# Latest

**URL:** https://discuss.elastic.co/latest.md?page=686

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 687

---

## [Empty certificate chain on internode handshake with different certificate on each node](https://discuss.elastic.co/t/empty-certificate-chain-on-internode-handshake-with-different-certificate-on-each-node/332836)

<div class="topic-metadata">

**Author:** [@Diana\_Mihutescu](https://discuss.elastic.co/u/Diana_Mihutescu)\
**Replies:** 0\
**Last updated:** [May 8, 2023, 5:49pm UTC](https://discuss.elastic.co/t/empty-certificate-chain-on-internode-handshake-with-different-certificate-on-each-node/332836 "2023-05-08T17:49:54Z")

</div>

Hello, I configured a two nodes cluster with xpack.security.enabled: true xpack.security.http.ssl.enabled: true xpack.security.transport.ssl.enabled: true xpack.security.transport.ssl.verification\_mode: "certificate" x…

---

## [Metric Aggregations on Multiple Filters](https://discuss.elastic.co/t/metric-aggregations-on-multiple-filters/332662)

<div class="topic-metadata">

**Author:** [@hi\_xavier](https://discuss.elastic.co/u/hi_xavier)\
**Replies:** 2\
**Last updated:** [May 8, 2023, 5:56pm UTC](https://discuss.elastic.co/t/metric-aggregations-on-multiple-filters/332662 "2023-05-08T17:56:45Z")

</div>

Hello, Is there a way to run the a metric aggregation (value count for example) on multiple filters. For example, I'm currently able to get the counts of successes and errors all users are getting with the following ag…

---

## [How to solve - "We couldn't log you in. Please try again." - error in kibana](https://discuss.elastic.co/t/how-to-solve-we-couldnt-log-you-in-please-try-again-error-in-kibana/332658)

<div class="topic-metadata">

**Author:** [@M\_S](https://discuss.elastic.co/u/M_S)\
**Replies:** 3\
**Last updated:** [May 8, 2023, 5:10pm UTC](https://discuss.elastic.co/t/how-to-solve-we-couldnt-log-you-in-please-try-again-error-in-kibana/332658 "2023-05-08T17:10:36Z")

</div>

I tried to open kibana on my properly working ELK stack one fine morning only to discover this error message - We couldn't log you in. Please try again. I opened kibana.log to discover this following log entry coming r…

---

## ["The processor action grok does not exist" in FileBeat. Why ? (Custom Logs Integration)](https://discuss.elastic.co/t/the-processor-action-grok-does-not-exist-in-filebeat-why-custom-logs-integration/332756)

<div class="topic-metadata">

**Author:** [@mehdi-lamrani](https://discuss.elastic.co/u/mehdi-lamrani)\
**Replies:** 3\
**Last updated:** [May 8, 2023, 4:00pm UTC](https://discuss.elastic.co/t/the-processor-action-grok-does-not-exist-in-filebeat-why-custom-logs-integration/332756 "2023-05-08T16:00:17Z")

</div>

I am a bit confused here. Grok is available in Ingest Processors but not in Filebeat processors May I ask why ? :thinking: I was hoping to do this , but it breaks, as I am getting the following error : \[elastic\_a…

---

## [Elastic Agent excessive cpu / log output in kubernetes](https://discuss.elastic.co/t/elastic-agent-excessive-cpu-log-output-in-kubernetes/330554)

<div class="topic-metadata">

**Author:** [@jlucas](https://discuss.elastic.co/u/jlucas)\
**Replies:** 2\
**Last updated:** [May 8, 2023, 3:24pm UTC](https://discuss.elastic.co/t/elastic-agent-excessive-cpu-log-output-in-kubernetes/330554 "2023-05-08T15:24:23Z")

</div>

Hello, I am noticing some undesirable behavior when using elastic agent within kubernetes on-prem. I have a fleet managed elastic agent running in kubernetes with APM, System, and Kubernetes integrations turned on. I wa…

---

## [Watcher configurtion](https://discuss.elastic.co/t/watcher-configurtion/332827)

<div class="topic-metadata">

**Author:** [@prithvi](https://discuss.elastic.co/u/prithvi)\
**Replies:** 0\
**Last updated:** [May 8, 2023, 2:34pm UTC](https://discuss.elastic.co/t/watcher-configurtion/332827 "2023-05-08T14:34:00Z")

</div>

Hi, Let me explain my architecture here, we have 3 master nodes and 10 data nodes. We need to configure watcher to trigger email alert. challenge here it is very secured environment. anyone pleas ehelp me to configure t…

---

## [Is the dot product score calculation for the vector of byte element\_type correct? I think it is a bug](https://discuss.elastic.co/t/is-the-dot-product-score-calculation-for-the-vector-of-byte-element-type-correct-i-think-it-is-a-bug/331033)

<div class="topic-metadata">

**Author:** [@wangyanbin](https://discuss.elastic.co/u/wangyanbin)\
**Replies:** 6\
**Last updated:** [May 8, 2023, 1:58pm UTC](https://discuss.elastic.co/t/is-the-dot-product-score-calculation-for-the-vector-of-byte-element-type-correct-i-think-it-is-a-bug/331033 "2023-05-08T13:58:10Z")

</div>

I found the dot product score calculation for the vector of byte element\_type is wrong: 0.5 + (dot\_product(query, vector) / (32768 \* dims)) which is same as : 0.5 + (dot\_product(query, vector) / (128\*128\*2\* dims)) ref…

---

## [Active Directory perfmon counter in metricbeat](https://discuss.elastic.co/t/active-directory-perfmon-counter-in-metricbeat/329537)

<div class="topic-metadata">

**Author:** [@Shaakxuur](https://discuss.elastic.co/u/Shaakxuur)\
**Replies:** 2\
**Last updated:** [May 8, 2023, 1:42pm UTC](https://discuss.elastic.co/t/active-directory-perfmon-counter-in-metricbeat/329537 "2023-05-08T13:42:51Z")

</div>

Hi! I have two questions about Active Directory perfmon counters. I´ve created some counters based on this article: And in this article I have seen then that this syntax no longer exists: Now I'm not sure how to …

---

## [Search for an exact Date, ignoring the time\_zone](https://discuss.elastic.co/t/search-for-an-exact-date-ignoring-the-time-zone/332716)

<div class="topic-metadata">

**Author:** [@wil93](https://discuss.elastic.co/u/wil93)\
**Replies:** 5\
**Last updated:** [May 8, 2023, 12:47pm UTC](https://discuss.elastic.co/t/search-for-an-exact-date-ignoring-the-time-zone/332716 "2023-05-08T12:47:16Z")

</div>

Given the following document: PUT /examples/\_doc/1 { "item": "Phone X", "price": 799, "lastUpdateDate" : "2023-05-01T01:00:00+02:00" } No explicit 'Mapping' for index 'examples' is provided (Elasticsearch will t…

---

## [Error when importing my custom dashboard through kibana UI with metricbeat](https://discuss.elastic.co/t/error-when-importing-my-custom-dashboard-through-kibana-ui-with-metricbeat/332421)

<div class="topic-metadata">

**Author:** [@\_Zeyad\_Elshater](https://discuss.elastic.co/u/_Zeyad_Elshater)\
**Replies:** 2\
**Last updated:** [May 8, 2023, 12:45pm UTC](https://discuss.elastic.co/t/error-when-importing-my-custom-dashboard-through-kibana-ui-with-metricbeat/332421 "2023-05-08T12:45:56Z")

</div>

I'm new to ELK , I have custom ndjson file that I imported through the kibana UI , I have some errors like "The field "nuix\_running\_worker" associated with this object no longer exists in the data view. Please use anothe…

---

## [Harvester for file is still running](https://discuss.elastic.co/t/harvester-for-file-is-still-running/332813)

<div class="topic-metadata">

**Author:** [@AndersBolager](https://discuss.elastic.co/u/AndersBolager)\
**Replies:** 0\
**Last updated:** [May 8, 2023, 12:09pm UTC](https://discuss.elastic.co/t/harvester-for-file-is-still-running/332813 "2023-05-08T12:09:13Z")

</div>

Hi. On one of my servers, after working for a few weeks, the following loglines are repeated, and nothing ends up on the elasticstack server: {"log.level":"debug","@timestamp":"2023-05-08T13:53:56.309+0200","log.logger…

---

## [Formatted time string with nanoseconds is not converted to nanosecond timestamp value when sorting on \_search queries](https://discuss.elastic.co/t/formatted-time-string-with-nanoseconds-is-not-converted-to-nanosecond-timestamp-value-when-sorting-on-search-queries/330046)

<div class="topic-metadata">

**Author:** [@jsun-m](https://discuss.elastic.co/u/jsun-m)\
**Replies:** 5\
**Last updated:** [May 8, 2023, 12:04pm UTC](https://discuss.elastic.co/t/formatted-time-string-with-nanoseconds-is-not-converted-to-nanosecond-timestamp-value-when-sorting-on-search-queries/330046 "2023-05-08T12:04:27Z")

</div>

Query: return { "sort": \[ { "time": "desc" }, \], "\_source": \["@timestamp", "message", "time"\], "runtime\_mappings": { "date\_has\_nanos": …

---

## [Elastic Agent Ouput to Logstash](https://discuss.elastic.co/t/elastic-agent-ouput-to-logstash/329809)

<div class="topic-metadata">

**Author:** [@praveen\_raju](https://discuss.elastic.co/u/praveen_raju)\
**Replies:** 1\
**Last updated:** [May 8, 2023, 11:56am UTC](https://discuss.elastic.co/t/elastic-agent-ouput-to-logstash/329809 "2023-05-08T11:56:51Z")

</div>

Hi, I'm trying to send the data from fleet to Logstash using agent policy which i configured by following below article. But when choose the output from dropdown, options are greyed out as shown figure. Please be no…

---

## [Elastic-agent to logstash mapper\_parsing\_exception with windows system integration](https://discuss.elastic.co/t/elastic-agent-to-logstash-mapper-parsing-exception-with-windows-system-integration/330300)

<div class="topic-metadata">

**Author:** [@irivas95](https://discuss.elastic.co/u/irivas95)\
**Replies:** 1\
**Last updated:** [May 8, 2023, 11:54am UTC](https://discuss.elastic.co/t/elastic-agent-to-logstash-mapper-parsing-exception-with-windows-system-integration/330300 "2023-05-08T11:54:11Z")

</div>

Hi, I am trying to send windows events via an elastic-agent (8.6.0) (with fleet in 8.6.0) to logstash (8.6.0). the eleastic-agent is configured with an agent policy that has a system integration configured as follows: …

---

## [Elasticsearch upgrade](https://discuss.elastic.co/t/elasticsearch-upgrade/332805)

<div class="topic-metadata">

**Author:** [@Krzysztof\_Dabrowski](https://discuss.elastic.co/u/Krzysztof_Dabrowski)\
**Replies:** 4\
**Last updated:** [May 8, 2023, 11:44am UTC](https://discuss.elastic.co/t/elasticsearch-upgrade/332805 "2023-05-08T11:44:10Z")

</div>

Hey. I wanted to upgrade elasticsearch from 7.16 to 8.7. First I upgraded ES to 7.17 but I didn't restarted the service and immediately upgraded to 8.7. Now Elasticsearch wont start due to error: cannot upgrade a node f…

---

## [Error: invalid connection string: must include a username unless a service token is provided](https://discuss.elastic.co/t/error-invalid-connection-string-must-include-a-username-unless-a-service-token-is-provided/332668)

<div class="topic-metadata">

**Author:** [@osdacita](https://discuss.elastic.co/u/osdacita)\
**Replies:** 1\
**Last updated:** [May 8, 2023, 11:33am UTC](https://discuss.elastic.co/t/error-invalid-connection-string-must-include-a-username-unless-a-service-token-is-provided/332668 "2023-05-08T11:33:58Z")

</div>

I'm trying to enroll a host using the fleet to properly use EndPoint Security, but trying directly causes problems so I resorted to the following commands: .\\elastic-agent enroll --fleet-server-es=https://:443 --flee…

---

## [Elasticsearch 7.10.2 backup](https://discuss.elastic.co/t/elasticsearch-7-10-2-backup/332642)

<div class="topic-metadata">

**Author:** [@jomaguca](https://discuss.elastic.co/u/jomaguca)\
**Replies:** 20\
**Last updated:** [May 8, 2023, 11:21am UTC](https://discuss.elastic.co/t/elasticsearch-7-10-2-backup/332642 "2023-05-08T11:21:52Z")

</div>

Hi everyone My name is José Manuel and I am trying to make a back from elasticsearch 7.10.2, but show me the next error # curl -X PUT localhost:9200/\_snapshot/my\_backup?pretty -H 'Content-Type: application/json' -d '{…

---

## [Using Dashboard Control to Filter Data Views](https://discuss.elastic.co/t/using-dashboard-control-to-filter-data-views/332771)

<div class="topic-metadata">

**Author:** [@Tim\_Mobley](https://discuss.elastic.co/u/Tim_Mobley)\
**Replies:** 2\
**Last updated:** [May 8, 2023, 10:36am UTC](https://discuss.elastic.co/t/using-dashboard-control-to-filter-data-views/332771 "2023-05-08T10:36:37Z")

</div>

I am attempting to make a dashboard control that has a list of data views (index patterns). Each of the associated indices contain a different category of computer assets by role. The end goal is that the dashboard user …

---

## [Logstash file input](https://discuss.elastic.co/t/logstash-file-input/332802)

<div class="topic-metadata">

**Author:** [@Vivek\_Shinde](https://discuss.elastic.co/u/Vivek_Shinde)\
**Replies:** 0\
**Last updated:** [May 8, 2023, 10:00am UTC](https://discuss.elastic.co/t/logstash-file-input/332802 "2023-05-08T10:00:15Z")

</div>

Hi Team, Need some advice regarding configuration options for file input. If we have multiple patterns for files to watch for, what are pros and cons for below options Configuring each file path pattern as a dedicated…

---

## [Alias creation](https://discuss.elastic.co/t/alias-creation/332273)

<div class="topic-metadata">

**Author:** [@sebinnsebastiann](https://discuss.elastic.co/u/sebinnsebastiann)\
**Replies:** 4\
**Last updated:** [May 8, 2023, 8:55am UTC](https://discuss.elastic.co/t/alias-creation/332273 "2023-05-08T08:55:08Z")

</div>

I deployed efk-8.7.0 using kubernetes. elasticsearch: docker.elastic.co/elasticsearch/elasticsearch:8.7.0 kibana: docker.elastic.co/kibana/kibana:8.7.0 fluentbit: fluent/fluent-bit:2.1.1 Everyday logs are created …

---

## [Unable to see some OTel log attributes on Elastic APM-Server 8.6.2](https://discuss.elastic.co/t/unable-to-see-some-otel-log-attributes-on-elastic-apm-server-8-6-2/332565)

<div class="topic-metadata">

**Author:** [@Chris\_Lai](https://discuss.elastic.co/u/Chris_Lai)\
**Replies:** 2\
**Last updated:** [May 8, 2023, 8:07am UTC](https://discuss.elastic.co/t/unable-to-see-some-otel-log-attributes-on-elastic-apm-server-8-6-2/332565 "2023-05-08T08:07:02Z")

</div>

Hi, I've set up OTel integration with Elastic stack with the following guide - OpenTelemetry native support | APM User Guide \[8.7\] | Elastic. The setup I've have is using OTel collector to send the logs data to APM ser…

---

## [Extracting unique labels in the field and wordcount](https://discuss.elastic.co/t/extracting-unique-labels-in-the-field-and-wordcount/332567)

<div class="topic-metadata">

**Author:** [@Rama\_Krishna2](https://discuss.elastic.co/u/Rama_Krishna2)\
**Replies:** 1\
**Last updated:** [May 8, 2023, 7:44am UTC](https://discuss.elastic.co/t/extracting-unique-labels-in-the-field-and-wordcount/332567 "2023-05-08T07:44:00Z")

</div>

Hello all, I have some data stored in Elastic Search Kibana 7.17.3 for one year time period, and I want to analyze a specific field to see how many unique labels it has and how many times each label was mentioned on a d…

---

## [Not able to integrate async-profiler with the APM agent](https://discuss.elastic.co/t/not-able-to-integrate-async-profiler-with-the-apm-agent/332794)

<div class="topic-metadata">

**Author:** [@Bhanu\_Praveen](https://discuss.elastic.co/u/Bhanu_Praveen)\
**Replies:** 0\
**Last updated:** [May 8, 2023, 7:23am UTC](https://discuss.elastic.co/t/not-able-to-integrate-async-profiler-with-the-apm-agent/332794 "2023-05-08T07:23:49Z")

</div>

Hello, Need to capture native threads and method information with profiling information. profiling\_inferred\_spans\_enabled=true profiling\_inferred\_spans\_sampling\_interval=50ms profiling\_inferred\_spans\_min\_duration=25…

---

## [Nested document or separate index](https://discuss.elastic.co/t/nested-document-or-separate-index/331011)

<div class="topic-metadata">

**Author:** [@Rishabh\_Jain1](https://discuss.elastic.co/u/Rishabh_Jain1)\
**Replies:** 2\
**Last updated:** [May 8, 2023, 6:23am UTC](https://discuss.elastic.co/t/nested-document-or-separate-index/331011 "2023-05-08T06:23:10Z")

</div>

Hi I want to use elasticsearch in our company. The usage is as following: We have million of influencers and each influencers have 1000s of posts just like instagram. I have 2 use cases: Search among these posts and …

---

## [ES hadoop spark connector having a issue with nested json](https://discuss.elastic.co/t/es-hadoop-spark-connector-having-a-issue-with-nested-json/332551)

<div class="topic-metadata">

**Author:** [@Kuldeep\_Pal](https://discuss.elastic.co/u/Kuldeep_Pal)\
**Replies:** 3\
**Last updated:** [May 4, 2023, 3:52pm UTC](https://discuss.elastic.co/t/es-hadoop-spark-connector-having-a-issue-with-nested-json/332551 "2023-05-04T15:52:26Z")

</div>

org.elasticsearch.hadoop.rest.EsHadoopParsingException: org.elasticsearch.hadoop.EsHadoopIllegalStateException: Position for 'contacts.phone' not found in row; typically this is caused by a mapping inconsistency Not abl…

---

## [Problems connecting to ES from Databricks using spark connector](https://discuss.elastic.co/t/problems-connecting-to-es-from-databricks-using-spark-connector/332411)

<div class="topic-metadata">

**Author:** [@lhfo](https://discuss.elastic.co/u/lhfo)\
**Replies:** 2\
**Last updated:** [May 5, 2023, 8:52am UTC](https://discuss.elastic.co/t/problems-connecting-to-es-from-databricks-using-spark-connector/332411 "2023-05-05T08:52:52Z")

</div>

Hi all, I am trying to connect with ES from our Databricks cluster. I have successfully installed elasticsearch-spark-30\_2.12:8.4.3 on the cluster and confirmed that the elastic version == 8.3.4. I am able to query d…

---

## [How to change the cluster name of an elk cluster with 3 master nodes](https://discuss.elastic.co/t/how-to-change-the-cluster-name-of-an-elk-cluster-with-3-master-nodes/332564)

<div class="topic-metadata">

**Author:** [@coy\_aprieto](https://discuss.elastic.co/u/coy_aprieto)\
**Replies:** 3\
**Last updated:** [May 5, 2023, 9:51am UTC](https://discuss.elastic.co/t/how-to-change-the-cluster-name-of-an-elk-cluster-with-3-master-nodes/332564 "2023-05-05T09:51:33Z")

</div>

Hi, I'm trying to find a way to change the cluster name of my whole elk cluster (7 data nodes, 3 master). If i change the cluster name in config and restart a non-current-master node, it will fail to rejoin cluster aft…

---

## [Convert text field to date in ingest pipeline](https://discuss.elastic.co/t/convert-text-field-to-date-in-ingest-pipeline/332595)

<div class="topic-metadata">

**Author:** [@KentLee](https://discuss.elastic.co/u/KentLee)\
**Replies:** 2\
**Last updated:** [May 5, 2023, 12:59pm UTC](https://discuss.elastic.co/t/convert-text-field-to-date-in-ingest-pipeline/332595 "2023-05-05T12:59:25Z")

</div>

Hi, I am creating a ingest pipeline to ingest application log to elastic and I have the log line format as follow: \[2023-05-03 16:12:19,420\] - \[Application Name\] - \[INFO\] - Log details goes here Based on this format I…

---

## [Elasticsearch IndexLifecycleRunner part of source code, log level Setting is not appropriate?](https://discuss.elastic.co/t/elasticsearch-indexlifecyclerunner-part-of-source-code-log-level-setting-is-not-appropriate/332542)

<div class="topic-metadata">

**Author:** [@yujie\_wang](https://discuss.elastic.co/u/yujie_wang)\
**Replies:** 1\
**Last updated:** [May 6, 2023, 2:37am UTC](https://discuss.elastic.co/t/elasticsearch-indexlifecyclerunner-part-of-source-code-log-level-setting-is-not-appropriate/332542 "2023-05-06T02:37:14Z")

</div>

Hi, Recently, I've been reading the source code of the latest version (8.7.1) of Elasticsearch and I have a question about the log level settings that I can't figure out. I noticed that the "current step \[{}\] for index…

---

## [No data received to server](https://discuss.elastic.co/t/no-data-received-to-server/332523)

<div class="topic-metadata">

**Author:** [@target\_test](https://discuss.elastic.co/u/target_test)\
**Replies:** 4\
**Last updated:** [May 8, 2023, 5:30am UTC](https://discuss.elastic.co/t/no-data-received-to-server/332523 "2023-05-08T05:30:21Z")

</div>

i have one agent with status healthy but didn't send any data to the elastic i got this problem after copying my windows machine \*extra note this agent use the agent before that already register

[Previous page](https://discuss.elastic.co/latest.md?page=685)

[Next page](https://discuss.elastic.co/latest.md?page=687)
