# Latest

**URL:** https://discuss.elastic.co/latest.md?page=653

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 654

---

## [How to encode the aggregation response and get doc by id response values in Elasticsearch 7.17.x](https://discuss.elastic.co/t/how-to-encode-the-aggregation-response-and-get-doc-by-id-response-values-in-elasticsearch-7-17-x/335220)

<div class="topic-metadata">

**Author:** [@Karunakaran-ti](https://discuss.elastic.co/u/Karunakaran-ti)\
**Replies:** 0\
**Last updated:** [June 5, 2023, 1:05pm UTC](https://discuss.elastic.co/t/how-to-encode-the-aggregation-response-and-get-doc-by-id-response-values-in-elasticsearch-7-17-x/335220 "2023-06-05T13:05:27Z")

</div>

I am writing a custom Elasticsearch plugin. I want to do encode the response values from aggregation response and get doc by id. Using Elasticsearch v7.17.x I want to know what are interface/classes to be used from Ela…

---

## [JWT Realm configuration for Elasticsearch REST APIs authentication](https://discuss.elastic.co/t/jwt-realm-configuration-for-elasticsearch-rest-apis-authentication/334776)

<div class="topic-metadata">

**Author:** [@asimelastic](https://discuss.elastic.co/u/asimelastic)\
**Replies:** 4\
**Last updated:** [June 5, 2023, 11:35am UTC](https://discuss.elastic.co/t/jwt-realm-configuration-for-elasticsearch-rest-apis-authentication/334776 "2023-06-05T11:35:13Z")

</div>

I am new to Elasticsearch JWT Realm configuration. I am using trail version of Elasticsearch 8.7.1. I am configuring JWT Realm as follows in elasticsearch.yml xpack.security.authc.realms.jwt.jwt1: order: 1 token\_type…

---

## [Elasticsearch NEST deserializing issue. (Potential BUG)](https://discuss.elastic.co/t/elasticsearch-nest-deserializing-issue-potential-bug/335200)

<div class="topic-metadata">

**Author:** [@Jacques\_du\_Plessis](https://discuss.elastic.co/u/Jacques_du_Plessis)\
**Replies:** 2\
**Last updated:** [June 5, 2023, 11:09am UTC](https://discuss.elastic.co/t/elasticsearch-nest-deserializing-issue-potential-bug/335200 "2023-06-05T11:09:06Z")

</div>

I am getting the following error while debugging the code. Basically I have an issue where I cant deserialize the response, see this How to run multiple search templates using NEST In frustration i pulled the github cod…

---

## [Filtering with nested query inner\_hits count](https://discuss.elastic.co/t/filtering-with-nested-query-inner-hits-count/335202)

<div class="topic-metadata">

**Author:** [@LaySoft](https://discuss.elastic.co/u/LaySoft)\
**Replies:** 0\
**Last updated:** [June 5, 2023, 10:08am UTC](https://discuss.elastic.co/t/filtering-with-nested-query-inner-hits-count/335202 "2023-06-05T10:08:26Z")

</div>

I have the following query: "query": { "nested": { "path": "cuccok", "inner\_hits": {}, "query": { "bool": { "must": \[ …

---

## [Highlight in the field response](https://discuss.elastic.co/t/highlight-in-the-field-response/334955)

<div class="topic-metadata">

**Author:** [@Kirtash](https://discuss.elastic.co/u/Kirtash)\
**Replies:** 3\
**Last updated:** [June 5, 2023, 10:07am UTC](https://discuss.elastic.co/t/highlight-in-the-field-response/334955 "2023-06-05T10:07:24Z")

</div>

Good morning, I have an application that read the results from my query in elasticsearch and I take all the fields of the response and after it, I put it in a windows form for the user. Now I would like remark the part…

---

## [Add\_docker\_metadata is not able to pick container.labels.com\_amazonaws\_ecs\_container-name for a short living containers](https://discuss.elastic.co/t/add-docker-metadata-is-not-able-to-pick-container-labels-com-amazonaws-ecs-container-name-for-a-short-living-containers/335196)

<div class="topic-metadata">

**Author:** [@Maciej\_Piasecki](https://discuss.elastic.co/u/Maciej_Piasecki)\
**Replies:** 0\
**Last updated:** [June 5, 2023, 9:32am UTC](https://discuss.elastic.co/t/add-docker-metadata-is-not-able-to-pick-container-labels-com-amazonaws-ecs-container-name-for-a-short-living-containers/335196 "2023-06-05T09:32:40Z")

</div>

Hi, I am running some short living containers and I noticed that add\_docker\_metadata is not able to access container.labels.com\_amazonaws\_ecs\_container-name at a random frequency. I am using a rename like this: - re…

---

## [C# ElasticClient search - field name upper case issue](https://discuss.elastic.co/t/c-elasticclient-search-field-name-upper-case-issue/334903)

<div class="topic-metadata">

**Author:** [@Yujie\_S](https://discuss.elastic.co/u/Yujie_S)\
**Replies:** 1\
**Last updated:** [June 5, 2023, 9:28am UTC](https://discuss.elastic.co/t/c-elasticclient-search-field-name-upper-case-issue/334903 "2023-06-05T09:28:09Z")

</div>

My record is like this: { "\_index": "cmmtest2", "id": "q3\_WdIgBcz5F0I953TG", "\_score": 1, "\_source": { "characteristic": "150 W8 Prof 0.1 J", "actual": 0.019991, "nominal": 0, "partno": "2022\_7933 S2", "XBAR"…

---

## [After updating Java APM agent from 1.36 to 1.37 context propagation in reactor is no longer working as expected](https://discuss.elastic.co/t/after-updating-java-apm-agent-from-1-36-to-1-37-context-propagation-in-reactor-is-no-longer-working-as-expected/332810)

<div class="topic-metadata">

**Author:** [@svenrienstra](https://discuss.elastic.co/u/svenrienstra)\
**Replies:** 11\
**Last updated:** [June 5, 2023, 9:25am UTC](https://discuss.elastic.co/t/after-updating-java-apm-agent-from-1-36-to-1-37-context-propagation-in-reactor-is-no-longer-working-as-expected/332810 "2023-06-05T09:25:59Z")

</div>

I have an issue with the Java APM agent, after updating from 1.36 to 1.37 or 1.38 one of my plugins stopped working. I have a plugin which adds instrumentation for the r2dbc postgres driver. The relevant code of this plu…

---

## [Enriching data with ProxyIP database](https://discuss.elastic.co/t/enriching-data-with-proxyip-database/335169)

<div class="topic-metadata">

**Author:** [@Hitz2403](https://discuss.elastic.co/u/Hitz2403)\
**Replies:** 5\
**Last updated:** [June 5, 2023, 8:50am UTC](https://discuss.elastic.co/t/enriching-data-with-proxyip-database/335169 "2023-06-05T08:50:40Z")

</div>

Hi everyone, I need help enriching data with IP Proxy database like geoip plugin, has anyone done this before? Docs or something can help?

---

## [Unable to find valid sertification path to requested target](https://discuss.elastic.co/t/unable-to-find-valid-sertification-path-to-requested-target/334810)

<div class="topic-metadata">

**Author:** [@ddoroshenko](https://discuss.elastic.co/u/ddoroshenko)\
**Replies:** 2\
**Last updated:** [June 5, 2023, 8:20am UTC](https://discuss.elastic.co/t/unable-to-find-valid-sertification-path-to-requested-target/334810 "2023-06-05T08:20:37Z")

</div>

Hi, I have a watcher with webhook action. And get an error when the watcher is firing "type": "s\_s\_l\_handshake\_exception", "reason": " PKIX path building failed: sun.security.provider.certpath.SunCertPathBuildException…

---

## [Apply ILM to existing index](https://discuss.elastic.co/t/apply-ilm-to-existing-index/334022)

<div class="topic-metadata">

**Author:** [@ppic](https://discuss.elastic.co/u/ppic)\
**Replies:** 8\
**Last updated:** [June 5, 2023, 8:05am UTC](https://discuss.elastic.co/t/apply-ilm-to-existing-index/334022 "2023-06-05T08:05:55Z")

</div>

Hello, I use Elastic 7.17. I have created an ILM and applied it to the existing indexes through the Kibana UI (section Index Management). Each day, an index is automaticaly created but has no ILM associated. How can …

---

## [I am getting CDC data from Transaction tables from MYSQL DB to Elastic search , How Can I see latest status of transactions?](https://discuss.elastic.co/t/i-am-getting-cdc-data-from-transaction-tables-from-mysql-db-to-elastic-search-how-can-i-see-latest-status-of-transactions/334902)

<div class="topic-metadata">

**Author:** [@nitinkapoor](https://discuss.elastic.co/u/nitinkapoor)\
**Replies:** 4\
**Last updated:** [June 5, 2023, 8:01am UTC](https://discuss.elastic.co/t/i-am-getting-cdc-data-from-transaction-tables-from-mysql-db-to-elastic-search-how-can-i-see-latest-status-of-transactions/334902 "2023-06-05T08:01:20Z")

</div>

I am getting CDC data from Transaction tables from MYSQL DB to Elastic search , How Can I see latest status of transactions ? Should I use Transforms ?

---

## [SSL/TLS connection between ELK-Stack with Docker](https://discuss.elastic.co/t/ssl-tls-connection-between-elk-stack-with-docker/331040)

<div class="topic-metadata">

**Author:** [@Lokutus25](https://discuss.elastic.co/u/Lokutus25)\
**Replies:** 5\
**Last updated:** [June 5, 2023, 8:01am UTC](https://discuss.elastic.co/t/ssl-tls-connection-between-elk-stack-with-docker/331040 "2023-06-05T08:01:08Z")

</div>

Hi, I have a big problem with my ELK-Stack (version 8.7.0) created with docker. I have created elasticsearch, kibana, logstash and filebeat with docker-compose. elasticsearch and kibana connects per ssl with the token…

---

## [ECK cachce issue](https://discuss.elastic.co/t/eck-cachce-issue/335189)

<div class="topic-metadata">

**Author:** [@Rick\_Vailer](https://discuss.elastic.co/u/Rick_Vailer)\
**Replies:** 0\
**Last updated:** [June 5, 2023, 7:41am UTC](https://discuss.elastic.co/t/eck-cachce-issue/335189 "2023-06-05T07:41:34Z")

</div>

Hello, We are experiencing these issues on our ECK instance running 5 concurrent pods, sporadically some pods stop and change to a crashloopbackoff state with the below errors. We are mounting the plugin cache folder a…

---

## [Is context.hits supported on 8.1](https://discuss.elastic.co/t/is-context-hits-supported-on-8-1/334105)

<div class="topic-metadata">

**Author:** [@nitisha](https://discuss.elastic.co/u/nitisha)\
**Replies:** 0\
**Last updated:** [May 23, 2023, 10:39am UTC](https://discuss.elastic.co/t/is-context-hits-supported-on-8-1/334105 "2023-05-23T10:39:20Z")

</div>

Hi Team, Is context.hits supported on kibana version 8.1? I am using "Rules and Connectors" type as "Inventory" to monitor CPU metric threshold. With the default action rule {{alertName}} - {{context.group}} is in a st…

---

## [Grok on logstash not working](https://discuss.elastic.co/t/grok-on-logstash-not-working/334172)

<div class="topic-metadata">

**Author:** [@nitisha](https://discuss.elastic.co/u/nitisha)\
**Replies:** 0\
**Last updated:** [May 24, 2023, 6:17am UTC](https://discuss.elastic.co/t/grok-on-logstash-not-working/334172 "2023-05-24T06:17:13Z")

</div>

Hi, I am monitoring CPU metric threshold of containers in our infra using elasticsearch using Connector as "Server Log" which defaults to kibana.log. I have created the following logstash configuration file to intercep…

---

## [How to use custom field as control filter with values](https://discuss.elastic.co/t/how-to-use-custom-field-as-control-filter-with-values/334077)

<div class="topic-metadata">

**Author:** [@PappuSingh](https://discuss.elastic.co/u/PappuSingh)\
**Replies:** 2\
**Last updated:** [June 5, 2023, 5:00am UTC](https://discuss.elastic.co/t/how-to-use-custom-field-as-control-filter-with-values/334077 "2023-06-05T05:00:20Z")

</div>

Hi, We have created a custom field and we want to use this field as a control filter but not fill the values under the Control filter, please see the attached snap for your reference.

---

## [Elasticsearch killed by oom-killer](https://discuss.elastic.co/t/elasticsearch-killed-by-oom-killer/334982)

<div class="topic-metadata">

**Author:** [@Andy\_Ni](https://discuss.elastic.co/u/Andy_Ni)\
**Replies:** 5\
**Last updated:** [June 5, 2023, 3:27am UTC](https://discuss.elastic.co/t/elasticsearch-killed-by-oom-killer/334982 "2023-06-05T03:27:33Z")

</div>

Elasticsearch version: 6.2.3 System: \[root@my-host-name\]# uname -s -r -v -m -p -i -o Linux 5.4.8-1.el7.elrepo.x86\_64 #1 SMP Sat Jan 4 15:29:03 EST 2020 x86\_64 x86\_64 x86\_64 GNU/Linux ErrorMessage in /var/log/message: …

---

## [Not able to create index patterns as kibana is not getting the indices](https://discuss.elastic.co/t/not-able-to-create-index-patterns-as-kibana-is-not-getting-the-indices/334565)

<div class="topic-metadata">

**Author:** [@kirankumarb](https://discuss.elastic.co/u/kirankumarb)\
**Replies:** 15\
**Last updated:** [June 5, 2023, 1:23am UTC](https://discuss.elastic.co/t/not-able-to-create-index-patterns-as-kibana-is-not-getting-the-indices/334565 "2023-06-05T01:23:30Z")

</div>

\-I am getting indices for most of services, but unable to get indices for few services. So I am unable to create index patterns. We are getting logs in servers but unable to see logs in Kibana dashboard. \_Filebeat is up…

---

## [how geo\_distance query works under the hood in Elasticsearch?](https://discuss.elastic.co/t/how-geo-distance-query-works-under-the-hood-in-elasticsearch/335154)

<div class="topic-metadata">

**Author:** [@maulik\_trapasiya](https://discuss.elastic.co/u/maulik_trapasiya)\
**Replies:** 1\
**Last updated:** [June 4, 2023, 8:38pm UTC](https://discuss.elastic.co/t/how-geo-distance-query-works-under-the-hood-in-elasticsearch/335154 "2023-06-04T20:38:32Z")

</div>

I need to use geo\_distance query on Elasticsearch. Need info about how it works under the hood and what is latency? I am not able to find any doc relevant to this. please help

---

## [Unable to restart the nginx service](https://discuss.elastic.co/t/unable-to-restart-the-nginx-service/335170)

<div class="topic-metadata">

**Author:** [@surajhekare](https://discuss.elastic.co/u/surajhekare)\
**Replies:** 1\
**Last updated:** [June 4, 2023, 7:48pm UTC](https://discuss.elastic.co/t/unable-to-restart-the-nginx-service/335170 "2023-06-04T19:48:02Z")

</div>

ubuntu@ip-172-31-37-106:~$ sudo service nginx restart Job for nginx.service failed because the control process exited with error code. See "systemctl status nginx.service" and "journalctl -xe" for details. systemctl s…

---

## [Error when attempting to create component template using the ECS generator](https://discuss.elastic.co/t/error-when-attempting-to-create-component-template-using-the-ecs-generator/335004)

<div class="topic-metadata">

**Author:** [@bvoros](https://discuss.elastic.co/u/bvoros)\
**Replies:** 1\
**Last updated:** [June 4, 2023, 6:40pm UTC](https://discuss.elastic.co/t/error-when-attempting-to-create-component-template-using-the-ecs-generator/335004 "2023-06-04T18:40:56Z")

</div>

Hello all, I am using the ECS mapping template generator to create the relevant components so we can start using the ECS fields. I cloned GitHub - elastic/ecs: Elastic Common Schema and generated essentially the default…

---

## [Elastisearch doesn't create .security index after loss of data](https://discuss.elastic.co/t/elastisearch-doesnt-create-security-index-after-loss-of-data/335123)

<div class="topic-metadata">

**Author:** [@Savva\_Morozov](https://discuss.elastic.co/u/Savva_Morozov)\
**Replies:** 4\
**Last updated:** [June 4, 2023, 2:30pm UTC](https://discuss.elastic.co/t/elastisearch-doesnt-create-security-index-after-loss-of-data/335123 "2023-06-04T14:30:40Z")

</div>

Hello! We are using Elasticsearch and Kibana on Kubernetes deployed via Helm charts and recently we occasionaly deleted all the data from persistent volumes that our two nodes Elasticsearch cluster uses. Since then we ca…

---

## [Configure es with logstash](https://discuss.elastic.co/t/configure-es-with-logstash/334604)

<div class="topic-metadata">

**Author:** [@sujata\_g](https://discuss.elastic.co/u/sujata_g)\
**Replies:** 6\
**Last updated:** [June 4, 2023, 10:25am UTC](https://discuss.elastic.co/t/configure-es-with-logstash/334604 "2023-06-04T10:25:52Z")

</div>

input { s3 { access\_key\_id =\> "" secret\_access\_key =\> "" bucket =\> "dumpsampleperigon" region =\> "us-west-1" } } output { elasticsearch { hosts =\> \["http://elasticsearch:9200"\] index =\> "logs-%{+YYYY.MM.dd}" …

---

## [Elastic Cluster Architecture Best Practices](https://discuss.elastic.co/t/elastic-cluster-architecture-best-practices/335138)

<div class="topic-metadata">

**Author:** [@A.Hani](https://discuss.elastic.co/u/A.Hani)\
**Replies:** 5\
**Last updated:** [June 4, 2023, 4:57am UTC](https://discuss.elastic.co/t/elastic-cluster-architecture-best-practices/335138 "2023-06-04T04:57:20Z")

</div>

Hi all, I have an upcoming project to set up a small cluster and thought would use the community help to validate the design scenario that I have in mind. A little background about available resources for that project: …

---

## [Failed to start Elasticsearch](https://discuss.elastic.co/t/failed-to-start-elasticsearch/335146)

<div class="topic-metadata">

**Author:** [@surajhekare](https://discuss.elastic.co/u/surajhekare)\
**Replies:** 2\
**Last updated:** [June 4, 2023, 4:36am UTC](https://discuss.elastic.co/t/failed-to-start-elasticsearch/335146 "2023-06-04T04:36:10Z")

</div>

ubuntu@ip-172-31-37-106:~$ systemctl status elasticsearch.service ● elasticsearch.service - Elasticsearch Loaded: loaded (/lib/systemd/system/elasticsearch.service; disabled; vendor preset: enabled) Active: failed (Re…

---

## [Index Life cycle settings disturbed after setting \_index\_template](https://discuss.elastic.co/t/index-life-cycle-settings-disturbed-after-setting-index-template/335141)

<div class="topic-metadata">

**Author:** [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Replies:** 0\
**Last updated:** [June 3, 2023, 8:09pm UTC](https://discuss.elastic.co/t/index-life-cycle-settings-disturbed-after-setting-index-template/335141 "2023-06-03T20:09:17Z")

</div>

Hello, I had a template named "30days\_cleanup\_template" set for a particular index which was part of the ILM policy named "cleanup-history". Template was set as follows: PUT \_template/30days\_cleanup\_template { "inde…

---

## [Logstash giving error which is not clear](https://discuss.elastic.co/t/logstash-giving-error-which-is-not-clear/335126)

<div class="topic-metadata">

**Author:** [@Patr123](https://discuss.elastic.co/u/Patr123)\
**Replies:** 7\
**Last updated:** [June 3, 2023, 7:06pm UTC](https://discuss.elastic.co/t/logstash-giving-error-which-is-not-clear/335126 "2023-06-03T19:06:59Z")

</div>

I am getting the following error in logstash-plain.log: \[2023-06-03T01:33:34,256\]\[INFO \]\[logstash.runner \] Log4j configuration path used is: /etc/logstash/log4j2.properties \[2023-06-03T01:33:34,272\]\[INFO \]\[logs…

---

## [ELastic-CertUtil erro trying to create Certificate-authorities, .crt, .key](https://discuss.elastic.co/t/elastic-certutil-erro-trying-to-create-certificate-authorities-crt-key/334865)

<div class="topic-metadata">

**Author:** [@yash2](https://discuss.elastic.co/u/yash2)\
**Replies:** 5\
**Last updated:** [June 3, 2023, 6:43pm UTC](https://discuss.elastic.co/t/elastic-certutil-erro-trying-to-create-certificate-authorities-crt-key/334865 "2023-06-03T18:43:19Z")

</div>

Hey guys, i am having issues with generating Ca, crt and key for my nodes specifically using any o the below file and this command : \\Users\\YashCyb\\Downloads\\elasticsearch-8.8.0-windows-x86\_64\\elasticsearch-8.8.0\\bin\>…

---

## [ElasticSearch TLS/SSL Certificate issues 1](https://discuss.elastic.co/t/elasticsearch-tls-ssl-certificate-issues-1/334898)

<div class="topic-metadata">

**Author:** [@yash2](https://discuss.elastic.co/u/yash2)\
**Replies:** 5\
**Last updated:** [June 3, 2023, 6:29pm UTC](https://discuss.elastic.co/t/elasticsearch-tls-ssl-certificate-issues-1/334898 "2023-06-03T18:29:55Z")

</div>

Hey everyone, a very quick question, i have tried to modify my elasticsearch so it may resemble and work with my generated openssl Certificate.crt + private.key. ┌──(root㉿kali)-\[/etc\] └─# openssl req -x509 -nodes -days …

[Previous page](https://discuss.elastic.co/latest.md?page=652)

[Next page](https://discuss.elastic.co/latest.md?page=654)
