# Latest

**URL:** https://discuss.elastic.co/latest.md?page=672

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 673

---

## [Warning: Body deprecated in hybrid search](https://discuss.elastic.co/t/warning-body-deprecated-in-hybrid-search/330613)

<div class="topic-metadata">

**Author:** [@Francisco\_Rocha](https://discuss.elastic.co/u/Francisco_Rocha)\
**Replies:** 1\
**Last updated:** [May 18, 2023, 10:04pm UTC](https://discuss.elastic.co/t/warning-body-deprecated-in-hybrid-search/330613 "2023-05-18T22:04:29Z")

</div>

Hi there, don't know how to remove this warning: DeprecationWarning: The 'body' parameter is deprecated for the 'search' API and will be removed in a future version. Instead use API parameters directly. The following …

---

## [Having an empty hits and response from elasticsearch when trying to query them via an api](https://discuss.elastic.co/t/having-an-empty-hits-and-response-from-elasticsearch-when-trying-to-query-them-via-an-api/333698)

<div class="topic-metadata">

**Author:** [@Bettaieb\_Walid](https://discuss.elastic.co/u/Bettaieb_Walid)\
**Replies:** 3\
**Last updated:** [May 18, 2023, 9:56pm UTC](https://discuss.elastic.co/t/having-an-empty-hits-and-response-from-elasticsearch-when-trying-to-query-them-via-an-api/333698 "2023-05-18T21:56:27Z")

</div>

hello , I am developing backend using strapi , and i am going to store some data inside elasticsearch , and i would like to be able to consume the data, and fetch them. here is the different configuration files routes: …

---

## [Exclude a lost of mac addresses in alert with elasticsearch query](https://discuss.elastic.co/t/exclude-a-lost-of-mac-addresses-in-alert-with-elasticsearch-query/333590)

<div class="topic-metadata">

**Author:** [@odelacruzc93](https://discuss.elastic.co/u/odelacruzc93)\
**Replies:** 1\
**Last updated:** [May 18, 2023, 9:40pm UTC](https://discuss.elastic.co/t/exclude-a-lost-of-mac-addresses-in-alert-with-elasticsearch-query/333590 "2023-05-18T21:40:25Z")

</div>

Hi There! Please I need your help, I am ingesting logs ARP and DHCP to find IPs outside my porganizatión, so I implemented an alarm but I must exclude 1650 MAC addresses, can I create a list with these MAC addresses to a…

---

## [@elastic/apm-rum-angular Integration with Angular 16 Not Working](https://discuss.elastic.co/t/elastic-apm-rum-angular-integration-with-angular-16-not-working/333819)

<div class="topic-metadata">

**Author:** [@Tucker\_Schell](https://discuss.elastic.co/u/Tucker_Schell)\
**Replies:** 0\
**Last updated:** [May 18, 2023, 9:37pm UTC](https://discuss.elastic.co/t/elastic-apm-rum-angular-integration-with-angular-16-not-working/333819 "2023-05-18T21:37:46Z")

</div>

Hi, two weeks ago I integrated the apm-rum-angular package (2.1.7) in an Angular 15 application by following this doc and it worked just fine: Today, I updated Angular to 16 and now I get the following error: 'ApmMod…

---

## [Elasticsearch not able to form a cluster](https://discuss.elastic.co/t/elasticsearch-not-able-to-form-a-cluster/333817)

<div class="topic-metadata">

**Author:** [@neerajg](https://discuss.elastic.co/u/neerajg)\
**Replies:** 0\
**Last updated:** [May 18, 2023, 9:19pm UTC](https://discuss.elastic.co/t/elasticsearch-not-able-to-form-a-cluster/333817 "2023-05-18T21:19:10Z")

</div>

Hi, We have 3 nodes (Linux Ubuntu 20.04) I have modified the /etc/hosts file to add node1 node2 and node3 as DNS with their IPs I have installed elasticsearch but for some reason elasticsearch is not able to form a cl…

---

## [I installed elasticsearch 8.7 but icant acess it through my browser down here is my yml file](https://discuss.elastic.co/t/i-installed-elasticsearch-8-7-but-icant-acess-it-through-my-browser-down-here-is-my-yml-file/333538)

<div class="topic-metadata">

**Author:** [@coolin\_dady](https://discuss.elastic.co/u/coolin_dady)\
**Replies:** 4\
**Last updated:** [May 18, 2023, 9:04pm UTC](https://discuss.elastic.co/t/i-installed-elasticsearch-8-7-but-icant-acess-it-through-my-browser-down-here-is-my-yml-file/333538 "2023-05-18T21:04:55Z")

</div>

\# ======================== Elasticsearch Configuration ========================= # # NOTE: Elasticsearch comes with reasonable defaults for most settings. # Before you set out to tweak and tune the configuration, make…

---

## [Move shard to another node error](https://discuss.elastic.co/t/move-shard-to-another-node-error/333235)

<div class="topic-metadata">

**Author:** [@mpniel](https://discuss.elastic.co/u/mpniel)\
**Replies:** 3\
**Last updated:** [May 18, 2023, 9:02pm UTC](https://discuss.elastic.co/t/move-shard-to-another-node-error/333235 "2023-05-18T21:02:02Z")

</div>

Hello, I need to move shards to another node. I get the following error. The command is first and the error after it: error to check post \_cluster/reroute { "commands": \[ { "move": { "index": "yeshut\_2022.03.31-0…

---

## [Apply ingest pipeline to custom logs](https://discuss.elastic.co/t/apply-ingest-pipeline-to-custom-logs/333539)

<div class="topic-metadata">

**Author:** [@temuccio](https://discuss.elastic.co/u/temuccio)\
**Replies:** 1\
**Last updated:** [May 18, 2023, 8:51pm UTC](https://discuss.elastic.co/t/apply-ingest-pipeline-to-custom-logs/333539 "2023-05-18T20:51:58Z")

</div>

Hi all. I have installed a fresh installation of stack ELK. Into kibana, I have installed a Elastic Agent for get custom logs from a syslog server. It works fine ad I see the log. I have make a Ingest Pipeline and I …

---

## [elasticsearch/client.go:408 Cannot index event publisher.Event](https://discuss.elastic.co/t/elasticsearch-client-go-408-cannot-index-event-publisher-event/333809)

<div class="topic-metadata">

**Author:** [@reddyk001](https://discuss.elastic.co/u/reddyk001)\
**Replies:** 0\
**Last updated:** [May 18, 2023, 8:50pm UTC](https://discuss.elastic.co/t/elasticsearch-client-go-408-cannot-index-event-publisher-event/333809 "2023-05-18T20:50:17Z")

</div>

Hello All, i was trying to send k8s container logs to Elasticsearch through filebeat. we are getting more logs that expected and also it is trigger the below warning continuously from filebeat side and it trying write …

---

## [Elasticsearch "delete by query" not released disk space](https://discuss.elastic.co/t/elasticsearch-delete-by-query-not-released-disk-space/333768)

<div class="topic-metadata">

**Author:** [@sanjeevtomar](https://discuss.elastic.co/u/sanjeevtomar)\
**Replies:** 3\
**Last updated:** [May 18, 2023, 8:35pm UTC](https://discuss.elastic.co/t/elasticsearch-delete-by-query-not-released-disk-space/333768 "2023-05-18T20:35:10Z")

</div>

After running "delete by query ", disk space did not released. What should I do to make disk space release?

---

## [DSL compound Queries](https://discuss.elastic.co/t/dsl-compound-queries/330591)

<div class="topic-metadata">

**Author:** [@waitangi](https://discuss.elastic.co/u/waitangi)\
**Replies:** 4\
**Last updated:** [May 18, 2023, 8:25pm UTC](https://discuss.elastic.co/t/dsl-compound-queries/330591 "2023-05-18T20:25:11Z")

</div>

Hi everyone I have following DSL queries: GET eclaims-logs-2023.04.21/\_search { "query": { "bool": { "must": \[ { "match": { "thread\_name" : "http-nio-5050-exec-7" } …

---

## [KIbana failover to a healthy ES node](https://discuss.elastic.co/t/kibana-failover-to-a-healthy-es-node/333574)

<div class="topic-metadata">

**Author:** [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Replies:** 4\
**Last updated:** [May 18, 2023, 6:35pm UTC](https://discuss.elastic.co/t/kibana-failover-to-a-healthy-es-node/333574 "2023-05-18T18:35:15Z")

</div>

Hi All, We are facing an issue where Kibana does not failover to a healthy Elasticsearch node in case a node goes down. Login into Kibana console stops working unless the bad node is brought up. KIbana config is as fo…

---

## [Elastic Synthetics Journey: Set \`playwrightOptions\` from parameters](https://discuss.elastic.co/t/elastic-synthetics-journey-set-playwrightoptions-from-parameters/330762)

<div class="topic-metadata">

**Author:** [@DougR](https://discuss.elastic.co/u/DougR)\
**Replies:** 9\
**Last updated:** [May 18, 2023, 6:24pm UTC](https://discuss.elastic.co/t/elastic-synthetics-journey-set-playwrightoptions-from-parameters/330762 "2023-05-18T18:24:50Z")

</div>

I am writing an Elastic Journey with @elastic/synthetics=1.0.0-beta.43. I've got everything working as expected, however there is one issue. In my synthetics.config.ts file, I need to pass in the httpCredentials as part…

---

## [Policy settings/event collection - differentiate public vs private network access](https://discuss.elastic.co/t/policy-settings-event-collection-differentiate-public-vs-private-network-access/332661)

<div class="topic-metadata">

**Author:** [@yak990](https://discuss.elastic.co/u/yak990)\
**Replies:** 2\
**Last updated:** [May 18, 2023, 5:46pm UTC](https://discuss.elastic.co/t/policy-settings-event-collection-differentiate-public-vs-private-network-access/332661 "2023-05-18T17:46:45Z")

</div>

It would be great if we could limit network event tracking to just external access attempts instead of everything. Maybe have two checkboxes - internal network and external network, where internal network is defined as …

---

## [Sorting by max value of property of nested object array](https://discuss.elastic.co/t/sorting-by-max-value-of-property-of-nested-object-array/333778)

<div class="topic-metadata">

**Author:** [@ndtreviv](https://discuss.elastic.co/u/ndtreviv)\
**Replies:** 1\
**Last updated:** [May 18, 2023, 5:20pm UTC](https://discuss.elastic.co/t/sorting-by-max-value-of-property-of-nested-object-array/333778 "2023-05-18T17:20:01Z")

</div>

I have the following object model: { ... "classification": \[ { "label": "aaa", "probability": 0.9923 }, { "label": "bbb", "probability": 0.3452 }, { "label": "ccc", "probability": 0.0012 …

---

## [Elastic Defend Policy response failure](https://discuss.elastic.co/t/elastic-defend-policy-response-failure/332933)

<div class="topic-metadata">

**Author:** [@xqaiviwjxzw](https://discuss.elastic.co/u/xqaiviwjxzw)\
**Replies:** 3\
**Last updated:** [May 18, 2023, 5:00pm UTC](https://discuss.elastic.co/t/elastic-defend-policy-response-failure/332933 "2023-05-18T17:00:39Z")

</div>

Hello，The following error is displayed in fleet, what is the reason? How to solve it? Policy response failure The Endpoint did not apply the Policy correctly. Expand the Policy response above for more details.

---

## [Intermittently slow queries after migrating from self-hosted ES6 to ECK 8.7.1 on GCP](https://discuss.elastic.co/t/intermittently-slow-queries-after-migrating-from-self-hosted-es6-to-eck-8-7-1-on-gcp/333787)

<div class="topic-metadata">

**Author:** [@wazim](https://discuss.elastic.co/u/wazim)\
**Replies:** 0\
**Last updated:** [May 18, 2023, 4:17pm UTC](https://discuss.elastic.co/t/intermittently-slow-queries-after-migrating-from-self-hosted-es6-to-eck-8-7-1-on-gcp/333787 "2023-05-18T16:17:24Z")

</div>

Hey all, We were running Elasticsearch 6 for a few years and the performance was good but we decided to upgraded to Elasticsearch 8 and leveraging the Elasticsearch operator and ECK stack. The node machine is the same a…

---

## [Cannot remove or resolve metric alerts](https://discuss.elastic.co/t/cannot-remove-or-resolve-metric-alerts/333783)

<div class="topic-metadata">

**Author:** [@cfqnjohn](https://discuss.elastic.co/u/cfqnjohn)\
**Replies:** 0\
**Last updated:** [May 18, 2023, 3:44pm UTC](https://discuss.elastic.co/t/cannot-remove-or-resolve-metric-alerts/333783 "2023-05-18T15:44:22Z")

</div>

Hello, I have some alerts that were created for Disk Usage alerting. It seems that they triggered awhile back on April 19th, and have not updated since. The alert threshold was modified to 80% originally it was set to 7…

---

## [Change the index allocation requirement](https://discuss.elastic.co/t/change-the-index-allocation-requirement/333781)

<div class="topic-metadata">

**Author:** [@mpniel](https://discuss.elastic.co/u/mpniel)\
**Replies:** 0\
**Last updated:** [May 18, 2023, 3:39pm UTC](https://discuss.elastic.co/t/change-the-index-allocation-requirement/333781 "2023-05-18T15:39:59Z")

</div>

How to change the index and remove the allocation requirement "cold" ?

---

## [I am sending 30 GB data from databricks to elasticsearch through the elasticsearch apache hadoop connector, It is taking around 2 hours for sending it. How to make it fast? How much time it should take ideally?](https://discuss.elastic.co/t/i-am-sending-30-gb-data-from-databricks-to-elasticsearch-through-the-elasticsearch-apache-hadoop-connector-it-is-taking-around-2-hours-for-sending-it-how-to-make-it-fast-how-much-time-it-should-take-ideally/333715)

<div class="topic-metadata">

**Author:** [@Sagnik\_Mandal](https://discuss.elastic.co/u/Sagnik_Mandal)\
**Replies:** 6\
**Last updated:** [May 18, 2023, 2:40pm UTC](https://discuss.elastic.co/t/i-am-sending-30-gb-data-from-databricks-to-elasticsearch-through-the-elasticsearch-apache-hadoop-connector-it-is-taking-around-2-hours-for-sending-it-how-to-make-it-fast-how-much-time-it-should-take-ideally/333715 "2023-05-18T14:40:17Z")

</div>

My elasticsearch connector configs are: .option("es.write.operation.parallelism", "4") .option("es.batch.size.bytes", "10mb") .option("es.batch.size.entries", "1000") .option("es.batch.write.retry.coun…

---

## [Referencing canvas variables with outputs of other variables](https://discuss.elastic.co/t/referencing-canvas-variables-with-outputs-of-other-variables/333775)

<div class="topic-metadata">

**Author:** [@dreynolds](https://discuss.elastic.co/u/dreynolds)\
**Replies:** 0\
**Last updated:** [May 18, 2023, 1:51pm UTC](https://discuss.elastic.co/t/referencing-canvas-variables-with-outputs-of-other-variables/333775 "2023-05-18T13:51:24Z")

</div>

I have multiple variables defined that have the number of hosts a department should have: hr\_hosts: 35, it\_hosts:45, acct\_hosts:5 I'm running a query to pull host scans, which includes the department names as a column …

---

## [Reindex 1 index to multiple indexes](https://discuss.elastic.co/t/reindex-1-index-to-multiple-indexes/333667)

<div class="topic-metadata">

**Author:** [@elasticvakif](https://discuss.elastic.co/u/elasticvakif)\
**Replies:** 7\
**Last updated:** [May 18, 2023, 12:07pm UTC](https://discuss.elastic.co/t/reindex-1-index-to-multiple-indexes/333667 "2023-05-18T12:07:20Z")

</div>

We have an index which is around 120 gb. we want to split it multiple indices. Is there any way to do that ? I guess reindex supports 1 to 1. I need 1 to many. It doesn't matter which document is in which index. We can u…

---

## [Hiding non-indexed/ non-searchable fields in "Available fields" section in Kibana discover](https://discuss.elastic.co/t/hiding-non-indexed-non-searchable-fields-in-available-fields-section-in-kibana-discover/333723)

<div class="topic-metadata">

**Author:** [@Saindra\_K](https://discuss.elastic.co/u/Saindra_K)\
**Replies:** 1\
**Last updated:** [May 18, 2023, 10:50am UTC](https://discuss.elastic.co/t/hiding-non-indexed-non-searchable-fields-in-available-fields-section-in-kibana-discover/333723 "2023-05-18T10:50:45Z")

</div>

In Kibana discover is there a way to automatically hide the non indexed fields/ non searchable fields in "Available fields" ? I see in available fields setting, by filtering Searchable to Yes we can hide, but this is no…

---

## [Cross Cluster Replication - Dev Environment](https://discuss.elastic.co/t/cross-cluster-replication-dev-environment/333758)

<div class="topic-metadata">

**Author:** [@to185030](https://discuss.elastic.co/u/to185030)\
**Replies:** 0\
**Last updated:** [May 18, 2023, 10:47am UTC](https://discuss.elastic.co/t/cross-cluster-replication-dev-environment/333758 "2023-05-18T10:47:43Z")

</div>

Can someone tell me if it is possible to setup CCR on Elasticsearch for my application in a Dev environment - for a very limited window of time, without having to bear the expenses for the licenses of all the Platinum li…

---

## [Frozen tier - Conenience in multiple zones](https://discuss.elastic.co/t/frozen-tier-conenience-in-multiple-zones/333475)

<div class="topic-metadata">

**Author:** [@Alberallo](https://discuss.elastic.co/u/Alberallo)\
**Replies:** 8\
**Last updated:** [May 18, 2023, 9:48am UTC](https://discuss.elastic.co/t/frozen-tier-conenience-in-multiple-zones/333475 "2023-05-18T09:48:42Z")

</div>

HI, since high availability is guaranteed by default for frozen nodes, why should there be any convenience in configuring a cluster with more than one zone for the frozen tier? In particular, during the execution of th…

---

## [Failed to parse date field with format strict\_date\_optional\_time||epoch\_millis](https://discuss.elastic.co/t/failed-to-parse-date-field-with-format-strict-date-optional-time-epoch-millis/333734)

<div class="topic-metadata">

**Author:** [@Sachinda](https://discuss.elastic.co/u/Sachinda)\
**Replies:** 1\
**Last updated:** [May 18, 2023, 9:08am UTC](https://discuss.elastic.co/t/failed-to-parse-date-field-with-format-strict-date-optional-time-epoch-millis/333734 "2023-05-18T09:08:02Z")

</div>

Hi All, We are observing the following error in the Logstash serves only for the 2023.05.09 logs. This issue is not occurring in other date indexes. so we can see the 2023.05.08 and 2023.05.10 logs are available on the …

---

## [Refresh API taking too long](https://discuss.elastic.co/t/refresh-api-taking-too-long/333562)

<div class="topic-metadata">

**Author:** [@blacar](https://discuss.elastic.co/u/blacar)\
**Replies:** 4\
**Last updated:** [May 18, 2023, 8:56am UTC](https://discuss.elastic.co/t/refresh-api-taking-too-long/333562 "2023-05-18T08:56:24Z")

</div>

Hi folks, I am having some 409 - versioning conflict problems when using deleteByQuery so I decided to run a POST /\_refresh when I receive a 409 and just before trying again. The rate of operations recovery using this …

---

## [Bulk insert in elasticsearch datastream using elasticsearch-java 8.6.2](https://discuss.elastic.co/t/bulk-insert-in-elasticsearch-datastream-using-elasticsearch-java-8-6-2/333744)

<div class="topic-metadata">

**Author:** [@ayanarora0101](https://discuss.elastic.co/u/ayanarora0101)\
**Replies:** 0\
**Last updated:** [May 18, 2023, 8:54am UTC](https://discuss.elastic.co/t/bulk-insert-in-elasticsearch-datastream-using-elasticsearch-java-8-6-2/333744 "2023-05-18T08:54:55Z")

</div>

I'm trying to bulk insert documents in datastream in elasticsearch using java with (ElasticsearchClient) (elasticsearch-java) 8.6.2. I checked documentation of elasticsearch-java and found information around bulk indexi…

---

## [Java - not able to load FFI provider: How to start the logstash without the error?](https://discuss.elastic.co/t/java-not-able-to-load-ffi-provider-how-to-start-the-logstash-without-the-error/332788)

<div class="topic-metadata">

**Author:** [@karthic](https://discuss.elastic.co/u/karthic)\
**Replies:** 3\
**Last updated:** [May 18, 2023, 7:33am UTC](https://discuss.elastic.co/t/java-not-able-to-load-ffi-provider-how-to-start-the-logstash-without-the-error/332788 "2023-05-18T07:33:35Z")

</div>

Tried to load logstash in a Centos environment \[INFO \]\[logstash.runner \] JVM bootstrap flags: \[-Xms1g, -Xmx1g, -Djava.awt.headless=true, -Dfile.encoding=UTF-8, -Djruby.compile.invokedynamic=true, -XX:+HeapDumpOnOutOfMem…

---

## [Is there a limit for number of routing values](https://discuss.elastic.co/t/is-there-a-limit-for-number-of-routing-values/333719)

<div class="topic-metadata">

**Author:** [@alper](https://discuss.elastic.co/u/alper)\
**Replies:** 1\
**Last updated:** [May 18, 2023, 7:01am UTC](https://discuss.elastic.co/t/is-there-a-limit-for-number-of-routing-values/333719 "2023-05-18T07:01:14Z")

</div>

Hi, The index contains one routing field and has 50 shards. I use the routing field in search requests. I do, however, wonder if there would be a performance problem if I sent 1000 routing values in a single query. Sho…

[Previous page](https://discuss.elastic.co/latest.md?page=671)

[Next page](https://discuss.elastic.co/latest.md?page=673)
