# Latest

**URL:** https://discuss.elastic.co/latest.md?page=615

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 616

---

## [How to update preconfigured fleet agent policies](https://discuss.elastic.co/t/how-to-update-preconfigured-fleet-agent-policies/337801)

<div class="topic-metadata">

**Author:** [@GeorgeGkinis](https://discuss.elastic.co/u/GeorgeGkinis)\
**Replies:** 2\
**Last updated:** [July 7, 2023, 7:10am UTC](https://discuss.elastic.co/t/how-to-update-preconfigured-fleet-agent-policies/337801 "2023-07-07T07:10:15Z")

</div>

Hi, I have a question regarding on how to update preconfigured agent policies residing in kibana.yml. We deploy on ECK and our stack is version 8.8.1. The first time we deploy kibana the preconfigured policies residin…

---

## [ERROR co.elastic.apm.agent.bci.IndyBootstrap - Advice threw an exception, this should never happen!](https://discuss.elastic.co/t/error-co-elastic-apm-agent-bci-indybootstrap-advice-threw-an-exception-this-should-never-happen/337589)

<div class="topic-metadata">

**Author:** [@miguel.longo](https://discuss.elastic.co/u/miguel.longo)\
**Replies:** 11\
**Last updated:** [July 7, 2023, 6:51am UTC](https://discuss.elastic.co/t/error-co-elastic-apm-agent-bci-indybootstrap-advice-threw-an-exception-this-should-never-happen/337589 "2023-07-07T06:51:37Z")

</div>

Kibana version: 8.6.0 Elasticsearch version: 8.6.0 APM Server version: 8.6.0 APM Agent language and version: 1.36.0 Original install method (e.g. download page, yum, deb, from source, etc.) and version: Docker stack …

---

## [Reindexing failed with TAG Mismatch Exception](https://discuss.elastic.co/t/reindexing-failed-with-tag-mismatch-exception/335839)

<div class="topic-metadata">

**Author:** [@awenest](https://discuss.elastic.co/u/awenest)\
**Replies:** 2\
**Last updated:** [July 7, 2023, 5:23am UTC](https://discuss.elastic.co/t/reindexing-failed-with-tag-mismatch-exception/335839 "2023-07-07T05:23:55Z")

</div>

I have increased the socket timeout to 15 minutes since I am trying to reindex ~ 40k records. But within 6 minutes I get below exception : Caused by: org.springframework.dao.DataAccessResourceFailureException: Tag mism…

---

## [Winlogbeat Fatal Error 8.7.0+ name already used](https://discuss.elastic.co/t/winlogbeat-fatal-error-8-7-0-name-already-used/337093)

<div class="topic-metadata">

**Author:** [@dwissm1](https://discuss.elastic.co/u/dwissm1)\
**Replies:** 12\
**Last updated:** [July 7, 2023, 12:33am UTC](https://discuss.elastic.co/t/winlogbeat-fatal-error-8-7-0-name-already-used/337093 "2023-07-07T00:33:28Z")

</div>

Hey Folks, Running into some fatal errors with Winlogbeat. Started happening around 8.7.0 and I am now getting to try to fix it. I was on 8.6.2 and and was working fine, anything 8.7+ it has a fatal error but if I go …

---

## [How work many output jdbc at same time?](https://discuss.elastic.co/t/how-work-many-output-jdbc-at-same-time/337746)

<div class="topic-metadata">

**Author:** [@inbeom\_cho](https://discuss.elastic.co/u/inbeom_cho)\
**Replies:** 1\
**Last updated:** [July 7, 2023, 12:10am UTC](https://discuss.elastic.co/t/how-work-many-output-jdbc-at-same-time/337746 "2023-07-07T00:10:47Z")

</div>

hi all, my pipelines.yml - pipeline.id: test1 pipeline.workers: 1 path.config: "/app/logstash/config/conf.d/test1.conf" - pipeline.id: test2 pipeline.workers: 1 path.config: "/app/logstash/config/conf.d/test2.c…

---

## [MountVolume.SetUp failed for volume "elasticsearch-master-certs" : secret "elasticsearch-master-certs" not found](https://discuss.elastic.co/t/mountvolume-setup-failed-for-volume-elasticsearch-master-certs-secret-elasticsearch-master-certs-not-found/337850)

<div class="topic-metadata">

**Author:** [@Shikder\_Reyad](https://discuss.elastic.co/u/Shikder_Reyad)\
**Replies:** 0\
**Last updated:** [July 6, 2023, 11:58pm UTC](https://discuss.elastic.co/t/mountvolume-setup-failed-for-volume-elasticsearch-master-certs-secret-elasticsearch-master-certs-not-found/337850 "2023-07-06T23:58:43Z")

</div>

Warning FailedMount 5s (x8 over 69s) kubelet MountVolume.SetUp failed for volume "elasticsearch-master-certs" : secret "elasticsearch-master-certs" not found container create stuck filebeat-filebeat-bvbnl…

---

## [Regarding the ranking of the inspection results of elasticsearch](https://discuss.elastic.co/t/regarding-the-ranking-of-the-inspection-results-of-elasticsearch/337424)

<div class="topic-metadata">

**Author:** [@kimjinyoung](https://discuss.elastic.co/u/kimjinyoung)\
**Replies:** 4\
**Last updated:** [July 6, 2023, 11:52pm UTC](https://discuss.elastic.co/t/regarding-the-ranking-of-the-inspection-results-of-elasticsearch/337424 "2023-07-06T23:52:02Z")

</div>

hi! I would like to ask you about Elasticsearch's test result ranking. "If there is ""kimchy"" in the data below." user.id kimchy\_00 kimchy\_01 kimchy\_02 .. kimchy\_50 example of elasticsearch below GET /\_search { "…

---

## [Downloading the kibana report from outside](https://discuss.elastic.co/t/downloading-the-kibana-report-from-outside/337784)

<div class="topic-metadata">

**Author:** [@Vatsal\_Sharma](https://discuss.elastic.co/u/Vatsal_Sharma)\
**Replies:** 1\
**Last updated:** [July 6, 2023, 10:01pm UTC](https://discuss.elastic.co/t/downloading-the-kibana-report-from-outside/337784 "2023-07-06T22:01:41Z")

</div>

I was trying to download report from kibana in csv format, from the discover section and outside kibana, I used the post url and as per documentation generated a path where the kibana report is there as wrtten in the doc…

---

## [Why \`/\_cat/indices\` shows system indices?](https://discuss.elastic.co/t/why-cat-indices-shows-system-indices/337837)

<div class="topic-metadata">

**Author:** [@Mike\_Z](https://discuss.elastic.co/u/Mike_Z)\
**Replies:** 1\
**Last updated:** [July 6, 2023, 10:00pm UTC](https://discuss.elastic.co/t/why-cat-indices-shows-system-indices/337837 "2023-07-06T22:00:44Z")

</div>

The system indices have names starting with a dot, like .xxxxxx. And usually, the command GET \_cat/indices/\_all does not show the system indices, so they are hidden by default. For learning purposes, we recently went th…

---

## [Elastic-apm-node issues regarding transaction and logging](https://discuss.elastic.co/t/elastic-apm-node-issues-regarding-transaction-and-logging/337648)

<div class="topic-metadata">

**Author:** [@Kesha\_Shah](https://discuss.elastic.co/u/Kesha_Shah)\
**Replies:** 1\
**Last updated:** [July 6, 2023, 9:38pm UTC](https://discuss.elastic.co/t/elastic-apm-node-issues-regarding-transaction-and-logging/337648 "2023-07-06T21:38:32Z")

</div>

Kibana version: 8.8.1 Elasticsearch version: 8.8.1 APM Server version: 8.8.1 APM Agent language and version: NodeJs Agent elastic-apm-node": "^3.47.0 Fresh install or upgraded from other version? Upgraded from 7.17 r…

---

## [Help understanding boolean query and boosting?](https://discuss.elastic.co/t/help-understanding-boolean-query-and-boosting/337842)

<div class="topic-metadata">

**Author:** [@reswob](https://discuss.elastic.co/u/reswob)\
**Replies:** 2\
**Last updated:** [July 6, 2023, 9:22pm UTC](https://discuss.elastic.co/t/help-understanding-boolean-query-and-boosting/337842 "2023-07-06T21:22:52Z")

</div>

So I'm doing some self training in my lab. I wanted to create a query looking for value A in field A OR value B in field B and return all records that met that either criteria. Value A is type long and value B is text …

---

## [Counter using geofence](https://discuss.elastic.co/t/counter-using-geofence/337832)

<div class="topic-metadata">

**Author:** [@rafaelrangel](https://discuss.elastic.co/u/rafaelrangel)\
**Replies:** 1\
**Last updated:** [July 6, 2023, 9:20pm UTC](https://discuss.elastic.co/t/counter-using-geofence/337832 "2023-07-06T21:20:31Z")

</div>

Good afternoon people. I'm new here and I have a question. I have two indexes: 1 - Data being indexed through a json that contains mainly location (latitude and londitude) and the name of an asset. 2- A geofence with…

---

## [Socket Hang Up Error with Kibana Login](https://discuss.elastic.co/t/socket-hang-up-error-with-kibana-login/337712)

<div class="topic-metadata">

**Author:** [@josh42](https://discuss.elastic.co/u/josh42)\
**Replies:** 1\
**Last updated:** [July 6, 2023, 8:49pm UTC](https://discuss.elastic.co/t/socket-hang-up-error-with-kibana-login/337712 "2023-07-06T20:49:24Z")

</div>

I've been getting a "Socket Hang Up" error when trying to launch Kibana and could use some help troubleshooting the cause. Some background context: My employer requires their own CA, so I had to setup Kibana manually w…

---

## [Unable to parse grokpattern for below log in opensearch ](https://discuss.elastic.co/t/unable-to-parse-grokpattern-for-below-log-in-opensearch/337839)

<div class="topic-metadata">

**Author:** [@David\_Kumar\_Duggu](https://discuss.elastic.co/u/David_Kumar_Duggu)\
**Replies:** 2\
**Last updated:** [July 6, 2023, 8:13pm UTC](https://discuss.elastic.co/t/unable-to-parse-grokpattern-for-below-log-in-opensearch/337839 "2023-07-06T20:13:34Z")

</div>

I am trying to parse the below log using Grok pattern, Grok pattern is parsing in grokdebugger but it is not able to parse in open search. Please find the log attached {"level":"info","msg":"method:offlineActivate,name:…

---

## [Reverse word order search (with shingles)](https://discuss.elastic.co/t/reverse-word-order-search-with-shingles/336792)

<div class="topic-metadata">

**Author:** [@RS232](https://discuss.elastic.co/u/RS232)\
**Replies:** 4\
**Last updated:** [July 6, 2023, 7:19pm UTC](https://discuss.elastic.co/t/reverse-word-order-search-with-shingles/336792 "2023-07-06T19:19:00Z")

</div>

Hello dear Elasticsearch users, Wanted to ask if anyone has a suggestion how to handle this situation. We have source data with phrases like "mazda 3" And two search scenarios: Customer should be able to find it via…

---

## [Problems with aggregations: Data too large](https://discuss.elastic.co/t/problems-with-aggregations-data-too-large/337591)

<div class="topic-metadata">

**Author:** [@tmslara.a](https://discuss.elastic.co/u/tmslara.a)\
**Replies:** 6\
**Last updated:** [July 6, 2023, 7:13pm UTC](https://discuss.elastic.co/t/problems-with-aggregations-data-too-large/337591 "2023-07-06T19:13:42Z")

</div>

Hi, I have problems when trying to get aggregations. I have a cluster with one node, and I'm trying to interact with an index that contains 534,737,088 documents (around 32 GB). Some aggregations work, and Elasticsearch…

---

## [Elastic multy match query with order of words given shoul follow in resulted records](https://discuss.elastic.co/t/elastic-multy-match-query-with-order-of-words-given-shoul-follow-in-resulted-records/337827)

<div class="topic-metadata">

**Author:** [@Lakshmikiran](https://discuss.elastic.co/u/Lakshmikiran)\
**Replies:** 1\
**Last updated:** [July 6, 2023, 6:49pm UTC](https://discuss.elastic.co/t/elastic-multy-match-query-with-order-of-words-given-shoul-follow-in-resulted-records/337827 "2023-07-06T18:49:53Z")

</div>

Using multi match queries in each query different words line word1 word2 word3 respectively. After search results also I'm expecting the words in same order, but in between of the words it could be present or not also. B…

---

## [Grok pattern for datadog to get everything between two curly braces {}](https://discuss.elastic.co/t/grok-pattern-for-datadog-to-get-everything-between-two-curly-braces/337665)

<div class="topic-metadata">

**Author:** [@shekhsadiq21](https://discuss.elastic.co/u/shekhsadiq21)\
**Replies:** 8\
**Last updated:** [July 6, 2023, 4:47pm UTC](https://discuss.elastic.co/t/grok-pattern-for-datadog-to-get-everything-between-two-curly-braces/337665 "2023-07-06T16:47:47Z")

</div>

Hi All, Can anyone help to get GROK pattern of logs everthing between two curly braces logsample: { CONNECTION: keep-alive X-ORIGINAL-URL: /Data/RetailItem.js?Log=1&Sync=0 X-FORWARDED-PROTO: https X-FORWARDED-PORT:…

---

## [How to update Kibana Advance Settings via API request](https://discuss.elastic.co/t/how-to-update-kibana-advance-settings-via-api-request/337720)

<div class="topic-metadata">

**Author:** [@Nama\_Chintamani\_Illo](https://discuss.elastic.co/u/Nama_Chintamani_Illo)\
**Replies:** 4\
**Last updated:** [July 6, 2023, 4:08pm UTC](https://discuss.elastic.co/t/how-to-update-kibana-advance-settings-via-api-request/337720 "2023-07-06T16:08:47Z")

</div>

I am trying to update the advance settings of a specific space via an API request. I am attempting to change the "metaFields" setting to include the "\_size" field and would like to send the command via an API without h…

---

## [S3 moving the data from 1 AWS S3 repo to new AWS repo](https://discuss.elastic.co/t/s3-moving-the-data-from-1-aws-s3-repo-to-new-aws-repo/337821)

<div class="topic-metadata">

**Author:** [@shani\_angarkadu](https://discuss.elastic.co/u/shani_angarkadu)\
**Replies:** 0\
**Last updated:** [July 6, 2023, 4:04pm UTC](https://discuss.elastic.co/t/s3-moving-the-data-from-1-aws-s3-repo-to-new-aws-repo/337821 "2023-07-06T16:04:34Z")

</div>

We have AWS S3 repo1 and we have cold phase data but we are planning to move that data to new AWS S3 repo. What is the best way to do it?

---

## [Bulk insert with Spark causes org.elasticsearch.hadoop.rest.EsHadoopNoNodesLeftException: Connection error (check network and/or proxy settings)- all nodes failed](https://discuss.elastic.co/t/bulk-insert-with-spark-causes-org-elasticsearch-hadoop-rest-eshadoopnonodesleftexception-connection-error-check-network-and-or-proxy-settings-all-nodes-failed/337631)

<div class="topic-metadata">

**Author:** [@Thijsvdp](https://discuss.elastic.co/u/Thijsvdp)\
**Replies:** 6\
**Last updated:** [July 6, 2023, 3:17pm UTC](https://discuss.elastic.co/t/bulk-insert-with-spark-causes-org-elasticsearch-hadoop-rest-eshadoopnonodesleftexception-connection-error-check-network-and-or-proxy-settings-all-nodes-failed/337631 "2023-07-06T15:17:06Z")

</div>

Hi all, I am having trouble with writing to a 5-node Elasticsearch cluster with Spark. Some basic details about the cluster: 5 nodes 6TB of disk 5x28 GB of RAM (half is Heap) 5x6 CPU Allocated 140 shards for the relev…

---

## [Problem in query in logstash](https://discuss.elastic.co/t/problem-in-query-in-logstash/337781)

<div class="topic-metadata">

**Author:** [@Hind\_Alla](https://discuss.elastic.co/u/Hind_Alla)\
**Replies:** 5\
**Last updated:** [July 6, 2023, 2:28pm UTC](https://discuss.elastic.co/t/problem-in-query-in-logstash/337781 "2023-07-06T14:28:23Z")

</div>

input { jdbc { jdbc\_driver\_library =\> "XXXX" jdbc\_driver\_class =\> "Java::oracle.jdbc.driver.OracleDriver" jdbc\_connection\_string =\> "XXXX" jdbc\_user =\> "XXXX" jdbc\_password =\> "XXXX" statement =\> "SELECT \* FROM MO…

---

## [How To Add Remote metric Data in Inventory](https://discuss.elastic.co/t/how-to-add-remote-metric-data-in-inventory/337804)

<div class="topic-metadata">

**Author:** [@aurangzeb99](https://discuss.elastic.co/u/aurangzeb99)\
**Replies:** 0\
**Last updated:** [July 6, 2023, 2:14pm UTC](https://discuss.elastic.co/t/how-to-add-remote-metric-data-in-inventory/337804 "2023-07-06T14:14:12Z")

</div>

Hi team, I am monitoring devices where I cannot install agent ( Router ,Switches etc ). so I am forwarding metric and logs Data to a VM to Elasticsearch. But I want to View metric data into Observability ----\>Infrastr…

---

## [Read an index and count in other index](https://discuss.elastic.co/t/read-an-index-and-count-in-other-index/337803)

<div class="topic-metadata">

**Author:** [@reed](https://discuss.elastic.co/u/reed)\
**Replies:** 0\
**Last updated:** [July 6, 2023, 2:00pm UTC](https://discuss.elastic.co/t/read-an-index-and-count-in-other-index/337803 "2023-07-06T14:00:43Z")

</div>

Hi all, I have two index: index\_master name - code m1 - c1 m2 - c2 m3 - c3 index\_details code - other fields c1 - data field c1 - data field c1 - data field c1 - data field c2 - data field c2 - dat…

---

## [Logging from painless script in ingest pipeline](https://discuss.elastic.co/t/logging-from-painless-script-in-ingest-pipeline/337716)

<div class="topic-metadata">

**Author:** [@akhil\_reddy](https://discuss.elastic.co/u/akhil_reddy)\
**Replies:** 1\
**Last updated:** [July 6, 2023, 2:00pm UTC](https://discuss.elastic.co/t/logging-from-painless-script-in-ingest-pipeline/337716 "2023-07-06T14:00:12Z")

</div>

Hi, I have a requirement where I am indexing my raw docs to an index (original\_index). I am creating a rollup job for this index which runs every hour. My rollup index goes through an ingest pipeline which has a script. …

---

## [Migration from OpenSearch2.5 to Elasticsearch8.8.1](https://discuss.elastic.co/t/migration-from-opensearch2-5-to-elasticsearch8-8-1/336491)

<div class="topic-metadata">

**Author:** [@tatsuya](https://discuss.elastic.co/u/tatsuya)\
**Replies:** 8\
**Last updated:** [July 6, 2023, 12:57pm UTC](https://discuss.elastic.co/t/migration-from-opensearch2-5-to-elasticsearch8-8-1/336491 "2023-07-06T12:57:41Z")

</div>

Hello. I'm thinking of migrating from AWS OpenSearch to Elastic Cloud. First, I launched Elasticsearch 8.8.1 locally with docker and checked if the data could be migrated. Data migration experimented with Snapshot & R…

---

## [Hi all i am getting error like Logstash stopped processing because of an error: (SystemExit) exit](https://discuss.elastic.co/t/hi-all-i-am-getting-error-like-logstash-stopped-processing-because-of-an-error-systemexit-exit/337536)

<div class="topic-metadata">

**Author:** [@maheswari1](https://discuss.elastic.co/u/maheswari1)\
**Replies:** 4\
**Last updated:** [July 6, 2023, 12:07pm UTC](https://discuss.elastic.co/t/hi-all-i-am-getting-error-like-logstash-stopped-processing-because-of-an-error-systemexit-exit/337536 "2023-07-06T12:07:29Z")

</div>

Logstash stopped processing because of an error: (SystemExit) exit

---

## [Combine multiple index and nested in search elasticsearch](https://discuss.elastic.co/t/combine-multiple-index-and-nested-in-search-elasticsearch/337753)

<div class="topic-metadata">

**Author:** [@stephane\_chan](https://discuss.elastic.co/u/stephane_chan)\
**Replies:** 1\
**Last updated:** [July 6, 2023, 11:43am UTC](https://discuss.elastic.co/t/combine-multiple-index-and-nested-in-search-elasticsearch/337753 "2023-07-06T11:43:03Z")

</div>

How to search multiple indexes with nested and non-nested fields ? I have an audio index with the results like this : { "\_index" : "audios", "\_type" : "\_doc", "\_id" : "145", "\_score" : 9…

---

## [Elastic Cloud - Data onboarding - line break issue](https://discuss.elastic.co/t/elastic-cloud-data-onboarding-line-break-issue/337507)

<div class="topic-metadata">

**Author:** [@inventsekar](https://discuss.elastic.co/u/inventsekar)\
**Replies:** 5\
**Last updated:** [July 6, 2023, 11:38am UTC](https://discuss.elastic.co/t/elastic-cloud-data-onboarding-line-break-issue/337507 "2023-07-06T11:38:23Z")

</div>

Hi All.. A complete newbie to ELK.. booked a 2 weeks Elastic cloud and onboarded some sample logs. got stuck with the line break issue. (checked the logs and searched on youtube, but no luck) i mean.. the sample log is…

---

## ["ClusterFormationFailureHelper" master not discovered error while master node is run an stable elected](https://discuss.elastic.co/t/clusterformationfailurehelper-master-not-discovered-error-while-master-node-is-run-an-stable-elected/337789)

<div class="topic-metadata">

**Author:** [@Mohammad\_Hossein\_Ela](https://discuss.elastic.co/u/Mohammad_Hossein_Ela)\
**Replies:** 0\
**Last updated:** [July 6, 2023, 11:22am UTC](https://discuss.elastic.co/t/clusterformationfailurehelper-master-not-discovered-error-while-master-node-is-run-an-stable-elected/337789 "2023-07-06T11:22:01Z")

</div>

I have two two nodes. the first node is master. this node is running without any error. but another node cannot discover this node. The full log of second node as below: \[2023-07-06T09:39:30,479\]\[INFO \]\[o.e.n.Node …

[Previous page](https://discuss.elastic.co/latest.md?page=614)

[Next page](https://discuss.elastic.co/latest.md?page=616)
