# Latest

**URL:** https://discuss.elastic.co/latest.md?page=667

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 668

---

## [Rule based on the @timestamp field](https://discuss.elastic.co/t/rule-based-on-the-timestamp-field/334230)

<div class="topic-metadata">

**Author:** [@hdia](https://discuss.elastic.co/u/hdia)\
**Replies:** 0\
**Last updated:** [May 24, 2023, 2:30pm UTC](https://discuss.elastic.co/t/rule-based-on-the-timestamp-field/334230 "2023-05-24T14:30:56Z")

</div>

Hello, I want to create a rule to detect any connection attempt between 7pm and 7am the next day. But unfortunately I am obliged to put the whole date (year, month, day, hour, minute and second) which obliges me to modi…

---

## [Elasticsearch Get All data which has specified value for some of the field](https://discuss.elastic.co/t/elasticsearch-get-all-data-which-has-specified-value-for-some-of-the-field/334201)

<div class="topic-metadata">

**Author:** [@Mustafa\_AYDOGDU](https://discuss.elastic.co/u/Mustafa_AYDOGDU)\
**Replies:** 1\
**Last updated:** [May 24, 2023, 2:22pm UTC](https://discuss.elastic.co/t/elasticsearch-get-all-data-which-has-specified-value-for-some-of-the-field/334201 "2023-05-24T14:22:57Z")

</div>

Hello, I have a query which gets data with project\_id=1 and project\_user\_id=1: GET /tweet\_user\_id\_index/\_search { "query": { "bool": { "should": \[ { "term": { "project\_id": { …

---

## ['\_source' filtering is slower than query without '\_source' field](https://discuss.elastic.co/t/source-filtering-is-slower-than-query-without-source-field/333556)

<div class="topic-metadata">

**Author:** [@nadeem.akhter](https://discuss.elastic.co/u/nadeem.akhter)\
**Replies:** 7\
**Last updated:** [May 24, 2023, 2:17pm UTC](https://discuss.elastic.co/t/source-filtering-is-slower-than-query-without-source-field/333556 "2023-05-24T14:17:17Z")

</div>

I have an elasticsearch instance with some data on it, and when trying queries on the data, it is slower to filter '\_source' in query than not mentioning the '\_source' key at all. Is there any specific reason for this? P…

---

## [Writing PySpark dataframe to Elastic Cloud (Cannot detect ES version)](https://discuss.elastic.co/t/writing-pyspark-dataframe-to-elastic-cloud-cannot-detect-es-version/334176)

<div class="topic-metadata">

**Author:** [@Dmytro\_Ostapchuk](https://discuss.elastic.co/u/Dmytro_Ostapchuk)\
**Replies:** 6\
**Last updated:** [May 24, 2023, 2:06pm UTC](https://discuss.elastic.co/t/writing-pyspark-dataframe-to-elastic-cloud-cannot-detect-es-version/334176 "2023-05-24T14:06:12Z")

</div>

Hi there! My use case Run PySpark job on EMR Serverless that reads data from S3 and writes it into Elastic cloud. Errors Cannot detect ES version - typically this happens if the network/Elasticsearch cluster is not a…

---

## [Filebeat not sending logs to elasticsearch](https://discuss.elastic.co/t/filebeat-not-sending-logs-to-elasticsearch/334106)

<div class="topic-metadata">

**Author:** [@mohammad\_messiah](https://discuss.elastic.co/u/mohammad_messiah)\
**Replies:** 1\
**Last updated:** [May 24, 2023, 1:47pm UTC](https://discuss.elastic.co/t/filebeat-not-sending-logs-to-elasticsearch/334106 "2023-05-24T13:47:04Z")

</div>

Filebeat not sending logs to elasticsearch. Tried restart of elasticstack, reinstall of filebeat agent on few nodes, renaming the registry files to force index rebuild, removing lock file under /var/lib/filebeat but noth…

---

## [Unable to create index with %{type} in logstash output](https://discuss.elastic.co/t/unable-to-create-index-with-type-in-logstash-output/334079)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 2\
**Last updated:** [May 24, 2023, 1:18pm UTC](https://discuss.elastic.co/t/unable-to-create-index-with-type-in-logstash-output/334079 "2023-05-24T13:18:10Z")

</div>

Hi here is my logstash config file input { beats { port =\> 5044 } } output { elasticsearch { hosts =\> "http://IP:9200" index =\> "%{type}%{+YYYY.MM.dd}" user =\> "elastic" password =\> "pwd" } …

---

## [Need Watcher configuration and settings ElasticSearch yml](https://discuss.elastic.co/t/need-watcher-configuration-and-settings-elasticsearch-yml/330291)

<div class="topic-metadata">

**Author:** [@Praveen\_kr](https://discuss.elastic.co/u/Praveen_kr)\
**Replies:** 20\
**Last updated:** [May 24, 2023, 1:11pm UTC](https://discuss.elastic.co/t/need-watcher-configuration-and-settings-elasticsearch-yml/330291 "2023-05-24T13:11:06Z")

</div>

Hi Team, , Anyone one Could you please help me with the watcher configuration elasticsearch yml setup as we have 13 nodes I need to add the watcher settings to send a mail alert (outlook). Challenges what am facing her…

---

## [.kibana\_task\_manager UNASSIGNED ALLOCATION\_FAILED](https://discuss.elastic.co/t/kibana-task-manager-unassigned-allocation-failed/334211)

<div class="topic-metadata">

**Author:** [@cyberzlo](https://discuss.elastic.co/u/cyberzlo)\
**Replies:** 0\
**Last updated:** [May 24, 2023, 11:44am UTC](https://discuss.elastic.co/t/kibana-task-manager-unassigned-allocation-failed/334211 "2023-05-24T11:44:27Z")

</div>

I have a single node (without a cluster of several machines) that had an uncontrolled reboot due to power failure. How can I fix this problem? kibana\[4428\]: no\_shard\_available\_action\_exception: null'. Re…

---

## [Kibana Error - Failed to open PIT](https://discuss.elastic.co/t/kibana-error-failed-to-open-pit/334166)

<div class="topic-metadata">

**Author:** [@Yos](https://discuss.elastic.co/u/Yos)\
**Replies:** 1\
**Last updated:** [May 24, 2023, 12:16pm UTC](https://discuss.elastic.co/t/kibana-error-failed-to-open-pit/334166 "2023-05-24T12:16:39Z")

</div>

Kibana Version : 8.5.3 Hello The following error is intermittently logged in Kibana's logs Please let me know the cause of this and how to address it. Best Regards \[2023-05-24T11:30:54.572+09:00\]\[ERROR\]\[savedobject…

---

## [NiFi flow not able to write into Elasticsearch because of exceeding maximum shards](https://discuss.elastic.co/t/nifi-flow-not-able-to-write-into-elasticsearch-because-of-exceeding-maximum-shards/334204)

<div class="topic-metadata">

**Author:** [@Yasser\_Alsawy](https://discuss.elastic.co/u/Yasser_Alsawy)\
**Replies:** 3\
**Last updated:** [May 24, 2023, 10:52am UTC](https://discuss.elastic.co/t/nifi-flow-not-able-to-write-into-elasticsearch-because-of-exceeding-maximum-shards/334204 "2023-05-24T10:52:49Z")

</div>

I have only one node elasticsearch at my cluster. I'm trying to write into elasticsearch using PutElasticsearchHttp control at my NiFi flow but I get an error: 2023-05-24 07:00:17,347 ERROR \[Timer-Driven Process Thread-…

---

## [Sending all elasticsearch logs to a diode](https://discuss.elastic.co/t/sending-all-elasticsearch-logs-to-a-diode/334207)

<div class="topic-metadata">

**Author:** [@willsy](https://discuss.elastic.co/u/willsy)\
**Replies:** 0\
**Last updated:** [May 24, 2023, 10:49am UTC](https://discuss.elastic.co/t/sending-all-elasticsearch-logs-to-a-diode/334207 "2023-05-24T10:49:57Z")

</div>

Hi there, I am completing some dev work and trying to input all of the ingested elasticsearch data from my system, into logstash (on the same server as elasticsearch) and output this to a one way data diode to allow the…

---

## [Cluster State Yellow: 2 shards initializing with multiple failed attempts: IllegalArgumentException \[ReleasableBytesStreamOutput cannot hold more than 2GB of data](https://discuss.elastic.co/t/cluster-state-yellow-2-shards-initializing-with-multiple-failed-attempts-illegalargumentexception-releasablebytesstreamoutput-cannot-hold-more-than-2gb-of-data/334008)

<div class="topic-metadata">

**Author:** [@Sarit\_Ghosh](https://discuss.elastic.co/u/Sarit_Ghosh)\
**Replies:** 5\
**Last updated:** [May 24, 2023, 9:43am UTC](https://discuss.elastic.co/t/cluster-state-yellow-2-shards-initializing-with-multiple-failed-attempts-illegalargumentexception-releasablebytesstreamoutput-cannot-hold-more-than-2gb-of-data/334008 "2023-05-24T09:43:51Z")

</div>

For about a week, we are seeing the following error and cluster state yellow. On checking the \_cluster/state we get this - Elastic Search Version - 7.17 (Please let me know if more data is needed) {"state":"INITIALIZIN…

---

## [Service unavailable error code 503 all shard failed](https://discuss.elastic.co/t/service-unavailable-error-code-503-all-shard-failed/333976)

<div class="topic-metadata">

**Author:** [@target\_test](https://discuss.elastic.co/u/target_test)\
**Replies:** 11\
**Last updated:** [May 24, 2023, 9:30am UTC](https://discuss.elastic.co/t/service-unavailable-error-code-503-all-shard-failed/333976 "2023-05-24T09:30:24Z")

</div>

Hello all, I got this problem showing that service unavailable {"statusCode":503,"error":"Service Unavailable","message":"\[all shards failed: search\_phase\_execution\_exception\\n\\tRoot causes:\\n\\t\\tno\_shard\_available\_act…

---

## [Same Query different results in .NET client](https://discuss.elastic.co/t/same-query-different-results-in-net-client/334180)

<div class="topic-metadata">

**Author:** [@LhamoDev](https://discuss.elastic.co/u/LhamoDev)\
**Replies:** 2\
**Last updated:** [May 24, 2023, 9:25am UTC](https://discuss.elastic.co/t/same-query-different-results-in-net-client/334180 "2023-05-24T09:25:01Z")

</div>

Hello, I've been working on a query that can search a Document from my reservation index, These Reservations has a "SequenceId" on which thesearch query works with. This is the format of the ID: LLL-0000-000000 Produ…

---

## [当调用ElasticsearchClient的query方法时, static字段丢失或者改变, 这是为什么呀](https://discuss.elastic.co/t/elasticsearchclient-query-static/334181)

<div class="topic-metadata">

**Author:** [@xiaochunyong](https://discuss.elastic.co/u/xiaochunyong)\
**Replies:** 2\
**Last updated:** [May 24, 2023, 9:24am UTC](https://discuss.elastic.co/t/elasticsearchclient-query-static/334181 "2023-05-24T09:24:28Z")

</div>

Java API client version: 7.17.10 Java version: jdk-17.0.3.1 Elasticsearch Version: 7.17 我有个代码仓库可以复现这个问题: GitHub - xiaochunyong/elasticsearch-threadlocal-reference-changed 有一个类UserHolder, 里面有个ThreadLocal变量 public cla…

---

## [How to show several docs with the same field?](https://discuss.elastic.co/t/how-to-show-several-docs-with-the-same-field/334198)

<div class="topic-metadata">

**Author:** [@asebalo98](https://discuss.elastic.co/u/asebalo98)\
**Replies:** 0\
**Last updated:** [May 24, 2023, 9:20am UTC](https://discuss.elastic.co/t/how-to-show-several-docs-with-the-same-field/334198 "2023-05-24T09:20:52Z")

</div>

I have documents that have a ”CompanyId” field that can be the same for multiple documents. I want Elasticsearch to take up to 3 documents with the same “CompanyId” and the highest score, and then rank them in the overa…

---

## [Warm tier shards being allocated to data nodes](https://discuss.elastic.co/t/warm-tier-shards-being-allocated-to-data-nodes/334136)

<div class="topic-metadata">

**Author:** [@Mirko\_Katunar](https://discuss.elastic.co/u/Mirko_Katunar)\
**Replies:** 1\
**Last updated:** [May 24, 2023, 8:18am UTC](https://discuss.elastic.co/t/warm-tier-shards-being-allocated-to-data-nodes/334136 "2023-05-24T08:18:29Z")

</div>

Hello, I have a hot, warm architecture and 3 master nodes that are also data nodes. At some point Elastic started to allocate data stream shards that are in warm tier to master/data nodes. As plain data node can fill a…

---

## [How to find openssl Version](https://discuss.elastic.co/t/how-to-find-openssl-version/334038)

<div class="topic-metadata">

**Author:** [@kannan\_raj](https://discuss.elastic.co/u/kannan_raj)\
**Replies:** 1\
**Last updated:** [May 24, 2023, 8:08am UTC](https://discuss.elastic.co/t/how-to-find-openssl-version/334038 "2023-05-24T08:08:43Z")

</div>

Hello Team, Does Elasticsearch use openssl when using the SSL / TLS protocol? If so, where can I find the version of openssl? Regards Kannan P

---

## [Pytorch\_inference silenty disappear during reindex using pretrained machine learning model](https://discuss.elastic.co/t/pytorch-inference-silenty-disappear-during-reindex-using-pretrained-machine-learning-model/330896)

<div class="topic-metadata">

**Author:** [@tomotaka](https://discuss.elastic.co/u/tomotaka)\
**Replies:** 4\
**Last updated:** [May 24, 2023, 8:05am UTC](https://discuss.elastic.co/t/pytorch-inference-silenty-disappear-during-reindex-using-pretrained-machine-learning-model/330896 "2023-05-24T08:05:57Z")

</div>

We are planning to build a vector-based search application with pretrained machine learning model which is based on mBERT model. So now I wrote some code to check how Elasticsearch works and I found that pytorch\_inferen…

---

## [How to get list of documents created by reindex API in destination index](https://discuss.elastic.co/t/how-to-get-list-of-documents-created-by-reindex-api-in-destination-index/333540)

<div class="topic-metadata">

**Author:** [@Sumeet\_Koli](https://discuss.elastic.co/u/Sumeet_Koli)\
**Replies:** 2\
**Last updated:** [May 24, 2023, 6:44am UTC](https://discuss.elastic.co/t/how-to-get-list-of-documents-created-by-reindex-api-in-destination-index/333540 "2023-05-24T06:44:27Z")

</div>

I have a query around the reindex API . Is there a way to get a list of all the documents created by the reindex API in the destination index? Context: I am using the reindex API to migrate a few indices from a remote …

---

## [Sending logs from Filebeat(windows) to Logstash(Linux)](https://discuss.elastic.co/t/sending-logs-from-filebeat-windows-to-logstash-linux/334112)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 2\
**Last updated:** [May 24, 2023, 6:18am UTC](https://discuss.elastic.co/t/sending-logs-from-filebeat-windows-to-logstash-linux/334112 "2023-05-24T06:18:57Z")

</div>

Hi, I have installed filebeat on windows machine and configured it to send logs to logstash. Here is my filebeat config filebeat.inputs: # Each - is an input. Most options can be set at the input level, so # you can …

---

## [Should clause within nested query not giving results](https://discuss.elastic.co/t/should-clause-within-nested-query-not-giving-results/334167)

<div class="topic-metadata">

**Author:** [@discuss\_lipak](https://discuss.elastic.co/u/discuss_lipak)\
**Replies:** 0\
**Last updated:** [May 24, 2023, 5:07am UTC](https://discuss.elastic.co/t/should-clause-within-nested-query-not-giving-results/334167 "2023-05-24T05:07:40Z")

</div>

I am trying to retrieve a specific document with nested query on the identityLinks element. My requirement: either identityLinks.userId should match specific userid when identityLinks.type is "assignee" OR identityLin…

---

## [Using value from the returned documents and recalculating the score of the documents](https://discuss.elastic.co/t/using-value-from-the-returned-documents-and-recalculating-the-score-of-the-documents/334154)

<div class="topic-metadata">

**Author:** [@akhil\_reddy](https://discuss.elastic.co/u/akhil_reddy)\
**Replies:** 2\
**Last updated:** [May 24, 2023, 4:10am UTC](https://discuss.elastic.co/t/using-value-from-the-returned-documents-and-recalculating-the-score-of-the-documents/334154 "2023-05-24T04:10:01Z")

</div>

Hi, I have a use case where I need to perform a search request, then use a value from the returned documents in recalculating the score. Below is the example of returned documents for my search request { \_score: 1.7, \_…

---

## [How to resolve failed requests to ES database after rebuilding the site](https://discuss.elastic.co/t/how-to-resolve-failed-requests-to-es-database-after-rebuilding-the-site/333365)

<div class="topic-metadata">

**Author:** [@stan4o](https://discuss.elastic.co/u/stan4o)\
**Replies:** 4\
**Last updated:** [May 24, 2023, 1:54am UTC](https://discuss.elastic.co/t/how-to-resolve-failed-requests-to-es-database-after-rebuilding-the-site/333365 "2023-05-24T01:54:11Z")

</div>

After our website (system) was rebuilt on a new server (Digital Ocean) all the requests to the Elastic search are failing = we cannot access the Elastic search. How to resolve this issue? I am not a programmer. This is w…

---

## [APM server did not respond within 10s of gzip stream finish](https://discuss.elastic.co/t/apm-server-did-not-respond-within-10s-of-gzip-stream-finish/333845)

<div class="topic-metadata">

**Author:** [@khteh](https://discuss.elastic.co/u/khteh)\
**Replies:** 1\
**Last updated:** [May 23, 2023, 11:09pm UTC](https://discuss.elastic.co/t/apm-server-did-not-respond-within-10s-of-gzip-stream-finish/333845 "2023-05-23T23:09:14Z")

</div>

If you are asking about a problem you are experiencing, please use the following template, as it will help us help you. If you have a different problem, please delete all of this text :slight\_smile: TIP 1: select at lea…

---

## [Elasticsearch memory data ratio recommendations for logging use case](https://discuss.elastic.co/t/elasticsearch-memory-data-ratio-recommendations-for-logging-use-case/334076)

<div class="topic-metadata">

**Author:** [@Farah\_Bhr](https://discuss.elastic.co/u/Farah_Bhr)\
**Replies:** 0\
**Last updated:** [May 23, 2023, 6:15am UTC](https://discuss.elastic.co/t/elasticsearch-memory-data-ratio-recommendations-for-logging-use-case/334076 "2023-05-23T06:15:43Z")

</div>

Hello , I am planning to create an Elasticsearch Cluster for logging and metrics purpose I am using time-based indexes I want to calculate the optimal data nodes and shards this cluster requires The logs reach a maxi…

---

## [ElasticSearch NEST - Search Query Not Returning Expected Results](https://discuss.elastic.co/t/elasticsearch-nest-search-query-not-returning-expected-results/334160)

<div class="topic-metadata">

**Author:** [@mmobley](https://discuss.elastic.co/u/mmobley)\
**Replies:** 0\
**Last updated:** [May 23, 2023, 10:12pm UTC](https://discuss.elastic.co/t/elasticsearch-nest-search-query-not-returning-expected-results/334160 "2023-05-23T22:12:41Z")

</div>

I'm working on a project that searches parts using Elasticsearch and NEST (7.x). Here's my Model (adjusted for simplicity): \[ElasticsearchType\] public class PartInfo { public string Make { get; set; } public str…

---

## [Unable to track errors with elastic-apm-node in Nextjs App](https://discuss.elastic.co/t/unable-to-track-errors-with-elastic-apm-node-in-nextjs-app/333257)

<div class="topic-metadata">

**Author:** [@prakashks](https://discuss.elastic.co/u/prakashks)\
**Replies:** 4\
**Last updated:** [May 23, 2023, 10:02pm UTC](https://discuss.elastic.co/t/unable-to-track-errors-with-elastic-apm-node-in-nextjs-app/333257 "2023-05-23T22:02:16Z")

</div>

APM Server version: 8.71 APM Agent language and version: 3 Browser version: Chrome 112 Original install method (e.g. download page, yum, deb, from source, etc.) and version: yarn add elastic-apm-node Fresh instal…

---

## [Write a RegEx to match the event pattern in log file](https://discuss.elastic.co/t/write-a-regex-to-match-the-event-pattern-in-log-file/334048)

<div class="topic-metadata">

**Author:** [@hamzeha](https://discuss.elastic.co/u/hamzeha)\
**Replies:** 1\
**Last updated:** [May 23, 2023, 9:31pm UTC](https://discuss.elastic.co/t/write-a-regex-to-match-the-event-pattern-in-log-file/334048 "2023-05-23T21:31:33Z")

</div>

Hi Everyone, I have application log file which contains the application requests and responses, the complete request and response looks like the below, I tried different patterns using RegEx but unfortunately without an…

---

## [Network Packet Capture integration still updates npcap](https://discuss.elastic.co/t/network-packet-capture-integration-still-updates-npcap/333659)

<div class="topic-metadata">

**Author:** [@jaegerschnitzel](https://discuss.elastic.co/u/jaegerschnitzel)\
**Replies:** 3\
**Last updated:** [May 23, 2023, 8:39pm UTC](https://discuss.elastic.co/t/network-packet-capture-integration-still-updates-npcap/333659 "2023-05-23T20:39:01Z")

</div>

Sorry for opening a third thread about npcap. The first and the second thread were closed in the meantime. We updated our servers to Elastic Agent 8.7.1 and Network Packet Capture integration 1.16.0. After that we roll…

[Previous page](https://discuss.elastic.co/latest.md?page=666)

[Next page](https://discuss.elastic.co/latest.md?page=668)
