# Latest

**URL:** https://discuss.elastic.co/latest.md?page=626

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 627

---

## [I have a problem with EL and Xenforo](https://discuss.elastic.co/t/i-have-a-problem-with-el-and-xenforo/336872)

<div class="topic-metadata">

**Author:** [@Hi\_Welt](https://discuss.elastic.co/u/Hi_Welt)\
**Replies:** 4\
**Last updated:** [June 27, 2023, 2:08pm UTC](https://discuss.elastic.co/t/i-have-a-problem-with-el-and-xenforo/336872 "2023-06-27T14:08:47Z")

</div>

HI I have been using EL in xenforo for a longtime but now I randomly starts shutingdown since updating from EL7 to EL8. cat /var/log/elasticsearch/elasticsearch.log \[2023-06-26T03:24:33,901\]\[INFO \]\[o.e.n.Node …

---

## [What are the ways to combine the scores of keyword search + vector search other than the RRF ranking recently used?](https://discuss.elastic.co/t/what-are-the-ways-to-combine-the-scores-of-keyword-search-vector-search-other-than-the-rrf-ranking-recently-used/336914)

<div class="topic-metadata">

**Author:** [@Rahul\_Agarwal1](https://discuss.elastic.co/u/Rahul_Agarwal1)\
**Replies:** 1\
**Last updated:** [June 27, 2023, 1:27pm UTC](https://discuss.elastic.co/t/what-are-the-ways-to-combine-the-scores-of-keyword-search-vector-search-other-than-the-rrf-ranking-recently-used/336914 "2023-06-27T13:27:31Z")

</div>

I want to combine the scores of knn search + normal keyword search. What are the ways of doing it other than the RRF ranking recently added?

---

## [Stopping logstash](https://discuss.elastic.co/t/stopping-logstash/336586)

<div class="topic-metadata">

**Author:** [@Hanni](https://discuss.elastic.co/u/Hanni)\
**Replies:** 13\
**Last updated:** [June 27, 2023, 1:06pm UTC](https://discuss.elastic.co/t/stopping-logstash/336586 "2023-06-27T13:06:11Z")

</div>

Hello, i'm currently working on logstash and i have a question. To launch my logtash script, i use this command: sudo /usr/share/logstash/bin/logstash -f /etc/logstash/conf.d/test.conf When I run it in my terminal, to…

---

## [8.1, some confusion about successfulShardExecution in AbstractSearchAsyncAction](https://discuss.elastic.co/t/8-1-some-confusion-about-successfulshardexecution-in-abstractsearchasyncaction/336987)

<div class="topic-metadata">

**Author:** [@cm\_z](https://discuss.elastic.co/u/cm_z)\
**Replies:** 0\
**Last updated:** [June 27, 2023, 12:32pm UTC](https://discuss.elastic.co/t/8-1-some-confusion-about-successfulshardexecution-in-abstractsearchasyncaction/336987 "2023-06-27T12:32:34Z")

</div>

"Every response of shard result will trigger the successfulShardExecution method of AbstractSearchAsyncAction. I am confused about why we use shardsIt.remaining() + 1 to calculate ops, shouldn't it be +1 for each shard?" …

---

## [Not able to see request body for errors in NodeJS elastic-apm agent for express framework](https://discuss.elastic.co/t/not-able-to-see-request-body-for-errors-in-nodejs-elastic-apm-agent-for-express-framework/336760)

<div class="topic-metadata">

**Author:** [@Kesha\_Shah](https://discuss.elastic.co/u/Kesha_Shah)\
**Replies:** 4\
**Last updated:** [June 27, 2023, 12:05pm UTC](https://discuss.elastic.co/t/not-able-to-see-request-body-for-errors-in-nodejs-elastic-apm-agent-for-express-framework/336760 "2023-06-27T12:05:54Z")

</div>

Kibana version: 8.8.1 Elasticsearch version: 8.8.1 APM Server version: 8.8.1 APM Agent language and version: NodeJs Agent elastic-apm-node": "^3.47.0 Fresh install or upgraded from other version? Upgraded from 7.17 r…

---

## [Using the "docker.elastic.co" container registry behind a firewall](https://discuss.elastic.co/t/using-the-docker-elastic-co-container-registry-behind-a-firewall/336888)

<div class="topic-metadata">

**Author:** [@haseHH](https://discuss.elastic.co/u/haseHH)\
**Replies:** 2\
**Last updated:** [June 27, 2023, 11:42am UTC](https://discuss.elastic.co/t/using-the-docker-elastic-co-container-registry-behind-a-firewall/336888 "2023-06-27T11:42:49Z")

</div>

Hi everyone, I am looking for guidance on how to properly access the "docker.elastic.co" CR behind a corporate firewall. This question was already posed back in 2020, but never answered. Here's that original topic. Wha…

---

## [How to filter by "Count of records" within Kibana Lens](https://discuss.elastic.co/t/how-to-filter-by-count-of-records-within-kibana-lens/336197)

<div class="topic-metadata">

**Author:** [@fim](https://discuss.elastic.co/u/fim)\
**Replies:** 3\
**Last updated:** [June 27, 2023, 11:10am UTC](https://discuss.elastic.co/t/how-to-filter-by-count-of-records-within-kibana-lens/336197 "2023-06-27T11:10:35Z")

</div>

My goal is to filter by counts for a field "tracking\_no" where the value inside of the field is exactly similar. In Kibana Lens I created a simple table with a count aggregation. The table show exactly what I expect, bu…

---

## [Docs: reindex.remote.whitelist takes and array and not comma separated list](https://discuss.elastic.co/t/docs-reindex-remote-whitelist-takes-and-array-and-not-comma-separated-list/336976)

<div class="topic-metadata">

**Author:** [@adopauco](https://discuss.elastic.co/u/adopauco)\
**Replies:** 0\
**Last updated:** [June 27, 2023, 10:49am UTC](https://discuss.elastic.co/t/docs-reindex-remote-whitelist-takes-and-array-and-not-comma-separated-list/336976 "2023-06-27T10:49:41Z")

</div>

According to this piece of documentation, I need to configure reindex.remote.whitelist to allow reindexing from a remote elastic cluster. It states that the value should be a string with comma separated list of allowed …

---

## [Elastic search upgrade from 7.16.2 to 7.17.7](https://discuss.elastic.co/t/elastic-search-upgrade-from-7-16-2-to-7-17-7/336579)

<div class="topic-metadata">

**Author:** [@Bibhutibhusan\_Sahoo](https://discuss.elastic.co/u/Bibhutibhusan_Sahoo)\
**Replies:** 2\
**Last updated:** [June 27, 2023, 10:25am UTC](https://discuss.elastic.co/t/elastic-search-upgrade-from-7-16-2-to-7-17-7/336579 "2023-06-27T10:25:52Z")

</div>

Hi Team, we are trying to upgrade Elasticsearch from 7.16.2 to 7.17.7 through rpm package and getting following error One or more requisite failed: service.elastic.elasticsearch.service, Can someone help here? What is …

---

## [Error fetching data for metricset logstash.node\_stats: error making http request: port 9600 connection refused](https://discuss.elastic.co/t/error-fetching-data-for-metricset-logstash-node-stats-error-making-http-request-port-9600-connection-refused/336965)

<div class="topic-metadata">

**Author:** [@deepier](https://discuss.elastic.co/u/deepier)\
**Replies:** 0\
**Last updated:** [June 27, 2023, 9:48am UTC](https://discuss.elastic.co/t/error-fetching-data-for-metricset-logstash-node-stats-error-making-http-request-port-9600-connection-refused/336965 "2023-06-27T09:48:45Z")

</div>

Hello Everyone, Good day, I already setup my elastic and metricbeat. I already enable some metricbeat modules like elasticsearch-xpack configured the yml. Now im tryng to add logstash via metricbeat but when i restart…

---

## [Unable to delete snapshot](https://discuss.elastic.co/t/unable-to-delete-snapshot/336952)

<div class="topic-metadata">

**Author:** [@rakesh08](https://discuss.elastic.co/u/rakesh08)\
**Replies:** 1\
**Last updated:** [June 27, 2023, 8:31am UTC](https://discuss.elastic.co/t/unable-to-delete-snapshot/336952 "2023-06-27T08:31:12Z")

</div>

In our environment, having 2 different elasticsearch servers running on eks cluster and leveraging elasticsearch-curator tool to take periodic snapshot on AWS s3 bucket. On both the ES servers, the elasticsearch-curator…

---

## [How to generate the enrollment-token for another node with ssl?](https://discuss.elastic.co/t/how-to-generate-the-enrollment-token-for-another-node-with-ssl/336574)

<div class="topic-metadata">

**Author:** [@merson](https://discuss.elastic.co/u/merson)\
**Replies:** 6\
**Last updated:** [June 27, 2023, 7:38am UTC](https://discuss.elastic.co/t/how-to-generate-the-enrollment-token-for-another-node-with-ssl/336574 "2023-06-27T07:38:20Z")

</div>

Unable to create enrollment token for scope\[node\] ERROR: Unable to create an enrollment token. Elasticsearch node HTTP layer ssl configuration Keystore doesn't contain any private entries where the associated certificat…

---

## [Elasticsearch-create-enrollment-token is not possible without a keystore ( aka with PEM certificates)](https://discuss.elastic.co/t/elasticsearch-create-enrollment-token-is-not-possible-without-a-keystore-aka-with-pem-certificates/336136)

<div class="topic-metadata">

**Author:** [@DavidDPD](https://discuss.elastic.co/u/DavidDPD)\
**Replies:** 3\
**Last updated:** [June 27, 2023, 7:33am UTC](https://discuss.elastic.co/t/elasticsearch-create-enrollment-token-is-not-possible-without-a-keystore-aka-with-pem-certificates/336136 "2023-06-27T07:33:58Z")

</div>

This has been posted a few times, but threads have been auto-closed without an explicit explanation. I'm posting this as this really either needs to be changed/fixed in Elasticsearch, or DOCUMENTED. It does not seem to…

---

## [Logstash HTTP filter shows ruby exception NoMethodError strip for nil class](https://discuss.elastic.co/t/logstash-http-filter-shows-ruby-exception-nomethoderror-strip-for-nil-class/336947)

<div class="topic-metadata">

**Author:** [@Disha\_Bodade](https://discuss.elastic.co/u/Disha_Bodade)\
**Replies:** 0\
**Last updated:** [June 27, 2023, 7:28am UTC](https://discuss.elastic.co/t/logstash-http-filter-shows-ruby-exception-nomethoderror-strip-for-nil-class/336947 "2023-06-27T07:28:30Z")

</div>

Hi Team, I am extracting contents of thousands of URLs using http filter. But some urls throws below error which is stopping pipeline. Pipeline worker error, the pipeline will be stopped {:pipeline\_id=\>"new-english-pd…

---

## [Need help in how to rebuild the node\_modules present in kibana source code with code changes](https://discuss.elastic.co/t/need-help-in-how-to-rebuild-the-node-modules-present-in-kibana-source-code-with-code-changes/335934)

<div class="topic-metadata">

**Author:** [@Ashigha\_JR](https://discuss.elastic.co/u/Ashigha_JR)\
**Replies:** 2\
**Last updated:** [June 27, 2023, 6:21am UTC](https://discuss.elastic.co/t/need-help-in-how-to-rebuild-the-node-modules-present-in-kibana-source-code-with-code-changes/335934 "2023-06-27T06:21:19Z")

</div>

I have changed some CSS properties like button color, text color etc.. present inside "kibana-8.1.1/node\_modules/@kbn/ui-shared-deps-npm/shared\_built\_assets/kibana-ui-shared-deps-npm.v8.light.css" file, that changes need…

---

## [Need help to how to customize the theme color of the kibana dashboard](https://discuss.elastic.co/t/need-help-to-how-to-customize-the-theme-color-of-the-kibana-dashboard/335824)

<div class="topic-metadata">

**Author:** [@Ashigha\_JR](https://discuss.elastic.co/u/Ashigha_JR)\
**Replies:** 5\
**Last updated:** [June 27, 2023, 6:20am UTC](https://discuss.elastic.co/t/need-help-to-how-to-customize-the-theme-color-of-the-kibana-dashboard/335824 "2023-06-27T06:20:50Z")

</div>

Is it possible to customize the theme color of the kibana dashboard apart from default light and dark theme. I need to change the kibana dashboard theme color into purple , also need to change the color of the time filt…

---

## [Attach two pipeline to a single index in kibana 6.7.0](https://discuss.elastic.co/t/attach-two-pipeline-to-a-single-index-in-kibana-6-7-0/336898)

<div class="topic-metadata">

**Author:** [@danialumer](https://discuss.elastic.co/u/danialumer)\
**Replies:** 3\
**Last updated:** [June 27, 2023, 6:00am UTC](https://discuss.elastic.co/t/attach-two-pipeline-to-a-single-index-in-kibana-6-7-0/336898 "2023-06-27T06:00:15Z")

</div>

I have an issue that i have written two pipelines using devtools in v6.7.0, but do not know how to attach them with index, Can someone please assist on this?

---

## [Elasticsearch Index management strategy](https://discuss.elastic.co/t/elasticsearch-index-management-strategy/336833)

<div class="topic-metadata">

**Author:** [@Narcissus666](https://discuss.elastic.co/u/Narcissus666)\
**Replies:** 4\
**Last updated:** [June 27, 2023, 5:28am UTC](https://discuss.elastic.co/t/elasticsearch-index-management-strategy/336833 "2023-06-27T05:28:10Z")

</div>

Does Elasticsearch have a mechanismr like docke for storing logs? Docker log management divides logs into many files, and during rolling updates, only the oldest log files are deleted, rather than deleting the entire in…

---

## [Nested queries that refer to an expression on the parent](https://discuss.elastic.co/t/nested-queries-that-refer-to-an-expression-on-the-parent/336938)

<div class="topic-metadata">

**Author:** [@DaveG](https://discuss.elastic.co/u/DaveG)\
**Replies:** 0\
**Last updated:** [June 27, 2023, 3:11am UTC](https://discuss.elastic.co/t/nested-queries-that-refer-to-an-expression-on-the-parent/336938 "2023-06-27T03:11:20Z")

</div>

Hi All, I wish to write a query on nested data where there are expressions on the parent data as wells as expressions on the nested data all mixed together. For example, get me all the records that have id = 1 and exis…

---

## [.security-7 can't create replicas in elasticsearch 7.17.10](https://discuss.elastic.co/t/security-7-cant-create-replicas-in-elasticsearch-7-17-10/336936)

<div class="topic-metadata">

**Author:** [@Han2](https://discuss.elastic.co/u/Han2)\
**Replies:** 0\
**Last updated:** [June 27, 2023, 2:06am UTC](https://discuss.elastic.co/t/security-7-cant-create-replicas-in-elasticsearch-7-17-10/336936 "2023-06-27T02:06:59Z")

</div>

My cluster statu is yellow ,When i add new node to my cluster I use this order \_cluster/allocation/explain to exlpian this error and i don't know how to do someone can help me? PLZ

---

## [Performance hit when multiple filebeats are sending to same ES](https://discuss.elastic.co/t/performance-hit-when-multiple-filebeats-are-sending-to-same-es/335493)

<div class="topic-metadata">

**Author:** [@hjazz6](https://discuss.elastic.co/u/hjazz6)\
**Replies:** 22\
**Last updated:** [June 27, 2023, 1:09am UTC](https://discuss.elastic.co/t/performance-hit-when-multiple-filebeats-are-sending-to-same-es/335493 "2023-06-27T01:09:44Z")

</div>

Hi, I have a total of 5 servers, all sending Netflow data using filebeat to the same server (1 of the 5 servers) running ES. Each server is also running 2 instances of filebeat, so in total, I have 5 x 2 filebeat instan…

---

## [Excluding all fields from object property except for one (4096 byte limit error for large URI)](https://discuss.elastic.co/t/excluding-all-fields-from-object-property-except-for-one-4096-byte-limit-error-for-large-uri/336934)

<div class="topic-metadata">

**Author:** [@Akaash\_Mukherjee](https://discuss.elastic.co/u/Akaash_Mukherjee)\
**Replies:** 4\
**Last updated:** [June 26, 2023, 11:37pm UTC](https://discuss.elastic.co/t/excluding-all-fields-from-object-property-except-for-one-4096-byte-limit-error-for-large-uri/336934 "2023-06-26T23:37:07Z")

</div>

Hi, I'm trying to get ES to return me only currency in the example below in a concise way. The currency field: hits.hits.\_source.attributes.currency For the sake of the example I also have properties like this: hits…

---

## [Enrich vs Transform with 2 source indices](https://discuss.elastic.co/t/enrich-vs-transform-with-2-source-indices/336344)

<div class="topic-metadata">

**Author:** [@Marchelune](https://discuss.elastic.co/u/Marchelune)\
**Replies:** 2\
**Last updated:** [June 26, 2023, 11:17pm UTC](https://discuss.elastic.co/t/enrich-vs-transform-with-2-source-indices/336344 "2023-06-26T23:17:05Z")

</div>

Hi! I am faced with a situation where I am not sure whether an enrich processor or a transform should be used. In my situation, I have sensors sending events in batch to Elastic. Each sensor has a sensor\_key and the eve…

---

## [Filebeat handle multiline](https://discuss.elastic.co/t/filebeat-handle-multiline/334742)

<div class="topic-metadata">

**Author:** [@emily3](https://discuss.elastic.co/u/emily3)\
**Replies:** 1\
**Last updated:** [June 26, 2023, 10:26pm UTC](https://discuss.elastic.co/t/filebeat-handle-multiline/334742 "2023-06-26T22:26:54Z")

</div>

we have some logs. most of them are constructed, but for the traceback it was unconstructed and seperated in the log, such as \* 2023-05-30T20:52:15.545314-04:00 ssnode-proxy-1202-f09-2 proxy-server: err STDERR: Tracebac…

---

## [Converting filebeat message with logstash](https://discuss.elastic.co/t/converting-filebeat-message-with-logstash/336931)

<div class="topic-metadata">

**Author:** [@fizem](https://discuss.elastic.co/u/fizem)\
**Replies:** 1\
**Last updated:** [June 26, 2023, 9:32pm UTC](https://discuss.elastic.co/t/converting-filebeat-message-with-logstash/336931 "2023-06-26T21:32:37Z")

</div>

Hi, I have setup filebeat to parse my API logs and send messages to a centralized logstash cluster. filebeat will collect all the logs with a minimum CPU consumption. logstash can transform the data, define multiple …

---

## [ERROR instance/beat.go:1027 Exiting: 1 error: error loading config file: invalid config: yaml: line 85: did not find expected key Exiting: 1 error: error loading config file: invalid config: yaml: line 85: did not find expected key](https://discuss.elastic.co/t/error-instance-beat-go-1027-exiting-1-error-error-loading-config-file-invalid-config-yaml-line-85-did-not-find-expected-key-exiting-1-error-error-loading-config-file-invalid-config-yaml-line-85-did-not-find-expected-key/335171)

<div class="topic-metadata">

**Author:** [@yash2](https://discuss.elastic.co/u/yash2)\
**Replies:** 27\
**Last updated:** [June 26, 2023, 8:02pm UTC](https://discuss.elastic.co/t/error-instance-beat-go-1027-exiting-1-error-error-loading-config-file-invalid-config-yaml-line-85-did-not-find-expected-key-exiting-1-error-error-loading-config-file-invalid-config-yaml-line-85-did-not-find-expected-key/335171 "2023-06-26T20:02:08Z")

</div>

I have configured my filebeat.yml as follows : ###################### Filebeat Configuration Example ######################### # This file is an example configuration file highlighting only the most common # options. T…

---

## [Logs does not show in kibana](https://discuss.elastic.co/t/logs-does-not-show-in-kibana/334519)

<div class="topic-metadata">

**Author:** [@yash2](https://discuss.elastic.co/u/yash2)\
**Replies:** 13\
**Last updated:** [June 26, 2023, 7:54pm UTC](https://discuss.elastic.co/t/logs-does-not-show-in-kibana/334519 "2023-06-26T19:54:18Z")

</div>

Hi - I am having a little trouble pulling the logs to my Elasticsearch; currently, as I am on the main page, from the Discover menu , nothing shows up. I have Winlogbeat and sysmon installed as a service on my Windows ma…

---

## [Could not validate a connection to the.... No alive nodes found in your cluster](https://discuss.elastic.co/t/could-not-validate-a-connection-to-the-no-alive-nodes-found-in-your-cluster/336928)

<div class="topic-metadata">

**Author:** [@codepan](https://discuss.elastic.co/u/codepan)\
**Replies:** 1\
**Last updated:** [June 26, 2023, 7:39pm UTC](https://discuss.elastic.co/t/could-not-validate-a-connection-to-the-no-alive-nodes-found-in-your-cluster/336928 "2023-06-26T19:39:17Z")

</div>

Estou tendo fazer uma instalação do magento 2.4.6, mas estou recebendo esse erro na instalação. ● elasticsearch.service - Elasticsearch Loaded: loaded (/etc/systemd/system/elasticsearch.service; enabled; vendor preset…

---

## [Elasticsearch query to match all tokens inside a specific field](https://discuss.elastic.co/t/elasticsearch-query-to-match-all-tokens-inside-a-specific-field/336927)

<div class="topic-metadata">

**Author:** [@vsha041](https://discuss.elastic.co/u/vsha041)\
**Replies:** 0\
**Last updated:** [June 26, 2023, 7:17pm UTC](https://discuss.elastic.co/t/elasticsearch-query-to-match-all-tokens-inside-a-specific-field/336927 "2023-06-26T19:17:21Z")

</div>

We have a scenario where for one of the fields of the index should contain all the words in order for that field to be treated as a match. Whereas other fields can contain the rest of search query. Here are few examples.…

---

## [Re-index using a Machine Learning with custom Trained Models](https://discuss.elastic.co/t/re-index-using-a-machine-learning-with-custom-trained-models/336711)

<div class="topic-metadata">

**Author:** [@Lone\_Eagle](https://discuss.elastic.co/u/Lone_Eagle)\
**Replies:** 5\
**Last updated:** [June 26, 2023, 5:14pm UTC](https://discuss.elastic.co/t/re-index-using-a-machine-learning-with-custom-trained-models/336711 "2023-06-26T17:14:19Z")

</div>

We have currently a Production Elasticsearch using Elastic Cloud and want to experiment vectors using a Machine Learning with a custom trained model. Machine Learning Configuration: 32 GB RAM | 16.9 vCPU As a pipeline…

[Previous page](https://discuss.elastic.co/latest.md?page=625)

[Next page](https://discuss.elastic.co/latest.md?page=627)
