# Latest

**URL:** https://discuss.elastic.co/latest.md?page=632

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 633

---

## [Fleet not sending data after cluster upgrade](https://discuss.elastic.co/t/fleet-not-sending-data-after-cluster-upgrade/336625)

<div class="topic-metadata">

**Author:** [@mhoward](https://discuss.elastic.co/u/mhoward)\
**Replies:** 0\
**Last updated:** [June 21, 2023, 8:21pm UTC](https://discuss.elastic.co/t/fleet-not-sending-data-after-cluster-upgrade/336625 "2023-06-21T20:21:00Z")

</div>

Hello. Last Thursday I upgraded an Elastic cluster to 7.17.10. Since then, Fleet has not been collecting any data from agents and the Fleet server itself doesn't appear to communicating with the cluster. After restart…

---

## [Parse failure (object mapping for \[trace.detail\] tried to parse field \[null\] as object, but found a concrete value)](https://discuss.elastic.co/t/parse-failure-object-mapping-for-trace-detail-tried-to-parse-field-null-as-object-but-found-a-concrete-value/336551)

<div class="topic-metadata">

**Author:** [@a.emrekaraman](https://discuss.elastic.co/u/a.emrekaraman)\
**Replies:** 1\
**Last updated:** [June 21, 2023, 7:20pm UTC](https://discuss.elastic.co/t/parse-failure-object-mapping-for-trace-detail-tried-to-parse-field-null-as-object-but-found-a-concrete-value/336551 "2023-06-21T19:20:17Z")

</div>

Hi Team, I basically use json filter to parse log. But somewhere in json have 2 different type of log that's why I get this error (object mapping for \[trace.detail\] tried to parse field \[null\] as object, but found a conc…

---

## [Some helm charts of the Elasticsearch 8 version are not published yet](https://discuss.elastic.co/t/some-helm-charts-of-the-elasticsearch-8-version-are-not-published-yet/336615)

<div class="topic-metadata">

**Author:** [@Piyumitha\_Nirman](https://discuss.elastic.co/u/Piyumitha_Nirman)\
**Replies:** 1\
**Last updated:** [June 21, 2023, 6:08pm UTC](https://discuss.elastic.co/t/some-helm-charts-of-the-elasticsearch-8-version-are-not-published-yet/336615 "2023-06-21T18:08:59Z")

</div>

I need to add Elasticsearch 8.2.3 version for Kubernetes bare metal cluster. But I showed there is no helm release for the 8.2.3 version. what is the reason for it?

---

## [Elasticerach 8.5.1 version image gives this error curl: (52) Empty reply from server](https://discuss.elastic.co/t/elasticerach-8-5-1-version-image-gives-this-error-curl-52-empty-reply-from-server/336614)

<div class="topic-metadata">

**Author:** [@Piyumitha\_Nirman](https://discuss.elastic.co/u/Piyumitha_Nirman)\
**Replies:** 0\
**Last updated:** [June 21, 2023, 5:53pm UTC](https://discuss.elastic.co/t/elasticerach-8-5-1-version-image-gives-this-error-curl-52-empty-reply-from-server/336614 "2023-06-21T17:53:56Z")

</div>

I used Elasticsearch 8.5.1 image for my Kubernetes cluster. After installing using the helm chart pod is running correctly. but when I tried to check Elasticsearch cluster healthiness. it gave this error. curl 127.0.0.1:…

---

## [Different versions of ELK cluster](https://discuss.elastic.co/t/different-versions-of-elk-cluster/336486)

<div class="topic-metadata">

**Author:** [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Replies:** 5\
**Last updated:** [June 21, 2023, 3:58pm UTC](https://discuss.elastic.co/t/different-versions-of-elk-cluster/336486 "2023-06-21T15:58:30Z")

</div>

Hi All, I was able to create a working cluster using variety of product versions. Please let me know if this is ok: Filebeat: 7.6.2 Logstash: 8.6.2 Elasticsearch: 8.7.0 Kibana: 8.5.3 Thanks in advance!

---

## [Elastic Agent for Windows - visibility of Docker Containers in Kibana](https://discuss.elastic.co/t/elastic-agent-for-windows-visibility-of-docker-containers-in-kibana/336597)

<div class="topic-metadata">

**Author:** [@JackBurton](https://discuss.elastic.co/u/JackBurton)\
**Replies:** 1\
**Last updated:** [June 21, 2023, 3:48pm UTC](https://discuss.elastic.co/t/elastic-agent-for-windows-visibility-of-docker-containers-in-kibana/336597 "2023-06-21T15:48:39Z")

</div>

Hi, we are trialing a move to Fleet and the Elastic Agent. Everything looks good for Linux Hosts, but with our Windows one if I look at Observability \> Infrastructure \> Inventory, filter for the hosts and then select 'Sh…

---

## [Can I disable the ML controller?](https://discuss.elastic.co/t/can-i-disable-the-ml-controller/336206)

<div class="topic-metadata">

**Author:** [@theistian](https://discuss.elastic.co/u/theistian)\
**Replies:** 1\
**Last updated:** [June 21, 2023, 3:31pm UTC](https://discuss.elastic.co/t/can-i-disable-the-ml-controller/336206 "2023-06-21T15:31:07Z")

</div>

Hi! I'm configuring an ES 8 cluster, and I'm not interested in the ML capabilities so I'm disabling them using xpack.ml.enabled: false But when I start the node I still can see the process /usr/share/elasticsearch/mod…

---

## [Unable to drop specific event code data using Kibana pipeline](https://discuss.elastic.co/t/unable-to-drop-specific-event-code-data-using-kibana-pipeline/336601)

<div class="topic-metadata">

**Author:** [@hiruni.insyncit.net](https://discuss.elastic.co/u/hiruni.insyncit.net)\
**Replies:** 0\
**Last updated:** [June 21, 2023, 3:28pm UTC](https://discuss.elastic.co/t/unable-to-drop-specific-event-code-data-using-kibana-pipeline/336601 "2023-06-21T15:28:41Z")

</div>

Hi, I'm using Elasticsearch 8.1.2. Elastic agent type: winlogbeat Elastic agent version: 7.14.2 Currently I'm getting data from this Elastic agent. I tried to drop some event code using ingest pipeline that is config…

---

## [Not able to restart kibana](https://discuss.elastic.co/t/not-able-to-restart-kibana/336576)

<div class="topic-metadata">

**Author:** [@Samir\_Pawar](https://discuss.elastic.co/u/Samir_Pawar)\
**Replies:** 1\
**Last updated:** [June 21, 2023, 3:20pm UTC](https://discuss.elastic.co/t/not-able-to-restart-kibana/336576 "2023-06-21T15:20:51Z")

</div>

Elasticsearch vesrion is 6.8. Elasticsearch install in GCP compute engine.

---

## [ES Index Rate drops after every few hours](https://discuss.elastic.co/t/es-index-rate-drops-after-every-few-hours/336540)

<div class="topic-metadata">

**Author:** [@mukularora89](https://discuss.elastic.co/u/mukularora89)\
**Replies:** 10\
**Last updated:** [June 21, 2023, 2:48pm UTC](https://discuss.elastic.co/t/es-index-rate-drops-after-every-few-hours/336540 "2023-06-21T14:48:51Z")

</div>

Hi, We are observing a drop in ES index rate after every few hours. We have indexes created on daily basis and data is pushed into ES from logstash. In a day we expect 8 billion documents pushed to given day index. At t…

---

## [Fleet Server Agent Communication issue](https://discuss.elastic.co/t/fleet-server-agent-communication-issue/336599)

<div class="topic-metadata">

**Author:** [@willsy](https://discuss.elastic.co/u/willsy)\
**Replies:** 0\
**Last updated:** [June 21, 2023, 2:43pm UTC](https://discuss.elastic.co/t/fleet-server-agent-communication-issue/336599 "2023-06-21T14:43:25Z")

</div>

My fleet server and agents have become unhealthy and are presenting me with this error elastic\_agent\]\[warn\] Possible transient error during checkin with fleet-server, retrying \[elastic\_agent\]\[error\] Checkin request to …

---

## [Logstash docker-compose non root user](https://discuss.elastic.co/t/logstash-docker-compose-non-root-user/336598)

<div class="topic-metadata">

**Author:** [@maehue](https://discuss.elastic.co/u/maehue)\
**Replies:** 0\
**Last updated:** [June 21, 2023, 2:41pm UTC](https://discuss.elastic.co/t/logstash-docker-compose-non-root-user/336598 "2023-06-21T14:41:07Z")

</div>

To date we have been running logstash 7.16.2 as a non-root user in docker using a docker-compose configuration similar to below: version: 3.3 services: logstash: image: logstash:7.16.2 user: 10002:1001 …

---

## [Hiding some span.subtype into Kibana's APM UI](https://discuss.elastic.co/t/hiding-some-span-subtype-into-kibanas-apm-ui/336580)

<div class="topic-metadata">

**Author:** [@Noxis](https://discuss.elastic.co/u/Noxis)\
**Replies:** 1\
**Last updated:** [June 21, 2023, 2:35pm UTC](https://discuss.elastic.co/t/hiding-some-span-subtype-into-kibanas-apm-ui/336580 "2023-06-21T14:35:11Z")

</div>

Hello, We are currently using ECK to deploy our Elastic Stack in version 8.8.1 on GCP. I am actually configuring our applications to report to APM, we have multiple Vue and Quasar Frontends and some NestJS backends. I…

---

## [Elasticsearch code=exited, status=1/FAILURE](https://discuss.elastic.co/t/elasticsearch-code-exited-status-1-failure/336595)

<div class="topic-metadata">

**Author:** [@codepan](https://discuss.elastic.co/u/codepan)\
**Replies:** 4\
**Last updated:** [June 21, 2023, 2:23pm UTC](https://discuss.elastic.co/t/elasticsearch-code-exited-status-1-failure/336595 "2023-06-21T14:23:24Z")

</div>

Fiz a instalação do Elastic 8 no CentOs, mas o mesmo falha ao iniciar. systemctl status elasticsearch ● elasticsearch.service - Elasticsearch Loaded: loaded (/etc/systemd/system/elasticsearch.service; enabled; vendo…

---

## [Using the --tags option with @elastic/synthetics](https://discuss.elastic.co/t/using-the-tags-option-with-elastic-synthetics/330681)

<div class="topic-metadata">

**Author:** [@spaulovich](https://discuss.elastic.co/u/spaulovich)\
**Replies:** 2\
**Last updated:** [June 21, 2023, 1:50pm UTC](https://discuss.elastic.co/t/using-the-tags-option-with-elastic-synthetics/330681 "2023-06-21T13:50:28Z")

</div>

Any hints to correctly using the --tags option with @elastic/synthetics? Assuming a journey where I've added monitors.use({ tags: \["foo", "bar"\] }) If I run npx @elastic/synthetics . --tags "foo" I get No tests found! …

---

## [No access to kibana role management UI](https://discuss.elastic.co/t/no-access-to-kibana-role-management-ui/336286)

<div class="topic-metadata">

**Author:** [@Calvy93](https://discuss.elastic.co/u/Calvy93)\
**Replies:** 1\
**Last updated:** [June 21, 2023, 12:58pm UTC](https://discuss.elastic.co/t/no-access-to-kibana-role-management-ui/336286 "2023-06-21T12:58:54Z")

</div>

Hello everyone, I'm currently setting up the ELK-Stack + Filebeat and for the first configuration, I try to do without SSL as that was way too troublesome for a prototype when I first tried to implement it in every part…

---

## [Snapshot and restore using shared file system](https://discuss.elastic.co/t/snapshot-and-restore-using-shared-file-system/336365)

<div class="topic-metadata">

**Author:** [@Sann](https://discuss.elastic.co/u/Sann)\
**Replies:** 8\
**Last updated:** [June 21, 2023, 12:19pm UTC](https://discuss.elastic.co/t/snapshot-and-restore-using-shared-file-system/336365 "2023-06-21T12:19:19Z")

</div>

When using a cluster with more than one node is not enough to create local folders for shared fs repo. you need smb/nfs mounted drive because each node will check the "repo" and if there is no communication between nodes…

---

## [Does Edge Ngram Token filter creates Synonym for tokens?](https://discuss.elastic.co/t/does-edge-ngram-token-filter-creates-synonym-for-tokens/336572)

<div class="topic-metadata">

**Author:** [@Farnaz](https://discuss.elastic.co/u/Farnaz)\
**Replies:** 0\
**Last updated:** [June 21, 2023, 12:03pm UTC](https://discuss.elastic.co/t/does-edge-ngram-token-filter-creates-synonym-for-tokens/336572 "2023-06-21T12:03:42Z")

</div>

ave added Edge Ngram Token Filter to my analyzer, ngram\_back\_fa. Here is my analyzer: "ngram\_back\_fa": { "tokenizer": "standard", "filter": \[ "lowercase", …

---

## [Rule for Applocker](https://discuss.elastic.co/t/rule-for-applocker/334299)

<div class="topic-metadata">

**Author:** [@Leitner](https://discuss.elastic.co/u/Leitner)\
**Replies:** 2\
**Last updated:** [June 21, 2023, 11:31am UTC](https://discuss.elastic.co/t/rule-for-applocker/334299 "2023-06-21T11:31:16Z")

</div>

Hi, first of all: I'm a newby with Elastic. So sorry for this question. But I just can't get any further. I want to create a rule for MS Applocker. At Analytics - Discover with filter event.code : 8004 and event.provi…

---

## [Elasticsearch and Hive integration failure with es-hadoop-connector 8.8.1](https://discuss.elastic.co/t/elasticsearch-and-hive-integration-failure-with-es-hadoop-connector-8-8-1/336423)

<div class="topic-metadata">

**Author:** [@Bob\_Dorous](https://discuss.elastic.co/u/Bob_Dorous)\
**Replies:** 2\
**Last updated:** [June 21, 2023, 10:49am UTC](https://discuss.elastic.co/t/elasticsearch-and-hive-integration-failure-with-es-hadoop-connector-8-8-1/336423 "2023-06-21T10:49:43Z")

</div>

Hi there, I am trying to set up the newest release Elasticsearch (8.8.1) as a single-node service on an Ubuntu Azure VM and write and read to it with Hive 3.10+ on Hadoop HDInsight cluster (hortonworks based). For the …

---

## [Top hits aggregation does not work on nested object](https://discuss.elastic.co/t/top-hits-aggregation-does-not-work-on-nested-object/336347)

<div class="topic-metadata">

**Author:** [@JasonREC](https://discuss.elastic.co/u/JasonREC)\
**Replies:** 1\
**Last updated:** [June 21, 2023, 10:29am UTC](https://discuss.elastic.co/t/top-hits-aggregation-does-not-work-on-nested-object/336347 "2023-06-21T10:29:19Z")

</div>

Hi all, This is my nested object field And, I manually update the mapping like this And, this is how my top\_hit query look like Lastly, this is the query response I expected it should be return the entir…

---

## [Migration from ES 6.8 to 7.17 : Issues with negative date epoch timestamp](https://discuss.elastic.co/t/migration-from-es-6-8-to-7-17-issues-with-negative-date-epoch-timestamp/335259)

<div class="topic-metadata">

**Author:** [@Abhilashsr2008](https://discuss.elastic.co/u/Abhilashsr2008)\
**Replies:** 7\
**Last updated:** [June 21, 2023, 10:19am UTC](https://discuss.elastic.co/t/migration-from-es-6-8-to-7-17-issues-with-negative-date-epoch-timestamp/335259 "2023-06-21T10:19:06Z")

</div>

Hi Guys We are migrating our applications from 6.8 ES cluster to 7.17.10 ES cluster . The one thing which we identified is that the negative values are not supported for date type fields( "format": "epoch\_millis") . Is …

---

## [Create Rule API not working](https://discuss.elastic.co/t/create-rule-api-not-working/335228)

<div class="topic-metadata">

**Author:** [@A\_Mightiev](https://discuss.elastic.co/u/A_Mightiev)\
**Replies:** 1\
**Last updated:** [June 21, 2023, 10:17am UTC](https://discuss.elastic.co/t/create-rule-api-not-working/335228 "2023-06-21T10:17:32Z")

</div>

Hi I'm a bit struggling using the Rules creation API I'm trying to create a "rule\_type\_id":".es-query". In the parameters it asks me for the \`"es-Query"', I tried to use the triple quotes but it gives me an error tha…

---

## [Kibana to Elastic search communication is ending up with failure](https://discuss.elastic.co/t/kibana-to-elastic-search-communication-is-ending-up-with-failure/336438)

<div class="topic-metadata">

**Author:** [@Deepaklal\_KB](https://discuss.elastic.co/u/Deepaklal_KB)\
**Replies:** 5\
**Last updated:** [June 21, 2023, 9:42am UTC](https://discuss.elastic.co/t/kibana-to-elastic-search-communication-is-ending-up-with-failure/336438 "2023-06-21T09:42:23Z")

</div>

Getting an error as ünable to get issuer certificate in kibana logs once after starting the service. I am using DigicertCA.crt file to communicate with mu Elastic server LB. Which is a SAN certificate. This is happening…

---

## [CVE-2022-1471 is not listed in Security Issues site](https://discuss.elastic.co/t/cve-2022-1471-is-not-listed-in-security-issues-site/336553)

<div class="topic-metadata">

**Author:** [@Ayushi\_bhardwaj](https://discuss.elastic.co/u/Ayushi_bhardwaj)\
**Replies:** 1\
**Last updated:** [June 21, 2023, 8:38am UTC](https://discuss.elastic.co/t/cve-2022-1471-is-not-listed-in-security-issues-site/336553 "2023-06-21T08:38:33Z")

</div>

Is there any fix for that in any Logstash version? Is there any plan to update the damaged package of snakeyaml 1.31=\>2.0? Can I manually change the snakeyaml version? if so then how?

---

## [Elasitc-Agent APM integration on Kubernetes](https://discuss.elastic.co/t/elasitc-agent-apm-integration-on-kubernetes/336552)

<div class="topic-metadata">

**Author:** [@Piotr\_Pietka](https://discuss.elastic.co/u/Piotr_Pietka)\
**Replies:** 0\
**Last updated:** [June 21, 2023, 8:26am UTC](https://discuss.elastic.co/t/elasitc-agent-apm-integration-on-kubernetes/336552 "2023-06-21T08:26:44Z")

</div>

Hi, I've got deployed elastic-agents on kubernetes (rancher in my case). How to use APM integration to make it accessible to pods in cluster? Do I need to manualy create service or is that accessible by default? What is…

---

## [If condition loop on array](https://discuss.elastic.co/t/if-condition-loop-on-array/336518)

<div class="topic-metadata">

**Author:** [@plus](https://discuss.elastic.co/u/plus)\
**Replies:** 3\
**Last updated:** [June 21, 2023, 8:22am UTC](https://discuss.elastic.co/t/if-condition-loop-on-array/336518 "2023-06-21T08:22:29Z")

</div>

{ Hello, I was reading several posts how to loop through with array but I don't know how to iterate on each value and then rename. I tried with split but it creates a document for each value ( I want a doc with all val…

---

## [Why a cancelled task is still on the list?](https://discuss.elastic.co/t/why-a-cancelled-task-is-still-on-the-list/336413)

<div class="topic-metadata">

**Author:** [@HyebinHong](https://discuss.elastic.co/u/HyebinHong)\
**Replies:** 7\
**Last updated:** [June 21, 2023, 8:15am UTC](https://discuss.elastic.co/t/why-a-cancelled-task-is-still-on-the-list/336413 "2023-06-21T08:15:45Z")

</div>

Hello, elastic! While running multiple msearch API through Java clients, I found one of the tasks took abnormally long. So I executed Task Cancel API, but it doesn't seem cleanup properly. When I check the task via Ta…

---

## [java.util.concurrent.ExecutionException: ElasticsearchException\[java.util.concurrent.ExecutionException: CircuitBreakingException\[\[fielddata\] Data too large, data for \[apiVersion\] would be \[20659632080/19.2gb\], which is larger than the limit of \[206158430](https://discuss.elastic.co/t/java-util-concurrent-executionexception-elasticsearchexception-java-util-concurrent-executionexception-circuitbreakingexception-fielddata-data-too-large-data-for-apiversion-would-be-20659632080-19-2gb-which-is-larger-than-the-limit-of-206158430/336549)

<div class="topic-metadata">

**Author:** [@agusbuddi](https://discuss.elastic.co/u/agusbuddi)\
**Replies:** 1\
**Last updated:** [June 21, 2023, 8:05am UTC](https://discuss.elastic.co/t/java-util-concurrent-executionexception-elasticsearchexception-java-util-concurrent-executionexception-circuitbreakingexception-fielddata-data-too-large-data-for-apiversion-would-be-20659632080-19-2gb-which-is-larger-than-the-limit-of-206158430/336549 "2023-06-21T08:05:40Z")

</div>

java.util.concurrent.ExecutionException: ElasticsearchException\[java.util.concurrent.ExecutionException: CircuitBreakingException\[\[fielddata\] Data too large, data for \[apiVersion\] would be \[20659632080/19.2gb\], which is …

---

## [How to clean all the identites from Sailpoint?](https://discuss.elastic.co/t/how-to-clean-all-the-identites-from-sailpoint/336146)

<div class="topic-metadata">

**Author:** [@srikanth\_bollu](https://discuss.elastic.co/u/srikanth_bollu)\
**Replies:** 1\
**Last updated:** [June 21, 2023, 7:41am UTC](https://discuss.elastic.co/t/how-to-clean-all-the-identites-from-sailpoint/336146 "2023-06-21T07:41:41Z")

</div>

I want to clean all the identities and their accounts roles etc associated with identities. Is there any way to bulk delete sailpoint?

[Previous page](https://discuss.elastic.co/latest.md?page=631)

[Next page](https://discuss.elastic.co/latest.md?page=633)
