# Latest

**URL:** https://discuss.elastic.co/latest.md?page=726

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 727

---

## [Curl command to delete cluster settings](https://discuss.elastic.co/t/curl-command-to-delete-cluster-settings/329019)

<div class="topic-metadata">

**Author:** [@devarajsit](https://discuss.elastic.co/u/devarajsit)\
**Replies:** 2\
**Last updated:** [March 31, 2023, 9:15am UTC](https://discuss.elastic.co/t/curl-command-to-delete-cluster-settings/329019 "2023-03-31T09:15:54Z")

</div>

Hi Team, Is there any API where i can utilize to delete the cluster settings? I have configured the cluster settings to use sniff mode but when i tried to change that to proxy mode, i am getting error that its already …

---

## [Configure Username and password](https://discuss.elastic.co/t/configure-username-and-password/328913)

<div class="topic-metadata">

**Author:** [@ANUBHAV\_GUPTA](https://discuss.elastic.co/u/ANUBHAV_GUPTA)\
**Replies:** 6\
**Last updated:** [March 31, 2023, 9:11am UTC](https://discuss.elastic.co/t/configure-username-and-password/328913 "2023-03-31T09:11:47Z")

</div>

How to configure the username and password while running elasticsearch in Docker without docker-compose.

---

## [Date range not working as expected between Elasticsearch 7.17 and Elasticsearch 8.6](https://discuss.elastic.co/t/date-range-not-working-as-expected-between-elasticsearch-7-17-and-elasticsearch-8-6/328825)

<div class="topic-metadata">

**Author:** [@MarynaCherniavska](https://discuss.elastic.co/u/MarynaCherniavska)\
**Replies:** 3\
**Last updated:** [March 31, 2023, 8:50am UTC](https://discuss.elastic.co/t/date-range-not-working-as-expected-between-elasticsearch-7-17-and-elasticsearch-8-6/328825 "2023-03-31T08:50:08Z")

</div>

We're exploring a move from (self-managed) Elasticsearch 7.17 to Elasticsearch 8.6. Some of the tests on the application fail if we switch. We traced the failure to an inconsistency between the results on the range using…

---

## [When connected jira cloud with workplace search fields coming in are not same as earlier connection?](https://discuss.elastic.co/t/when-connected-jira-cloud-with-workplace-search-fields-coming-in-are-not-same-as-earlier-connection/328209)

<div class="topic-metadata">

**Author:** [@Fiza](https://discuss.elastic.co/u/Fiza)\
**Replies:** 6\
**Last updated:** [March 31, 2023, 8:42am UTC](https://discuss.elastic.co/t/when-connected-jira-cloud-with-workplace-search-fields-coming-in-are-not-same-as-earlier-connection/328209 "2023-03-31T08:42:07Z")

</div>

I connected my another enterprise search with the same jira cloud instance as before. Earlier when I connected, I was getting one field TTR which is missing right now in my new connection. I tried to find out the reason …

---

## [Elasticsearch installation using helm chart ..Used nfs-storageclass](https://discuss.elastic.co/t/elasticsearch-installation-using-helm-chart-used-nfs-storageclass/329025)

<div class="topic-metadata">

**Author:** [@thirumoorthy](https://discuss.elastic.co/u/thirumoorthy)\
**Replies:** 2\
**Last updated:** [March 31, 2023, 8:40am UTC](https://discuss.elastic.co/t/elasticsearch-installation-using-helm-chart-used-nfs-storageclass/329025 "2023-03-31T08:40:44Z")

</div>

ERROR: {"@timestamp":"2023-03-31T08:10:14.942Z", "log.level":"ERROR", "message":"uncaught exception in thread \[process reaper (pid 228)\]", "ecs.version": "1.2.0","service.name":"ES\_ECS","event.dataset":"elasticsearch.se…

---

## [CloudWatch input plugin not working with EC2 namespace](https://discuss.elastic.co/t/cloudwatch-input-plugin-not-working-with-ec2-namespace/329026)

<div class="topic-metadata">

**Author:** [@kanny](https://discuss.elastic.co/u/kanny)\
**Replies:** 0\
**Last updated:** [March 31, 2023, 8:19am UTC](https://discuss.elastic.co/t/cloudwatch-input-plugin-not-working-with-ec2-namespace/329026 "2023-03-31T08:19:16Z")

</div>

Hello, When I ran Logstash 8.6.2 version to collect EC2 CloudWatch metrics, the process returned "Exception: NameError". As far as I know by testing, this exception happends only for AWS/EC2 namespace, and setting for …

---

## [What should the bucket path be with a top hits](https://discuss.elastic.co/t/what-should-the-bucket-path-be-with-a-top-hits/329024)

<div class="topic-metadata">

**Author:** [@m.a.tanaka](https://discuss.elastic.co/u/m.a.tanaka)\
**Replies:** 0\
**Last updated:** [March 31, 2023, 8:16am UTC](https://discuss.elastic.co/t/what-should-the-bucket-path-be-with-a-top-hits/329024 "2023-03-31T08:16:17Z")

</div>

I am trying to create a query in elasticsearch, which is able to retrieve the documents for each group, which is the latest document within each group and meet a specific criteria. But I have not been able to solve this …

---

## [Logstash can't talk to Elasticsearch but I can access from the browser](https://discuss.elastic.co/t/logstash-cant-talk-to-elasticsearch-but-i-can-access-from-the-browser/328970)

<div class="topic-metadata">

**Author:** [@crimson\_med](https://discuss.elastic.co/u/crimson_med)\
**Replies:** 0\
**Last updated:** [March 30, 2023, 6:18pm UTC](https://discuss.elastic.co/t/logstash-cant-talk-to-elasticsearch-but-i-can-access-from-the-browser/328970 "2023-03-30T18:18:52Z")

</div>

I have been trying to configure the ELK stack to use our wildcard certificate however this has been impossible until now. Logstash and kibana are unable to talk to elasticsearch however i can curl with no issues. Resul…

---

## [Autocompletion by most popular phrases in the text](https://discuss.elastic.co/t/autocompletion-by-most-popular-phrases-in-the-text/329012)

<div class="topic-metadata">

**Author:** [@Quaerere](https://discuss.elastic.co/u/Quaerere)\
**Replies:** 0\
**Last updated:** [March 31, 2023, 6:52am UTC](https://discuss.elastic.co/t/autocompletion-by-most-popular-phrases-in-the-text/329012 "2023-03-31T06:52:59Z")

</div>

Let's say I have many text fields indexed: { "body": "The quick brown fox jumps over the lazy dog" } { "body": "There was a quick brown fox in a forest" } { "body": "Forest was a most fun place for a lazy dog to…

---

## ["Internal Server error" while pulling the data from elastic search](https://discuss.elastic.co/t/internal-server-error-while-pulling-the-data-from-elastic-search/328898)

<div class="topic-metadata">

**Author:** [@zameer712](https://discuss.elastic.co/u/zameer712)\
**Replies:** 2\
**Last updated:** [March 31, 2023, 6:46am UTC](https://discuss.elastic.co/t/internal-server-error-while-pulling-the-data-from-elastic-search/328898 "2023-03-31T06:46:28Z")

</div>

Hello team, we are using Elastic cloud on Azure and all the versions of kibana, filebeat , Elasticsearch is 8.6.2 right now. Facing an issue respect to one of our API please help by checking below error { "id": "c70b…

---

## [Why mutate will influence different pipelines?](https://discuss.elastic.co/t/why-mutate-will-influence-different-pipelines/328210)

<div class="topic-metadata">

**Author:** [@AlanChan](https://discuss.elastic.co/u/AlanChan)\
**Replies:** 9\
**Last updated:** [March 31, 2023, 6:44am UTC](https://discuss.elastic.co/t/why-mutate-will-influence-different-pipelines/328210 "2023-03-31T06:44:11Z")

</div>

Hi I'd like to process the same input data in different ways to get different results, so I'm trying to do with multiple pipelines. However, I notice that using mutate will influence other pipelines. Does anyone know ho…

---

## [Error parsing json but data still thrown to elastic](https://discuss.elastic.co/t/error-parsing-json-but-data-still-thrown-to-elastic/328922)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 5\
**Last updated:** [March 31, 2023, 4:03am UTC](https://discuss.elastic.co/t/error-parsing-json-but-data-still-thrown-to-elastic/328922 "2023-03-31T04:03:40Z")

</div>

Hi there, i want to ask about this error. anyone know what this error is trying to tell ? exception=\>java.lang.ClassCastException: class org.jruby.RubyHash cannot be cast to class org.jruby.RubyIO (org.jruby.RubyHash a…

---

## [API: Exporting the data into CSV file](https://discuss.elastic.co/t/api-exporting-the-data-into-csv-file/328967)

<div class="topic-metadata">

**Author:** [@mruthyu](https://discuss.elastic.co/u/mruthyu)\
**Replies:** 4\
**Last updated:** [March 31, 2023, 6:05am UTC](https://discuss.elastic.co/t/api-exporting-the-data-into-csv-file/328967 "2023-03-31T06:05:09Z")

</div>

Is there any API which supports the exports of data in CSV format from elasticsearch?

---

## [Issue connecting to Elastic from Metricbeat](https://discuss.elastic.co/t/issue-connecting-to-elastic-from-metricbeat/327833)

<div class="topic-metadata">

**Author:** [@SANTHOSH\_R](https://discuss.elastic.co/u/SANTHOSH_R)\
**Replies:** 5\
**Last updated:** [March 31, 2023, 5:32am UTC](https://discuss.elastic.co/t/issue-connecting-to-elastic-from-metricbeat/327833 "2023-03-31T05:32:09Z")

</div>

I am getting following error , when i tried to connect to elastic (which is in another server) from metricbeat server. What could be the issue ? Can you guys help on it . Thanks in Advance PS C:\\ELK\_PROD\\Metricbeat\> .\\m…

---

## [Recommended settings with close\_removed and clean\_removed false](https://discuss.elastic.co/t/recommended-settings-with-close-removed-and-clean-removed-false/327226)

<div class="topic-metadata">

**Author:** [@running\_banana](https://discuss.elastic.co/u/running_banana)\
**Replies:** 1\
**Last updated:** [March 31, 2023, 5:26am UTC](https://discuss.elastic.co/t/recommended-settings-with-close-removed-and-clean-removed-false/327226 "2023-03-31T05:26:23Z")

</div>

Hi, We were looking to tune our filebeat.autodiscover settings to better handle scraping of ephemeral docker containers. The main issue we have is that when the container is stopped and removed, its log file also gets r…

---

## [Unable to start logstash on Amazon EC2 with Windows Server 2022](https://discuss.elastic.co/t/unable-to-start-logstash-on-amazon-ec2-with-windows-server-2022/328986)

<div class="topic-metadata">

**Author:** [@xavier76](https://discuss.elastic.co/u/xavier76)\
**Replies:** 1\
**Last updated:** [March 31, 2023, 5:01am UTC](https://discuss.elastic.co/t/unable-to-start-logstash-on-amazon-ec2-with-windows-server-2022/328986 "2023-03-31T05:01:58Z")

</div>

The erorr I'm getting is below. \[2023-03-30T23:40:36,465\]\[INFO \]\[logstash.runner \] Starting Logstash {"logstash.version"=\>"8.6.2", "jruby.version"=\>"jruby 9.3.10.0 (2.6.8) 2023-02-01 107b2e6697 OpenJDK 64-Bit S…

---

## [Elastic Agents infinitely revisioning, stops sending data to Elasticsearch](https://discuss.elastic.co/t/elastic-agents-infinitely-revisioning-stops-sending-data-to-elasticsearch/328996)

<div class="topic-metadata">

**Author:** [@johnkim](https://discuss.elastic.co/u/johnkim)\
**Replies:** 0\
**Last updated:** [March 31, 2023, 4:50am UTC](https://discuss.elastic.co/t/elastic-agents-infinitely-revisioning-stops-sending-data-to-elasticsearch/328996 "2023-03-31T04:50:34Z")

</div>

I have a combination of problem symptoms that may be caused by multiple issues, but since I don't know for sure what is the cause I'm compiling my issues into one thread. First, my ECK is self-managed. There are two thi…

---

## [How to get creation timestamp of input file](https://discuss.elastic.co/t/how-to-get-creation-timestamp-of-input-file/328533)

<div class="topic-metadata">

**Author:** [@Zak1](https://discuss.elastic.co/u/Zak1)\
**Replies:** 4\
**Last updated:** [March 31, 2023, 4:54am UTC](https://discuss.elastic.co/t/how-to-get-creation-timestamp-of-input-file/328533 "2023-03-31T04:54:48Z")

</div>

Am using logstash to parse an input logfile and subsequently sends data to elasticsearch. I would like to capture the creation date/timestamp of the input logfile as a field on the event. How best to go about this? Fyi, …

---

## [Kibana URL template dynamic url generation](https://discuss.elastic.co/t/kibana-url-template-dynamic-url-generation/328951)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 0\
**Last updated:** [March 30, 2023, 2:50pm UTC](https://discuss.elastic.co/t/kibana-url-template-dynamic-url-generation/328951 "2023-03-30T14:50:20Z")

</div>

Hello All, I've a requrirement where in When I create index pattern under which I'd like to create url template that would dynamically update the host and port. ex: http://abc:8089/web-ui/#/login I'd like to know a w…

---

## [Elasticsearch 5.5.1 version not reflecting after installation on debian based system](https://discuss.elastic.co/t/elasticsearch-5-5-1-version-not-reflecting-after-installation-on-debian-based-system/328831)

<div class="topic-metadata">

**Author:** [@beju](https://discuss.elastic.co/u/beju)\
**Replies:** 5\
**Last updated:** [March 31, 2023, 4:36am UTC](https://discuss.elastic.co/t/elasticsearch-5-5-1-version-not-reflecting-after-installation-on-debian-based-system/328831 "2023-03-31T04:36:05Z")

</div>

wget https://artifacts.elastic.co/downloads/elasticsearch/elasticsearch-5.5.1.deb sha1sum elasticsearch-5.5.1.deb sudo dpkg -i elasticsearch-5.5.1.deb n# curl -XGET 'http://localhost:9200' { "name" : "advance365", …

---

## [Will legacy index template work after version 8 upgrade?](https://discuss.elastic.co/t/will-legacy-index-template-work-after-version-8-upgrade/327908)

<div class="topic-metadata">

**Author:** [@Umang\_Pachaury](https://discuss.elastic.co/u/Umang_Pachaury)\
**Replies:** 8\
**Last updated:** [March 31, 2023, 3:26am UTC](https://discuss.elastic.co/t/will-legacy-index-template-work-after-version-8-upgrade/327908 "2023-03-31T03:26:29Z")

</div>

Hello team, I currently working on cluster with version 7.17.7 and now I am thinking of upgrading it to version 8.x. I received an API deprecation log that Legacy index templates are deprecated in favor of composable te…

---

## [Is there anyway to store document to the index pattern {YYYY.MM.dd} but in CST time {YYYY.MM.dd} via logstash?](https://discuss.elastic.co/t/is-there-anyway-to-store-document-to-the-index-pattern-yyyy-mm-dd-but-in-cst-time-yyyy-mm-dd-via-logstash/328910)

<div class="topic-metadata">

**Author:** [@LongKang\_Fan](https://discuss.elastic.co/u/LongKang_Fan)\
**Replies:** 2\
**Last updated:** [March 31, 2023, 1:54am UTC](https://discuss.elastic.co/t/is-there-anyway-to-store-document-to-the-index-pattern-yyyy-mm-dd-but-in-cst-time-yyyy-mm-dd-via-logstash/328910 "2023-03-31T01:54:19Z")

</div>

Hi I have noticed Logstash stores documents to a {YYYY.MM.dd} index in UTC time. However, my local time is CST time. So, for example, my local time is now 2023/3/30 7:40 AM. The Logstash will store the data to index {20…

---

## [No support for nested math in formula?](https://discuss.elastic.co/t/no-support-for-nested-math-in-formula/327977)

<div class="topic-metadata">

**Author:** [@smchamberlin](https://discuss.elastic.co/u/smchamberlin)\
**Replies:** 2\
**Last updated:** [March 31, 2023, 1:49am UTC](https://discuss.elastic.co/t/no-support-for-nested-math-in-formula/327977 "2023-03-31T01:49:35Z")

</div>

Hello, I was able to get this working in python, but getting the following error when I try to nest math functions in an equation for a heat map lens: Is this not supported? Thank you.

---

## [Filebeat Registry File Growing](https://discuss.elastic.co/t/filebeat-registry-file-growing/328983)

<div class="topic-metadata">

**Author:** [@Rich\_Liberty](https://discuss.elastic.co/u/Rich_Liberty)\
**Replies:** 2\
**Last updated:** [March 30, 2023, 11:23pm UTC](https://discuss.elastic.co/t/filebeat-registry-file-growing/328983 "2023-03-30T23:23:25Z")

</div>

Filebeats 7.4.0 running in a relatively large and busy Tanzu Kubernetes cluster (1.20.x) The Filebeat registry file /var/lib/filebeat-data/registry/filebeat/data.json grows causing disk throttling as the file size gets…

---

## [Elastic cluster, auto-adds/resets new nodes into shard exclusion list](https://discuss.elastic.co/t/elastic-cluster-auto-adds-resets-new-nodes-into-shard-exclusion-list/328927)

<div class="topic-metadata">

**Author:** [@Deepak\_A](https://discuss.elastic.co/u/Deepak_A)\
**Replies:** 2\
**Last updated:** [March 30, 2023, 11:18pm UTC](https://discuss.elastic.co/t/elastic-cluster-auto-adds-resets-new-nodes-into-shard-exclusion-list/328927 "2023-03-30T23:18:10Z")

</div>

Hi All, Whenever I add a scale up my Elastic cluster through GCP console, I see my nodes getting added into cluster allocation exclusion list. Like: GET \_cluster/settings "transient" : { "cluster" : { "routin…

---

## [High CPU usage after updating filebeat from 7.12.0 to 8.6.2](https://discuss.elastic.co/t/high-cpu-usage-after-updating-filebeat-from-7-12-0-to-8-6-2/327249)

<div class="topic-metadata">

**Author:** [@germain\_nganko](https://discuss.elastic.co/u/germain_nganko)\
**Replies:** 10\
**Last updated:** [March 30, 2023, 11:17pm UTC](https://discuss.elastic.co/t/high-cpu-usage-after-updating-filebeat-from-7-12-0-to-8-6-2/327249 "2023-03-30T23:17:57Z")

</div>

After updating to filebeat to 8.6.2 I observe an increase in cpu usage. also tested on 8.6.1 same thing, went back to 8.0.0 and could also observe an increase there, however less than in 8.6.2 and 8.6.1. Is there anythi…

---

## [Issue when installing Elasticsearch using helm by staying in rancher](https://discuss.elastic.co/t/issue-when-installing-elasticsearch-using-helm-by-staying-in-rancher/328827)

<div class="topic-metadata">

**Author:** [@thirumoorthy](https://discuss.elastic.co/u/thirumoorthy)\
**Replies:** 1\
**Last updated:** [March 30, 2023, 11:15pm UTC](https://discuss.elastic.co/t/issue-when-installing-elasticsearch-using-helm-by-staying-in-rancher/328827 "2023-03-30T23:15:23Z")

</div>

my values.yaml file antiAffinity: hard antiAffinityTopologyKey: kubernetes.io/hostname clusterHealthCheckParams: wait\_for\_status=green&timeout=1s clusterName: elasticsearch createCert: true enableServiceLinks: tru…

---

## [Does multinode cluster require different certificates or just one will suffice?](https://discuss.elastic.co/t/does-multinode-cluster-require-different-certificates-or-just-one-will-suffice/328963)

<div class="topic-metadata">

**Author:** [@Umang\_Pachaury](https://discuss.elastic.co/u/Umang_Pachaury)\
**Replies:** 1\
**Last updated:** [March 30, 2023, 11:05pm UTC](https://discuss.elastic.co/t/does-multinode-cluster-require-different-certificates-or-just-one-will-suffice/328963 "2023-03-30T23:05:56Z")

</div>

Hey team, I have a multi node cluster running which has a hot warm architecture. I have multiple hot nodes running on a single machine as docker images and multiple warm nodes running on another machine(this is also a s…

---

## [doc\['LogMessage.keyword'\].size() returns 0 meaning there is no such field when that field exists and has value](https://discuss.elastic.co/t/doc-logmessage-keyword-size-returns-0-meaning-there-is-no-such-field-when-that-field-exists-and-has-value/328665)

<div class="topic-metadata">

**Author:** [@skazan](https://discuss.elastic.co/u/skazan)\
**Replies:** 2\
**Last updated:** [March 30, 2023, 10:04pm UTC](https://discuss.elastic.co/t/doc-logmessage-keyword-size-returns-0-meaning-there-is-no-such-field-when-that-field-exists-and-has-value/328665 "2023-03-30T22:04:52Z")

</div>

I coded a scripted field named "unique\_log\_message\_\_" as show below. The whole purpose of such field is to show a unique version of some other field named "LogMessage.keyword". And to get into a unique value, I simply re…

---

## [Is there a quick and easy way to check if my node is running in compressed oop?](https://discuss.elastic.co/t/is-there-a-quick-and-easy-way-to-check-if-my-node-is-running-in-compressed-oop/328971)

<div class="topic-metadata">

**Author:** [@linkerc](https://discuss.elastic.co/u/linkerc)\
**Replies:** 5\
**Last updated:** [March 30, 2023, 9:48pm UTC](https://discuss.elastic.co/t/is-there-a-quick-and-easy-way-to-check-if-my-node-is-running-in-compressed-oop/328971 "2023-03-30T21:48:52Z")

</div>

version 7.15.3

[Previous page](https://discuss.elastic.co/latest.md?page=725)

[Next page](https://discuss.elastic.co/latest.md?page=727)
