# Latest

**URL:** https://discuss.elastic.co/latest.md?page=636

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 637

---

## [Elasticsearch Master Not discovered](https://discuss.elastic.co/t/elasticsearch-master-not-discovered/336375)

<div class="topic-metadata">

**Author:** [@A.Hani](https://discuss.elastic.co/u/A.Hani)\
**Replies:** 2\
**Last updated:** [June 19, 2023, 3:16pm UTC](https://discuss.elastic.co/t/elasticsearch-master-not-discovered/336375 "2023-06-19T15:16:33Z")

</div>

Hi all, I'm trying to form a cluster of 3 Nodes using Elasticsearch V8.8. I'm testing how this should work on the first 2 nodes and this really driving me crazy. My initial attempt was to start the first node as a clust…

---

## [Club char\_filter for a regex pattern and synonyms in the same query](https://discuss.elastic.co/t/club-char-filter-for-a-regex-pattern-and-synonyms-in-the-same-query/336383)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 0\
**Last updated:** [June 19, 2023, 2:53pm UTC](https://discuss.elastic.co/t/club-char-filter-for-a-regex-pattern-and-synonyms-in-the-same-query/336383 "2023-06-19T14:53:58Z")

</div>

I have an index that has candidate resumes. Resume has 2 fields: a) name b) resume Name has name of candidate and resume has a blob of text like "address:""chicago.st", "skill":"python", "email":"myemail@ymail.com". I …

---

## [Filebeat log to multiple outputs like file and syslog](https://discuss.elastic.co/t/filebeat-log-to-multiple-outputs-like-file-and-syslog/335743)

<div class="topic-metadata">

**Author:** [@michaelbu](https://discuss.elastic.co/u/michaelbu)\
**Replies:** 7\
**Last updated:** [June 19, 2023, 2:53pm UTC](https://discuss.elastic.co/t/filebeat-log-to-multiple-outputs-like-file-and-syslog/335743 "2023-06-19T14:53:04Z")

</div>

Hi, I'm using filebeat on Linux in this version: $ rpm -qa | grep filebeat filebeat-8.7.0-1.x86\_64 I would like to log filebeat to logfiles and also to syslog. This is the configuration snippet: logging: to\_files: …

---

## [FATAL Error: Unable to complete saved object migrations for the \[.kibana\] index: Migrations failed. Reason: 2 transformation errors were encountered](https://discuss.elastic.co/t/fatal-error-unable-to-complete-saved-object-migrations-for-the-kibana-index-migrations-failed-reason-2-transformation-errors-were-encountered/336382)

<div class="topic-metadata">

**Author:** [@Jasmine\_Blooms](https://discuss.elastic.co/u/Jasmine_Blooms)\
**Replies:** 0\
**Last updated:** [June 19, 2023, 2:49pm UTC](https://discuss.elastic.co/t/fatal-error-unable-to-complete-saved-object-migrations-for-the-kibana-index-migrations-failed-reason-2-transformation-errors-were-encountered/336382 "2023-06-19T14:49:30Z")

</div>

Hi All, While performing migration of kibana using eck-operator from 7.8.1 to 7.17.10, we are facing the following issue: FATAL Error: Unable to complete saved object migrations for the \[.kibana\] index: Migrations fa…

---

## [Specify an index in search query](https://discuss.elastic.co/t/specify-an-index-in-search-query/336221)

<div class="topic-metadata">

**Author:** [@stephane\_chan](https://discuss.elastic.co/u/stephane_chan)\
**Replies:** 3\
**Last updated:** [June 19, 2023, 2:41pm UTC](https://discuss.elastic.co/t/specify-an-index-in-search-query/336221 "2023-06-19T14:41:30Z")

</div>

I need to search multiple indexes on Elasticsearch, My problem is that on each index I have the same field name (is\_active), how do I specify that it's the field of the other index ? GET index-1,index-2/\_search { "que…

---

## [Kibana watcher error throwing SSL handshake even though CA is same for both Kibana & Elasticsearch](https://discuss.elastic.co/t/kibana-watcher-error-throwing-ssl-handshake-even-though-ca-is-same-for-both-kibana-elasticsearch/336256)

<div class="topic-metadata">

**Author:** [@vee](https://discuss.elastic.co/u/vee)\
**Replies:** 1\
**Last updated:** [June 19, 2023, 2:21pm UTC](https://discuss.elastic.co/t/kibana-watcher-error-throwing-ssl-handshake-even-though-ca-is-same-for-both-kibana-elasticsearch/336256 "2023-06-19T14:21:28Z")

</div>

Kibana watcher error throwing SSL handshake even though CA is same for both Kibana & Elasticsearch. Here's the error: Attaching the watcher definition as well. "error" : { "root\_cause" : \[ …

---

## [elasticsearch/distribution/docker/src/docker/Dockerfile - regarding the absence of files with setuid](https://discuss.elastic.co/t/elasticsearch-distribution-docker-src-docker-dockerfile-regarding-the-absence-of-files-with-setuid/336378)

<div class="topic-metadata">

**Author:** [@raperez](https://discuss.elastic.co/u/raperez)\
**Replies:** 0\
**Last updated:** [June 19, 2023, 2:08pm UTC](https://discuss.elastic.co/t/elasticsearch-distribution-docker-src-docker-dockerfile-regarding-the-absence-of-files-with-setuid/336378 "2023-06-19T14:08:27Z")

</div>

Hi all! I am reaching you because I am working with the following Elasticsearch image as base, and I would like to ask some questions about the following line of the Dockerfile. The comments of the Dockerfile, regardin…

---

## [Character group tokenizer in ElasticSearch](https://discuss.elastic.co/t/character-group-tokenizer-in-elasticsearch/336212)

<div class="topic-metadata">

**Author:** [@Rakhshunda\_Noorein\_J](https://discuss.elastic.co/u/Rakhshunda_Noorein_J)\
**Replies:** 4\
**Last updated:** [June 19, 2023, 2:00pm UTC](https://discuss.elastic.co/t/character-group-tokenizer-in-elasticsearch/336212 "2023-06-19T14:00:53Z")

</div>

Hello, I want to implement Character group tokenizer in elasticsearch. How Do I implement an index with char\_group tokenizer. I am putting this setting in my index: { "index": { "analysis": { "number\_of\_sha…

---

## [Calculate and display failure rate based on a "keyword" field](https://discuss.elastic.co/t/calculate-and-display-failure-rate-based-on-a-keyword-field/336099)

<div class="topic-metadata">

**Author:** [@zebu14](https://discuss.elastic.co/u/zebu14)\
**Replies:** 3\
**Last updated:** [June 19, 2023, 1:53pm UTC](https://discuss.elastic.co/t/calculate-and-display-failure-rate-based-on-a-keyword-field/336099 "2023-06-19T13:53:32Z")

</div>

Hello, For a MFT platform, each transfer is tagged with a status\_code, based on letters "E" for Ended, "C" for Canceled. I have to find out the partners with high failure rates over time. Do you have an idea on how to…

---

## [Unable to find apikey warning](https://discuss.elastic.co/t/unable-to-find-apikey-warning/335956)

<div class="topic-metadata">

**Author:** [@A\_Abdellah](https://discuss.elastic.co/u/A_Abdellah)\
**Replies:** 4\
**Last updated:** [June 19, 2023, 1:41pm UTC](https://discuss.elastic.co/t/unable-to-find-apikey-warning/335956 "2023-06-19T13:41:05Z")

</div>

Hello, for the info my cluster is on version 7.17.4 and it's based on 3 nodes that are all master eligible and data nodes. I keep getting this warning on my master node logs non-stop, \[2023-06-13T15:44:07,212\]\[WARN \]\[…

---

## [Cannot initialize custom codec plugin](https://discuss.elastic.co/t/cannot-initialize-custom-codec-plugin/336371)

<div class="topic-metadata">

**Author:** [@ofekinger](https://discuss.elastic.co/u/ofekinger)\
**Replies:** 0\
**Last updated:** [June 19, 2023, 1:28pm UTC](https://discuss.elastic.co/t/cannot-initialize-custom-codec-plugin/336371 "2023-06-19T13:28:07Z")

</div>

Hello. I'm working on a new codec plugin that parses protobuf data in a unique way (meaning I can't use the existing protobuf plugin). Here's the plugin code: package com.ofekinger.logstash.plugins.mycodec; import co…

---

## [Osquery has results but not displaying them](https://discuss.elastic.co/t/osquery-has-results-but-not-displaying-them/334606)

<div class="topic-metadata">

**Author:** [@meni0n](https://discuss.elastic.co/u/meni0n)\
**Replies:** 2\
**Last updated:** [June 19, 2023, 1:01pm UTC](https://discuss.elastic.co/t/osquery-has-results-but-not-displaying-them/334606 "2023-06-19T13:01:01Z")

</div>

I have osquery agent returning results but the result page keeping saying "1 agent has responded, no osquery data has been reported."

---

## [Differnce in results when the search query contains a hyphen](https://discuss.elastic.co/t/differnce-in-results-when-the-search-query-contains-a-hyphen/336324)

<div class="topic-metadata">

**Author:** [@zigoo0](https://discuss.elastic.co/u/zigoo0)\
**Replies:** 1\
**Last updated:** [June 19, 2023, 1:00pm UTC](https://discuss.elastic.co/t/differnce-in-results-when-the-search-query-contains-a-hyphen/336324 "2023-06-19T13:00:46Z")

</div>

Hello team, I have an elasticsearch index that contains hostnames and email addresses. When searching the index, my aim is to retrieve all hostnames and emails that contains certain domain Following examples will expla…

---

## [Create button with filters in dashboards](https://discuss.elastic.co/t/create-button-with-filters-in-dashboards/336243)

<div class="topic-metadata">

**Author:** [@SYGH](https://discuss.elastic.co/u/SYGH)\
**Replies:** 5\
**Last updated:** [June 19, 2023, 12:39pm UTC](https://discuss.elastic.co/t/create-button-with-filters-in-dashboards/336243 "2023-06-19T12:39:35Z")

</div>

Hello, I need to create a button on the dashboard to enable a filter based on the value of X. At the same time, when you click it again, the filter is removed. Please tell me how to create this button.

---

## [Elasticsearch killed at time of start](https://discuss.elastic.co/t/elasticsearch-killed-at-time-of-start/336312)

<div class="topic-metadata">

**Author:** [@deepakmahajan00](https://discuss.elastic.co/u/deepakmahajan00)\
**Replies:** 1\
**Last updated:** [June 19, 2023, 12:28pm UTC](https://discuss.elastic.co/t/elasticsearch-killed-at-time-of-start/336312 "2023-06-19T12:28:49Z")

</div>

Starting Elasticsearch Server …

---

## [LogStash Configurations for Log4Net, Log4J etc](https://discuss.elastic.co/t/logstash-configurations-for-log4net-log4j-etc/336258)

<div class="topic-metadata">

**Author:** [@Tomahawk](https://discuss.elastic.co/u/Tomahawk)\
**Replies:** 2\
**Last updated:** [June 19, 2023, 11:55am UTC](https://discuss.elastic.co/t/logstash-configurations-for-log4net-log4j-etc/336258 "2023-06-19T11:55:34Z")

</div>

Bit of a left field question….. In a highly regulated space and restricted industry, log files coming from multiple apps (100-200) with Log4Net and Log4J, Python Native logging libraries. No real customisation done by t…

---

## [Format version is not supported (resource BufferedChecksumIndexInput (SimpleFSIndexInput))](https://discuss.elastic.co/t/format-version-is-not-supported-resource-bufferedchecksumindexinput-simplefsindexinput/336348)

<div class="topic-metadata">

**Author:** [@amal\_srivastava](https://discuss.elastic.co/u/amal_srivastava)\
**Replies:** 2\
**Last updated:** [June 19, 2023, 11:14am UTC](https://discuss.elastic.co/t/format-version-is-not-supported-resource-bufferedchecksumindexinput-simplefsindexinput/336348 "2023-06-19T11:14:44Z")

</div>

Hi, One of my elasticsearch index is red and when i dig this into deep i am getting this below error GET \_cluster/allocation/explain { "index" : "design", "shard" : 0, "primary" : true, "current\_state" : "unassign…

---

## [Errors Updating logstash from 8.5.3 to 8.8.0](https://discuss.elastic.co/t/errors-updating-logstash-from-8-5-3-to-8-8-0/335531)

<div class="topic-metadata">

**Author:** [@cperzrt10](https://discuss.elastic.co/u/cperzrt10)\
**Replies:** 6\
**Last updated:** [June 19, 2023, 10:03am UTC](https://discuss.elastic.co/t/errors-updating-logstash-from-8-5-3-to-8-8-0/335531 "2023-06-19T10:03:52Z")

</div>

I have update all my Elasticsearch cluster, and kibana to the version 8.8.0 from 8.5.3, when update Logstash it doesnt start runing and show the next error \[2023-06-08T13:06:33,163\]\[WARN \]\[logstash.outputs.elasticsearch…

---

## [Logstash batch import nested objects](https://discuss.elastic.co/t/logstash-batch-import-nested-objects/336342)

<div class="topic-metadata">

**Author:** [@Joker\_Lu](https://discuss.elastic.co/u/Joker_Lu)\
**Replies:** 0\
**Last updated:** [June 19, 2023, 9:23am UTC](https://discuss.elastic.co/t/logstash-batch-import-nested-objects/336342 "2023-06-19T09:23:55Z")

</div>

Hi everyone, I want to batch import nested objects to ES, but when i paging my nested objects, it will cover my previous data. Can anyone have a solution for this.

---

## [Issue with ingesting data and disk size](https://discuss.elastic.co/t/issue-with-ingesting-data-and-disk-size/336087)

<div class="topic-metadata">

**Author:** [@ANUBHAV\_GUPTA](https://discuss.elastic.co/u/ANUBHAV_GUPTA)\
**Replies:** 3\
**Last updated:** [June 19, 2023, 9:23am UTC](https://discuss.elastic.co/t/issue-with-ingesting-data-and-disk-size/336087 "2023-06-19T09:23:29Z")

</div>

I am facing a very weird issue. I tried uploading 30 GB of csv data in Elasticsearch using python client. The below is the disk usage when I quit ingestion:- shards disk.indices disk.used disk.avail disk.total disk.pe…

---

## [Upgrading kibana and Elastic from 7.9 to 8.7](https://discuss.elastic.co/t/upgrading-kibana-and-elastic-from-7-9-to-8-7/335906)

<div class="topic-metadata">

**Author:** [@Kumar\_Abhinav](https://discuss.elastic.co/u/Kumar_Abhinav)\
**Replies:** 5\
**Last updated:** [June 19, 2023, 8:49am UTC](https://discuss.elastic.co/t/upgrading-kibana-and-elastic-from-7-9-to-8-7/335906 "2023-06-19T08:49:42Z")

</div>

Hi. I am in the process to upgrade my kibana and Elasticsearch from 7.9 to 8.7. I installed 7.17 but did not back up the data from version 7.9. What shall I do now? Someone, please guide.

---

## [Server public URL Warning](https://discuss.elastic.co/t/server-public-url-warning/336338)

<div class="topic-metadata">

**Author:** [@Ganesh2303](https://discuss.elastic.co/u/Ganesh2303)\
**Replies:** 0\
**Last updated:** [June 19, 2023, 8:39am UTC](https://discuss.elastic.co/t/server-public-url-warning/336338 "2023-06-19T08:39:54Z")

</div>

HI Team, I'm using Version 7.16 ELK and when i try to hit the kibana URL im getting below warning message "server.publicBaseUrl is missing and should be configured when running in a production environment" if i add th…

---

## [No Logs appearing in Kibana](https://discuss.elastic.co/t/no-logs-appearing-in-kibana/336208)

<div class="topic-metadata">

**Author:** [@Shabu](https://discuss.elastic.co/u/Shabu)\
**Replies:** 15\
**Last updated:** [June 19, 2023, 8:21am UTC](https://discuss.elastic.co/t/no-logs-appearing-in-kibana/336208 "2023-06-19T08:21:27Z")

</div>

Those are my statistics. When I tcpdump port 5044 I see traffic coming from the host where I have winlogbeat running and when I tcpdump port 9200 on the server I see a lot of traffic. So I suppose Data is reaching ela…

---

## [Fleet: This output type currently does not support connectivity to a remote Elasticsearch cluster](https://discuss.elastic.co/t/fleet-this-output-type-currently-does-not-support-connectivity-to-a-remote-elasticsearch-cluster/336336)

<div class="topic-metadata">

**Author:** [@tomx1](https://discuss.elastic.co/u/tomx1)\
**Replies:** 0\
**Last updated:** [June 19, 2023, 8:15am UTC](https://discuss.elastic.co/t/fleet-this-output-type-currently-does-not-support-connectivity-to-a-remote-elasticsearch-cluster/336336 "2023-06-19T08:15:22Z")

</div>

I'm currently testing Fleet and added a dedicated fleet server and a dedicated "collector server" VM with elastic agent installed. Everything is now managed via Kibana and my goal is to collect stuff via the collector VM…

---

## [Getting unrelated data while searching with -\* in simple\_query\_string](https://discuss.elastic.co/t/getting-unrelated-data-while-searching-with-in-simple-query-string/336192)

<div class="topic-metadata">

**Author:** [@ms.t](https://discuss.elastic.co/u/ms.t)\
**Replies:** 4\
**Last updated:** [June 19, 2023, 8:10am UTC](https://discuss.elastic.co/t/getting-unrelated-data-while-searching-with-in-simple-query-string/336192 "2023-06-19T08:10:50Z")

</div>

Hi I am using simple\_query\_string method with suffix \* (operator) for getting result But when i am searching with odd number of - getting unrelated data but with even number of - getting empty data.

---

## [Failed sending events! DOMException: The user aborted a request](https://discuss.elastic.co/t/failed-sending-events-domexception-the-user-aborted-a-request/336257)

<div class="topic-metadata">

**Author:** [@Thiago\_Medeiros](https://discuss.elastic.co/u/Thiago_Medeiros)\
**Replies:** 1\
**Last updated:** [June 19, 2023, 8:00am UTC](https://discuss.elastic.co/t/failed-sending-events-domexception-the-user-aborted-a-request/336257 "2023-06-19T08:00:00Z")

</div>

I have APM and RUM configured as documentation says, and Vue in the frontend. APM Server version: 8.8.1 This is my whole apm-server.yml: host: 0.0.0.0:8200 output.elasticsearch: hosts: - elasticsearch:9200 …

---

## [Need help with Elasticsearch and Elastic agent](https://discuss.elastic.co/t/need-help-with-elasticsearch-and-elastic-agent/335502)

<div class="topic-metadata">

**Author:** [@SanketBaraiya](https://discuss.elastic.co/u/SanketBaraiya)\
**Replies:** 7\
**Last updated:** [June 19, 2023, 7:20am UTC](https://discuss.elastic.co/t/need-help-with-elasticsearch-and-elastic-agent/335502 "2023-06-19T07:20:21Z")

</div>

I am facing the problem in my elk server. Whenever I start the elasticsearch service the outgoing traffic increases to \>10 MBps. This is what is shown in the processes. I also have stopped both filebeat and metricbea…

---

## [Upgrde 7.8 to 7](https://discuss.elastic.co/t/upgrde-7-8-to-7/336264)

<div class="topic-metadata">

**Author:** [@Abhishek\_Tiwari1](https://discuss.elastic.co/u/Abhishek_Tiwari1)\
**Replies:** 3\
**Last updated:** [June 19, 2023, 6:39am UTC](https://discuss.elastic.co/t/upgrde-7-8-to-7/336264 "2023-06-19T06:39:42Z")

</div>

HI Team, Need help , we are facing issue after upgrade elasticseach from 7.8 to 7.17.10, Issue first it incresed respoonce time Chche value decresed drasticily from 7.8 to 7.17.10 on search . Please help Thanks Abh…

---

## [How to delete/clear an invalidated api key from '/\_security/api\_key' list?](https://discuss.elastic.co/t/how-to-delete-clear-an-invalidated-api-key-from-security-api-key-list/336069)

<div class="topic-metadata">

**Author:** [@ade.syseng](https://discuss.elastic.co/u/ade.syseng)\
**Replies:** 1\
**Last updated:** [June 19, 2023, 4:30am UTC](https://discuss.elastic.co/t/how-to-delete-clear-an-invalidated-api-key-from-security-api-key-list/336069 "2023-06-19T04:30:27Z")

</div>

Hi, Is it possible to delete these invalidated api keys from '/\_security/api\_key'? I just want to keep the list clean from invalidated keys. Any suggestion or solution for this issue? Note: Elasticsearch and Kibana …

---

## [Index status red with reason failed engine (reason: \[merge failed\])](https://discuss.elastic.co/t/index-status-red-with-reason-failed-engine-reason-merge-failed/336249)

<div class="topic-metadata">

**Author:** [@Fajaruddin\_Shiddiq](https://discuss.elastic.co/u/Fajaruddin_Shiddiq)\
**Replies:** 7\
**Last updated:** [June 19, 2023, 1:55am UTC](https://discuss.elastic.co/t/index-status-red-with-reason-failed-engine-reason-merge-failed/336249 "2023-06-19T01:55:47Z")

</div>

Hi, one of my index seems corrupt because of failed during merge process as below org.apache.lucene.index.MergePolicy$MergeException: org.apache.lucene.index.CorruptIndexException: docs out of order (594 \<= 594 ) (reso…

[Previous page](https://discuss.elastic.co/latest.md?page=635)

[Next page](https://discuss.elastic.co/latest.md?page=637)
