of-strings/339948 "2023-08-02T14:18:33Z")

</div>

Hi, I'm wanting to filter out strings starting with a number of characters. I've been able to solve this using a DSL query. Let me provide the example first: # Cleanup DELETE discuss-338708 # Create an index PUT discus…

---

## [Remote Reindex from a datastream to another index](https://discuss.elastic.co/t/remote-reindex-from-a-datastream-to-another-index/339951)

<div class="topic-metadata">

**Author:** [@San72](https://discuss.elastic.co/u/San72)\
**Replies:** 0\
**Last updated:** [August 2, 2023, 2:37pm UTC](https://discuss.elastic.co/t/remote-reindex-from-a-datastream-to-another-index/339951 "2023-08-02T14:37:59Z")

</div>

Hi Guys, we are trying to reindex some data (from another cluster) and ran into an issue. POST \_reindex { "source": { "remote": { "host": "https://COOL\_IP\_ADDRESS:9200", "username": "elastic", "passw…

---

## [Tried making a runtime script to modify field, but now visualize with the index shows all empty fields](https://discuss.elastic.co/t/tried-making-a-runtime-script-to-modify-field-but-now-visualize-with-the-index-shows-all-empty-fields/338708)

<div class="topic-metadata">

**Author:** [@michael\_c\_michael](https://discuss.elastic.co/u/michael_c_michael)\
**Replies:** 6\
**Last updated:** [August 2, 2023, 1:35pm UTC](https://discuss.elastic.co/t/tried-making-a-runtime-script-to-modify-field-but-now-visualize-with-the-index-shows-all-empty-fields/338708 "2023-08-02T13:35:52Z")

</div>

I have an index with 130 fields. One field I would like to change ranges over longs: 0, 1, 2. In order to do this, I added a runtime field with the following description: def names = \['0': 'Other', '1':'Friendly', '2':…

---

## [Trying to delete documents in index older than XXX](https://discuss.elastic.co/t/trying-to-delete-documents-in-index-older-than-xxx/339852)

<div class="topic-metadata">

**Author:** [@guy\_guy](https://discuss.elastic.co/u/guy_guy)\
**Replies:** 0\
**Last updated:** [August 1, 2023, 7:45pm UTC](https://discuss.elastic.co/t/trying-to-delete-documents-in-index-older-than-xxx/339852 "2023-08-01T19:45:00Z")

</div>

I need to delete some documents from indexes older than XXX days, but delete\_by\_query doesn't seem to be working for me. Here is an example query I'm trying to run POST shipment-log/\_delete\_by\_query { "query": { …

---

## [Elastic Serverless Forwarder not able to send Cloudwatch Logs to Elastic](https://discuss.elastic.co/t/elastic-serverless-forwarder-not-able-to-send-cloudwatch-logs-to-elastic/339801)

<div class="topic-metadata">

**Author:** [@Vedant14](https://discuss.elastic.co/u/Vedant14)\
**Replies:** 0\
**Last updated:** [August 1, 2023, 1:28pm UTC](https://discuss.elastic.co/t/elastic-serverless-forwarder-not-able-to-send-cloudwatch-logs-to-elastic/339801 "2023-08-01T13:28:26Z")

</div>

We deployed elastic-serverless-forwarder application on AWS lambda and also configured the config.yaml for specifying the outputs to Elastic and Kibana. We are not able to get the Cloudwatch Logs in Elastic . I have shar…

---

## [Ingest Real time logs to elasticsearch using Logstash](https://discuss.elastic.co/t/ingest-real-time-logs-to-elasticsearch-using-logstash/339788)

<div class="topic-metadata">

**Author:** [@harshal](https://discuss.elastic.co/u/harshal)\
**Replies:** 3\
**Last updated:** [August 2, 2023, 1:17pm UTC](https://discuss.elastic.co/t/ingest-real-time-logs-to-elasticsearch-using-logstash/339788 "2023-08-02T13:17:55Z")

</div>

I want to Ingest Realtime logs of Apps into Elasticsearch using Logstash and Create Report on Kibana, So Guide me

---

## [How to monitor different ES cloud clusters from different organizations centrally using ES cloud monitoring cluster.](https://discuss.elastic.co/t/how-to-monitor-different-es-cloud-clusters-from-different-organizations-centrally-using-es-cloud-monitoring-cluster/339813)

<div class="topic-metadata">

**Author:** [@latsayya](https://discuss.elastic.co/u/latsayya)\
**Replies:** 5\
**Last updated:** [August 2, 2023, 1:17pm UTC](https://discuss.elastic.co/t/how-to-monitor-different-es-cloud-clusters-from-different-organizations-centrally-using-es-cloud-monitoring-cluster/339813 "2023-08-02T13:17:26Z")

</div>

Is there any feature in the Elastic Cloud version to monitor all our customers' ES production clusters from our cluster as central monitoring? Please suggest how we can do it if there is no available straight feature. A…

---

## [Unable to get logs to elastalert with helk](https://discuss.elastic.co/t/unable-to-get-logs-to-elastalert-with-helk/339926)

<div class="topic-metadata">

**Author:** [@deloittepocra](https://discuss.elastic.co/u/deloittepocra)\
**Replies:** 1\
**Last updated:** [August 2, 2023, 1:16pm UTC](https://discuss.elastic.co/t/unable-to-get-logs-to-elastalert-with-helk/339926 "2023-08-02T13:16:59Z")

</div>

Hi Team, I have successfully set up helk by following the instructions provided in the GitHub repository. Additionally, I have configured winlogbeat to send my event/sysmon logs to Kibana through Kafka. Now, my goal is …

---

## [Unknown reason of All Elastic indices deletion repeatedly](https://discuss.elastic.co/t/unknown-reason-of-all-elastic-indices-deletion-repeatedly/339934)

<div class="topic-metadata">

**Author:** [@usman1](https://discuss.elastic.co/u/usman1)\
**Replies:** 6\
**Last updated:** [August 2, 2023, 12:25pm UTC](https://discuss.elastic.co/t/unknown-reason-of-all-elastic-indices-deletion-repeatedly/339934 "2023-08-02T12:25:49Z")

</div>

My elasticsearch instance is deployed in an EC2 instance and due to some reason, all my indices got deleted on 20th of July. After recovering the data on 30th, they got deleted again on 31st and then on 1st of August aga…

---

## [Filter vector search results to get only relevant documents?](https://discuss.elastic.co/t/filter-vector-search-results-to-get-only-relevant-documents/339543)

<div class="topic-metadata">

**Author:** [@john\_nicolas](https://discuss.elastic.co/u/john_nicolas)\
**Replies:** 10\
**Last updated:** [August 2, 2023, 12:15pm UTC](https://discuss.elastic.co/t/filter-vector-search-results-to-get-only-relevant-documents/339543 "2023-08-02T12:15:55Z")

</div>

I am not an expert in elastic queries, I have not found a solution to filter my results. My index contains 450,000 documents. The issue is that when I perform a search, it always returns all 450,000 documents, sorted by …

---

## [Caused by: java.lang.NoSuchMethodError: 'void co.elastic.clients.transport.rest\_client.RestClientTransport.\<init\>](https://discuss.elastic.co/t/caused-by-java-lang-nosuchmethoderror-void-co-elastic-clients-transport-rest-client-restclienttransport-init/339573)

<div class="topic-metadata">

**Author:** [@aph](https://discuss.elastic.co/u/aph)\
**Replies:** 8\
**Last updated:** [August 2, 2023, 12:04pm UTC](https://discuss.elastic.co/t/caused-by-java-lang-nosuchmethoderror-void-co-elastic-clients-transport-rest-client-restclienttransport-init/339573 "2023-08-02T12:04:08Z")

</div>

Maven build is failing with no method found error. Caused by: java.lang.NoSuchMethodError: 'void co.elastic.clients.transport.rest\_client.RestClientTransport.\<init\> Here is the pom.xml \<?xml version="1.0" encoding="UT…

---

## [Auditbeat lost events](https://discuss.elastic.co/t/auditbeat-lost-events/339935)

<div class="topic-metadata">

**Author:** [@KevinShi](https://discuss.elastic.co/u/KevinShi)\
**Replies:** 1\
**Last updated:** [August 2, 2023, 11:34am UTC](https://discuss.elastic.co/t/auditbeat-lost-events/339935 "2023-08-02T11:34:50Z")

</div>

My auditbeat drop all events when it start a minutes. And auditbeat status info: Aug 02 19:11:51 auditbeat\[29357\]: 2023-08-02T19:11:51.440+0800 INFO \[auditd\] auditd/audit\_linux.go:286 audit…

---

## [Not able to see watcher option in kibana using entrerprise edition](https://discuss.elastic.co/t/not-able-to-see-watcher-option-in-kibana-using-entrerprise-edition/339541)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 2\
**Last updated:** [August 2, 2023, 11:09am UTC](https://discuss.elastic.co/t/not-able-to-see-watcher-option-in-kibana-using-entrerprise-edition/339541 "2023-08-02T11:09:50Z")

</div>

Hello All, I'm unable to see watcher option in kibana and using enterprise edition. I want to configure alerts based on some string or if certain condition meets.For this watcher is required, but unable to see that opt…

---

## [Fail to start Elasticsearch in Linux](https://discuss.elastic.co/t/fail-to-start-elasticsearch-in-linux/339920)

<div class="topic-metadata">

**Author:** [@Saeed\_Ramezani](https://discuss.elastic.co/u/Saeed_Ramezani)\
**Replies:** 0\
**Last updated:** [August 2, 2023, 10:11am UTC](https://discuss.elastic.co/t/fail-to-start-elasticsearch-in-linux/339920 "2023-08-02T10:11:49Z")

</div>

I'm just trying to install Elasticsearch on Linux(ubuntu 22) by this article All the following commands passed by but when I reach to command ./bin/elasticsearch this error accord: ERROR: Elasticsearch exited unexpecte…

---

## [Understanding add\_process\_metadata and add\_docker\_metadata](https://discuss.elastic.co/t/understanding-add-process-metadata-and-add-docker-metadata/339916)

<div class="topic-metadata">

**Author:** [@charles\_ragg](https://discuss.elastic.co/u/charles_ragg)\
**Replies:** 0\
**Last updated:** [August 2, 2023, 9:59am UTC](https://discuss.elastic.co/t/understanding-add-process-metadata-and-add-docker-metadata/339916 "2023-08-02T09:59:37Z")

</div>

Hey everyone, I am having trouble understanding how these two processes work with a containerised application. my goal here is to add container.id and other docker-related labels to my logs in order to: Have some co…

---

## [Kibana Calculations Give Wrong Results](https://discuss.elastic.co/t/kibana-calculations-give-wrong-results/339778)

<div class="topic-metadata">

**Author:** [@Nabeel\_Ahmed\_NAK](https://discuss.elastic.co/u/Nabeel_Ahmed_NAK)\
**Replies:** 10\
**Last updated:** [August 2, 2023, 9:49am UTC](https://discuss.elastic.co/t/kibana-calculations-give-wrong-results/339778 "2023-08-02T09:49:42Z")

</div>

I'm Getting wrong counts in version 8.5.0 Time range is selected absolute values. The count of records are 102,118 hits When I create it's widget metrics of count it's same as expected: 102118 When I create unique co…

---

## [.NET 6 APM with Serilog throws exception inside Elastic.CommonSchema.Serilog](https://discuss.elastic.co/t/net-6-apm-with-serilog-throws-exception-inside-elastic-commonschema-serilog/339410)

<div class="topic-metadata">

**Author:** [@guisantos](https://discuss.elastic.co/u/guisantos)\
**Replies:** 2\
**Last updated:** [August 2, 2023, 9:29am UTC](https://discuss.elastic.co/t/net-6-apm-with-serilog-throws-exception-inside-elastic-commonschema-serilog/339410 "2023-08-02T09:29:19Z")

</div>

Kibana version: v8.9.0 Elasticsearch version: v8.9.0 APM Server version: v8.9.0 APM Agent language and version: .NET Core - Elastic.Apm.NetCoreAll v. 1.22.0 Original install method (e.g. download page, yum, deb, …

---

## [Increase in container memory when pipelines reload in logstash](https://discuss.elastic.co/t/increase-in-container-memory-when-pipelines-reload-in-logstash/338738)

<div class="topic-metadata">

**Author:** [@Nikhitha\_Karennagari](https://discuss.elastic.co/u/Nikhitha_Karennagari)\
**Replies:** 11\
**Last updated:** [August 2, 2023, 9:24am UTC](https://discuss.elastic.co/t/increase-in-container-memory-when-pipelines-reload-in-logstash/338738 "2023-08-02T09:24:02Z")

</div>

We have a service for which certificate renewal happens for every half an hour. Whenever the certificate renewal happens , when the change is detected in the certificates, automatic reload happens in logstash and all the…

---

## [Kibana dashboard to limited anonymous user](https://discuss.elastic.co/t/kibana-dashboard-to-limited-anonymous-user/338086)

<div class="topic-metadata">

**Author:** [@sunny2502](https://discuss.elastic.co/u/sunny2502)\
**Replies:** 11\
**Last updated:** [August 2, 2023, 9:16am UTC](https://discuss.elastic.co/t/kibana-dashboard-to-limited-anonymous-user/338086 "2023-08-02T09:16:24Z")

</div>

Hi I want my dashboard to be viewable to limited no of users, but I dont want them to get into login page. Can it be done? I know kibana support anonymous authentication but that will open my dashboard for public which…

---

## [Cannot use \_delete\_by\_query in ESSingleNodeTestCase tests with 8.X version.](https://discuss.elastic.co/t/cannot-use-delete-by-query-in-essinglenodetestcase-tests-with-8-x-version/338564)

<div class="topic-metadata">

**Author:** [@fusiasty](https://discuss.elastic.co/u/fusiasty)\
**Replies:** 1\
**Last updated:** [August 2, 2023, 8:32am UTC](https://discuss.elastic.co/t/cannot-use-delete-by-query-in-essinglenodetestcase-tests-with-8-x-version/338564 "2023-08-02T08:32:12Z")

</div>

Hi, I'm just migrating my application from ES 7.17 to ES 8.8.2 and faced one issue. I'm using ESSingleNodeTestCase to check my implementation. My application uses Java API Client 8.8. I figured out how to run HTTP in…

---

## [Service account for metricbeat](https://discuss.elastic.co/t/service-account-for-metricbeat/339904)

<div class="topic-metadata">

**Author:** [@\_Zeyad\_Elshater](https://discuss.elastic.co/u/_Zeyad_Elshater)\
**Replies:** 0\
**Last updated:** [August 2, 2023, 8:19am UTC](https://discuss.elastic.co/t/service-account-for-metricbeat/339904 "2023-08-02T08:19:08Z")

</div>

Hi all, is it a best practice to create a separate account for the beats , specially " metricbeat " to run as log in for its windows service , if yes , what permission does it needs thanks in adnvace

---

## [How to wait for indexing to finish before closing bulkingester](https://discuss.elastic.co/t/how-to-wait-for-indexing-to-finish-before-closing-bulkingester/339875)

<div class="topic-metadata">

**Author:** [@ALX\_DM](https://discuss.elastic.co/u/ALX_DM)\
**Replies:** 1\
**Last updated:** [August 2, 2023, 8:15am UTC](https://discuss.elastic.co/t/how-to-wait-for-indexing-to-finish-before-closing-bulkingester/339875 "2023-08-02T08:15:08Z")

</div>

how to wait for indexing to finish before closing bulkingester. previously we have awaitClose() for bulkprocessor. is is same for bulkingester? there is no awaitClose, but there is wait() in bulkIngester. I am not sur…

---

## [Why are my indexes automatically removed?](https://discuss.elastic.co/t/why-are-my-indexes-automatically-removed/339857)

<div class="topic-metadata">

**Author:** [@Miguel3](https://discuss.elastic.co/u/Miguel3)\
**Replies:** 5\
**Last updated:** [August 2, 2023, 8:13am UTC](https://discuss.elastic.co/t/why-are-my-indexes-automatically-removed/339857 "2023-08-02T08:13:59Z")

</div>

I have a problem with my elastic instance, after a few days of creating and uploading data to my indexes they are automatically deleted, I don't understand why it's happening and I don't see any message in the logs that …

---

## [Wildcard in control](https://discuss.elastic.co/t/wildcard-in-control/339687)

<div class="topic-metadata">

**Author:** [@martinsbleu](https://discuss.elastic.co/u/martinsbleu)\
**Replies:** 2\
**Last updated:** [August 2, 2023, 7:45am UTC](https://discuss.elastic.co/t/wildcard-in-control/339687 "2023-08-02T07:45:12Z")

</div>

Hello Team, Is there a way for control in Dashboard to have wildcard search ? If not, how can I open a request for it ? Thanks in advance,

---

## [Span duration missing resource loading time from Chrome devtools](https://discuss.elastic.co/t/span-duration-missing-resource-loading-time-from-chrome-devtools/339512)

<div class="topic-metadata">

**Author:** [@Morten\_Bjerre](https://discuss.elastic.co/u/Morten_Bjerre)\
**Replies:** 2\
**Last updated:** [August 2, 2023, 7:37am UTC](https://discuss.elastic.co/t/span-duration-missing-resource-loading-time-from-chrome-devtools/339512 "2023-08-02T07:37:56Z")

</div>

Hi! APM Agent language and version: Elastic APM RUM JavaScript agent, 5.12.0 Browser version: Chrome 114 In our project, we use custom transactions since the website is old and uses a lot of iframes, but the spans tha…

---

## [Too\_many\_clauses: maxClauseCount is set to 1337](https://discuss.elastic.co/t/too-many-clauses-maxclausecount-is-set-to-1337/339894)

<div class="topic-metadata">

**Author:** [@drorp\_korra](https://discuss.elastic.co/u/drorp_korra)\
**Replies:** 0\
**Last updated:** [August 2, 2023, 7:29am UTC](https://discuss.elastic.co/t/too-many-clauses-maxclausecount-is-set-to-1337/339894 "2023-08-02T07:29:16Z")

</div>

Hello, i'm getting the this error: ApiError(500, 'search\_phase\_execution\_exception', 'too\_many\_clauses: maxClauseCount is set to 1337') The query that is use is: { "bool": { "filter": \[ { "term": { "fi…

---

## [{“statusCode”:503,”error”:”Service Unavailable”,”message”:”License is not available.”}](https://discuss.elastic.co/t/statuscode-503-error-service-unavailable-message-license-is-not-available/339891)

<div class="topic-metadata">

**Author:** [@R1d3rBG](https://discuss.elastic.co/u/R1d3rBG)\
**Replies:** 0\
**Last updated:** [August 2, 2023, 7:15am UTC](https://discuss.elastic.co/t/statuscode-503-error-service-unavailable-message-license-is-not-available/339891 "2023-08-02T07:15:18Z")

</div>

Hello, Since a few days its starting again with the same error. Almost every morning when I check the machine its stopped with the following error when I open the URL. {"statusCode":503,"error":"Service Unavailable","m…

---

## [When I signed up for Elastic Cloud and clicked on "Create deployment," after logging in, the dashboard appears empty.](https://discuss.elastic.co/t/when-i-signed-up-for-elastic-cloud-and-clicked-on-create-deployment-after-logging-in-the-dashboard-appears-empty/339859)

<div class="topic-metadata">

**Author:** [@danbeeStudy](https://discuss.elastic.co/u/danbeeStudy)\
**Replies:** 1\
**Last updated:** [August 2, 2023, 5:20am UTC](https://discuss.elastic.co/t/when-i-signed-up-for-elastic-cloud-and-clicked-on-create-deployment-after-logging-in-the-dashboard-appears-empty/339859 "2023-08-02T05:20:29Z")

</div>

When I signed up for Elastic Cloud and clicked on "Create deployment," after logging in, the dashboard appears empty. How can I proceed? By creating the "Create deployment," is it possible for the Elasticsearch Servic…

---

## [Field mapping \[field with constant name\]. --\> \[field with a changing/dynamic name\] --\> \[fields with constant names\]](https://discuss.elastic.co/t/field-mapping-field-with-constant-name-field-with-a-changing-dynamic-name-fields-with-constant-names/339886)

<div class="topic-metadata">

**Author:** [@stcdarrell](https://discuss.elastic.co/u/stcdarrell)\
**Replies:** 2\
**Last updated:** [August 2, 2023, 5:12am UTC](https://discuss.elastic.co/t/field-mapping-field-with-constant-name-field-with-a-changing-dynamic-name-fields-with-constant-names/339886 "2023-08-02T05:12:34Z")

</div>

hi.. i've run into a problem with elasticsearch mapping.. i'm sure there is a way to deal with it.. but i cant figure it out.. or even the terminology to use to search for a solution. i'm trying to import a json from sh…

[Previous page](https://discuss.elastic.co/latest.md?page=584)

[Next page](https://discuss.elastic.co/latest.md?page=586)
