# Latest

**URL:** https://discuss.elastic.co/latest.md?page=635

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 636

---

## [Min and Max timestamp difference](https://discuss.elastic.co/t/min-and-max-timestamp-difference/334634)

<div class="topic-metadata">

**Author:** [@SUBIN\_B\_MATHEW](https://discuss.elastic.co/u/SUBIN_B_MATHEW)\
**Replies:** 1\
**Last updated:** [June 20, 2023, 8:04am UTC](https://discuss.elastic.co/t/min-and-max-timestamp-difference/334634 "2023-06-20T08:04:11Z")

</div>

Aggregated the Min and Max timestamp based on the message id. I wanted to calculate the time difference between min and Max time and show it in a data table on kibana dashboard , could you please help me on this?

---

## [What is the reason for the delay official launch other 8 versions of elastic search helm? Still only has the 8.5.1 version for the helm repo](https://discuss.elastic.co/t/what-is-the-reason-for-the-delay-official-launch-other-8-versions-of-elastic-search-helm-still-only-has-the-8-5-1-version-for-the-helm-repo/336446)

<div class="topic-metadata">

**Author:** [@Piyumitha\_Nirman](https://discuss.elastic.co/u/Piyumitha_Nirman)\
**Replies:** 0\
**Last updated:** [June 20, 2023, 7:42am UTC](https://discuss.elastic.co/t/what-is-the-reason-for-the-delay-official-launch-other-8-versions-of-elastic-search-helm-still-only-has-the-8-5-1-version-for-the-helm-repo/336446 "2023-06-20T07:42:10Z")

</div>

I need to add Elasticsearch 8.2.3 version for Kubernetes bare metal cluster. But I showed there is no helm release for the 8.2.3 version. what is the reason for it?

---

## [Is there a way to install ES plugins using ENV variables in docker?](https://discuss.elastic.co/t/is-there-a-way-to-install-es-plugins-using-env-variables-in-docker/336445)

<div class="topic-metadata">

**Author:** [@ANUBHAV\_GUPTA](https://discuss.elastic.co/u/ANUBHAV_GUPTA)\
**Replies:** 1\
**Last updated:** [June 20, 2023, 7:30am UTC](https://discuss.elastic.co/t/is-there-a-way-to-install-es-plugins-using-env-variables-in-docker/336445 "2023-06-20T07:30:59Z")

</div>

Hi there, I need to install s3-repository plugin in the ES running using docker. I do not want to edit my elasticsearch.yml file. Is there a way I want install plugins using ENV variables?

---

## [What is the best candidate for the Filestream ID for Autodiscover Kubernetes Provider?](https://discuss.elastic.co/t/what-is-the-best-candidate-for-the-filestream-id-for-autodiscover-kubernetes-provider/336397)

<div class="topic-metadata">

**Author:** [@lprakashv](https://discuss.elastic.co/u/lprakashv)\
**Replies:** 1\
**Last updated:** [June 20, 2023, 7:30am UTC](https://discuss.elastic.co/t/what-is-the-best-candidate-for-the-filestream-id-for-autodiscover-kubernetes-provider/336397 "2023-06-20T07:30:46Z")

</div>

Based on thg logs, it seems that the filestream ID is not unique and this could cause data duplication. However, my rationale towards setting a combination of ${data.kubernetes.pod.name} and ${data.kubernetes.container.i…

---

## [How to get Distinct results using Search API](https://discuss.elastic.co/t/how-to-get-distinct-results-using-search-api/336217)

<div class="topic-metadata">

**Author:** [@asimelastic](https://discuss.elastic.co/u/asimelastic)\
**Replies:** 2\
**Last updated:** [June 20, 2023, 7:03am UTC](https://discuss.elastic.co/t/how-to-get-distinct-results-using-search-api/336217 "2023-06-20T07:03:08Z")

</div>

I have a "customer" index with fields "FirstName" and "LastName". My index contains data as follows: First Name | LastName Richard | Lockwood Richard | Lockwood 2 Richard | Lockwood 3 Richard | Lockwood 4 Richard …

---

## [Facing challange during segregate the data from one index to another index](https://discuss.elastic.co/t/facing-challange-during-segregate-the-data-from-one-index-to-another-index/336349)

<div class="topic-metadata">

**Author:** [@Tek\_Chand](https://discuss.elastic.co/u/Tek_Chand)\
**Replies:** 2\
**Last updated:** [June 20, 2023, 6:37am UTC](https://discuss.elastic.co/t/facing-challange-during-segregate-the-data-from-one-index-to-another-index/336349 "2023-06-20T06:37:27Z")

</div>

Hello Team, We are using Akamai for CDN and WAF. We have configured datastream on akamai and getting those logs on our elasticsaerch. Please refer the below link for same: Stream logs to Elasticsearch As per doc we ha…

---

## [Logstash config for transactions](https://discuss.elastic.co/t/logstash-config-for-transactions/336294)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 5\
**Last updated:** [June 20, 2023, 6:25am UTC](https://discuss.elastic.co/t/logstash-config-for-transactions/336294 "2023-06-20T06:25:36Z")

</div>

Hi need to write logstash config that parse log file from this path: "/tmp/logs/\*" store in elastic. here is the log: 09:54:37:566 R\[SRV1\]L\[477\]T\[0300\]ID\[696119\] 09:54:37:566 S\[SRV2\]L\[477\]T\[0300\]ID\[696119\] 09:54:55:28…

---

## [How to upgrade elk license from trail to community version](https://discuss.elastic.co/t/how-to-upgrade-elk-license-from-trail-to-community-version/336427)

<div class="topic-metadata">

**Author:** [@sraman](https://discuss.elastic.co/u/sraman)\
**Replies:** 1\
**Last updated:** [June 20, 2023, 6:13am UTC](https://discuss.elastic.co/t/how-to-upgrade-elk-license-from-trail-to-community-version/336427 "2023-06-20T06:13:44Z")

</div>

Hi, Currently our elk runs on trial license and it's been expired, is there a way to upgrade to community version?

---

## [Logstash update sql\_last\_value while using paging](https://discuss.elastic.co/t/logstash-update-sql-last-value-while-using-paging/336362)

<div class="topic-metadata">

**Author:** [@zalseryani](https://discuss.elastic.co/u/zalseryani)\
**Replies:** 3\
**Last updated:** [June 20, 2023, 6:00am UTC](https://discuss.elastic.co/t/logstash-update-sql-last-value-while-using-paging/336362 "2023-06-20T06:00:52Z")

</div>

sql\_last\_value update with Paging I am configuring logstash to use jdbc input knowing that I am using jdbc\_paging with the configuration. what I am facing now is that sql\_last\_value is being updated after all record…

---

## [Run a query after grouping and finding max](https://discuss.elastic.co/t/run-a-query-after-grouping-and-finding-max/336414)

<div class="topic-metadata">

**Author:** [@arvidh](https://discuss.elastic.co/u/arvidh)\
**Replies:** 2\
**Last updated:** [June 20, 2023, 5:33am UTC](https://discuss.elastic.co/t/run-a-query-after-grouping-and-finding-max/336414 "2023-06-20T05:33:12Z")

</div>

Here is some test data I have in an index: {"name" : "almara" , "version" : "1" , "groups" : "blueHouse", "data1" : " value1"} {"name" : "almara" , "version" : "2" , "groups" : "blueHouse", "data1" : " Something"} {"nam…

---

## [Indices are not getting deleted](https://discuss.elastic.co/t/indices-are-not-getting-deleted/335590)

<div class="topic-metadata">

**Author:** [@shubham.s](https://discuss.elastic.co/u/shubham.s)\
**Replies:** 3\
**Last updated:** [June 20, 2023, 5:27am UTC](https://discuss.elastic.co/t/indices-are-not-getting-deleted/335590 "2023-06-20T05:27:42Z")

</div>

Hi, I have update policy from kibana GUI to deleted traces after 5days but still indices are not getting deleted GET \_ilm/policy/apm\_test { "apm\_test": { "version": 4, "modified\_date": "2023-06-02T07:15:29.3…

---

## [Elastic agent installation failed on windows](https://discuss.elastic.co/t/elastic-agent-installation-failed-on-windows/336424)

<div class="topic-metadata">

**Author:** [@esijati](https://discuss.elastic.co/u/esijati)\
**Replies:** 0\
**Last updated:** [June 20, 2023, 5:23am UTC](https://discuss.elastic.co/t/elastic-agent-installation-failed-on-windows/336424 "2023-06-20T05:23:40Z")

</div>

Fleet managed Elastic agent installation failed on windows With error Error: fail to enroll: fail to execute request to fleet-server: Proxy Authentication Required. Enroll command failed with exist code: 1 Event view…

---

## [Logstash filling up disk space beyond queue.max\_bytes](https://discuss.elastic.co/t/logstash-filling-up-disk-space-beyond-queue-max-bytes/336388)

<div class="topic-metadata">

**Author:** [@Sindhu\_Bandi](https://discuss.elastic.co/u/Sindhu_Bandi)\
**Replies:** 4\
**Last updated:** [June 20, 2023, 5:19am UTC](https://discuss.elastic.co/t/logstash-filling-up-disk-space-beyond-queue-max-bytes/336388 "2023-06-20T05:19:39Z")

</div>

Logstash persistent volume size is increasing beyond configured queue.max\_bytes Scenario: Logstash : 7.17.3 Env : On Kubernetes cluster Persistence: Enabled logstash.yml: ---- http.host: "0.0.0.0" path.config: /usr/…

---

## [Occasionally NoAliveNodesFound with HAProxy as Loadbalancer](https://discuss.elastic.co/t/occasionally-noalivenodesfound-with-haproxy-as-loadbalancer/335890)

<div class="topic-metadata">

**Author:** [@oliver.hart](https://discuss.elastic.co/u/oliver.hart)\
**Replies:** 2\
**Last updated:** [June 20, 2023, 4:30am UTC](https://discuss.elastic.co/t/occasionally-noalivenodesfound-with-haproxy-as-loadbalancer/335890 "2023-06-20T04:30:32Z")

</div>

Hello, we have kind of a special problem, so I try to explain everything in detail. Setup The above diagram shows our current setup (simplified). Our app runs within a Kubernetes / Openshift Cluster. The Deploymen…

---

## [Elasticsearch backup](https://discuss.elastic.co/t/elasticsearch-backup/335848)

<div class="topic-metadata">

**Author:** [@Akshay\_Patidar](https://discuss.elastic.co/u/Akshay_Patidar)\
**Replies:** 1\
**Last updated:** [June 20, 2023, 4:30am UTC](https://discuss.elastic.co/t/elasticsearch-backup/335848 "2023-06-20T04:30:10Z")

</div>

As specific date interval for slm policy in not possible so what is the alternative way for taking backup of Elasticsearch for specific date interval Example : like I wanted to take backup daily from 15/06 to 30/06

---

## [Enrichment doesn't work sometimes](https://discuss.elastic.co/t/enrichment-doesnt-work-sometimes/336366)

<div class="topic-metadata">

**Author:** [@matled](https://discuss.elastic.co/u/matled)\
**Replies:** 2\
**Last updated:** [June 20, 2023, 4:27am UTC](https://discuss.elastic.co/t/enrichment-doesnt-work-sometimes/336366 "2023-06-20T04:27:43Z")

</div>

Currently we have a situation where the enrichment processor of the elasticsearch ingest pipeline doesn't always work. Elastic-Stack: 8.8.1 The syslog messages have the identical structure and are parsed correctly. …

---

## [Switching 'cluster.routing.allocation' between node-upgrades](https://discuss.elastic.co/t/switching-cluster-routing-allocation-between-node-upgrades/335843)

<div class="topic-metadata">

**Author:** [@slash24](https://discuss.elastic.co/u/slash24)\
**Replies:** 1\
**Last updated:** [June 20, 2023, 4:26am UTC](https://discuss.elastic.co/t/switching-cluster-routing-allocation-between-node-upgrades/335843 "2023-06-20T04:26:49Z")

</div>

We have a three-node cluster onprem, and during rolling upgrade of the individual Elastic-nodes, we tend to toggle 'cluster.routing.allocation.enable' between 'primaries' and null. Is this necessary to do between each i…

---

## [Multiple child inastances of a single client or multiple clients, which is better for bulk indexing in large rates?](https://discuss.elastic.co/t/multiple-child-inastances-of-a-single-client-or-multiple-clients-which-is-better-for-bulk-indexing-in-large-rates/336293)

<div class="topic-metadata">

**Author:** [@shameel](https://discuss.elastic.co/u/shameel)\
**Replies:** 6\
**Last updated:** [June 20, 2023, 4:23am UTC](https://discuss.elastic.co/t/multiple-child-inastances-of-a-single-client-or-multiple-clients-which-is-better-for-bulk-indexing-in-large-rates/336293 "2023-06-20T04:23:26Z")

</div>

Hi Im using Elasticsearch v7.5.0 and I have a huge number of documents being ingested per second, as per the documentation it is recommended to use multiple clients for bulk indexing to reduce load. Can I get the same re…

---

## [\[percolate\_query\] mapping for \`percolator type\` in script(painless)](https://discuss.elastic.co/t/percolate-query-mapping-for-percolator-type-in-script-painless/336408)

<div class="topic-metadata">

**Author:** [@SEUNGHYO](https://discuss.elastic.co/u/SEUNGHYO)\
**Replies:** 0\
**Last updated:** [June 20, 2023, 12:38am UTC](https://discuss.elastic.co/t/percolate-query-mapping-for-percolator-type-in-script-painless/336408 "2023-06-20T00:38:20Z")

</div>

Hello I'm Checking how to update "percolate query" \> "percolator type" field through \_update\_by\_query. But, # Create Index PUT test\_shlee\_percolate\_20230619 { "mappings": { "properties": { "pa001": { …

---

## [Elastic agent and port mirroring](https://discuss.elastic.co/t/elastic-agent-and-port-mirroring/336185)

<div class="topic-metadata">

**Author:** [@Ammar\_Mostafa](https://discuss.elastic.co/u/Ammar_Mostafa)\
**Replies:** 1\
**Last updated:** [June 20, 2023, 12:31am UTC](https://discuss.elastic.co/t/elastic-agent-and-port-mirroring/336185 "2023-06-20T00:31:36Z")

</div>

If i have a server that i make it as destination of port mirroring how can i use this mirrored traffic to ingest it in elastic agent to parse it and deliver it to Elasticsearch.

---

## [Multiple index templates may not match during index creation](https://discuss.elastic.co/t/multiple-index-templates-may-not-match-during-index-creation/336186)

<div class="topic-metadata">

**Author:** [@alpine\_f1](https://discuss.elastic.co/u/alpine_f1)\
**Replies:** 1\
**Last updated:** [June 20, 2023, 12:30am UTC](https://discuss.elastic.co/t/multiple-index-templates-may-not-match-during-index-creation/336186 "2023-06-20T00:30:15Z")

</div>

Hello, We are currently running Elastic v7.17 as docker containers in my organization. I tried upgrading to 8.7.1 and during deployment , I am getting below errors and the containers are down. How should I address t…

---

## [Can I have mutiple key-value pair in watcher params?](https://discuss.elastic.co/t/can-i-have-mutiple-key-value-pair-in-watcher-params/336187)

<div class="topic-metadata">

**Author:** [@JasonREC](https://discuss.elastic.co/u/JasonREC)\
**Replies:** 0\
**Last updated:** [June 16, 2023, 4:18am UTC](https://discuss.elastic.co/t/can-i-have-mutiple-key-value-pair-in-watcher-params/336187 "2023-06-16T04:18:20Z")

</div>

Hi, I am curretly using watcher to set up tasks. But when I set up condition part, I want to make the params can contan mutiple key-value pair, so that in future I can easily change them to other value I want, but I enc…

---

## [C# Client 8.0.10 does not have the DateRange filter](https://discuss.elastic.co/t/c-client-8-0-10-does-not-have-the-daterange-filter/336121)

<div class="topic-metadata">

**Author:** [@Jose\_Mieses](https://discuss.elastic.co/u/Jose_Mieses)\
**Replies:** 0\
**Last updated:** [June 15, 2023, 4:02pm UTC](https://discuss.elastic.co/t/c-client-8-0-10-does-not-have-the-daterange-filter/336121 "2023-06-15T16:02:11Z")

</div>

I'm interested to know when the DataRange query will be available in .Net Client. We are trying to implement this features to one of our apps. I checked the latest release notes and nothing has been mentioned.

---

## [How Statsd output plugin work](https://discuss.elastic.co/t/how-statsd-output-plugin-work/336298)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 3\
**Last updated:** [June 19, 2023, 10:55pm UTC](https://discuss.elastic.co/t/how-statsd-output-plugin-work/336298 "2023-06-19T22:55:12Z")

</div>

Hi I have logfile that need to count number of this string on it "connection failed" now question is log file created last day and continuously new log add to it. which of these Statsd output configuration options "co…

---

## [Format version is not supported (resource BufferedChecksumIndexInput (SimpleFSIndexInput))](https://discuss.elastic.co/t/format-version-is-not-supported-resource-bufferedchecksumindexinput-simplefsindexinput/336390)

<div class="topic-metadata">

**Author:** [@amal\_srivastava](https://discuss.elastic.co/u/amal_srivastava)\
**Replies:** 1\
**Last updated:** [June 19, 2023, 8:49pm UTC](https://discuss.elastic.co/t/format-version-is-not-supported-resource-bufferedchecksumindexinput-simplefsindexinput/336390 "2023-06-19T20:49:27Z")

</div>

Hi, One of my elasticsearch index is red and when i dig this into deep i am getting this below error GET \_cluster/allocation/explain { "index" : "design", "shard" : 0, "primary" : true, "current\_state" : "unassign…

---

## [aws-cloudwatch obtaining logs exception](https://discuss.elastic.co/t/aws-cloudwatch-obtaining-logs-exception/336401)

<div class="topic-metadata">

**Author:** [@Askas00](https://discuss.elastic.co/u/Askas00)\
**Replies:** 0\
**Last updated:** [June 19, 2023, 7:38pm UTC](https://discuss.elastic.co/t/aws-cloudwatch-obtaining-logs-exception/336401 "2023-06-19T19:38:14Z")

</div>

When I use the aws-cloudwatch input plug-in to obtain the logs stored in cloudwatchlogs, the number of logs obtained is inconsistent with the number of logs in cloudwatchlogs. The route53 logs are stored in cloudwatchlog…

---

## [\[ERROR\]\[logstash.agent \] Failed to execute action {:action=\>LogStash::PipelineAction::Create/pipeline\_id:main, :exception=\>"LogStash::ConfigurationError", :message=\>"Expected one of \[ \\\\t\\\\r\\\\n\], \\"#\\", \\"input\\", \\"filter\\", \\"output\\" at line](https://discuss.elastic.co/t/error-logstash-agent-failed-to-execute-action-action-logstash-create-pipeline-id-main-exception-logstash-configurationerror-message-expected-one-of-t-r-n-input-filter-output-at-line/336352)

<div class="topic-metadata">

**Author:** [@dropp.dev.hamidreza](https://discuss.elastic.co/u/dropp.dev.hamidreza)\
**Replies:** 6\
**Last updated:** [June 19, 2023, 7:36pm UTC](https://discuss.elastic.co/t/error-logstash-agent-failed-to-execute-action-action-logstash-create-pipeline-id-main-exception-logstash-configurationerror-message-expected-one-of-t-r-n-input-filter-output-at-line/336352 "2023-06-19T19:36:41Z")

</div>

Hi, I'm trying to set up ELK stack with docker and docker compose and while setting up pipeline in logstash is gave me error in logstash container logs: \[INFO \]\[logstash.runner \] JVM bootstrap flags: \[-Xms4g, -…

---

## [APM missing custom spans and incorrect name](https://discuss.elastic.co/t/apm-missing-custom-spans-and-incorrect-name/336325)

<div class="topic-metadata">

**Author:** [@Francis\_Lewis](https://discuss.elastic.co/u/Francis_Lewis)\
**Replies:** 2\
**Last updated:** [June 19, 2023, 7:25pm UTC](https://discuss.elastic.co/t/apm-missing-custom-spans-and-incorrect-name/336325 "2023-06-19T19:25:59Z")

</div>

Kibana version: 6.8.0 APM Server version: APM Agent language and version: PHP 1.8.3 Browser version: Google Chrome 114 Original install method (e.g. download page, yum, deb, from source, etc.) and version: Install fr…

---

## [Elastic prebuilt rules error](https://discuss.elastic.co/t/elastic-prebuilt-rules-error/334086)

<div class="topic-metadata">

**Author:** [@hasan.idriss](https://discuss.elastic.co/u/hasan.idriss)\
**Replies:** 2\
**Last updated:** [June 19, 2023, 6:56pm UTC](https://discuss.elastic.co/t/elastic-prebuilt-rules-error/334086 "2023-06-19T18:56:32Z")

</div>

hi guys am facing an issue with all prebuilt rules in Elasticsearch, when I enable the rules it runs with the following error An error occurred during rule execution: message: "verification\_exception Root causes: veri…

---

## [The client is unable to verify that the server is Elasticsearch](https://discuss.elastic.co/t/the-client-is-unable-to-verify-that-the-server-is-elasticsearch/335912)

<div class="topic-metadata">

**Author:** [@marcosrobles-qo](https://discuss.elastic.co/u/marcosrobles-qo)\
**Replies:** 1\
**Last updated:** [June 19, 2023, 4:09pm UTC](https://discuss.elastic.co/t/the-client-is-unable-to-verify-that-the-server-is-elasticsearch/335912 "2023-06-19T16:09:22Z")

</div>

Kibana version: Elasticsearch version: 8.6.0 APM Server version: APM Agent language and version: 8.6.0 - C# Browser version: Original install method (e.g. download page, yum, deb, from source, etc.) and version: …

[Previous page](https://discuss.elastic.co/latest.md?page=634)

[Next page](https://discuss.elastic.co/latest.md?page=636)
