# Latest

**URL:** https://discuss.elastic.co/latest.md?page=622

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 623

---

## [Legacy metric to display unique count of a combination of 3 fields](https://discuss.elastic.co/t/legacy-metric-to-display-unique-count-of-a-combination-of-3-fields/336985)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 1\
**Last updated:** [June 30, 2023, 9:38am UTC](https://discuss.elastic.co/t/legacy-metric-to-display-unique-count-of-a-combination-of-3-fields/336985 "2023-06-30T09:38:54Z")

</div>

Hi, I am working on a kibana dashboard and using a legacy metric visualization. How can i display a unique count of a combination of three fields in the data view? there is an option of selecting only one field. { "m…

---

## [How to configure the THESPIAN\_BASE\_IPADDR when encounter 'ActorAddr-(T|:1900) is not a valid ActorSystem admin'](https://discuss.elastic.co/t/how-to-configure-the-thespian-base-ipaddr-when-encounter-actoraddr-t-1900-is-not-a-valid-actorsystem-admin/336802)

<div class="topic-metadata">

**Author:** [@tengfei225](https://discuss.elastic.co/u/tengfei225)\
**Replies:** 2\
**Last updated:** [June 30, 2023, 9:10am UTC](https://discuss.elastic.co/t/how-to-configure-the-thespian-base-ipaddr-when-encounter-actoraddr-t-1900-is-not-a-valid-actorsystem-admin/336802 "2023-06-30T09:10:48Z")

</div>

Hi I am a new user of Esrally, currently I have created my custom track in order to benchmark the elastic cloud in azure when I try the below command, the actor system can not be started esrally race --track=percolato…

---

## [Is there a way to dynamically group overlapping events?](https://discuss.elastic.co/t/is-there-a-way-to-dynamically-group-overlapping-events/337290)

<div class="topic-metadata">

**Author:** [@landre](https://discuss.elastic.co/u/landre)\
**Replies:** 0\
**Last updated:** [June 30, 2023, 9:03am UTC](https://discuss.elastic.co/t/is-there-a-way-to-dynamically-group-overlapping-events/337290 "2023-06-30T09:03:29Z")

</div>

I am importing data from MySQL using logstash, that contains events with a start and an end date. However, some of these events overlap and, in some conditions, need to be treated as a single event, starting at the start…

---

## [SSL ISSUE FOR ELASTIC](https://discuss.elastic.co/t/ssl-issue-for-elastic/337276)

<div class="topic-metadata">

**Author:** [@Nupur\_Srivastava1](https://discuss.elastic.co/u/Nupur_Srivastava1)\
**Replies:** 1\
**Last updated:** [June 30, 2023, 9:02am UTC](https://discuss.elastic.co/t/ssl-issue-for-elastic/337276 "2023-06-30T09:02:04Z")

</div>

Hi Team, when I try to start Elasticsearch service after enabling TLS I am getting below error: \[2023-06-30T07:01:11,903\]\[ERROR\]\[o.e.b.Elasticsearch \] \[ip-10-0-8-194\] fatal exception while booting Elasticsearch or…

---

## [How to process the performance logs from JMeter to Elastic Kibana](https://discuss.elastic.co/t/how-to-process-the-performance-logs-from-jmeter-to-elastic-kibana/337286)

<div class="topic-metadata">

**Author:** [@anushyaadam](https://discuss.elastic.co/u/anushyaadam)\
**Replies:** 1\
**Last updated:** [June 30, 2023, 9:00am UTC](https://discuss.elastic.co/t/how-to-process-the-performance-logs-from-jmeter-to-elastic-kibana/337286 "2023-06-30T09:00:32Z")

</div>

Hi Team, The Application team is trying to process the live logs from JMeter to Elastic Kibana via API key. Is this possible to see the JMeter performance logs in Kibana ? If yes, please guide us on the steps to be take…

---

## [How to connect Angular logs](https://discuss.elastic.co/t/how-to-connect-angular-logs/337193)

<div class="topic-metadata">

**Author:** [@pavlod](https://discuss.elastic.co/u/pavlod)\
**Replies:** 7\
**Last updated:** [June 30, 2023, 8:56am UTC](https://discuss.elastic.co/t/how-to-connect-angular-logs/337193 "2023-06-30T08:56:05Z")

</div>

Hello! I have a task to connect frontend to Elasticsearch but I cannot find instructions how to connect it... For example I need to connect Angular to Elastic. Thanks!

---

## [Vega tree layout is not working in kibana](https://discuss.elastic.co/t/vega-tree-layout-is-not-working-in-kibana/337157)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 1\
**Last updated:** [June 30, 2023, 8:43am UTC](https://discuss.elastic.co/t/vega-tree-layout-is-not-working-in-kibana/337157 "2023-06-30T08:43:38Z")

</div>

Hi, I am trying the example given in the following link Tree Layout Example | Vega Here is the output after adding "autosize": "none", I am still getting the the error Data ingestion failed data/flare.json I am n…

---

## [Elasticsearch 8.8.2, 7.17.11 Security Update](https://discuss.elastic.co/t/elasticsearch-8-8-2-7-17-11-security-update/337205)

<div class="topic-metadata">

**Author:** [@ismisepaul](https://discuss.elastic.co/u/ismisepaul)\
**Replies:** 0\
**Last updated:** [June 29, 2023, 2:08pm UTC](https://discuss.elastic.co/t/elasticsearch-8-8-2-7-17-11-security-update/337205 "2023-06-29T14:08:31Z")

</div>

Elasticsearch Denial of Service (DoS) issue (ESA-2023-10) This issue only affects users that have at least one OpenID Connect authentication realm or at least one JWT authentication realm configured. A denial of servic…

---

## [ELK cluster issue after removing one of the master](https://discuss.elastic.co/t/elk-cluster-issue-after-removing-one-of-the-master/337267)

<div class="topic-metadata">

**Author:** [@Alwyn\_Tiu](https://discuss.elastic.co/u/Alwyn_Tiu)\
**Replies:** 5\
**Last updated:** [June 30, 2023, 8:00am UTC](https://discuss.elastic.co/t/elk-cluster-issue-after-removing-one-of-the-master/337267 "2023-06-30T08:00:06Z")

</div>

\[2023-06-30T13:43:27,396\]\[ERROR\]\[o.e.x.m.c.c.ClusterStatsCollector\] \[xxx-es-master-2.xxx.com\] collector \[cluster\_stats\] failed to collect data org.elasticsearch.action.search.SearchPhaseExecutionException: all shards fai…

---

## [ELK cluster issue failed after data node restart](https://discuss.elastic.co/t/elk-cluster-issue-failed-after-data-node-restart/337266)

<div class="topic-metadata">

**Author:** [@Alwyn\_Tiu](https://discuss.elastic.co/u/Alwyn_Tiu)\
**Replies:** 0\
**Last updated:** [June 30, 2023, 5:50am UTC](https://discuss.elastic.co/t/elk-cluster-issue-failed-after-data-node-restart/337266 "2023-06-30T05:50:52Z")

</div>

ELK cluster issue failed after data node restart Tried restarting all nodes, after restart the index starts to restore but during restoring there is an error message: .text-only,.text-card-text{white-space: pre;}.rich-t…

---

## [Get the hit count in EQL](https://discuss.elastic.co/t/get-the-hit-count-in-eql/335529)

<div class="topic-metadata">

**Author:** [@sanju1323](https://discuss.elastic.co/u/sanju1323)\
**Replies:** 2\
**Last updated:** [June 30, 2023, 5:42am UTC](https://discuss.elastic.co/t/get-the-hit-count-in-eql/335529 "2023-06-30T05:42:48Z")

</div>

Hi, I'm using the EQL queries for my search and want to get the hits.total.value . When I try the below query, i'm getting the hits.total.value as 10. But I'm not getting the total count of the hits for the search. G…

---

## [Kibana Fleet UI not displaying CPU and Memory Stats for Agents](https://discuss.elastic.co/t/kibana-fleet-ui-not-displaying-cpu-and-memory-stats-for-agents/337002)

<div class="topic-metadata">

**Author:** [@Kang\_Tze\_Ng](https://discuss.elastic.co/u/Kang_Tze_Ng)\
**Replies:** 1\
**Last updated:** [June 30, 2023, 5:00am UTC](https://discuss.elastic.co/t/kibana-fleet-ui-not-displaying-cpu-and-memory-stats-for-agents/337002 "2023-06-30T05:00:11Z")

</div>

As in title. Fleet server is displaying fine. Verified that metrics are indeed being collected.

---

## [Is it possible to get http.max\_content\_length in AWS Elasticsearch?](https://discuss.elastic.co/t/is-it-possible-to-get-http-max-content-length-in-aws-elasticsearch/337223)

<div class="topic-metadata">

**Author:** [@a-moondance-94](https://discuss.elastic.co/u/a-moondance-94)\
**Replies:** 10\
**Last updated:** [June 30, 2023, 3:40am UTC](https://discuss.elastic.co/t/is-it-possible-to-get-http-max-content-length-in-aws-elasticsearch/337223 "2023-06-30T03:40:45Z")

</div>

I need to get the max\_content\_length to limit the size of the bulk request I am sending to AWS Elasticsearch. In my local installation of Elasticsearch I am able to do this using GET \_cluster/settings?include\_defaults A…

---

## [SHA1 error msgs from 'dnf update' (centos9.x)](https://discuss.elastic.co/t/sha1-error-msgs-from-dnf-update-centos9-x/337206)

<div class="topic-metadata">

**Author:** [@ethrbunny](https://discuss.elastic.co/u/ethrbunny)\
**Replies:** 1\
**Last updated:** [June 30, 2023, 2:10am UTC](https://discuss.elastic.co/t/sha1-error-msgs-from-dnf-update-centos9-x/337206 "2023-06-30T02:10:36Z")

</div>

Looks like elastic is signing 8.8.x \*beat package updates with SHA1. CentOS 9 doesn't support this anymore. I can bypass it but maybe it's time to update these to something that's supported? journal is chock full of er…

---

## [Why count(distinct patient\_id) is larger than count(patient\_id)?](https://discuss.elastic.co/t/why-count-distinct-patient-id-is-larger-than-count-patient-id/337250)

<div class="topic-metadata">

**Author:** [@DongPoJuShi\_Dj](https://discuss.elastic.co/u/DongPoJuShi_Dj)\
**Replies:** 0\
**Last updated:** [June 30, 2023, 1:24am UTC](https://discuss.elastic.co/t/why-count-distinct-patient-id-is-larger-than-count-patient-id/337250 "2023-06-30T01:24:29Z")

</div>

There is an index alias that includes two indexes, and the index structure is as follows: { "scientific\_data\_group1": { "aliases": { "scientific\_data\_group": {} }, "mappings": { "properties": {…

---

## [Elasticsearch Query cache shows no data](https://discuss.elastic.co/t/elasticsearch-query-cache-shows-no-data/336306)

<div class="topic-metadata">

**Author:** [@mhr](https://discuss.elastic.co/u/mhr)\
**Replies:** 8\
**Last updated:** [June 30, 2023, 1:08am UTC](https://discuss.elastic.co/t/elasticsearch-query-cache-shows-no-data/336306 "2023-06-30T01:08:42Z")

</div>

The problem we are facing is that query cache is not being used at all in our ES cluster except version 7.8.1. We are using ES version 7.8.1 and we see data in Query Cache as show below. After upgrading to ES versio…

---

## [Call runtime field to another runtime field while creating](https://discuss.elastic.co/t/call-runtime-field-to-another-runtime-field-while-creating/337235)

<div class="topic-metadata">

**Author:** [@rubhamra](https://discuss.elastic.co/u/rubhamra)\
**Replies:** 1\
**Last updated:** [June 29, 2023, 10:11pm UTC](https://discuss.elastic.co/t/call-runtime-field-to-another-runtime-field-while-creating/337235 "2023-06-29T22:11:59Z")

</div>

I have question about runtime field, I want to call a runtime field to another runtime field. Suppose I have created a runtime field called (numberOfdays) which is calculating count of days between two dates. Now I ha…

---

## [Authentication of \[elastic\] was terminated by realm \[reserved\] - failed to authenticate user \[elastic\]](https://discuss.elastic.co/t/authentication-of-elastic-was-terminated-by-realm-reserved-failed-to-authenticate-user-elastic/336330)

<div class="topic-metadata">

**Author:** [@aaronlbk](https://discuss.elastic.co/u/aaronlbk)\
**Replies:** 8\
**Last updated:** [June 29, 2023, 10:10pm UTC](https://discuss.elastic.co/t/authentication-of-elastic-was-terminated-by-realm-reserved-failed-to-authenticate-user-elastic/336330 "2023-06-29T22:10:24Z")

</div>

Hello When I start elastic, I am getting the error below: Authentication of \[elastic\] was terminated by realm \[reserved\] - failed to authenticate user \[elastic\] I didn't have this error previously. When I try to auth…

---

## [Authentication using apikey failed - unable to find apikey with id](https://discuss.elastic.co/t/authentication-using-apikey-failed-unable-to-find-apikey-with-id/337217)

<div class="topic-metadata">

**Author:** [@p\_vimal](https://discuss.elastic.co/u/p_vimal)\
**Replies:** 3\
**Last updated:** [June 29, 2023, 9:58pm UTC](https://discuss.elastic.co/t/authentication-using-apikey-failed-unable-to-find-apikey-with-id/337217 "2023-06-29T21:58:01Z")

</div>

Hello, We are running Elasticsearch 7.17.8 and have many error entries like this on in the elastic logs: \[WARN \]\[o.e.x.s.a.ApiKeyAuthenticator\] \[NODENAMEE\] Authentication using apikey failed - unable to find apikey wi…

---

## [Child document is occasionally not searchable](https://discuss.elastic.co/t/child-document-is-occasionally-not-searchable/337240)

<div class="topic-metadata">

**Author:** [@kved](https://discuss.elastic.co/u/kved)\
**Replies:** 0\
**Last updated:** [June 29, 2023, 8:33pm UTC](https://discuss.elastic.co/t/child-document-is-occasionally-not-searchable/337240 "2023-06-29T20:33:36Z")

</div>

Child documents are sometimes not searchable. I have a parent-child relationship where the mapping looks like { "parent": { "id": "keyword", "name": "text" } "childId": "keyword", …

---

## [Filebeat setup. could not load template error](https://discuss.elastic.co/t/filebeat-setup-could-not-load-template-error/337135)

<div class="topic-metadata">

**Author:** [@ashmistry](https://discuss.elastic.co/u/ashmistry)\
**Replies:** 7\
**Last updated:** [June 29, 2023, 6:38pm UTC](https://discuss.elastic.co/t/filebeat-setup-could-not-load-template-error/337135 "2023-06-29T18:38:14Z")

</div>

Trying to setup filebeat on my stack. It's Elasticsearch OSS 7.10.2 with opensearch 2.4.1. I am using filebeat oss 7.12.1 and got a successful test output \[root\]# filebeat test output elasticsearch: https://xyz:9200... …

---

## [ElasticSearch does not start and not even cluster](https://discuss.elastic.co/t/elasticsearch-does-not-start-and-not-even-cluster/337017)

<div class="topic-metadata">

**Author:** [@TomTom](https://discuss.elastic.co/u/TomTom)\
**Replies:** 10\
**Last updated:** [June 29, 2023, 6:29pm UTC](https://discuss.elastic.co/t/elasticsearch-does-not-start-and-not-even-cluster/337017 "2023-06-29T18:29:46Z")

</div>

I'm trying to create an Elasticsearch cluster with 3 nodes, each node being eligible as a master, as stated in this doc. This cluster will be used by the end user only on our local network through an nginx proxy that wi…

---

## [JsonProviderImpl not found but only for UpdateByQuery responses](https://discuss.elastic.co/t/jsonproviderimpl-not-found-but-only-for-updatebyquery-responses/337051)

<div class="topic-metadata">

**Author:** [@ndtreviv](https://discuss.elastic.co/u/ndtreviv)\
**Replies:** 1\
**Last updated:** [June 29, 2023, 6:00pm UTC](https://discuss.elastic.co/t/jsonproviderimpl-not-found-but-only-for-updatebyquery-responses/337051 "2023-06-29T18:00:42Z")

</div>

I'm getting the following error only when deserialising UpdateByQuery responses: 2023-06-27 18:00:18:193 +0000 \[http-nio-8080-exec-4\] ERROR Error: Provider org.glassfish.json.JsonProviderImpl not found jakarta.json.Json…

---

## [Help with grok filter for \[::ffff:127.0.0.1\] hybrid + port](https://discuss.elastic.co/t/help-with-grok-filter-for-127-0-0-1-hybrid-port/337198)

<div class="topic-metadata">

**Author:** [@SedonD](https://discuss.elastic.co/u/SedonD)\
**Replies:** 2\
**Last updated:** [June 29, 2023, 5:26pm UTC](https://discuss.elastic.co/t/help-with-grok-filter-for-127-0-0-1-hybrid-port/337198 "2023-06-29T17:26:19Z")

</div>

Hi there, I need some help to filter (Grok) the following, f.e.: \[::ffff:88.88.88.88\]:4262,... this is a log snippet where I need to filter out the IP and port from the following formats... "New request 366c89e6-9c94-…

---

## [I can't filter nested](https://discuss.elastic.co/t/i-cant-filter-nested/337230)

<div class="topic-metadata">

**Author:** [@Vahid\_Hajiagazadeh](https://discuss.elastic.co/u/Vahid_Hajiagazadeh)\
**Replies:** 0\
**Last updated:** [June 29, 2023, 5:06pm UTC](https://discuss.elastic.co/t/i-cant-filter-nested/337230 "2023-06-29T17:06:10Z")

</div>

I have a document that is in the form of nested data But I can't filter in a nested way and all the products return a category, while in the query I have only filtered products that have attribute\_id 40. my mapping { …

---

## [Elastic Certified Observaibility Trainning Course - Lab 4.3](https://discuss.elastic.co/t/elastic-certified-observaibility-trainning-course-lab-4-3/337072)

<div class="topic-metadata">

**Author:** [@Sara\_YB](https://discuss.elastic.co/u/Sara_YB)\
**Replies:** 2\
**Last updated:** [June 29, 2023, 4:12pm UTC](https://discuss.elastic.co/t/elastic-certified-observaibility-trainning-course-lab-4-3/337072 "2023-06-29T16:12:19Z")

</div>

Course: \<Which course are you asking about?\> Elastic Observability Engineer Version: \<And which particular version?\> 7.9 Question: \<Please add details here!\> I am struggling with lab 4.3, here are what i exactly did: …

---

## [Problems connecting to ES Cross cluster search cluster indexes from Databricks using spark connector](https://discuss.elastic.co/t/problems-connecting-to-es-cross-cluster-search-cluster-indexes-from-databricks-using-spark-connector/335030)

<div class="topic-metadata">

**Author:** [@srinivas\_a1](https://discuss.elastic.co/u/srinivas_a1)\
**Replies:** 3\
**Last updated:** [June 29, 2023, 4:56pm UTC](https://discuss.elastic.co/t/problems-connecting-to-es-cross-cluster-search-cluster-indexes-from-databricks-using-spark-connector/335030 "2023-06-29T16:56:32Z")

</div>

Hi All, I am trying to connect with ES from our Databricks cluster using elasticsearch\_spark\_30\_2\_12\_7\_16\_3.jar. I'm not able to read the data from cross cluster indexes which are starting with "\*:xxxxxxx", However able…

---

## [Logstash input S3 module problem](https://discuss.elastic.co/t/logstash-input-s3-module-problem/334662)

<div class="topic-metadata">

**Author:** [@San9](https://discuss.elastic.co/u/San9)\
**Replies:** 7\
**Last updated:** [June 29, 2023, 3:12pm UTC](https://discuss.elastic.co/t/logstash-input-s3-module-problem/334662 "2023-06-29T15:12:08Z")

</div>

The problem is in the operation of the S3 module, the module starts for some time, everything works, but after a couple of hours the module is left with an error: Error: Too many open files - Too many open files May 25 …

---

## [Elasticsearch Java API Client throwing error for empty fields](https://discuss.elastic.co/t/elasticsearch-java-api-client-throwing-error-for-empty-fields/337221)

<div class="topic-metadata">

**Author:** [@Shakhzod\_Khashimov](https://discuss.elastic.co/u/Shakhzod_Khashimov)\
**Replies:** 0\
**Last updated:** [June 29, 2023, 2:50pm UTC](https://discuss.elastic.co/t/elasticsearch-java-api-client-throwing-error-for-empty-fields/337221 "2023-06-29T14:50:26Z")

</div>

Hi, we changed our elasticsearch from RestHighLevelClient to ElasticsearchClient, our document can have empty values, but in new Elasticsearch Java API Client it is throwing error saying: org.springframework.data.elasti…

---

## [Add more metrics](https://discuss.elastic.co/t/add-more-metrics/337046)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 4\
**Last updated:** [June 29, 2023, 2:37pm UTC](https://discuss.elastic.co/t/add-more-metrics/337046 "2023-06-29T14:37:05Z")

</div>

Hi Team, We are using ELK stack with platinum license . In our architecture we are using metricbeat for monitoring Oracle database . We are using metricbeat 7.17 version but in that only few metricsets are available t…

[Previous page](https://discuss.elastic.co/latest.md?page=621)

[Next page](https://discuss.elastic.co/latest.md?page=623)
