# Latest

**URL:** https://discuss.elastic.co/latest.md?page=617

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 618

---

## [Enrolling elastic-agent, the production-ready way?](https://discuss.elastic.co/t/enrolling-elastic-agent-the-production-ready-way/337697)

<div class="topic-metadata">

**Author:** [@UPPERCASE](https://discuss.elastic.co/u/UPPERCASE)\
**Replies:** 5\
**Last updated:** [July 5, 2023, 7:07pm UTC](https://discuss.elastic.co/t/enrolling-elastic-agent-the-production-ready-way/337697 "2023-07-05T19:07:39Z")

</div>

I want to use Fleet, but I have some doubts about the documented deployment method. I think it would've been better if it was possible to just install the elastic-agent as an RPM/DEB and then configure a yaml file, then …

---

## [Logs are getting parsed in messages field for M365 Defender Logs](https://discuss.elastic.co/t/logs-are-getting-parsed-in-messages-field-for-m365-defender-logs/337698)

<div class="topic-metadata">

**Author:** [@elastic12](https://discuss.elastic.co/u/elastic12)\
**Replies:** 0\
**Last updated:** [July 5, 2023, 4:27pm UTC](https://discuss.elastic.co/t/logs-are-getting-parsed-in-messages-field-for-m365-defender-logs/337698 "2023-07-05T16:27:11Z")

</div>

The issue is with the logs in Microsoft 365 Defender. All of the logs are being stored in a single message field, instead of being stored in individual fields as shown in Elasticsearch documentation. Previously, the logs…

---

## [Vector search for large amount of data with limited RAM resources](https://discuss.elastic.co/t/vector-search-for-large-amount-of-data-with-limited-ram-resources/337681)

<div class="topic-metadata">

**Author:** [@louis\_sg](https://discuss.elastic.co/u/louis_sg)\
**Replies:** 3\
**Last updated:** [July 5, 2023, 4:03pm UTC](https://discuss.elastic.co/t/vector-search-for-large-amount-of-data-with-limited-ram-resources/337681 "2023-07-05T16:03:15Z")

</div>

Hi there, I am new here trying to use Elasticsearch for vector similarity search. My dataset is as large as 100M records, each containing a 384 dimensions vector and a string payload. I am building the HNSW index type…

---

## [Stacktrace logged by several lines in kibana](https://discuss.elastic.co/t/stacktrace-logged-by-several-lines-in-kibana/337539)

<div class="topic-metadata">

**Author:** [@ANARAN](https://discuss.elastic.co/u/ANARAN)\
**Replies:** 3\
**Last updated:** [July 5, 2023, 3:59pm UTC](https://discuss.elastic.co/t/stacktrace-logged-by-several-lines-in-kibana/337539 "2023-07-05T15:59:45Z")

</div>

Hello, I'm trying to improve the display of stacktraces for an application I'm working on. Now, the stacktrace look like this : I work with log4j (I know, it's deprecated) and logstash, but not filebeat. How can I…

---

## [Max retries exceeded with url: /pmc/documents.json.bz2 SSLCertVerificationError \[SSL: CERTIFICATE\_VERIFY\_FAILED\]](https://discuss.elastic.co/t/max-retries-exceeded-with-url-pmc-documents-json-bz2-sslcertverificationerror-ssl-certificate-verify-failed/335708)

<div class="topic-metadata">

**Author:** [@Swathi\_Kakumanu](https://discuss.elastic.co/u/Swathi_Kakumanu)\
**Replies:** 7\
**Last updated:** [July 5, 2023, 3:51pm UTC](https://discuss.elastic.co/t/max-retries-exceeded-with-url-pmc-documents-json-bz2-sslcertverificationerror-ssl-certificate-verify-failed/335708 "2023-07-05T15:51:39Z")

</div>

Hi, I am facing an issue with SSL Verification of esrally for rally-tracks.elastic.co', port=443 , however curl request and openssl works fine. FYI, internet works on the rally VM. Command used to run: esrally race -…

---

## [Text embedding different in elastic search and python library](https://discuss.elastic.co/t/text-embedding-different-in-elastic-search-and-python-library/329164)

<div class="topic-metadata">

**Author:** [@Roshan\_Kumar1](https://discuss.elastic.co/u/Roshan_Kumar1)\
**Replies:** 5\
**Last updated:** [July 5, 2023, 3:07pm UTC](https://discuss.elastic.co/t/text-embedding-different-in-elastic-search-and-python-library/329164 "2023-07-05T15:07:51Z")

</div>

Deploying sentence transformer model as provided in this blog, using eland on Elasticsearch returns only the embedding corresponding to the first token. However, while using the python implementation to encode the text r…

---

## [Api Search in Python - how to get bad return code](https://discuss.elastic.co/t/api-search-in-python-how-to-get-bad-return-code/337686)

<div class="topic-metadata">

**Author:** [@RickT](https://discuss.elastic.co/u/RickT)\
**Replies:** 0\
**Last updated:** [July 5, 2023, 2:43pm UTC](https://discuss.elastic.co/t/api-search-in-python-how-to-get-bad-return-code/337686 "2023-07-05T14:43:47Z")

</div>

Hi, I'm using the search API running from Python to collect some documents. The request goes well as long as the connection is OK. However, when the connection is timeout, the Python script crashes and i can't used any…

---

## [Installation document for ELK 8.7](https://discuss.elastic.co/t/installation-document-for-elk-8-7/337635)

<div class="topic-metadata">

**Author:** [@SivaPrasadELK](https://discuss.elastic.co/u/SivaPrasadELK)\
**Replies:** 1\
**Last updated:** [July 5, 2023, 1:59pm UTC](https://discuss.elastic.co/t/installation-document-for-elk-8-7/337635 "2023-07-05T13:59:40Z")

</div>

While trying to install the ELK 8.7 and its components such as file beat logstash kibana and Elasticsearch and trying to setup the ELK as below Filebeat =====\> Logstash ======\> elastic =======\>kibana keeping this workf…

---

## [Get and set Elasticsearch data via plugin](https://discuss.elastic.co/t/get-and-set-elasticsearch-data-via-plugin/337626)

<div class="topic-metadata">

**Author:** [@Sheereen](https://discuss.elastic.co/u/Sheereen)\
**Replies:** 6\
**Last updated:** [July 5, 2023, 1:29pm UTC](https://discuss.elastic.co/t/get-and-set-elasticsearch-data-via-plugin/337626 "2023-07-05T13:29:39Z")

</div>

Hi, I am developing a custom plugin in Kibana using React, in Kibana 8.8.1. I want to set and get Elasticsearch data via the plugin. Which of the 2 is a better option? Elasticsearch service Elasticsearch service …

---

## [Is it possible to use encrypted elascticsearch instead of direct username, password in Output plugin of logstash?](https://discuss.elastic.co/t/is-it-possible-to-use-encrypted-elascticsearch-instead-of-direct-username-password-in-output-plugin-of-logstash/337647)

<div class="topic-metadata">

**Author:** [@merson](https://discuss.elastic.co/u/merson)\
**Replies:** 1\
**Last updated:** [July 5, 2023, 1:24pm UTC](https://discuss.elastic.co/t/is-it-possible-to-use-encrypted-elascticsearch-instead-of-direct-username-password-in-output-plugin-of-logstash/337647 "2023-07-05T13:24:57Z")

</div>

I want to use encrypted elasticsearch, So I don't want to use directly username ,password of elasticsearch in logstash. Please provide the any answers.

---

## [Query\_suggestion does not work on Elasticsearch-index based engine](https://discuss.elastic.co/t/query-suggestion-does-not-work-on-elasticsearch-index-based-engine/337630)

<div class="topic-metadata">

**Author:** [@JohMat](https://discuss.elastic.co/u/JohMat)\
**Replies:** 3\
**Last updated:** [July 5, 2023, 1:03pm UTC](https://discuss.elastic.co/t/query-suggestion-does-not-work-on-elasticsearch-index-based-engine/337630 "2023-07-05T13:03:16Z")

</div>

I have an issue where queries to enterprisesearch's app\_search (8.8.2) "query\_suggestion" endpoint does not return suggestions when the engine is based on an elasticsearch index. The endpoint works and are returning sug…

---

## [JVM crash originating from APM agent](https://discuss.elastic.co/t/jvm-crash-originating-from-apm-agent/337265)

<div class="topic-metadata">

**Author:** [@svenrienstra](https://discuss.elastic.co/u/svenrienstra)\
**Replies:** 7\
**Last updated:** [July 5, 2023, 12:58pm UTC](https://discuss.elastic.co/t/jvm-crash-originating-from-apm-agent/337265 "2023-07-05T12:58:53Z")

</div>

We've been experiencing a SIGSEV JVM crash on our production cluster which seems to originate from the APM Java agent. We haven't been able to establish a pattern of when this happens or what triggers this. The second in…

---

## [Logstash build from Source failing](https://discuss.elastic.co/t/logstash-build-from-source-failing/337611)

<div class="topic-metadata">

**Author:** [@tejas7](https://discuss.elastic.co/u/tejas7)\
**Replies:** 2\
**Last updated:** [July 5, 2023, 12:58pm UTC](https://discuss.elastic.co/t/logstash-build-from-source-failing/337611 "2023-07-05T12:58:49Z")

</div>

Hello Team , I am trying to build logstash from source code from the main branch. It is failing with the following error: \* Exception is: org.gradle.api.tasks.TaskExecutionException: Execution failed for task ':install…

---

## [SAML without Elasticsearch SSL (using Traefik as a reverse proxy)](https://discuss.elastic.co/t/saml-without-elasticsearch-ssl-using-traefik-as-a-reverse-proxy/336396)

<div class="topic-metadata">

**Author:** [@rushil791](https://discuss.elastic.co/u/rushil791)\
**Replies:** 4\
**Last updated:** [July 5, 2023, 12:50pm UTC](https://discuss.elastic.co/t/saml-without-elasticsearch-ssl-using-traefik-as-a-reverse-proxy/336396 "2023-07-05T12:50:00Z")

</div>

Hi there, I want to be able to use SAML with my Elasticsearch-Kibana setup in Docker, but I need to be able to use my organisation's CA cert. I do not have access to the CA's private key, so I can't use the certutil to …

---

## [Login Elasticsearch and Kibana](https://discuss.elastic.co/t/login-elasticsearch-and-kibana/337661)

<div class="topic-metadata">

**Author:** [@stephane\_chan](https://discuss.elastic.co/u/stephane_chan)\
**Replies:** 0\
**Last updated:** [July 5, 2023, 11:14am UTC](https://discuss.elastic.co/t/login-elasticsearch-and-kibana/337661 "2023-07-05T11:14:09Z")

</div>

Hi, Is it possible to generate a token on the elasticsearch API? A sort of login (username/password) and the same on kibana? Currently, there's no such thing on my elasticsearch and kibana instance, and anyone can make…

---

## [Is it possible to restore a specific index from a datastream to a datastream from snapshot](https://discuss.elastic.co/t/is-it-possible-to-restore-a-specific-index-from-a-datastream-to-a-datastream-from-snapshot/334710)

<div class="topic-metadata">

**Author:** [@Kay\_Khan](https://discuss.elastic.co/u/Kay_Khan)\
**Replies:** 3\
**Last updated:** [July 5, 2023, 10:50am UTC](https://discuss.elastic.co/t/is-it-possible-to-restore-a-specific-index-from-a-datastream-to-a-datastream-from-snapshot/334710 "2023-07-05T10:50:47Z")

</div>

Recently we migrated our elasticsearch cluster and used snapshot/restore to do this. Unfortunately we forgot about a change we made to the lifecycle policy of a the apm traces datastream. Which meant data older than 90 …

---

## [Elasticsearch 8.5.2 -- Restoring datastreams isn’t working as planned](https://discuss.elastic.co/t/elasticsearch-8-5-2-restoring-datastreams-isn-t-working-as-planned/337645)

<div class="topic-metadata">

**Author:** [@Gautier\_Franchini](https://discuss.elastic.co/u/Gautier_Franchini)\
**Replies:** 1\
**Last updated:** [July 5, 2023, 10:48am UTC](https://discuss.elastic.co/t/elasticsearch-8-5-2-restoring-datastreams-isn-t-working-as-planned/337645 "2023-07-05T10:48:37Z")

</div>

Hello, I encountered an issue during a datastream restore this morning: What I want to achieve: restore the backuped indices from may 2023 in the same current working datastream ; I would like to avoid interruption of…

---

## [Cluster overshard issue](https://discuss.elastic.co/t/cluster-overshard-issue/337603)

<div class="topic-metadata">

**Author:** [@JasonREC](https://discuss.elastic.co/u/JasonREC)\
**Replies:** 1\
**Last updated:** [July 5, 2023, 10:22am UTC](https://discuss.elastic.co/t/cluster-overshard-issue/337603 "2023-07-05T10:22:20Z")

</div>

Hi, I have question about how to solve the cluster overshard issue sot that things can get back to normal/ Currently, I am renting 2 node in 2 different zone. And, I've encountered oversharding issue, show in the b…

---

## [Cannot connect to elasticsearch, via functionbeat(using AWS Lambda)](https://discuss.elastic.co/t/cannot-connect-to-elasticsearch-via-functionbeat-using-aws-lambda/337657)

<div class="topic-metadata">

**Author:** [@Kavan\_Dalwadi](https://discuss.elastic.co/u/Kavan_Dalwadi)\
**Replies:** 0\
**Last updated:** [July 5, 2023, 10:42am UTC](https://discuss.elastic.co/t/cannot-connect-to-elasticsearch-via-functionbeat-using-aws-lambda/337657 "2023-07-05T10:42:39Z")

</div>

Currently I have deployed Elasticstack (ELK) on AWS EKS and Im using NodePort service for all the application My elasticsearch is running at- 54.2xx.xxx.xxx:30092/ (Which is the public IP address of EC2). I have lamb…

---

## [Error while performing snapshot and restore in 3 node elk cluster](https://discuss.elastic.co/t/error-while-performing-snapshot-and-restore-in-3-node-elk-cluster/337656)

<div class="topic-metadata">

**Author:** [@Raushan\_kumar](https://discuss.elastic.co/u/Raushan_kumar)\
**Replies:** 0\
**Last updated:** [July 5, 2023, 10:40am UTC](https://discuss.elastic.co/t/error-while-performing-snapshot-and-restore-in-3-node-elk-cluster/337656 "2023-07-05T10:40:49Z")

</div>

so i am trying to perform snapshot and restore on 3 node cluster in elasticsearch 8.7 through nfs.but when i am putting the path.repo same path of shared directory so its giving me that this path.repo is not accessible.n…

---

## [Add id processor filebeat](https://discuss.elastic.co/t/add-id-processor-filebeat/337655)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 0\
**Last updated:** [July 5, 2023, 10:39am UTC](https://discuss.elastic.co/t/add-id-processor-filebeat/337655 "2023-07-05T10:39:00Z")

</div>

Hi there, just want to ask, i have configured filebeat as a container and the filebeat has been ingested millions of logs every minutes. first of all, this is my filebeat config precisely on processor part: as can y…

---

## [How to not use Keyword type when importing csv?](https://discuss.elastic.co/t/how-to-not-use-keyword-type-when-importing-csv/337601)

<div class="topic-metadata">

**Author:** [@tavd-projects](https://discuss.elastic.co/u/tavd-projects)\
**Replies:** 2\
**Last updated:** [July 5, 2023, 10:10am UTC](https://discuss.elastic.co/t/how-to-not-use-keyword-type-when-importing-csv/337601 "2023-07-05T10:10:37Z")

</div>

Hello. How to make columns not indexed as Keyword when importing CSV? (I'm using the standard integration, not Logstash). The problem is that I can't seem to change the Keyword to a specific data type in any way. I will …

---

## [Not able to find a way to add event.json in APM serverless Lambda transactions](https://discuss.elastic.co/t/not-able-to-find-a-way-to-add-event-json-in-apm-serverless-lambda-transactions/336984)

<div class="topic-metadata">

**Author:** [@Kesha\_Shah](https://discuss.elastic.co/u/Kesha_Shah)\
**Replies:** 4\
**Last updated:** [July 5, 2023, 9:19am UTC](https://discuss.elastic.co/t/not-able-to-find-a-way-to-add-event-json-in-apm-serverless-lambda-transactions/336984 "2023-07-05T09:19:06Z")

</div>

Kibana version: 8.8.1 Elasticsearch version: 8.8.1 APM Server version: 8.8.1 APM Agent language and version: NodeJs Agent elastic-apm-node": "^3.47.0 Fresh install or upgraded from other version? Upgraded from 7.17 r…

---

## [When the master node publishes the cluster state, if a certain slave node fails to respond consistently and no timeout is set, does it mean that it will keep waiting and cannot complete?](https://discuss.elastic.co/t/when-the-master-node-publishes-the-cluster-state-if-a-certain-slave-node-fails-to-respond-consistently-and-no-timeout-is-set-does-it-mean-that-it-will-keep-waiting-and-cannot-complete/337595)

<div class="topic-metadata">

**Author:** [@cm\_z](https://discuss.elastic.co/u/cm_z)\
**Replies:** 2\
**Last updated:** [July 5, 2023, 9:47am UTC](https://discuss.elastic.co/t/when-the-master-node-publishes-the-cluster-state-if-a-certain-slave-node-fails-to-respond-consistently-and-no-timeout-is-set-does-it-mean-that-it-will-keep-waiting-and-cannot-complete/337595 "2023-07-05T09:47:35Z")

</div>

I found that when the master node publishes the cluster state, in the second phase, it will wait for all slave nodes to respond (successfully or unsuccessfully) before proceeding with the subsequent process. If a request…

---

## [Change path of data file](https://discuss.elastic.co/t/change-path-of-data-file/337633)

<div class="topic-metadata">

**Author:** [@Hi\_u\_Thu\_n](https://discuss.elastic.co/u/Hi_u_Thu_n)\
**Replies:** 4\
**Last updated:** [July 5, 2023, 9:39am UTC](https://discuss.elastic.co/t/change-path-of-data-file/337633 "2023-07-05T09:39:22Z")

</div>

I change path in file elasticsearch.yml but it not working! # ----------------------------------- Paths ------------------------------------ # # Path to directory where to store the data (separate multiple locations by …

---

## [Can not create update index pipeline without unique identifier in database](https://discuss.elastic.co/t/can-not-create-update-index-pipeline-without-unique-identifier-in-database/337494)

<div class="topic-metadata">

**Author:** [@PodarcisMuralis](https://discuss.elastic.co/u/PodarcisMuralis)\
**Replies:** 3\
**Last updated:** [July 5, 2023, 9:31am UTC](https://discuss.elastic.co/t/can-not-create-update-index-pipeline-without-unique-identifier-in-database/337494 "2023-07-05T09:31:05Z")

</div>

Hi all. I want to create an update index using jdbc input and elasticsearch output. I have a left joined table consists of 4 tables in database. But I do not have a unique identifier in db. Therefore I can not create …

---

## [No node formation by changing bootstrap.password on all node](https://discuss.elastic.co/t/no-node-formation-by-changing-bootstrap-password-on-all-node/337643)

<div class="topic-metadata">

**Author:** [@MALKARAJ\_K](https://discuss.elastic.co/u/MALKARAJ_K)\
**Replies:** 0\
**Last updated:** [July 5, 2023, 9:06am UTC](https://discuss.elastic.co/t/no-node-formation-by-changing-bootstrap-password-on-all-node/337643 "2023-07-05T09:06:30Z")

</div>

Elasticsearch nodes couldn't form the cluster by changing bootstrap.password on each node

---

## [I want to implement automatic user login to a Kibana dashboard from a web application](https://discuss.elastic.co/t/i-want-to-implement-automatic-user-login-to-a-kibana-dashboard-from-a-web-application/337233)

<div class="topic-metadata">

**Author:** [@dilshadpaleri](https://discuss.elastic.co/u/dilshadpaleri)\
**Replies:** 1\
**Last updated:** [July 5, 2023, 9:05am UTC](https://discuss.elastic.co/t/i-want-to-implement-automatic-user-login-to-a-kibana-dashboard-from-a-web-application/337233 "2023-07-05T09:05:55Z")

</div>

I want to implement automatic user login to a Kibana dashboard from a web application. I have successfully enabled x-pack security and attempted to authenticate users through the HTTP header. However, I am facing an issu…

---

## [Parameters in Kibana](https://discuss.elastic.co/t/parameters-in-kibana/337574)

<div class="topic-metadata">

**Author:** [@Olga\_Nalivaiko](https://discuss.elastic.co/u/Olga_Nalivaiko)\
**Replies:** 5\
**Last updated:** [July 5, 2023, 7:43am UTC](https://discuss.elastic.co/t/parameters-in-kibana/337574 "2023-07-05T07:43:07Z")

</div>

Hello! I'm new to Kibana and I have been trying to find such a control feature as parameter. For example, a dropdown with a list of fields so that the user could select one for the chart or a dropdown with numeric value…

---

## [Logstash JDBC Input - Time difference problem](https://discuss.elastic.co/t/logstash-jdbc-input-time-difference-problem/337542)

<div class="topic-metadata">

**Author:** [@thibaut\_a](https://discuss.elastic.co/u/thibaut_a)\
**Replies:** 2\
**Last updated:** [July 5, 2023, 7:20am UTC](https://discuss.elastic.co/t/logstash-jdbc-input-time-difference-problem/337542 "2023-07-05T07:20:45Z")

</div>

Hi, I receive entries from a PostgreSQL database in my Logstash Docker container. I get what I want but I'm facing a problem with the timestamp. When I do a request in pgAdmin, it shows timestamps with the local time (Fr…

[Previous page](https://discuss.elastic.co/latest.md?page=616)

[Next page](https://discuss.elastic.co/latest.md?page=618)
