# Latest

**URL:** https://discuss.elastic.co/latest.md?page=677

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 678

---

## [Elastic Agent silent install](https://discuss.elastic.co/t/elastic-agent-silent-install/329543)

<div class="topic-metadata">

**Author:** [@poky](https://discuss.elastic.co/u/poky)\
**Replies:** 2\
**Last updated:** [May 15, 2023, 7:47pm UTC](https://discuss.elastic.co/t/elastic-agent-silent-install/329543 "2023-05-15T19:47:49Z")

</div>

Hi Folks, I want to distribute the Elastic Agent through Windows SCCM onto 100 Windows Server. Therefore, I would like to do a silent install of the elastic Agent on Windows. Is there a way to give all the required pa…

---

## [Please help](https://discuss.elastic.co/t/please-help/333433)

<div class="topic-metadata">

**Author:** [@Bojan\_Dokic](https://discuss.elastic.co/u/Bojan_Dokic)\
**Replies:** 1\
**Last updated:** [May 15, 2023, 5:20pm UTC](https://discuss.elastic.co/t/please-help/333433 "2023-05-15T17:20:18Z")

</div>

I am experiencing following error when trying to install elastic agent on linux macine: Error: fail to enroll: fail to execute request to fleet-server: lookup fleet: Temporary failure in name resolution Error: enroll c…

---

## [Parsing error in date format](https://discuss.elastic.co/t/parsing-error-in-date-format/333466)

<div class="topic-metadata">

**Author:** [@Sachchan](https://discuss.elastic.co/u/Sachchan)\
**Replies:** 2\
**Last updated:** [May 15, 2023, 4:47pm UTC](https://discuss.elastic.co/t/parsing-error-in-date-format/333466 "2023-05-15T16:47:28Z")

</div>

Hi Team getting below error in parsing the date in logstash. Kindly suggest how this can be resolved. "error"=\>{"type"=\>"mapper\_parsing\_exception", "reason"=\>"failed to parse field \[ResponseTime\] of type \[date\] in docu…

---

## [10 days log deletion policy using kibana tool](https://discuss.elastic.co/t/10-days-log-deletion-policy-using-kibana-tool/332462)

<div class="topic-metadata">

**Author:** [@kumar918](https://discuss.elastic.co/u/kumar918)\
**Replies:** 5\
**Last updated:** [May 15, 2023, 4:31pm UTC](https://discuss.elastic.co/t/10-days-log-deletion-policy-using-kibana-tool/332462 "2023-05-15T16:31:07Z")

</div>

Hi All, Could you please provide the step by step to configure the 90 days log retention automatically. tried the following steps, but it seems the logs are not deleting Stack management -\> created a new life cycle…

---

## [Missing logs in k8s](https://discuss.elastic.co/t/missing-logs-in-k8s/333487)

<div class="topic-metadata">

**Author:** [@spi\_nik](https://discuss.elastic.co/u/spi_nik)\
**Replies:** 0\
**Last updated:** [May 15, 2023, 4:15pm UTC](https://discuss.elastic.co/t/missing-logs-in-k8s/333487 "2023-05-15T16:15:57Z")

</div>

Hello. I've issue with harvest logs from my cluster k8s with filebeat. In my config file I use next path: symlinks: true path: - /var/log/containers/\*-${data.kubernetes.container.id}.log But some my apps write a lot…

---

## [Retrieving top N hits from nested documents across all matching documents](https://discuss.elastic.co/t/retrieving-top-n-hits-from-nested-documents-across-all-matching-documents/333485)

<div class="topic-metadata">

**Author:** [@Raja\_Sekhara\_Reddy\_K](https://discuss.elastic.co/u/Raja_Sekhara_Reddy_K)\
**Replies:** 0\
**Last updated:** [May 15, 2023, 4:06pm UTC](https://discuss.elastic.co/t/retrieving-top-n-hits-from-nested-documents-across-all-matching-documents/333485 "2023-05-15T16:06:32Z")

</div>

Hello, I'm currently working with an Elasticsearch index where each document contains a nested field embedingContent representing "chunks" of the document. Each chunk has its own vector embedding, and I want to perform …

---

## [Append ingest processor stringifies arrays instead of processing the elements one by one](https://discuss.elastic.co/t/append-ingest-processor-stringifies-arrays-instead-of-processing-the-elements-one-by-one/333486)

<div class="topic-metadata">

**Author:** [@Technici4n](https://discuss.elastic.co/u/Technici4n)\
**Replies:** 0\
**Last updated:** [May 15, 2023, 4:13pm UTC](https://discuss.elastic.co/t/append-ingest-processor-stringifies-arrays-instead-of-processing-the-elements-one-by-one/333486 "2023-05-15T16:13:30Z")

</div>

Hello, it seems that the append processor "stringifies" input arrays instead of processing the elements one by one. Could that be? (Using elasticsearch 8.6.2) Pipeline: "description": "testing issues with append", …

---

## [How to customize fleet agent policy integration](https://discuss.elastic.co/t/how-to-customize-fleet-agent-policy-integration/333478)

<div class="topic-metadata">

**Author:** [@Jobin\_James](https://discuss.elastic.co/u/Jobin_James)\
**Replies:** 0\
**Last updated:** [May 15, 2023, 3:13pm UTC](https://discuss.elastic.co/t/how-to-customize-fleet-agent-policy-integration/333478 "2023-05-15T15:13:29Z")

</div>

Hello, I am currently setting up an Elasticsearch cluster using the ECK operator, and I would like to know how I can customize the fleet integration configuration using the kibana.yml The problems I am facing. I can …

---

## [Cannot start filebeat with configuration file](https://discuss.elastic.co/t/cannot-start-filebeat-with-configuration-file/333338)

<div class="topic-metadata">

**Author:** [@Yasser\_Alsawy](https://discuss.elastic.co/u/Yasser_Alsawy)\
**Replies:** 19\
**Last updated:** [May 15, 2023, 2:23pm UTC](https://discuss.elastic.co/t/cannot-start-filebeat-with-configuration-file/333338 "2023-05-15T14:23:31Z")

</div>

I'm not able to start filebeat with below config file: filebeat.inputs: - type: filestream id: input1-id paths: - /home/yasser/data/sample1.log output.elasticsearch: hosts: \["https://localhost:9200"\] …

---

## [Unable to open index after config change while closed](https://discuss.elastic.co/t/unable-to-open-index-after-config-change-while-closed/333325)

<div class="topic-metadata">

**Author:** [@matt-monacelli](https://discuss.elastic.co/u/matt-monacelli)\
**Replies:** 5\
**Last updated:** [May 15, 2023, 2:26pm UTC](https://discuss.elastic.co/t/unable-to-open-index-after-config-change-while-closed/333325 "2023-05-15T14:26:13Z")

</div>

ES version: 7.10.2 (running in AWS) I mistakenly added a configuration that had been deprecated and is now preventing me from opening the index. To reproduce, close an index, set the index.mpper.dynamic setting to fals…

---

## [Elasticsearch 7.17.9 - current step is not recognized for shrink action, despite not having a shrink action defined](https://discuss.elastic.co/t/elasticsearch-7-17-9-current-step-is-not-recognized-for-shrink-action-despite-not-having-a-shrink-action-defined/330990)

<div class="topic-metadata">

**Author:** [@Chris\_Austin](https://discuss.elastic.co/u/Chris_Austin)\
**Replies:** 6\
**Last updated:** [May 15, 2023, 1:34pm UTC](https://discuss.elastic.co/t/elasticsearch-7-17-9-current-step-is-not-recognized-for-shrink-action-despite-not-having-a-shrink-action-defined/330990 "2023-05-15T13:34:20Z")

</div>

This is logged at the ERROR level and I'm not sure why. The ILM policy does not have a shrink action defined. Sample log, with the index name changed only to swap the account ID with 12345. current step \[{"phase":"warm…

---

## [Springboot maven project - RUM & APM Traces are not having same trace id](https://discuss.elastic.co/t/springboot-maven-project-rum-apm-traces-are-not-having-same-trace-id/332924)

<div class="topic-metadata">

**Author:** [@pratikshatiwari](https://discuss.elastic.co/u/pratikshatiwari)\
**Replies:** 2\
**Last updated:** [May 15, 2023, 1:23pm UTC](https://discuss.elastic.co/t/springboot-maven-project-rum-apm-traces-are-not-having-same-trace-id/332924 "2023-05-15T13:23:56Z")

</div>

hello team, I came across the issue whee i am not getting same trace id for RUM & APM transaction. E.g. i initiate the transaction "login" and i get the transaction detail in APM (service - springboot-consumer) & RUM (…

---

## [Count distinct groups when using collapse](https://discuss.elastic.co/t/count-distinct-groups-when-using-collapse/333463)

<div class="topic-metadata">

**Author:** [@dorian-marchal](https://discuss.elastic.co/u/dorian-marchal)\
**Replies:** 0\
**Last updated:** [May 15, 2023, 1:11pm UTC](https://discuss.elastic.co/t/count-distinct-groups-when-using-collapse/333463 "2023-05-15T13:11:29Z")

</div>

When collapsing results, the total number of hits (using track\_total\_hits) doesn't take collapsing into account, i.e. the total number of documents is returned, not the number of collapsed groups. E.g. if I index 150854…

---

## [Logging.files.name not working in filebeat 8.7.1](https://discuss.elastic.co/t/logging-files-name-not-working-in-filebeat-8-7-1/333462)

<div class="topic-metadata">

**Author:** [@Weiyu\_Fang](https://discuss.elastic.co/u/Weiyu_Fang)\
**Replies:** 0\
**Last updated:** [May 15, 2023, 1:06pm UTC](https://discuss.elastic.co/t/logging-files-name-not-working-in-filebeat-8-7-1/333462 "2023-05-15T13:06:50Z")

</div>

I upgraded my filebeat from 7.6 to 8.7, then I found the filebeat logs lost in my ES. I googled and found that Beats logs are now ECS compliant, which matches my situation where the logs name is like filebeat-20230515.nd…

---

## [High ram usage](https://discuss.elastic.co/t/high-ram-usage/333270)

<div class="topic-metadata">

**Author:** [@fnitz](https://discuss.elastic.co/u/fnitz)\
**Replies:** 6\
**Last updated:** [May 15, 2023, 12:55pm UTC](https://discuss.elastic.co/t/high-ram-usage/333270 "2023-05-15T12:55:41Z")

</div>

Hello, after some posts and good answers we optimize our Elasticsearch. Actually we use: 6 x hot nodes a 32 gb ram / heap space a 16 gb 22 x cold nodes a 16 gb / 8 gb space We reduce 8 primaries shards to 6 shards A…

---

## [Index data level security](https://discuss.elastic.co/t/index-data-level-security/332843)

<div class="topic-metadata">

**Author:** [@Msacs](https://discuss.elastic.co/u/Msacs)\
**Replies:** 3\
**Last updated:** [May 15, 2023, 12:38pm UTC](https://discuss.elastic.co/t/index-data-level-security/332843 "2023-05-15T12:38:44Z")

</div>

Wanted some guidance on how to setup data level security . I have a index with a field plant\_id and I have user list that I intend to map users to the corresponding plant id and when users searches ES or access Kibana da…

---

## [Pipeline not working in logstash / very strange work of logstash](https://discuss.elastic.co/t/pipeline-not-working-in-logstash-very-strange-work-of-logstash/332818)

<div class="topic-metadata">

**Author:** [@San9](https://discuss.elastic.co/u/San9)\
**Replies:** 2\
**Last updated:** [May 15, 2023, 12:26pm UTC](https://discuss.elastic.co/t/pipeline-not-working-in-logstash-very-strange-work-of-logstash/332818 "2023-05-15T12:26:10Z")

</div>

I've encountered strange behavior of Lostash. I have a configuration that reads files locally on the server, then analyzes them and then poisons them into elastic. When I test the config everything works for me /usr/sha…

---

## [Loading Coordinates in Elastic Maps](https://discuss.elastic.co/t/loading-coordinates-in-elastic-maps/333356)

<div class="topic-metadata">

**Author:** [@Denni](https://discuss.elastic.co/u/Denni)\
**Replies:** 4\
**Last updated:** [May 15, 2023, 12:25pm UTC](https://discuss.elastic.co/t/loading-coordinates-in-elastic-maps/333356 "2023-05-15T12:25:36Z")

</div>

Hi, I am very new to elasticsearch and kibana. I am trying to visualise some data I have collected, using the analytics, maps function. My file with Coordinates is read and loaded in. However it only shows the first data…

---

## [Problem with Kubernetes agent status showing as offline](https://discuss.elastic.co/t/problem-with-kubernetes-agent-status-showing-as-offline/333351)

<div class="topic-metadata">

**Author:** [@dbstjdghks25](https://discuss.elastic.co/u/dbstjdghks25)\
**Replies:** 1\
**Last updated:** [May 15, 2023, 10:56am UTC](https://discuss.elastic.co/t/problem-with-kubernetes-agent-status-showing-as-offline/333351 "2023-05-15T10:56:32Z")

</div>

I checked the health of a specific pod in Kubernetes by accessing it, and the fleet appears to be healthy, but the logs are not being sent to the agents and they appear as offline. However, when I check the Elasticsearch…

---

## [I am not getting the latest logs for few services in kibana dashboard](https://discuss.elastic.co/t/i-am-not-getting-the-latest-logs-for-few-services-in-kibana-dashboard/333440)

<div class="topic-metadata">

**Author:** [@kirankumarb](https://discuss.elastic.co/u/kirankumarb)\
**Replies:** 0\
**Last updated:** [May 15, 2023, 10:49am UTC](https://discuss.elastic.co/t/i-am-not-getting-the-latest-logs-for-few-services-in-kibana-dashboard/333440 "2023-05-15T10:49:59Z")

</div>

In discover panel, I am not getting latest logs for few services and getting latest logs for few services. Filebeat service is up and running Please help on this

---

## [Backup of Elasticsearch](https://discuss.elastic.co/t/backup-of-elasticsearch/332816)

<div class="topic-metadata">

**Author:** [@raw](https://discuss.elastic.co/u/raw)\
**Replies:** 4\
**Last updated:** [May 15, 2023, 10:25am UTC](https://discuss.elastic.co/t/backup-of-elasticsearch/332816 "2023-05-15T10:25:19Z")

</div>

I have a cluster of 3 nodes. I have set the backup directory on the 3 nodes to be: /var/lib/elasticsearch/backups. I tried to restore the content of a snapshot I took from kibana and restore it on another cluster. It sh…

---

## [Can someone explain how to use "Intervals query"?](https://discuss.elastic.co/t/can-someone-explain-how-to-use-intervals-query/333045)

<div class="topic-metadata">

**Author:** [@Eduard\_mart](https://discuss.elastic.co/u/Eduard_mart)\
**Replies:** 2\
**Last updated:** [May 15, 2023, 9:57am UTC](https://discuss.elastic.co/t/can-someone-explain-how-to-use-intervals-query/333045 "2023-05-15T09:57:51Z")

</div>

How to use them? What is the difference with query\_string and what are the benefits of using "Intervals query"? The documentation is really unclear and hard to understand.

---

## [Delete By query On Fields of type Text](https://discuss.elastic.co/t/delete-by-query-on-fields-of-type-text/333427)

<div class="topic-metadata">

**Author:** [@Martim\_Mourao](https://discuss.elastic.co/u/Martim_Mourao)\
**Replies:** 4\
**Last updated:** [May 15, 2023, 9:47am UTC](https://discuss.elastic.co/t/delete-by-query-on-fields-of-type-text/333427 "2023-05-15T09:47:55Z")

</div>

Elasticsearch Version: 8.7.1 We needed to do some deletes by Query using: Delete by query API | Elasticsearch Guide \[8.7\] | Elastic Our Request using dev tools on Kibana: POST /INDEX/\_delete\_by\_query { "query": { …

---

## [The length \[1133164\] of field \[code\] in doc\[8927\]/index\[ovaledge\_prasanthi4567890\_oequery\] exceeds the \[index.highlight.max\_analyzed\_offset\] limit \[1000000\]. To avoid this error, set the query parameter \[max\_analyzed\_offset\] to a value less than index set](https://discuss.elastic.co/t/the-length-1133164-of-field-code-in-doc-8927-index-ovaledge-prasanthi4567890-oequery-exceeds-the-index-highlight-max-analyzed-offset-limit-1000000-to-avoid-this-error-set-the-query-parameter-max-analyzed-offset-to-a-value-less-than-index-set/333412)

<div class="topic-metadata">

**Author:** [@g\_prashanth](https://discuss.elastic.co/u/g_prashanth)\
**Replies:** 2\
**Last updated:** [May 15, 2023, 8:55am UTC](https://discuss.elastic.co/t/the-length-1133164-of-field-code-in-doc-8927-index-ovaledge-prasanthi4567890-oequery-exceeds-the-index-highlight-max-analyzed-offset-limit-1000000-to-avoid-this-error-set-the-query-parameter-max-analyzed-offset-to-a-value-less-than-index-set/333412 "2023-05-15T08:55:49Z")

</div>

Every time increase index.highlight.max\_analyzed\_offset is not correct right, suppose if the field string having 100 match take first match and ignore remaining matches in the highlight.

---

## [Identifying the cause of an unresponsive ES Cluster](https://discuss.elastic.co/t/identifying-the-cause-of-an-unresponsive-es-cluster/331050)

<div class="topic-metadata">

**Author:** [@viera120](https://discuss.elastic.co/u/viera120)\
**Replies:** 23\
**Last updated:** [May 15, 2023, 8:38am UTC](https://discuss.elastic.co/t/identifying-the-cause-of-an-unresponsive-es-cluster/331050 "2023-05-15T08:38:58Z")

</div>

We are running a 3 node cluster to index logs from a firewall. The nodes are VMs (8 Core CPUs, 8GB RAM). The host runs on Intel i7, and has SSD storage. We have Kibana running on one of the nodes. The interface becomes…

---

## [Kibana user reset password through email](https://discuss.elastic.co/t/kibana-user-reset-password-through-email/333424)

<div class="topic-metadata">

**Author:** [@Sandeepa\_Kariyawasam](https://discuss.elastic.co/u/Sandeepa_Kariyawasam)\
**Replies:** 1\
**Last updated:** [May 15, 2023, 8:34am UTC](https://discuss.elastic.co/t/kibana-user-reset-password-through-email/333424 "2023-05-15T08:34:15Z")

</div>

I'm not sure whether this is already available. We have multiple Kibana users, mostly with viewer and editor privileges. Currently we have to use a superuser and access server to reset user passwords. When we created u…

---

## [Data view http\_poller is not time based Anomaly detection can only be run over indices which are time based](https://discuss.elastic.co/t/data-view-http-poller-is-not-time-based-anomaly-detection-can-only-be-run-over-indices-which-are-time-based/332758)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 1\
**Last updated:** [May 15, 2023, 8:28am UTC](https://discuss.elastic.co/t/data-view-http-poller-is-not-time-based-anomaly-detection-can-only-be-run-over-indices-which-are-time-based/332758 "2023-05-15T08:28:36Z")

</div>

Hi when i want to create new ML job it will give me this error: Data view http\_poller is not time based Anomaly detection can only be run over indices which are time based. FYI: this view contain indice(index) that c…

---

## [Elastic Machine learning, Datafeed has missed xxx documents due to ingest latency](https://discuss.elastic.co/t/elastic-machine-learning-datafeed-has-missed-xxx-documents-due-to-ingest-latency/332870)

<div class="topic-metadata">

**Author:** [@JasonREC](https://discuss.elastic.co/u/JasonREC)\
**Replies:** 1\
**Last updated:** [May 15, 2023, 8:25am UTC](https://discuss.elastic.co/t/elastic-machine-learning-datafeed-has-missed-xxx-documents-due-to-ingest-latency/332870 "2023-05-15T08:25:44Z")

</div>

Hi, I currenly have a APM server which running on cloud and receiving my php app transaction log. Basiclly, request will keep sending to my php api endpoint. And, I am using the APM generated index pattern log to fee…

---

## [Model Bound in periodic processes](https://discuss.elastic.co/t/model-bound-in-periodic-processes/333281)

<div class="topic-metadata">

**Author:** [@Kirtash](https://discuss.elastic.co/u/Kirtash)\
**Replies:** 1\
**Last updated:** [May 15, 2023, 8:20am UTC](https://discuss.elastic.co/t/model-bound-in-periodic-processes/333281 "2023-05-15T08:20:39Z")

</div>

Good morning, I have a doubt about the model bounds, I have a few services that only have request in periodic moments and although I think that is logic, when this service receive requests it show me that is critical. I…

---

## [Import CSV with date fields not usable as timestamp field](https://discuss.elastic.co/t/import-csv-with-date-fields-not-usable-as-timestamp-field/333373)

<div class="topic-metadata">

**Author:** [@Vortex\_SLT](https://discuss.elastic.co/u/Vortex_SLT)\
**Replies:** 6\
**Last updated:** [May 14, 2023, 8:02pm UTC](https://discuss.elastic.co/t/import-csv-with-date-fields-not-usable-as-timestamp-field/333373 "2023-05-14T20:02:32Z")

</div>

Hello, I'm currently try to use a date fields imported form a CVS via filebeat to the elasticsearch. (v 7.17.10) The field have this format : "2023-03-07 15:19:11" and I would like to use it as timestamp field. I trie…

[Previous page](https://discuss.elastic.co/latest.md?page=676)

[Next page](https://discuss.elastic.co/latest.md?page=678)
