Connector known issues

Important

Enterprise Search is not available in Elastic Stack 9.0+.

The connector service has the following known issues:

  • OOM errors when syncing large database tables

    Syncs after the initial sync can cause out-of-memory (OOM) errors when syncing large database tables. This occurs because database connectors load and store IDs in memory. For tables with millions of records, this can lead to memory exhaustion if the connector service has insufficient RAM.

    To mitigate this issue, you can:

    • Increase RAM allocation:

      • Self-managed: Increase RAM allocation for the machine/container running the connector service.

    • Optimize sync rules:

      • Review and optimize sync rules to filter and reduce data retrieved from the source before syncing.
  • Upgrades from deployments running on versions earlier than 8.9.0 can cause sync job failures

    Due to a bug, the job_type field mapping will be missing after upgrading from deployments running on versions earlier than 8.9.0. Sync jobs won’t be displayed in the Kibana UI (job history) and the connector service won’t be able to start new sync jobs. This will only occur if you have previously scheduled sync jobs.

    To resolve this issue, you can manually add the missing field with the following command and trigger a sync job:

    				PUT .elastic-connectors-sync-jobs-v1/_mapping
    					{
      "properties": {
        "job_type": {
          "type": "keyword"
        }
      }
    }
    		
  • The connector service will fail to sync when the connector tries to fetch more more than 2,147,483,647 (2^31-1) documents from a data source

    A workaround is to manually partition the data to be synced using multiple search indices.

  • Custom scheduling might break when upgrading from version 8.6 or earlier.

    If you encounter the error 'custom_schedule_triggered': undefined method 'each' for nil:NilClass (NoMethodError), it means the custom scheduling feature migration failed. You can use the following manual workaround:

    				POST /.elastic-connectors/_update/connector-id
    					{
      "doc": {
        "custom_scheduling": {}
      }
    }
    		

    This error can appear on Connectors or Crawlers that aren’t the cause of the issue. If the error continues, try running the above command for every document in the .elastic-connectors index.

  • Connectors upgrading from 8.7 or earlier can be missing configuration fields

    A connector that was created prior to 8.8 can sometimes be missing configuration fields. This is a known issue for the MySQL connector but could also affect other connectors.

    If the self-managed connector raises the error Connector for <connector_id> has missing configuration fields: <field_a>, <field_b>..., you can resolve the error by manually adding the missing configuration fields via the Dev Tools. Only the following two field properties are required, as the rest will be autopopulated by the self-managed connector:

    • type: one of str, int, bool, or list

    • value: any value, as long as it is of the correct type (list type values should be saved as comma-separated strings)

      				POST /.elastic-connectors/_update/connector_id
      					{
        "doc" : {
          "configuration": {
            "field_a": {
              "type": "str",
              "value": ""
            },
            "field_b": {
              "type": "bool",
              "value": false
            },
            "field_c": {
              "type": "int",
              "value": 1
            },
            "field_d": {
              "type": "list",
              "value": "a,b"
            }
          }
        }
      }
      		
  • Python connectors that upgraded from 8.7.1 will report document volumes in gigabytes (GB) instead of megabytes (MB)

    As a result, true document volume will be under-reported by a factor of 1024.

  • DLS queries fail to match documents for content indices created on 9.0+

    The DLS query template stored in access control documents (.search-acl-filter-* indices) references the sub-field _allow_access_control.enum. This sub-field was created by a custom dynamic mapping template that was removed in connectors v9.0.0. Under Elasticsearch's default dynamic mapping, the correct sub-field is _allow_access_control.keyword. As a result, DLS-protected documents are silently filtered out — users see no results for documents that have access control set.

    Affected versions: 9.0.0+, for any content index created after upgrading. Indices created before 9.0 are not affected because the old mapping is preserved.

    Workaround: After fetching the DLS query from the access control document, replace _allow_access_control.enum with _allow_access_control.keyword before using it in an API key role descriptor.

    Fix: Tracked in elastic/connectors#4005. After the fix is deployed, re-run an access control sync so the corrected query template is written to the .search-acl-filter-* documents.

  • Generic database connectors fail to sync with ModuleNotFoundError: No module named 'pkg_resources'

    The pinned python-tds 1.12.0 dependency, loaded transitively by the generic database connectors through sqlalchemy_pytds, imports pkg_resources at module load time. Starting in 9.3.0, the official elastic-connectors Docker image no longer ships setuptools in the connector service's Python environment, and therefore does not provide pkg_resources. As a result, the connectors fail with ModuleNotFoundError: No module named 'pkg_resources' when attempting to connect to the data source, and syncs cannot start.

    Affected versions: docker.elastic.co/integrations/elastic-connectors images 9.3.0 and later. Earlier versions are not affected because their image still ships setuptools. Self-managed deployments that install setuptools into their Python environment are also unaffected.

    Fix: Tracked in elastic/connectors#4014. The fix is to bump python-tds to >=1.15.0, where the pkg_resources import was removed.

  • Content Connectors entry in Stack Management is visible to users without the content_connectors capability

    Even if a user did not have the management.data.content_connectors capability, they saw the Content Connectors entry in the Stack Management sidebar. Navigating to it returned a 403.

    Affected versions: Kibana 9.1 through 9.4.

    Fix: Resolved in elastic/kibana#271709 and shipped in Kibana 9.3.6, 9.4.3, and 9.5.0

  • Jira Server/Data Center syncs fail to fetch issues

    elastic/connectors#3710 migrated the Jira issues endpoint to the cursor-based rest/api/3/search/jql endpoint. That endpoint is not available on Jira Server/Data Center pre-v10, so syncs against those instances fail when fetching issues.

    Affected versions: 8.18.8+, 8.19.5-8.19.16, 9.0.8+, 9.1.5+, 9.2.0+, 9.3.0–9.3.5, and 9.4.0–9.4.2. Jira Cloud is not affected.

    Fix: elastic/connectors#4059, shipped in 8.19.17, 9.3.6, 9.4.3, and 9.5.0.

  • Outlook connector fails to sync on non-English Exchange servers

    The connector resolved default folders by English display names (Contacts, Archive). On localized on-prem Exchange servers these names differ, raising ErrorFolderNotFound and aborting the sync.

    Affected versions: 8.11.0–8.19.16, 9.0.0–9.3.5, and 9.4.0–9.4.2. Non-English on-prem Exchange servers only.

    Fix: elastic/connectors#4065, shipped in 8.19.17, 9.3.6, 9.4.3, and 9.5.0. Folders are now resolved by locale-agnostic distinguished folder IDs; the Archive leaf folder still has no distinguished ID in Exchange and is skipped on localized servers when absent.

  • Outlook connector fails when Active Directory users lack a mail attribute

    On on-prem Exchange, the connector passed the raw LDAP mail attribute into exchangelib.Account. When the attribute is missing, ldap3 returns [], causing ValueError: primary_smtp_address [] is not an email address and aborting the sync.

    Affected versions: 8.11.0–8.19.16, 9.0.0–9.3.5, and 9.4.0–9.4.2. On-prem Exchange with Active Directory only.

    Fix: elastic/connectors#4078, shipped in 8.19.17, 9.3.6, 9.4.3, and 9.5.0.

  • Outlook connector aborts the sync for mailbox-less accounts or when SSL is enabled without a certificate

    On on-prem Exchange, AD users with an SMTP address but no mailbox caused ErrorNonExistentMailbox and aborted the whole sync. Separately, ssl_enabled with an empty certificate wrote an empty CA file and raised NO_CERTIFICATE_OR_CRL_FOUND.

    Affected versions: 8.11.0–8.19.17, 9.0.0–9.3.6, and 9.4.0–9.4.2. On-prem Exchange only.

    Fix: elastic/connectors#4085, shipped in 8.19.18, 9.3.7, 9.4.3, and 9.5.0. Mailbox-less accounts are skipped with a warning; SSL with no certificate falls back to an unverified connection and logs a warning.

  • Outlook connector syncs intermittently fail with NO_CERTIFICATE_OR_CRL_FOUND when SSL is enabled

    With SSL enabled, the connector wrote the configured CA to a fixed file on disk (outlook_cert.cer) shared across the process. Concurrent or overlapping syncs raced on it, causing an intermittent SSLError: [X509] no certificate or crl found (NO_CERTIFICATE_OR_CRL_FOUND) that aborted syncs with no configuration change between runs.

    Affected versions: 8.11.0–8.19.18, 9.0.0–9.3.7, and 9.4.0–9.4.3. On-prem Exchange with SSL enabled only.

    Fix: elastic/connectors#4094, shipped in 8.19.19, 9.3.8, 9.4.4, and 9.5.0.

  • Confluence Data Center / Server syncs can fail with HTTP 500 and require site-admin credentials

    Content search expanded unused space.permissions on Data Center / Server. That expansion can return HTTP 500 for non-administrator accounts (CONFSERVER-99908), which forced customers to over-grant site admin to the functional user. Confluence Cloud is not affected.

    Affected versions: 8.7.0–8.19.18, 9.0.0–9.3.7, and 9.4.0–9.4.3. Confluence Data Center / Server only.

    Fix: elastic/connectors#4118, shipped in 8.19.19, 9.3.8, 9.4.4, and 9.5.0.

  • GitHub connector syncs can succeed while indexing little or no data

    Page-level fetch failures were caught by a broad except Exception, logged as a warning, and swallowed. A sync could therefore complete successfully after failing to fetch issues, pull requests, or files — and the framework could delete previously indexed documents as a result.

    Affected versions: 8.10.0–8.19.18, 9.0.0–9.3.7, and 9.4.0–9.4.3.

    Fix: elastic/connectors#4119, shipped in 8.19.19, 9.3.8, 9.4.4, and 9.5.0. Page-level fetch errors now fail the sync; only per-document enrichment errors are skipped.

  • Outlook connector aborts the sync when Exchange items have null field values

    A single mail, calendar, contact, or attachment item with a missing nullable field (for example mail.sender → 'NoneType' object has no attribute 'email_address') aborted the entire sync. Optional folders that were absent also failed the account.

    Affected versions: 8.11.0–8.19.18, 9.0.0–9.3.7, and 9.4.0–9.4.3. On-prem Exchange only.

    Fix: elastic/connectors#4123, shipped in 8.19.19, 9.3.8, 9.4.4, and 9.5.0.

  • Outlook connector aborts the sync when the Contacts folder contains a distribution list

    The Contacts folder returns both Contact and DistributionList items, but the formatter assumed every item was a Contact, raising 'DistributionList' object has no attribute 'email_addresses' and aborting the sync. Shared and resource mailboxes that lack Calendar or Tasks folders hit the same abort path.

    Affected versions: 8.11.0–8.19.18, 9.0.0–9.3.7, and 9.4.0–9.4.3. On-prem Exchange only.

    Fix: elastic/connectors#4147, shipped in 8.19.19, 9.3.8, 9.4.4, 9.5.0, and 9.6.0.

  • MongoDB connector syncs fail on out-of-range BSON datetimes

    Documents with dates outside the Python datetime range (years 1–9999) cause pymongo to raise InvalidBSON (for example year 643385 is out of range) and abort the sync. The default datetime_conversion value remains DATETIME (raise).

    Affected versions: All versions that use the default DATETIME conversion, including after the mitigation below.

    Workaround: In advanced configuration, set datetime_conversion to DATETIME_CLAMP so out-of-range values are clamped to valid dates and the sync can continue. See the MongoDB connector reference.

    Fix: Mitigation added in elastic/connectors#4148, shipped in 8.19.19, 9.3.8, 9.4.4, 9.5.0, and 9.6.0.

  • Outlook connector aborts the sync on unexpected Exchange item types or folder errors

    Folders could contain stray item types (for example a CalendarItem in a mail folder → 'CalendarItem' object has no attribute 'sender'), or raise ErrorManagedFolderNotFound / ErrorAccessDenied. Any of these aborted the sync instead of skipping the bad item, folder, or account.

    Affected versions: 8.11.0–8.19.19, 9.0.0–9.3.8, and 9.4.0–9.4.4. On-prem Exchange only.

    Fix: elastic/connectors#4158, shipped in 8.19.20, 9.3.9, 9.4.5, 9.5.0, and 9.6.0.

  • Outlook connector aborts calendar sync on unrecognised EWS elements

    Some Exchange servers return elements such as EndTimeZone as siblings of calendar items. exchangelib raises ValueError: Item type …EndTimeZone was unexpected in a BaseFolder folder while loading the folder, which aborted the sync before per-item handling ran.

    Affected versions: 8.11.0–8.19.19, 9.0.0–9.3.8, and 9.4.0–9.4.4. On-prem Exchange only.

    Fix: elastic/connectors#4287, shipped in 8.19.20, 9.3.9, 9.4.5, 9.5.0, and 9.6.0.

  • Outlook connector DLS hides mailbox content from its owner

    With document-level security enabled, access control documents grant prefixed identities (email:user@example.com) while content documents stored the raw SMTP address. The DLS terms query intersection is empty, so mailbox owners see none of their own documents.

    Affected versions: All versions with Outlook DLS enabled, through 8.19.19, 9.3.8, and 9.4.4.

    Fix: elastic/connectors#4291, shipped in 9.3.9, 9.4.5, 9.5.0, and 9.6.0. After upgrading, run a full content sync so _allow_access_control is rewritten on existing documents; an access control sync alone is not enough.

  • Confluence connector DLS over-grants access on pages with inherited restrictions

    When a page inherits view restrictions from ancestors (or must satisfy both its own and parent restrictions), the connector ignored or incompletely applied the ancestor chain and fell back to broad space permissions. Users could see pages in Elasticsearch that they cannot view in Confluence.

    Affected versions: All versions with Confluence DLS enabled, through 8.19.19, 9.3.8, and 9.4.4. Cloud, Server, and Data Center.

    Fix: elastic/connectors#4297, shipped in 8.19.20, 9.3.9, 9.4.5, 9.5.0, and 9.6.0. After upgrading, run a full content sync to rewrite _allow_access_control.

  • SharePoint Online syncs abort on the system list SharePointHomeCacheList

    Microsoft Graph can return the system list SharePointHomeCacheList. Fetching its attachments via SharePoint REST returns Unauthorized and aborts the whole sync. Sync-rule exclusions cannot prevent this because they apply after the list is fetched.

    Affected versions: 8.9.0–8.19.19, 9.0.0–9.3.8, and 9.4.0–9.4.4.

    Fix: elastic/connectors#4306, shipped in 8.19.20, 9.3.9, 9.4.5, 9.5.0, and 9.6.0.

  • Long-running syncs are marked idle and fail after Elasticsearch ConnectionTimeout on index refresh

    During an active sync, the connector service refreshed connector and sync-job system indices on every status poll. Under bulk-ingest load, refresh calls could time out, the ingestion heartbeat stopped updating, and the job was marked ERROR even though indexing was still in progress.

    Affected versions: All versions through 8.19.20, 9.3.9, 9.4.5, and 9.5.1.

    Fix: elastic/connectors#4345, shipped in 8.19.21, 9.4.6, 9.5.2, and 9.6.0.

  • Long-running syncs fail on transient bulk SerializationError or lose bulk failures silently

    Elasticsearch _bulk responses such as Client Closed Request were not retried, and failures from concurrent bulk tasks could be dropped instead of failing the sync.

    Affected versions: All versions through 8.19.20, 9.3.9, 9.4.5, and 9.5.2.

    Fix: elastic/connectors#4384, shipped in 8.19.21, 9.4.6, 9.5.3, and 9.6.0.

  • SharePoint Online syncs fail when a drive delta link expires (410 Gone)

    An expired Microsoft Graph drive delta token aborted the sync after partial indexing.

    Affected versions: 8.9.0–8.19.20, 9.0.0–9.3.9, 9.4.0–9.4.5, and 9.5.0–9.5.2.

    Fix: elastic/connectors#4370, shipped in 8.19.21, 9.4.6, 9.5.3, and 9.6.0.

  • SharePoint Online DLS exposes unpublished site pages to viewers

    Unpublished pages kept view ACLs from their published state, so users with former view access could still find them in Elasticsearch after the page was unpublished.

    Affected versions: All versions with SharePoint Online DLS enabled, through 8.19.21, 9.0.0–9.3.9, 9.4.0–9.4.7, and 9.5.0–9.5.4.

    Fix: elastic/connectors#4437, shipped in 8.19.22, 9.4.8, 9.5.5, and 9.6.0. After upgrading, run a full content sync; an access control sync alone is not enough.

  • SharePoint Online DLS can exhaust Elasticsearch memory when site groups are expanded on each document

    Document-level security expanded every site group member onto _allow_access_control, producing very large ACL arrays per document.

    Affected versions: All versions with SharePoint Online DLS enabled that expand site group members, including after the mitigation below. Site group expansion is the default.

    Workaround: On releases that include the mitigation, set Expand site group members (expand_site_group_members) to false, then run a full content sync and an access control sync. Earlier releases do not expose this setting and have no workaround.

    Fix: Opt-in mitigation added in elastic/connectors#4396, shipped in 8.19.23, 9.4.8, 9.5.5, and 9.6.0. Upgrading alone does not change behavior; the setting must be disabled.

  • ServiceNow DLS can exhaust Elasticsearch memory when role members are expanded on each document

    Document-level security expanded every role member onto each content document (and attachment). Large roles, including public, could create hundreds of thousands of ACL entries per document. Advanced sync rules could also stamp an empty ACL on batched documents.

    Affected versions: All versions with ServiceNow DLS enabled that expand role members, including after the mitigation below. Role member expansion is the default.

    Workaround: On releases that include the mitigation, set Expand role members (expand_role_members) to false, then run a full content sync and an access control sync. Earlier releases do not expose this setting and have no workaround.

    Fix: Opt-in mitigation added in elastic/connectors#4392, shipped in 8.19.22, 9.4.7, 9.5.4, and 9.6.0. Upgrading alone does not change behavior; the setting must be disabled.

  • ServiceNow access control syncs stall when compact DLS preloads sys_user_has_role

    With Expand role members disabled, offset pagination on sys_user_has_role could run for many hours with no documents indexed on large tenants.

    Affected versions: 8.19.22, 9.4.7, and 9.5.4, with ServiceNow DLS and Expand role members disabled. Earlier releases do not offer compact mode.

    Fix: elastic/connectors#4509, shipped in 8.19.23, 9.4.8, 9.5.5, and 9.6.0.

  • OneDrive connector fails with KeyError: '_allow_access_control' when advanced sync rules and DLS are both enabled

    The advanced sync rules code path did not decorate documents with access control metadata before indexing.

    Affected versions: All versions with OneDrive DLS and advanced sync rules, through 8.19.21, 9.0.0–9.3.9, 9.4.0–9.4.6, and 9.5.0–9.5.3.

    Fix: elastic/connectors#4404, shipped in 8.19.22, 9.4.7, 9.5.4, and 9.6.0.

  • Network Drive DLS grants read access for write-only allow permissions

    Allow ACEs that grant write but not read were treated as read access, so users who could only write a file could still see it in search results.

    Affected versions: All versions with Network Drive DLS enabled, through 8.19.21, 9.0.0–9.3.9, 9.4.0–9.4.6, and 9.5.0–9.5.3.

    Fix: elastic/connectors#4410, shipped in 8.19.22, 9.4.7, 9.5.4, and 9.6.0.

  • Outlook connector aborts the sync when Active Directory mail is not the primary SMTP address

    Exchange raises ErrorNonPrimarySmtpAddress when impersonation uses a proxy address instead of the primary SMTP address, aborting the entire sync.

    Affected versions: 8.11.0–8.19.21, 9.0.0–9.3.9, 9.4.0–9.4.6, and 9.5.0–9.5.3. On-prem Exchange with Active Directory only.

    Fix: elastic/connectors#4406, shipped in 8.19.22, 9.4.7, 9.5.4, and 9.6.0.

  • Outlook connector aborts long syncs when the LDAP connection to Active Directory is reset

    A single cached LDAP connection could sit idle for hours between user batches; a dropped connection then failed user enumeration and aborted the sync.

    Affected versions: 8.11.0–8.19.21, 9.0.0–9.3.9, 9.4.0–9.4.7, and 9.5.0–9.5.4. On-prem Exchange with Active Directory only.

    Fix: elastic/connectors#4441, shipped in 8.19.22, 9.4.8, 9.5.5, and 9.6.0.

  • Outlook connector fails when Exchange returns ErrorMailboxStoreUnavailable while reading folders

    A transient mailbox store error while materializing folder items aborted the sync with no retry.

    Affected versions: 8.11.0–8.19.22, 9.0.0–9.3.9, 9.4.0–9.4.7, and 9.5.0–9.5.4. On-prem Exchange only.

    Fix: elastic/connectors#4529, shipped in 8.19.23, 9.4.8, 9.5.5, and 9.6.0.

  • Microsoft SQL Server connector syncs fail with Invalid TDS marker on retried queries

    Retrying a streaming query on a shared pytds connection after a failure could leave a poisoned connection and raise Invalid TDS marker.

    Affected versions: All generic database connector versions using the MSSQL source, through 8.19.21, 9.0.0–9.3.9, 9.4.0–9.4.6, and 9.5.0–9.5.3.

    Fix: elastic/connectors#4407, shipped in 8.19.22, 9.4.7, 9.5.4, and 9.6.0.

  • Elastic Agent deployments ignore Elasticsearch output ssl.verification_mode

    Connectors running under Elastic Agent always verified TLS certificates, even when the agent policy set ssl.verification_mode to none for self-signed clusters.

    Affected versions: Agent-managed connectors through 8.19.21, 9.0.0–9.3.9, 9.4.0–9.4.6, and 9.5.0–9.5.2.

    Fix: elastic/connectors#4391, shipped in 8.19.22, 9.4.7, 9.5.3, and 9.6.0.

  • Elastic Agent-managed connectors crash on check-in when the output policy includes an ssl block

    Reading agent SSL settings with dict access on protobuf Struct values raised AttributeError during check-in.

    Affected versions: Agent-managed connectors on 9.5.3 only. This is a regression from #4391; the 8.19.22 and 9.4.7 releases contain both changes and are not affected.

    Fix: elastic/connectors#4456, shipped in 8.19.22, 9.4.7, 9.5.4, and 9.6.0.

  • Connector syncs fail on FIPS-enabled hosts when MD5 is blocked

    Document ID hashing used hashlib.md5() without usedforsecurity=False, which OpenSSL rejects in FIPS mode.

    Affected versions: FIPS-enabled connector deployments through 8.19.21, 9.0.0–9.3.9, 9.4.0–9.4.6, and 9.5.0–9.5.3.

    Fix: elastic/connectors#4416, shipped in 8.19.22, 9.4.7, 9.5.4, and 9.6.0.

  • Content Connectors remain in the list after delete in Kibana

    Kibana soft-deleted connectors in Elasticsearch, so deleted connectors could still appear in the UI while GET by id returned an empty document.

    Affected versions: All Kibana versions with the Content Connectors UI, through 8.19.22, 9.4.7, and 9.5.4. The 9.1 through 9.3 lines are also affected and do not receive this fix.

    Fix: elastic/kibana#290859, shipped in Kibana 8.19.23, 9.4.8, 9.5.5, and 9.6.0.

Individual connectors may have additional known issues. Refer to each connector’s reference documentation for connector-specific known issues.