# Latest

**URL:** https://discuss.elastic.co/latest.md?page=718

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 719

---

## [Search for a keyword in the field in the title, which can occur simultaneously several matching words from the query](https://discuss.elastic.co/t/search-for-a-keyword-in-the-field-in-the-title-which-can-occur-simultaneously-several-matching-words-from-the-query/329608)

<div class="topic-metadata">

**Author:** [@oleksiiorel](https://discuss.elastic.co/u/oleksiiorel)\
**Replies:** 0\
**Last updated:** [April 8, 2023, 10:25am UTC](https://discuss.elastic.co/t/search-for-a-keyword-in-the-field-in-the-title-which-can-occur-simultaneously-several-matching-words-from-the-query/329608 "2023-04-08T10:25:38Z")

</div>

I want to find blenders in elastic of a certain name & color and brand. To do this, specify 3 fields for the search, specifying in which field elastic should start the search. Elastic returns products that I have not sea…

---

## [Filebeat can not talk to ELK on AWS EKS](https://discuss.elastic.co/t/filebeat-can-not-talk-to-elk-on-aws-eks/329600)

<div class="topic-metadata">

**Author:** [@williamsun](https://discuss.elastic.co/u/williamsun)\
**Replies:** 2\
**Last updated:** [April 8, 2023, 9:49am UTC](https://discuss.elastic.co/t/filebeat-can-not-talk-to-elk-on-aws-eks/329600 "2023-04-08T09:49:31Z")

</div>

Hello Everyone, I am using the follow doc to setup the filebeat on EKS. curl -L -O https://raw.githubusercontent.com/elastic/beats/8.7/deploy/kubernetes/filebeat-kubernetes.yaml Default Setting does not work name: …

---

## [Logs in kibana are shown every hour, not during the hour](https://discuss.elastic.co/t/logs-in-kibana-are-shown-every-hour-not-during-the-hour/329607)

<div class="topic-metadata">

**Author:** [@habib\_huseyn](https://discuss.elastic.co/u/habib_huseyn)\
**Replies:** 0\
**Last updated:** [April 8, 2023, 8:33am UTC](https://discuss.elastic.co/t/logs-in-kibana-are-shown-every-hour-not-during-the-hour/329607 "2023-04-08T08:33:44Z")

</div>

I send logs from palo alto to the syslog server using rsyslog. If from the syslog server, I send it to elasticsearch with the agent. but in kibana, the logs are shown in every hour, not during the hour

---

## [Schedule , scroll , size Elasticsearch input plugin Plugin more explanation](https://discuss.elastic.co/t/schedule-scroll-size-elasticsearch-input-plugin-plugin-more-explanation/329606)

<div class="topic-metadata">

**Author:** [@alex\_petrov](https://discuss.elastic.co/u/alex_petrov)\
**Replies:** 0\
**Last updated:** [April 8, 2023, 6:11am UTC](https://discuss.elastic.co/t/schedule-scroll-size-elasticsearch-input-plugin-plugin-more-explanation/329606 "2023-04-08T06:11:51Z")

</div>

I am using elasticsearch index as my input in logstash.I read the documentation and don't understand the usage of schedule , scroll , size option.I need more explanation to understand these featues. Thanks

---

## [Design Index & Document](https://discuss.elastic.co/t/design-index-document/329596)

<div class="topic-metadata">

**Author:** [@YB\_Coding](https://discuss.elastic.co/u/YB_Coding)\
**Replies:** 0\
**Last updated:** [April 7, 2023, 6:47pm UTC](https://discuss.elastic.co/t/design-index-document/329596 "2023-04-07T18:47:45Z")

</div>

Hello everyone I have a hard time designing my documents. I do not know if I need to create multiple indexes, use nested fieds or index multiple times my documents with a field with a "versionning filter". Below my analo…

---

## [Updating @elastic/elasticsearch version on npm](https://discuss.elastic.co/t/updating-elastic-elasticsearch-version-on-npm/329595)

<div class="topic-metadata">

**Author:** [@Chukwuma\_Nwaugha](https://discuss.elastic.co/u/Chukwuma_Nwaugha)\
**Replies:** 0\
**Last updated:** [April 7, 2023, 6:01pm UTC](https://discuss.elastic.co/t/updating-elastic-elasticsearch-version-on-npm/329595 "2023-04-07T18:01:27Z")

</div>

The latest version of @elastic/elasticsearch is 8.7.0 but the version on npm is still at 8.6.0. When should an update be expected? Thanks and best regards, Chukwuma.

---

## [Creating an indicator match Watcher Alert](https://discuss.elastic.co/t/creating-an-indicator-match-watcher-alert/329590)

<div class="topic-metadata">

**Author:** [@Banderson02](https://discuss.elastic.co/u/Banderson02)\
**Replies:** 0\
**Last updated:** [April 7, 2023, 5:26pm UTC](https://discuss.elastic.co/t/creating-an-indicator-match-watcher-alert/329590 "2023-04-07T17:26:25Z")

</div>

Hello, Has anyone been able to replicate an indicator match alert like what is provided in Kibana security as an Elasticsearch Watcher alert? I have a deployment where we do not have access to Kibana Security, so I nee…

---

## [Can we create dependent inputs in logstash pipeline?](https://discuss.elastic.co/t/can-we-create-dependent-inputs-in-logstash-pipeline/329436)

<div class="topic-metadata">

**Author:** [@Disha\_Bodade](https://discuss.elastic.co/u/Disha_Bodade)\
**Replies:** 2\
**Last updated:** [April 7, 2023, 4:51pm UTC](https://discuss.elastic.co/t/can-we-create-dependent-inputs-in-logstash-pipeline/329436 "2023-04-07T16:51:15Z")

</div>

Hi Team, I have requirement to get the links from rss feed and extract each link and store its XML page source as a document in ES. I am trying to use rss and http\_poller input plugin together, something like below con…

---

## [Enforce Double quotes using csv codec plugin](https://discuss.elastic.co/t/enforce-double-quotes-using-csv-codec-plugin/329585)

<div class="topic-metadata">

**Author:** [@uzair13151](https://discuss.elastic.co/u/uzair13151)\
**Replies:** 1\
**Last updated:** [April 7, 2023, 4:30pm UTC](https://discuss.elastic.co/t/enforce-double-quotes-using-csv-codec-plugin/329585 "2023-04-07T16:30:09Z")

</div>

Hi All, Is it possible to wrap the data in the rows to be encapsulated by double quotes using csv codec plugin. Currently I am getting: Column1|Column2|Column3 Data1|Data2|"" Expectation: "Column1"|"Column2"|"Colum…

---

## [Elastic Agent show \`Error dialing x509: certificate signed by unknown authority\` but it is healthy in fleet](https://discuss.elastic.co/t/elastic-agent-show-error-dialing-x509-certificate-signed-by-unknown-authority-but-it-is-healthy-in-fleet/329514)

<div class="topic-metadata">

**Author:** [@Kelvin\_Chan](https://discuss.elastic.co/u/Kelvin_Chan)\
**Replies:** 3\
**Last updated:** [April 7, 2023, 5:09am UTC](https://discuss.elastic.co/t/elastic-agent-show-error-dialing-x509-certificate-signed-by-unknown-authority-but-it-is-healthy-in-fleet/329514 "2023-04-07T05:09:06Z")

</div>

I am building elastic stack for testing, which uses self-signed certificate. And i use docker compose to deploy them. Here is part of compose efleet: image: docker.elastic.co/beats/elastic-agent:${STACK\_VERSION} …

---

## [I don't see my index in index management](https://discuss.elastic.co/t/i-dont-see-my-index-in-index-management/329515)

<div class="topic-metadata">

**Author:** [@Hanni](https://discuss.elastic.co/u/Hanni)\
**Replies:** 2\
**Last updated:** [April 7, 2023, 8:59am UTC](https://discuss.elastic.co/t/i-dont-see-my-index-in-index-management/329515 "2023-04-07T08:59:16Z")

</div>

Hello, I'm trying to send data from a CSV file to Elasticsearch using Logstash. I have configured my input, filter, and output, but I cannot find my index in Elasticsearch. I have the impression that Logstash is not proc…

---

## [Workplace search loading time problem](https://discuss.elastic.co/t/workplace-search-loading-time-problem/329268)

<div class="topic-metadata">

**Author:** [@Gunbay\_Park](https://discuss.elastic.co/u/Gunbay_Park)\
**Replies:** 8\
**Last updated:** [April 7, 2023, 6:48am UTC](https://discuss.elastic.co/t/workplace-search-loading-time-problem/329268 "2023-04-07T06:48:07Z")

</div>

HI, there. I'm testing workplace search in internetless intranet env. When I start workplace search (x.x.x.x:5601/ws/search) , it takes time too long to open first page. it takes almost 90 seconds. After opening fir…

---

## [ES upgrade from 5.6 to 8.7](https://discuss.elastic.co/t/es-upgrade-from-5-6-to-8-7/329568)

<div class="topic-metadata">

**Author:** [@salimtb](https://discuss.elastic.co/u/salimtb)\
**Replies:** 1\
**Last updated:** [April 7, 2023, 4:54am UTC](https://discuss.elastic.co/t/es-upgrade-from-5-6-to-8-7/329568 "2023-04-07T04:54:58Z")

</div>

Hi All, I am planning to upgrade the Elasticsearch from 5.6 to 8.7, I wanted to seek suggestions to see if it is a good idea to go directly from 5.6 to 8.7, or do a roll upgrade, application is built on Django and uses …

---

## [Elastic-operator version upgrade](https://discuss.elastic.co/t/elastic-operator-version-upgrade/329571)

<div class="topic-metadata">

**Author:** [@Satyajeet](https://discuss.elastic.co/u/Satyajeet)\
**Replies:** 0\
**Last updated:** [April 7, 2023, 6:42am UTC](https://discuss.elastic.co/t/elastic-operator-version-upgrade/329571 "2023-04-07T06:42:33Z")

</div>

These are our existing environment parameters, GKE version 1.21.14-gke.14100 We had installed Elasticsearch with the following version previously, Elasticsearch version 7.9.2 Elastic Operator version 1.2.1 This is o…

---

## [Backfill with previous indexed data](https://discuss.elastic.co/t/backfill-with-previous-indexed-data/329321)

<div class="topic-metadata">

**Author:** [@suminlim](https://discuss.elastic.co/u/suminlim)\
**Replies:** 1\
**Last updated:** [April 7, 2023, 3:02am UTC](https://discuss.elastic.co/t/backfill-with-previous-indexed-data/329321 "2023-04-07T03:02:23Z")

</div>

using logstash, is it available ? input { elasticsearch { hosts =\> "localhost" index =\> "logs" query =\> '{ "sort": \[ "timeinfo" \] }' } } filter { if \[location\] == "" { // how to get previous data …

---

## [Backfill with previous indexed data](https://discuss.elastic.co/t/backfill-with-previous-indexed-data/329278)

<div class="topic-metadata">

**Author:** [@suminlim](https://discuss.elastic.co/u/suminlim)\
**Replies:** 7\
**Last updated:** [April 7, 2023, 3:01am UTC](https://discuss.elastic.co/t/backfill-with-previous-indexed-data/329278 "2023-04-07T03:01:09Z")

</div>

When the document sorted by timestamp, is there any solution that backfill location data into next row with previous row ???

---

## [Ingest pipeline gsub processor back reference not working](https://discuss.elastic.co/t/ingest-pipeline-gsub-processor-back-reference-not-working/329090)

<div class="topic-metadata">

**Author:** [@kmfreder1](https://discuss.elastic.co/u/kmfreder1)\
**Replies:** 8\
**Last updated:** [April 7, 2023, 12:36am UTC](https://discuss.elastic.co/t/ingest-pipeline-gsub-processor-back-reference-not-working/329090 "2023-04-07T00:36:18Z")

</div>

I am having trouble getting a back reference to work using the gsub processor in the elasticsearch ingest node pipeline. I am trying to get just the TLD from a dns.question.name field and using very similar syntax to wh…

---

## [Azure Elastic Cloud - NEST Client - API call fails with Faulted](https://discuss.elastic.co/t/azure-elastic-cloud-nest-client-api-call-fails-with-faulted/329558)

<div class="topic-metadata">

**Author:** [@rahul-reveation](https://discuss.elastic.co/u/rahul-reveation)\
**Replies:** 0\
**Last updated:** [April 6, 2023, 9:56pm UTC](https://discuss.elastic.co/t/azure-elastic-cloud-nest-client-api-call-fails-with-faulted/329558 "2023-04-06T21:56:28Z")

</div>

On Azure, we have a.Net Core App that connects to ES Cloud. The app makes use of the NEST client. We've recently noticed intermittent issues where the client call to ES would fail at random. Azure Insight reports that it…

---

## [Max limit for number of search results](https://discuss.elastic.co/t/max-limit-for-number-of-search-results/329544)

<div class="topic-metadata">

**Author:** [@mruthyu](https://discuss.elastic.co/u/mruthyu)\
**Replies:** 1\
**Last updated:** [April 6, 2023, 7:29pm UTC](https://discuss.elastic.co/t/max-limit-for-number-of-search-results/329544 "2023-04-06T19:29:08Z")

</div>

What is the limit on number of search results by Elasticsearch? Is it 10,000? Which config parameter drives this count? Is it possible to export documents in terms of millions?

---

## [Desired Balance Allocator stuck - preventing assignment of new shards](https://discuss.elastic.co/t/desired-balance-allocator-stuck-preventing-assignment-of-new-shards/328633)

<div class="topic-metadata">

**Author:** [@itizir](https://discuss.elastic.co/u/itizir)\
**Replies:** 15\
**Last updated:** [April 6, 2023, 7:17pm UTC](https://discuss.elastic.co/t/desired-balance-allocator-stuck-preventing-assignment-of-new-shards/328633 "2023-04-06T19:17:54Z")

</div>

Hello, On one of our larger stacks, we have recently seen (twice last week) a problem seemingly related to the new 'desired balance allocator'. The documentation seems to imply this is purely a background operation so t…

---

## [Update to 8.7.0](https://discuss.elastic.co/t/update-to-8-7-0/329525)

<div class="topic-metadata">

**Author:** [@adis3421](https://discuss.elastic.co/u/adis3421)\
**Replies:** 4\
**Last updated:** [April 6, 2023, 6:18pm UTC](https://discuss.elastic.co/t/update-to-8-7-0/329525 "2023-04-06T18:18:39Z")

</div>

Hi, I have problem with kibana Analitycs \> Discover after update to version 8.7.0 from 8.6.1 on Oracle Linux 8.7 many options working without error

---

## [How to pass the aggs top 1 value to the query](https://discuss.elastic.co/t/how-to-pass-the-aggs-top-1-value-to-the-query/329496)

<div class="topic-metadata">

**Author:** [@vrviji](https://discuss.elastic.co/u/vrviji)\
**Replies:** 6\
**Last updated:** [April 6, 2023, 4:38pm UTC](https://discuss.elastic.co/t/how-to-pass-the-aggs-top-1-value-to-the-query/329496 "2023-04-06T16:38:35Z")

</div>

I am trying to create an alert using ElasticDSL 7.17 query. I need to filter the documents based on certain condition and group the documents on a field and get the top first group. My query should match only the top gro…

---

## [I need help creating a Kibana visualization](https://discuss.elastic.co/t/i-need-help-creating-a-kibana-visualization/329535)

<div class="topic-metadata">

**Author:** [@em817m](https://discuss.elastic.co/u/em817m)\
**Replies:** 2\
**Last updated:** [April 6, 2023, 4:30pm UTC](https://discuss.elastic.co/t/i-need-help-creating-a-kibana-visualization/329535 "2023-04-06T16:30:16Z")

</div>

I am new to Kibana and need to create a visualization for some performance data that I have collected. I am running Kibana 6.3.0. The data is extracted from a CSV file and looks like this in Kibana Discover window: W…

---

## [Effects of changing ILM policy](https://discuss.elastic.co/t/effects-of-changing-ilm-policy/329516)

<div class="topic-metadata">

**Author:** [@india](https://discuss.elastic.co/u/india)\
**Replies:** 1\
**Last updated:** [April 6, 2023, 3:54pm UTC](https://discuss.elastic.co/t/effects-of-changing-ilm-policy/329516 "2023-04-06T15:54:04Z")

</div>

I am using Elasticsearch 7.17.0. I have configured ILM policy in following way: "post\_policy" : { "version" : 1, "modified\_date" : "2021-07-26T19:20:56.981Z", "policy" : { "phases" : { "hot…

---

## [Express.js not sending compressed files to front-end after compression enabled](https://discuss.elastic.co/t/express-js-not-sending-compressed-files-to-front-end-after-compression-enabled/329532)

<div class="topic-metadata">

**Author:** [@Akaash\_Mukherjee](https://discuss.elastic.co/u/Akaash_Mukherjee)\
**Replies:** 0\
**Last updated:** [April 6, 2023, 3:49pm UTC](https://discuss.elastic.co/t/express-js-not-sending-compressed-files-to-front-end-after-compression-enabled/329532 "2023-04-06T15:49:47Z")

</div>

I have an express.js server that's pulling data from Elasticsearch and serving it to the browser. I was under the impression that all I needed to do for the express app to send compressed responses was activating compres…

---

## [Ingest Pipeline - Date Processor Timezone](https://discuss.elastic.co/t/ingest-pipeline-date-processor-timezone/329457)

<div class="topic-metadata">

**Author:** [@tmslara.a](https://discuss.elastic.co/u/tmslara.a)\
**Replies:** 7\
**Last updated:** [April 6, 2023, 3:48pm UTC](https://discuss.elastic.co/t/ingest-pipeline-date-processor-timezone/329457 "2023-04-06T15:48:39Z")

</div>

Hello, I'm trying to configure an ingest pipeline using Kibana. I'm ingesting data into Elasticsearch using filebeat and this pipeline. Among other fields, I'm ingesting the document's timestamp. To "parse" the date fro…

---

## [Parse log file line by line](https://discuss.elastic.co/t/parse-log-file-line-by-line/329518)

<div class="topic-metadata">

**Author:** [@pen120](https://discuss.elastic.co/u/pen120)\
**Replies:** 3\
**Last updated:** [April 6, 2023, 1:58pm UTC](https://discuss.elastic.co/t/parse-log-file-line-by-line/329518 "2023-04-06T13:58:53Z")

</div>

I have a log file with output repetitive below, I want to parse this log line by line in fields to extract the value for each line 10:31:07 2022/10/16 ZBXTRAP 192.168.23.2 PDU INFO: messageid 0 …

---

## [Engine index disappeared After upgrading from version 7.16.2 to 7.17.9 in Elasticsearch App Search](https://discuss.elastic.co/t/engine-index-disappeared-after-upgrading-from-version-7-16-2-to-7-17-9-in-elasticsearch-app-search/329476)

<div class="topic-metadata">

**Author:** [@ikngoo](https://discuss.elastic.co/u/ikngoo)\
**Replies:** 1\
**Last updated:** [April 6, 2023, 1:58pm UTC](https://discuss.elastic.co/t/engine-index-disappeared-after-upgrading-from-version-7-16-2-to-7-17-9-in-elasticsearch-app-search/329476 "2023-04-06T13:58:44Z")

</div>

After upgrading from version 7.16.2 to 7.17.9, we encountered an issue in Elasticsearch App Search where the engine index disappeared. We were still able to query the documents in the original index, but we were unable t…

---

## [Elastic licences](https://discuss.elastic.co/t/elastic-licences/329174)

<div class="topic-metadata">

**Author:** [@Joel\_Goncalves](https://discuss.elastic.co/u/Joel_Goncalves)\
**Replies:** 21\
**Last updated:** [April 6, 2023, 1:17pm UTC](https://discuss.elastic.co/t/elastic-licences/329174 "2023-04-06T13:17:42Z")

</div>

Hello, I have a cluster with 1 master and 2 nodes, if I install the enterpise license on a node, will it move to the other node or to the master?

---

## [Unable to authenticate user \[logstash\_internal\] for REST request \[/bulk\]](https://discuss.elastic.co/t/unable-to-authenticate-user-logstash-internal-for-rest-request-bulk/329473)

<div class="topic-metadata">

**Author:** [@oscardoudou](https://discuss.elastic.co/u/oscardoudou)\
**Replies:** 3\
**Last updated:** [April 6, 2023, 12:59pm UTC](https://discuss.elastic.co/t/unable-to-authenticate-user-logstash-internal-for-rest-request-bulk/329473 "2023-04-06T12:59:33Z")

</div>

logstash 7.17.9 \[2023-04-05T22:50:02,837\]\[ERROR\]\[logstash.outputs.elasticsearch\]\[main\] Encountered a retryable error (will retry with exponential backoff) {:code=\>401, :url=\>"http://server:9200/\_bulk", :content\_length=\>…

[Previous page](https://discuss.elastic.co/latest.md?page=717)

[Next page](https://discuss.elastic.co/latest.md?page=719)
