# Latest

**URL:** https://discuss.elastic.co/latest.md?page=671

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 672

---

## ["Elasticsearch connection failure" on newly installed Elastic Security server](https://discuss.elastic.co/t/elasticsearch-connection-failure-on-newly-installed-elastic-security-server/333707)

<div class="topic-metadata">

**Author:** [@Timothy\_Dilbert](https://discuss.elastic.co/u/Timothy_Dilbert)\
**Replies:** 1\
**Last updated:** [May 19, 2023, 10:50pm UTC](https://discuss.elastic.co/t/elasticsearch-connection-failure-on-newly-installed-elastic-security-server/333707 "2023-05-19T22:50:55Z")

</div>

I recently installed Elastic Security following the belowlinked YouTube video: Under Management \> Fleet it is showing "Fleet Server is not Healthy. A healthy Fleet server is required before you can enroll …

---

## [Need to update Elastic documents by a key](https://discuss.elastic.co/t/need-to-update-elastic-documents-by-a-key/333881)

<div class="topic-metadata">

**Author:** [@ace540i](https://discuss.elastic.co/u/ace540i)\
**Replies:** 1\
**Last updated:** [May 19, 2023, 9:02pm UTC](https://discuss.elastic.co/t/need-to-update-elastic-documents-by-a-key/333881 "2023-05-19T21:02:56Z")

</div>

How do you update a single field in elastic documents using a query or condition?

---

## [Error wen put pipeline line on conf file (version 8.7)](https://discuss.elastic.co/t/error-wen-put-pipeline-line-on-conf-file-version-8-7/333887)

<div class="topic-metadata">

**Author:** [@jefin\_dark](https://discuss.elastic.co/u/jefin_dark)\
**Replies:** 5\
**Last updated:** [May 19, 2023, 8:49pm UTC](https://discuss.elastic.co/t/error-wen-put-pipeline-line-on-conf-file-version-8-7/333887 "2023-05-19T20:49:55Z")

</div>

Hello, i cant start service, because the logstash bring me this error when i put this lines in conf file. The given configuration is invalid. Reason: Expected one of \[ \\t\\r\\n\], "#", "input", "filter", "output" at line 1…

---

## [Role Template with reference to metadata property from Open ID Realm](https://discuss.elastic.co/t/role-template-with-reference-to-metadata-property-from-open-id-realm/333869)

<div class="topic-metadata">

**Author:** [@Artem\_Ruzak](https://discuss.elastic.co/u/Artem_Ruzak)\
**Replies:** 1\
**Last updated:** [May 19, 2023, 7:59pm UTC](https://discuss.elastic.co/t/role-template-with-reference-to-metadata-property-from-open-id-realm/333869 "2023-05-19T19:59:13Z")

</div>

Hello, we are having SSO solution implemented based with Keycloak and based on OpenID concept It is working well and we are able to assign roles by username or with reference to realm.name As a next step I want to imp…

---

## [Searching by ngrams](https://discuss.elastic.co/t/searching-by-ngrams/333872)

<div class="topic-metadata">

**Author:** [@orlenkoda5](https://discuss.elastic.co/u/orlenkoda5)\
**Replies:** 9\
**Last updated:** [May 19, 2023, 4:57pm UTC](https://discuss.elastic.co/t/searching-by-ngrams/333872 "2023-05-19T16:57:33Z")

</div>

I use search with query string in index analyzed with ngrams. When I try to search doc with field\_1 = SU0001023277 it's ok. But when I try to use less letters, like SU0001023 the resultset is 0. Why it comes out like th…

---

## [Nested type is removed from the new index while reindexing](https://discuss.elastic.co/t/nested-type-is-removed-from-the-new-index-while-reindexing/333876)

<div class="topic-metadata">

**Author:** [@Maitri](https://discuss.elastic.co/u/Maitri)\
**Replies:** 4\
**Last updated:** [May 19, 2023, 4:14pm UTC](https://discuss.elastic.co/t/nested-type-is-removed-from-the-new-index-while-reindexing/333876 "2023-05-19T16:14:15Z")

</div>

I have an index which a property with nested type. I am reindexing the index into new index. But, in the destination index every mapping are same except the property which was having nested type in the source index. nest…

---

## [When I am trying to open Dev\_tools in Kibana, Why I am getting Black page](https://discuss.elastic.co/t/when-i-am-trying-to-open-dev-tools-in-kibana-why-i-am-getting-black-page/333839)

<div class="topic-metadata">

**Author:** [@Anand\_Konagala](https://discuss.elastic.co/u/Anand_Konagala)\
**Replies:** 6\
**Last updated:** [May 19, 2023, 3:48pm UTC](https://discuss.elastic.co/t/when-i-am-trying-to-open-dev-tools-in-kibana-why-i-am-getting-black-page/333839 "2023-05-19T15:48:41Z")

</div>

This is how it will shows when I am opening elasticsearch devTools

---

## [Reindex error : "type":"mapper\_parsing\_exception","reason":"failed to parse field \[date\] of type \[date\]](https://discuss.elastic.co/t/reindex-error-type-mapper-parsing-exception-reason-failed-to-parse-field-date-of-type-date/333798)

<div class="topic-metadata">

**Author:** [@GenSSC](https://discuss.elastic.co/u/GenSSC)\
**Replies:** 5\
**Last updated:** [May 19, 2023, 3:25pm UTC](https://discuss.elastic.co/t/reindex-error-type-mapper-parsing-exception-reason-failed-to-parse-field-date-of-type-date/333798 "2023-05-19T15:25:12Z")

</div>

Hello, While using the reindexing API, I am running into 4 indices that are giving me errors. It seems like the date in the document matches the template but I guess it is not. I don't really know how to tackle this. …

---

## [Logstash ConfigurationError - Failed to execute action](https://discuss.elastic.co/t/logstash-configurationerror-failed-to-execute-action/333874)

<div class="topic-metadata">

**Author:** [@Yasser\_Alsawy](https://discuss.elastic.co/u/Yasser_Alsawy)\
**Replies:** 1\
**Last updated:** [May 19, 2023, 2:25pm UTC](https://discuss.elastic.co/t/logstash-configurationerror-failed-to-execute-action/333874 "2023-05-19T14:25:51Z")

</div>

I'm getting a configuration error when try to start logstash: at line 13, column 28 (byte 213) after filter {\\n grok {\\n match =\> { \\"message\\" =\> \\"%{COMBINEDAPACHELOG}\\" }\\n }\\n date {\\n match =\> \[ \\"times…

---

## [Disable Kibana Session Timeout](https://discuss.elastic.co/t/disable-kibana-session-timeout/332966)

<div class="topic-metadata">

**Author:** [@pocketcolin](https://discuss.elastic.co/u/pocketcolin)\
**Replies:** 3\
**Last updated:** [May 19, 2023, 1:49pm UTC](https://discuss.elastic.co/t/disable-kibana-session-timeout/332966 "2023-05-19T13:49:24Z")

</div>

I have a dashboard displayed on a TV in my office that shows auto-refreshed stats through a Kibana dashboard. I am trying to disable the Kibana Session Timeout so that it never logs out, but the Kibana documentation does…

---

## [Kibana Import JSON : File structure cannot be determined](https://discuss.elastic.co/t/kibana-import-json-file-structure-cannot-be-determined/333275)

<div class="topic-metadata">

**Author:** [@Julien069](https://discuss.elastic.co/u/Julien069)\
**Replies:** 2\
**Last updated:** [May 19, 2023, 1:42pm UTC](https://discuss.elastic.co/t/kibana-import-json-file-structure-cannot-be-determined/333275 "2023-05-19T13:42:20Z")

</div>

Hi , I want to import this index-pattern : Kibana index-pattern When I import it , I have this error : I tried to override Timestamp with this option but it doesn't work : I tried to make timestamp\_format to n…

---

## [Kibana 8.7.1 plugin fails to launch](https://discuss.elastic.co/t/kibana-8-7-1-plugin-fails-to-launch/333506)

<div class="topic-metadata">

**Author:** [@kbujold\_wr](https://discuss.elastic.co/u/kbujold_wr)\
**Replies:** 1\
**Last updated:** [May 19, 2023, 1:15pm UTC](https://discuss.elastic.co/t/kibana-8-7-1-plugin-fails-to-launch/333506 "2023-05-19T13:15:12Z")

</div>

Hi, Our plugin which was working in ELK 8.6.2 is failing in 8.7.1 with this failure "\[FATAL\]\[root\] Error: Cannot find module '../../../../../../packages/kbn-config-schema'" This should still be supported? 'yarn kbn boo…

---

## [Knn vectors](https://discuss.elastic.co/t/knn-vectors/333199)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 2\
**Last updated:** [May 19, 2023, 12:41pm UTC](https://discuss.elastic.co/t/knn-vectors/333199 "2023-05-19T12:41:37Z")

</div>

Let us say I am building an ecommerce app and there are 2 users: user A : always searches for electronics (laptop, headphones, etc) user B: searches for snacks, beverages Is it possible to show a page with banner that…

---

## [Logstash w/ s3 output plugin - slow/delay](https://discuss.elastic.co/t/logstash-w-s3-output-plugin-slow-delay/333836)

<div class="topic-metadata">

**Author:** [@alexus](https://discuss.elastic.co/u/alexus)\
**Replies:** 2\
**Last updated:** [May 19, 2023, 12:32pm UTC](https://discuss.elastic.co/t/logstash-w-s3-output-plugin-slow-delay/333836 "2023-05-19T12:32:12Z")

</div>

Hello, I'm using Logstash 7.17.10 with S3 output plugin, and getting poor performance (possibly not related to performance) my pipeline: input { elasticsearch { docinfo =\> true docinfo\_fields =\> \[ …

---

## [Elasticsearch 8.7 2-node cluster](https://discuss.elastic.co/t/elasticsearch-8-7-2-node-cluster/333772)

<div class="topic-metadata">

**Author:** [@zen.xen](https://discuss.elastic.co/u/zen.xen)\
**Replies:** 6\
**Last updated:** [May 19, 2023, 11:22am UTC](https://discuss.elastic.co/t/elasticsearch-8-7-2-node-cluster/333772 "2023-05-19T11:22:54Z")

</div>

Hello, I want to create 2-node cluster and it doesn't work node-01: path.data: /bitnami/elasticsearch/data cluster.name: zephyr node.name: node-01 node.roles: \[ master, data \] http.port: 9200 transport.port: 9300 boot…

---

## [Elasticsearch monitoring using telegraf](https://discuss.elastic.co/t/elasticsearch-monitoring-using-telegraf/333862)

<div class="topic-metadata">

**Author:** [@mhr](https://discuss.elastic.co/u/mhr)\
**Replies:** 0\
**Last updated:** [May 19, 2023, 10:58am UTC](https://discuss.elastic.co/t/elasticsearch-monitoring-using-telegraf/333862 "2023-05-19T10:58:07Z")

</div>

I am using telegraf to monitor elasticsearch. i am using below doc. i am not able to get the data elasticsearch\_network ' tcp\_in\_errs value=0 tcp\_passive\_opens value=16 tcp\_curr\_estab value=29 tcp\_in\_segs value=11…

---

## [Can I integrate APM services overview page to custom application?](https://discuss.elastic.co/t/can-i-integrate-apm-services-overview-page-to-custom-application/333829)

<div class="topic-metadata">

**Author:** [@whcmrshi](https://discuss.elastic.co/u/whcmrshi)\
**Replies:** 2\
**Last updated:** [May 19, 2023, 10:49am UTC](https://discuss.elastic.co/t/can-i-integrate-apm-services-overview-page-to-custom-application/333829 "2023-05-19T10:49:15Z")

</div>

Hi, I am developing a CMDB platform and would like to integrate the APM service overview page into it. Is there any way we can embed this part of the page (the red square in the image above) into a custom application,…

---

## [Unassigned shards, with status "Elasticsearch can allocate the shard" for all of them](https://discuss.elastic.co/t/unassigned-shards-with-status-elasticsearch-can-allocate-the-shard-for-all-of-them/333806)

<div class="topic-metadata">

**Author:** [@Petr.Simik](https://discuss.elastic.co/u/Petr.Simik)\
**Replies:** 6\
**Last updated:** [May 19, 2023, 9:49am UTC](https://discuss.elastic.co/t/unassigned-shards-with-status-elasticsearch-can-allocate-the-shard-for-all-of-them/333806 "2023-05-19T09:49:27Z")

</div>

Can you help me to explain why I have for several days 25 unassigned replica shards wich can\_allocate status = yes and allocation\_explanation = Elasticsearch can allocate the shard. I supposed rebalancing job will alloc…

---

## [Elastic pipeline processors grok for question!](https://discuss.elastic.co/t/elastic-pipeline-processors-grok-for-question/333852)

<div class="topic-metadata">

**Author:** [@Teresajw](https://discuss.elastic.co/u/Teresajw)\
**Replies:** 0\
**Last updated:** [May 19, 2023, 9:13am UTC](https://discuss.elastic.co/t/elastic-pipeline-processors-grok-for-question/333852 "2023-05-19T09:13:51Z")

</div>

When I parsed the nginx log using Filebeat pipeline, a user\_agent field in the log failed to be parsed. The following error is displayed. {"type":"mapper\_parsing\_exception","reason":"object mapping for \[user\_agent\] trie…

---

## [Which process comes first in Filebeat v.8？](https://discuss.elastic.co/t/which-process-comes-first-in-filebeat-v-8/333822)

<div class="topic-metadata">

**Author:** [@m-amano](https://discuss.elastic.co/u/m-amano)\
**Replies:** 1\
**Last updated:** [May 19, 2023, 9:13am UTC](https://discuss.elastic.co/t/which-process-comes-first-in-filebeat-v-8/333822 "2023-05-19T09:13:30Z")

</div>

Hello. I'm using Filebeat v.8.6.2 to send data to Logstash with filestream input type and I'm curious about which process comes first. Harvest input file data(end of file reached) Connecting Filebeat to Logstash

---

## [Logstash is not working properly. \_grokparsefailure](https://discuss.elastic.co/t/logstash-is-not-working-properly-grokparsefailure/333851)

<div class="topic-metadata">

**Author:** [@San9](https://discuss.elastic.co/u/San9)\
**Replies:** 0\
**Last updated:** [May 19, 2023, 9:07am UTC](https://discuss.elastic.co/t/logstash-is-not-working-properly-grokparsefailure/333851 "2023-05-19T09:07:16Z")

</div>

strange behavior of the logstash, everything is parsed in the debugger, but not in the config - gives an error - \_grokparsefailure my logs 10.10.10.10.1680263940261.385400.G\_B2C\_BETA,03/31/2023 15:02:05.465,sf\_sap\_put\_…

---

## [Ilm question/troubleshooting](https://discuss.elastic.co/t/ilm-question-troubleshooting/333676)

<div class="topic-metadata">

**Author:** [@Mark\_S](https://discuss.elastic.co/u/Mark_S)\
**Replies:** 2\
**Last updated:** [May 19, 2023, 8:25am UTC](https://discuss.elastic.co/t/ilm-question-troubleshooting/333676 "2023-05-19T08:25:20Z")

</div>

My ilm policy does not work, although I have created a similar one a couple of weeks before in another cluster and it is working just fine.. Here is what I did: I pointed Logstash towards ind\_alias Created index templ…

---

## [Logstash JDBC input plugin: Java::OrgPostgresqlUtil::PSQLException: An I/O error occurred while sending to the backend](https://discuss.elastic.co/t/logstash-jdbc-input-plugin-java-an-i-o-error-occurred-while-sending-to-the-backend/333848)

<div class="topic-metadata">

**Author:** [@Captain](https://discuss.elastic.co/u/Captain)\
**Replies:** 0\
**Last updated:** [May 19, 2023, 7:46am UTC](https://discuss.elastic.co/t/logstash-jdbc-input-plugin-java-an-i-o-error-occurred-while-sending-to-the-backend/333848 "2023-05-19T07:46:32Z")

</div>

I encountered this problem some time ago and have not been able to find a good solution. Finally, after I modified the configuration in the jvm.options file, the problem did not occur again. The original configuration "-…

---

## [Is it possible to implement rest encryption in elasticsearch level](https://discuss.elastic.co/t/is-it-possible-to-implement-rest-encryption-in-elasticsearch-level/333733)

<div class="topic-metadata">

**Author:** [@swchandu](https://discuss.elastic.co/u/swchandu)\
**Replies:** 3\
**Last updated:** [May 19, 2023, 7:45am UTC](https://discuss.elastic.co/t/is-it-possible-to-implement-rest-encryption-in-elasticsearch-level/333733 "2023-05-19T07:45:37Z")

</div>

Hi, Is it possible to implement rest encryption in Elasticsearch level. I am raising this question because, I could not find related info in documentation. But subscription shows that it is rest encryption feature is a…

---

## [Disk space is 100% after running a "delete by query" in devtool in kibana](https://discuss.elastic.co/t/disk-space-is-100-after-running-a-delete-by-query-in-devtool-in-kibana/333647)

<div class="topic-metadata">

**Author:** [@sanjeevtomar](https://discuss.elastic.co/u/sanjeevtomar)\
**Replies:** 5\
**Last updated:** [May 19, 2023, 5:24am UTC](https://discuss.elastic.co/t/disk-space-is-100-after-running-a-delete-by-query-in-devtool-in-kibana/333647 "2023-05-19T05:24:34Z")

</div>

After running the query below, server space is getting full in all data nodes ( ELK cluster: 3 masters, 3 data, 1 kibana node). POST /apic\_sandbox/\_delete\_by\_query?wait\_for\_completion=false //change index here accordi…

---

## [How to add Sudachi NLP into Elastic Cloud?](https://discuss.elastic.co/t/how-to-add-sudachi-nlp-into-elastic-cloud/333838)

<div class="topic-metadata">

**Author:** [@m-amano](https://discuss.elastic.co/u/m-amano)\
**Replies:** 0\
**Last updated:** [May 19, 2023, 4:23am UTC](https://discuss.elastic.co/t/how-to-add-sudachi-nlp-into-elastic-cloud/333838 "2023-05-19T04:23:53Z")

</div>

Hello. I want to use Japanese NLP Sudachi instead of the default library Kuromoji in Workplace Search in the deployment of Elastic Cloud. Is it possible to add Sudachi in the Elastic Cloud and install it to the specifi…

---

## [While accessing Kibana facing data view pulgin issue](https://discuss.elastic.co/t/while-accessing-kibana-facing-data-view-pulgin-issue/333834)

<div class="topic-metadata">

**Author:** [@MahithaSarala](https://discuss.elastic.co/u/MahithaSarala)\
**Replies:** 0\
**Last updated:** [May 19, 2023, 3:42am UTC](https://discuss.elastic.co/t/while-accessing-kibana-facing-data-view-pulgin-issue/333834 "2023-05-19T03:42:00Z")

</div>

Hi Team, Deployed both V7.17 (kibana and elasticsearch ) through helm, While accessing kibana facing data view plugin issue some time, after refreshing its working \< 46635/bundles/plugin/dataViews/kibana/dataViews.…

---

## [Expected behavior of tcp/input/ssl\_verify=true?](https://discuss.elastic.co/t/expected-behavior-of-tcp-input-ssl-verify-true/333835)

<div class="topic-metadata">

**Author:** [@bennbrian65](https://discuss.elastic.co/u/bennbrian65)\
**Replies:** 0\
**Last updated:** [May 19, 2023, 3:48am UTC](https://discuss.elastic.co/t/expected-behavior-of-tcp-input-ssl-verify-true/333835 "2023-05-19T03:48:38Z")

</div>

logstash 8.7.1, tcp input w/ssl\_verify=true. I expect that a sender using a cert w/no SANS and the sender’s host name does not match the cert’s CN would be rejected, but it is accepted. What does ssl\_verify=true govern?

---

## [Unable to authenticate with provided credentials and anonymous access is not allowed for this request](https://discuss.elastic.co/t/unable-to-authenticate-with-provided-credentials-and-anonymous-access-is-not-allowed-for-this-request/333518)

<div class="topic-metadata">

**Author:** [@vanhaiit90](https://discuss.elastic.co/u/vanhaiit90)\
**Replies:** 3\
**Last updated:** [May 19, 2023, 1:26am UTC](https://discuss.elastic.co/t/unable-to-authenticate-with-provided-credentials-and-anonymous-access-is-not-allowed-for-this-request/333518 "2023-05-19T01:26:48Z")

</div>

I getting case errror when I configure Fleetserver with run file script ./elastic-agents install. . And now show detail log error "message":"Fleet Server - Error - info fail \[401 Unauthorized\] {"error":{"root\_cause":\[{…

---

## [GCP LOGGING TO ELASTIC | security](https://discuss.elastic.co/t/gcp-logging-to-elastic-security/332596)

<div class="topic-metadata">

**Author:** [@Harper\_S1](https://discuss.elastic.co/u/Harper_S1)\
**Replies:** 11\
**Last updated:** [May 19, 2023, 12:30am UTC](https://discuss.elastic.co/t/gcp-logging-to-elastic-security/332596 "2023-05-19T00:30:00Z")

</div>

Hi, We have elasticsearch running on VMs and we are trying to share the logs from GCP to local elastic cluster. Thing is, GCP uses service account and key. Is there a way where we can add GCP service account credential…

[Previous page](https://discuss.elastic.co/latest.md?page=670)

[Next page](https://discuss.elastic.co/latest.md?page=672)
