# Latest

**URL:** https://discuss.elastic.co/latest.md?page=685

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 686

---

## [Will the elasticsearch input plugin of logstash ensure no repeat reading after restart?](https://discuss.elastic.co/t/will-the-elasticsearch-input-plugin-of-logstash-ensure-no-repeat-reading-after-restart/332962)

<div class="topic-metadata">

**Author:** [@liusanyong](https://discuss.elastic.co/u/liusanyong)\
**Replies:** 0\
**Last updated:** [May 9, 2023, 3:14pm UTC](https://discuss.elastic.co/t/will-the-elasticsearch-input-plugin-of-logstash-ensure-no-repeat-reading-after-restart/332962 "2023-05-09T15:14:19Z")

</div>

Hello, If use elasticsearch input plugin of logstash to read data from a elasticsearch index and do some processing. How to ensure it will not read repeated data after the logstash restarted ?

---

## [CVEs present in the latest version](https://discuss.elastic.co/t/cves-present-in-the-latest-version/332950)

<div class="topic-metadata">

**Author:** [@beltran-rubo](https://discuss.elastic.co/u/beltran-rubo)\
**Replies:** 1\
**Last updated:** [May 9, 2023, 3:03pm UTC](https://discuss.elastic.co/t/cves-present-in-the-latest-version/332950 "2023-05-09T15:03:18Z")

</div>

In the latest release, at this moment 8.7.1, there are vulnerabilities in some jar files included. From Trivy scanner: CVE-2020-15522 CVE-2020-8908 CVE-2021-29425 CVE-2021-40690 CVE-2022-1471 CVE-2022-45146 CVE-20…

---

## [Geo-Containment Issues](https://discuss.elastic.co/t/geo-containment-issues/332598)

<div class="topic-metadata">

**Author:** [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Replies:** 14\
**Last updated:** [May 9, 2023, 2:51pm UTC](https://discuss.elastic.co/t/geo-containment-issues/332598 "2023-05-09T14:51:11Z")

</div>

I've been trying to get a geo-containment rule to work, but it just wont alert. Anybody able to identify where I'm going wrong? I can't get it to trigger either of the actions. Running Elastic Stack 8.7.1. Here's the…

---

## [Does anyone know if Filebeat keystore is as secure as the Linux Shadow file?](https://discuss.elastic.co/t/does-anyone-know-if-filebeat-keystore-is-as-secure-as-the-linux-shadow-file/332611)

<div class="topic-metadata">

**Author:** [@danielc](https://discuss.elastic.co/u/danielc)\
**Replies:** 3\
**Last updated:** [May 9, 2023, 2:44pm UTC](https://discuss.elastic.co/t/does-anyone-know-if-filebeat-keystore-is-as-secure-as-the-linux-shadow-file/332611 "2023-05-09T14:44:10Z")

</div>

Does anyone know if Filebeat keystore is reversible? is it as secure as the Linux Shadow file?

---

## [Illegal\_argument\_exception](https://discuss.elastic.co/t/illegal-argument-exception/332923)

<div class="topic-metadata">

**Author:** [@Dnyaneshwar\_Chavan](https://discuss.elastic.co/u/Dnyaneshwar_Chavan)\
**Replies:** 1\
**Last updated:** [May 9, 2023, 2:28pm UTC](https://discuss.elastic.co/t/illegal-argument-exception/332923 "2023-05-09T14:28:02Z")

</div>

getting illegal\_argument\_exception", "reason" : "Text fields are not optimised for operations that require per-document field data like aggregations and sorting, so these operations are disabled by default. Please use a…

---

## [ECK Integration Fleet Kubernetes](https://discuss.elastic.co/t/eck-integration-fleet-kubernetes/332939)

<div class="topic-metadata">

**Author:** [@cboissavy](https://discuss.elastic.co/u/cboissavy)\
**Replies:** 0\
**Last updated:** [May 9, 2023, 1:34pm UTC](https://discuss.elastic.co/t/eck-integration-fleet-kubernetes/332939 "2023-05-09T13:34:51Z")

</div>

Hello, I am using ECK v8.6.2. I have 4 pods elasticsearch and 5 nodes Kubernetes in Scaleway. I have 5 Elastic Agent (one for each nodes) and I added the integration Kubernetes v1.36.0 I have enable "Collect Kubernet…

---

## [Logstash TCP and Syslog Plugin Error](https://discuss.elastic.co/t/logstash-tcp-and-syslog-plugin-error/330722)

<div class="topic-metadata">

**Author:** [@hanna](https://discuss.elastic.co/u/hanna)\
**Replies:** 4\
**Last updated:** [May 9, 2023, 1:26pm UTC](https://discuss.elastic.co/t/logstash-tcp-and-syslog-plugin-error/330722 "2023-05-09T13:26:55Z")

</div>

Hello, I'm experiencing a Logstash error with the syslog input plugin. The input plugin for my pipeline keeps crashing with the message Force-closing a channel whose registration task was not accepted by an event loop …

---

## [App Search Analytics - Number of Queries/hr](https://discuss.elastic.co/t/app-search-analytics-number-of-queries-hr/332932)

<div class="topic-metadata">

**Author:** [@alongaks](https://discuss.elastic.co/u/alongaks)\
**Replies:** 1\
**Last updated:** [May 9, 2023, 12:59pm UTC](https://discuss.elastic.co/t/app-search-analytics-number-of-queries-hr/332932 "2023-05-09T12:59:41Z")

</div>

Hello, I have a cloud and local deployment of Enterprise Search that is backing a website search experience for external and intranet websites. These sites are using the basic App Search analytics with '-X Enterprise-S…

---

## [Logstash logging](https://discuss.elastic.co/t/logstash-logging/332887)

<div class="topic-metadata">

**Author:** [@Haytham\_Shammout](https://discuss.elastic.co/u/Haytham_Shammout)\
**Replies:** 2\
**Last updated:** [May 9, 2023, 12:53pm UTC](https://discuss.elastic.co/t/logstash-logging/332887 "2023-05-09T12:53:34Z")

</div>

Hi! I was wondering if there is any location that stores the logs in Logstash before sending it to any destination? and if there, where and how can I find it? Thanks.

---

## [Disable exists query in Kibana 8.7](https://discuss.elastic.co/t/disable-exists-query-in-kibana-8-7/329753)

<div class="topic-metadata">

**Author:** [@Jonas\_S](https://discuss.elastic.co/u/Jonas_S)\
**Replies:** 14\
**Last updated:** [May 9, 2023, 12:45pm UTC](https://discuss.elastic.co/t/disable-exists-query-in-kibana-8-7/329753 "2023-05-09T12:45:20Z")

</div>

Hello, after the new controls came out and replaced the beta controls, i started to add them to every dashboard i'm managing. There was no exists query possible at all back then. Then a new update came out, introducing…

---

## [Importing dashboards into multiple spaces through the kibana api](https://discuss.elastic.co/t/importing-dashboards-into-multiple-spaces-through-the-kibana-api/332599)

<div class="topic-metadata">

**Author:** [@CarolynR](https://discuss.elastic.co/u/CarolynR)\
**Replies:** 4\
**Last updated:** [May 9, 2023, 12:42pm UTC](https://discuss.elastic.co/t/importing-dashboards-into-multiple-spaces-through-the-kibana-api/332599 "2023-05-09T12:42:04Z")

</div>

I have saved objects that I am trying to import into 2 different spaces. This worked under kibana 7, but is broken under kibana 8. I use s/spacename in the url when working with the different spaces Importing into the…

---

## [Queue.drain: true not working for logstash as K8s setup](https://discuss.elastic.co/t/queue-drain-true-not-working-for-logstash-as-k8s-setup/329236)

<div class="topic-metadata">

**Author:** [@Karthik\_N](https://discuss.elastic.co/u/Karthik_N)\
**Replies:** 18\
**Last updated:** [May 9, 2023, 12:21pm UTC](https://discuss.elastic.co/t/queue-drain-true-not-working-for-logstash-as-k8s-setup/329236 "2023-05-09T12:21:47Z")

</div>

Hi Team, We have issues in draining the logstash queue, this config is queue.drain: true not working. Our Current logstash setup in K8s and persistence queue setup in EBS volume, after killing our one of the logstash po…

---

## [Logstash - Convert JSON array and delete whitespaces from key fields](https://discuss.elastic.co/t/logstash-convert-json-array-and-delete-whitespaces-from-key-fields/332419)

<div class="topic-metadata">

**Author:** [@h49nakxs](https://discuss.elastic.co/u/h49nakxs)\
**Replies:** 3\
**Last updated:** [May 9, 2023, 11:55am UTC](https://discuss.elastic.co/t/logstash-convert-json-array-and-delete-whitespaces-from-key-fields/332419 "2023-05-09T11:55:33Z")

</div>

Hi there, I'm using Logstash to receive events from winlogbeat and send them to Kafka which will ultimately send them further. To be able to correctly process those events at the end of the pipe, I need to : Convert t…

---

## [Elastic-agent ignores logging level setting](https://discuss.elastic.co/t/elastic-agent-ignores-logging-level-setting/332560)

<div class="topic-metadata">

**Author:** [@vitalyrychkov](https://discuss.elastic.co/u/vitalyrychkov)\
**Replies:** 1\
**Last updated:** [May 9, 2023, 10:07am UTC](https://discuss.elastic.co/t/elastic-agent-ignores-logging-level-setting/332560 "2023-05-09T10:07:38Z")

</div>

I am trying to reduce the output of the elastic-agent containers in Kubernetes. I have added the following parameter to the configmap: agent: logging: level: error and restarted agents. There is still…

---

## [Logstash long nested messgage field in json format not getting parsed](https://discuss.elastic.co/t/logstash-long-nested-messgage-field-in-json-format-not-getting-parsed/332893)

<div class="topic-metadata">

**Author:** [@Alok\_ojha](https://discuss.elastic.co/u/Alok_ojha)\
**Replies:** 0\
**Last updated:** [May 9, 2023, 8:57am UTC](https://discuss.elastic.co/t/logstash-long-nested-messgage-field-in-json-format-not-getting-parsed/332893 "2023-05-09T08:57:45Z")

</div>

Please Help!! I had data in kafka, I used logstash config file to upload it to elasticsearch, data is coming to elasticsearch but the message field is very long and logstash is unable to parse it in key value pair. Is t…

---

## [Unable to Connect with elastic cloud](https://discuss.elastic.co/t/unable-to-connect-with-elastic-cloud/332456)

<div class="topic-metadata">

**Author:** [@Mohd\_Ahmad](https://discuss.elastic.co/u/Mohd_Ahmad)\
**Replies:** 4\
**Last updated:** [May 4, 2023, 2:46am UTC](https://discuss.elastic.co/t/unable-to-connect-with-elastic-cloud/332456 "2023-05-04T02:46:22Z")

</div>

Uncaught Elastic\\Transport\\Exception\\NoNodeAvailableException: No alive nodes. All the 1 nodes seem to be down. My php client is hosted at 000webhost and i am creating client with api key and cloud id but it is throwing…

---

## [Elastic and kibana is stop](https://discuss.elastic.co/t/elastic-and-kibana-is-stop/332889)

<div class="topic-metadata">

**Author:** [@Fatiha](https://discuss.elastic.co/u/Fatiha)\
**Replies:** 1\
**Last updated:** [May 9, 2023, 8:55am UTC](https://discuss.elastic.co/t/elastic-and-kibana-is-stop/332889 "2023-05-09T08:55:25Z")

</div>

HI everyone I want to create a project that visualize the data base saved in mysql using kibana in docker now I pull elastic and kibana and mysql cantainer and I run it and it is work but when I turn of my pc or …

---

## [Elasticsearch and kibana access](https://discuss.elastic.co/t/elasticsearch-and-kibana-access/329806)

<div class="topic-metadata">

**Author:** [@roshan\_vikhar](https://discuss.elastic.co/u/roshan_vikhar)\
**Replies:** 2\
**Last updated:** [May 9, 2023, 8:27am UTC](https://discuss.elastic.co/t/elasticsearch-and-kibana-access/329806 "2023-05-09T08:27:09Z")

</div>

I am new in ELK am using elastic ip for connecting both elasticsearch and kibana but only kibana i can access. what should be the changes i have to make in elasticsearch.yml and kibana.yml to make it work.

---

## [Is it possible to control the interval logstash send data to elasticsearch?](https://discuss.elastic.co/t/is-it-possible-to-control-the-interval-logstash-send-data-to-elasticsearch/332839)

<div class="topic-metadata">

**Author:** [@Wang\_Yin](https://discuss.elastic.co/u/Wang_Yin)\
**Replies:** 1\
**Last updated:** [May 9, 2023, 8:13am UTC](https://discuss.elastic.co/t/is-it-possible-to-control-the-interval-logstash-send-data-to-elasticsearch/332839 "2023-05-09T08:13:13Z")

</div>

I'm very new to ELK, I'd like to know is it possible to control the interval logstash send data to elasticsearch? For example, I have a simple logstash config file running in /etc/logstash/conf.d folder: input { file…

---

## [Lens Formula subtract first and last document](https://discuss.elastic.co/t/lens-formula-subtract-first-and-last-document/330837)

<div class="topic-metadata">

**Author:** [@deepack86](https://discuss.elastic.co/u/deepack86)\
**Replies:** 2\
**Last updated:** [May 9, 2023, 8:05am UTC](https://discuss.elastic.co/t/lens-formula-subtract-first-and-last-document/330837 "2023-05-09T08:05:37Z")

</div>

I want to subtract the last and the first document from a timerange to check how much engergy was consumed. So i make a lens with a formula like this : (last\_value(value.value\_float32) - min(value.value\_float32)) . I ta…

---

## [Ingesting multiline fields with the Grok processor](https://discuss.elastic.co/t/ingesting-multiline-fields-with-the-grok-processor/332876)

<div class="topic-metadata">

**Author:** [@adis](https://discuss.elastic.co/u/adis)\
**Replies:** 0\
**Last updated:** [May 9, 2023, 6:54am UTC](https://discuss.elastic.co/t/ingesting-multiline-fields-with-the-grok-processor/332876 "2023-05-09T06:54:06Z")

</div>

Hi I've cloned the Postgresql integration pipelines and changed its grok patterns to fit our custom postgresql log format. Almost everything gets parsed correctly with the following grok pattern: %{POSTGRESQL\_REMOTE\_H…

---

## [New semantic relevance ranking API for Elastic Enterprise Search](https://discuss.elastic.co/t/new-semantic-relevance-ranking-api-for-elastic-enterprise-search/322640)

<div class="topic-metadata">

**Author:** [@jamie\_l](https://discuss.elastic.co/u/jamie_l)\
**Replies:** 2\
**Last updated:** [May 9, 2023, 6:42am UTC](https://discuss.elastic.co/t/new-semantic-relevance-ranking-api-for-elastic-enterprise-search/322640 "2023-05-09T06:42:57Z")

</div>

Hi all! I’m on the product team at Cohere (a managed LLM provider). We are working on a new endpoint to provide easy semantic relevance scoring of search results using our language models. We think this could be especia…

---

## [Can i check elasticsearch index in file system](https://discuss.elastic.co/t/can-i-check-elasticsearch-index-in-file-system/332634)

<div class="topic-metadata">

**Author:** [@Skairik](https://discuss.elastic.co/u/Skairik)\
**Replies:** 9\
**Last updated:** [May 9, 2023, 6:42am UTC](https://discuss.elastic.co/t/can-i-check-elasticsearch-index-in-file-system/332634 "2023-05-09T06:42:18Z")

</div>

Hello, I wanted to know if there is a way for me to look at the logs of the different indexes directly on my server without going through kibana. After some research I was supposed to have a data folder in /var/lib/ela…

---

## [Issue with Multiple grok patterns in single log ingest pipeline](https://discuss.elastic.co/t/issue-with-multiple-grok-patterns-in-single-log-ingest-pipeline/332842)

<div class="topic-metadata">

**Author:** [@Jason\_Paralta](https://discuss.elastic.co/u/Jason_Paralta)\
**Replies:** 0\
**Last updated:** [May 8, 2023, 7:55pm UTC](https://discuss.elastic.co/t/issue-with-multiple-grok-patterns-in-single-log-ingest-pipeline/332842 "2023-05-08T19:55:07Z")

</div>

Hi All, I am trying to read different log paths, this logs are of different patterns. I have single elastic template for this and have settings of default pipeline configured on same template. Now in log ingest pipeline…

---

## [Kafka can collect java stack log but elastic search cannot. How to fix?](https://discuss.elastic.co/t/kafka-can-collect-java-stack-log-but-elastic-search-cannot-how-to-fix/332612)

<div class="topic-metadata">

**Author:** [@Alwyn\_Tiu](https://discuss.elastic.co/u/Alwyn_Tiu)\
**Replies:** 12\
**Last updated:** [May 9, 2023, 3:40am UTC](https://discuss.elastic.co/t/kafka-can-collect-java-stack-log-but-elastic-search-cannot-how-to-fix/332612 "2023-05-09T03:40:19Z")

</div>

Kafka can collect java stack log but Elasticsearch cannot. How to fix?

---

## ["There are no ingest nodes in this cluster, unable to forward request to an ingest node" errors](https://discuss.elastic.co/t/there-are-no-ingest-nodes-in-this-cluster-unable-to-forward-request-to-an-ingest-node-errors/332701)

<div class="topic-metadata">

**Author:** [@khteh](https://discuss.elastic.co/u/khteh)\
**Replies:** 2\
**Last updated:** [May 9, 2023, 3:02am UTC](https://discuss.elastic.co/t/there-are-no-ingest-nodes-in-this-cluster-unable-to-forward-request-to-an-ingest-node-errors/332701 "2023-05-09T03:02:10Z")

</div>

Kibana version: 8.7.1 Elasticsearch version: 8.7.1 APM Server version: 8.7.1 APM Agent language and version: Node.JS 19 Browser version: Original install method (e.g. download page, yum, deb, from source, etc.) and …

---

## [How to collect data in character special device like /dev/kmsg?](https://discuss.elastic.co/t/how-to-collect-data-in-character-special-device-like-dev-kmsg/332801)

<div class="topic-metadata">

**Author:** [@linrl3](https://discuss.elastic.co/u/linrl3)\
**Replies:** 2\
**Last updated:** [May 9, 2023, 2:35am UTC](https://discuss.elastic.co/t/how-to-collect-data-in-character-special-device-like-dev-kmsg/332801 "2023-05-09T02:35:47Z")

</div>

Like the title said, how can I use filebeat to collect from character device, for example /dev/kmsg.

---

## [Customize the indices name for ingesting data by elastic agent](https://discuss.elastic.co/t/customize-the-indices-name-for-ingesting-data-by-elastic-agent/332854)

<div class="topic-metadata">

**Author:** [@Jaydenchan1983](https://discuss.elastic.co/u/Jaydenchan1983)\
**Replies:** 0\
**Last updated:** [May 9, 2023, 2:12am UTC](https://discuss.elastic.co/t/customize-the-indices-name-for-ingesting-data-by-elastic-agent/332854 "2023-05-09T02:12:05Z")

</div>

I have installed elastic agent in 2 web server to collect iis log. Both log data are ingested to same indices. How could set different indices for different server data?

---

## [\[Filebeat 8.6.2\] How to add additional fileds in apache module](https://discuss.elastic.co/t/filebeat-8-6-2-how-to-add-additional-fileds-in-apache-module/332840)

<div class="topic-metadata">

**Author:** [@rohitguptaggg](https://discuss.elastic.co/u/rohitguptaggg)\
**Replies:** 1\
**Last updated:** [May 8, 2023, 11:04pm UTC](https://discuss.elastic.co/t/filebeat-8-6-2-how-to-add-additional-fileds-in-apache-module/332840 "2023-05-08T23:04:12Z")

</div>

Hello, I am using filebeat 6.8.2 and i have enabled the apache module and trying to add some extra fields but not working i alsi tried : Add fields | Filebeat Reference \[8.7\] | Elastic but this is not working with the …

---

## [Docs for manually enrolling cluster nodes without enrollment tokens?](https://discuss.elastic.co/t/docs-for-manually-enrolling-cluster-nodes-without-enrollment-tokens/332681)

<div class="topic-metadata">

**Author:** [@andrew.klaassen](https://discuss.elastic.co/u/andrew.klaassen)\
**Replies:** 2\
**Last updated:** [May 8, 2023, 6:40pm UTC](https://discuss.elastic.co/t/docs-for-manually-enrolling-cluster-nodes-without-enrollment-tokens/332681 "2023-05-08T18:40:38Z")

</div>

I'm trying to set up an Elasticsearch cluster using auto-renewing certs with certmonger from our enterprise CA. I'm running into a problem that has been discussed in many threads, where the answer always seems to be som…

[Previous page](https://discuss.elastic.co/latest.md?page=684)

[Next page](https://discuss.elastic.co/latest.md?page=686)
