# 中文提问与讨论

**URL:** https://discuss.elastic.co/c/in-your-native-tongue/chinese/46.md?page=1

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 2

---

## [Filebeat文件注册表无法更新，日志无法收集](https://discuss.elastic.co/t/filebeat/286429)

<div class="topic-metadata">

**Author:** [@StruggleYang](https://discuss.elastic.co/u/StruggleYang)\
**Replies:** 0\
**Last updated:** [October 12, 2021, 3:42am UTC](https://discuss.elastic.co/t/filebeat/286429 "2021-10-12T03:42:59Z")

</div>

filebeat注册表一直出现如下日志 2021-10-12T03:11:29.199Z ERROR registrar/registrar.go:374 Writing of registry returned error: rename /usr/share/filebeat/data/registry/filebeat/data.json.new /usr/share/filebeat/data/re…

---

## [如何给按条件分组的查询设置默认值](https://discuss.elastic.co/t/topic/284102)

<div class="topic-metadata">

**Author:** [@xxm404](https://discuss.elastic.co/u/xxm404)\
**Replies:** 0\
**Last updated:** [September 13, 2021, 3:59pm UTC](https://discuss.elastic.co/t/topic/284102 "2021-09-13T15:59:19Z")

</div>

我想使用 ELK 分析 Nginx 日志，统计每个接口的 Apdex 积分，所以我需要计算不同耗时区间内的请求数，但我发现某些接口在特定耗时区间请求数为 0，在 es 的查询结果中会显示为没有结果，这导致我无法进行后续的计算，请问我该如何解决这个问题，或者说有没有其他方法来计算接口的 Apdex 积分 我的查询大致如下： // 请求总数 logname:"access\_log" AND fields.tagname:"service…

---

## [关于多层nested 嵌套查询(多规格商品查询),数据查询要怎么做](https://discuss.elastic.co/t/nested/281930)

<div class="topic-metadata">

**Author:** [@XuShall](https://discuss.elastic.co/u/XuShall)\
**Replies:** 4\
**Last updated:** [September 10, 2021, 1:07am UTC](https://discuss.elastic.co/t/nested/281930 "2021-09-10T01:07:30Z")

</div>

关于多层nested 嵌套查询(多规格商品查询),数据查询要怎么做 结构 PUT goods { "mappings": { "properties": { "spu\_id": { "type": "integer" }, "title": { "type": "text", "analyzer": "ik\_smart" }, "sub\_title": { "typ…

---

## [7.6.2-- yarn kbn bootstrap --error Command failed with exit code 1](https://discuss.elastic.co/t/7-6-2-yarn-kbn-bootstrap-error-command-failed-with-exit-code-1/280503)

<div class="topic-metadata">

**Author:** [@lanju](https://discuss.elastic.co/u/lanju)\
**Replies:** 0\
**Last updated:** [August 5, 2021, 7:18am UTC](https://discuss.elastic.co/t/7-6-2-yarn-kbn-bootstrap-error-command-failed-with-exit-code-1/280503 "2021-08-05T07:18:06Z")

</div>

kibana7.6.2-- yarn kbn bootstrap --error Command failed with exit code 1.

---

## [請教如何令filebeat做到多個indexes配上不同template和ilm](https://discuss.elastic.co/t/filebeat-indexes-template-ilm/277106)

<div class="topic-metadata">

**Author:** [@cecil](https://discuss.elastic.co/u/cecil)\
**Replies:** 2\
**Last updated:** [July 21, 2021, 3:33am UTC](https://discuss.elastic.co/t/filebeat-indexes-template-ilm/277106 "2021-07-21T03:33:45Z")

</div>

我是新手，已測試了filebeat如何取得多個不同log源，也試了單一ilm是怎樣發生，也稍為明白template的用途。 現在有一個以下問題，目標是在同一伺服器上，把/var/log/syslog和/var/log/auth.log經filebeat分別套用在不同template上，然後各自也配不同ilm 例如syslog的ilm是hot 1day, delete 30days，而auth.log的ilm是hot 30 day, …

---

## [Elasticsearch购买xpack安全功能官方联系方式](https://discuss.elastic.co/t/elasticsearch-xpack/276859)

<div class="topic-metadata">

**Author:** [@peng-elasticsearch](https://discuss.elastic.co/u/peng-elasticsearch)\
**Replies:** 0\
**Last updated:** [June 24, 2021, 1:39am UTC](https://discuss.elastic.co/t/elasticsearch-xpack/276859 "2021-06-24T01:39:59Z")

</div>

elasticsearch购买xpack安全功能官方咨询渠道有哪些？？ 官网都没找见联系方式或者其他 麻烦具体发下链接或者联系方式信息

---

## [Logstash-plugin-s3 接收数据有延迟30分钟](https://discuss.elastic.co/t/logstash-plugin-s3-30/273599)

<div class="topic-metadata">

**Author:** [@xiaoloutingfengyu](https://discuss.elastic.co/u/xiaoloutingfengyu)\
**Replies:** 0\
**Last updated:** [May 21, 2021, 2:39am UTC](https://discuss.elastic.co/t/logstash-plugin-s3-30/273599 "2021-05-21T02:39:05Z")

</div>

使用logstash的s3插件接受aws上的数据，数据接受有延迟，延迟时间如果超过半小时会继续接受，直到和真实时间相差10分钟左右停止接受，然后等相差超过30分钟时logstash-plugin-s3会再次接受数据。请问这个问题如何调整，我想要接受的数据和真实时间相差不超过5分钟。

---

## [Ik 做不到分詞searching](https://discuss.elastic.co/t/ik-searching/260973)

<div class="topic-metadata">

**Author:** [@Tails](https://discuss.elastic.co/u/Tails)\
**Replies:** 0\
**Last updated:** [January 13, 2021, 10:40am UTC](https://discuss.elastic.co/t/ik-searching/260973 "2021-01-13T10:40:29Z")

</div>

入了 "張學友" 去dictionary 張學友 searching 正常 \[root@localhost scripts\]# curl -H 'Content-Type: application/json' -XPOST 'http://192.168.90.13:9200/p\_photo/\_search?pretty' -d' { "query" : { "term" : { "caption" : "張學友" }} }…

---

## [使用logstash7.4.2通过http方式接收数据发到es出现中文乱码](https://discuss.elastic.co/t/logstash7-4-2-http-es/260395)

<div class="topic-metadata">

**Author:** [@111351](https://discuss.elastic.co/u/111351)\
**Replies:** 0\
**Last updated:** [January 7, 2021, 1:34am UTC](https://discuss.elastic.co/t/logstash7-4-2-http-es/260395 "2021-01-07T01:34:35Z")

</div>

您好，我使用得配置文件如下，测试中通过浏览器地址栏直接发送请求会出现中文乱码，但是通过postman发送却可以正常显示。 input{ http{ } } output{ stdout{} }

---

## [Logstash 性能调优监控](https://discuss.elastic.co/t/logstash/258800)

<div class="topic-metadata">

**Author:** [@W1nter-3Z](https://discuss.elastic.co/u/W1nter-3Z)\
**Replies:** 0\
**Last updated:** [December 16, 2020, 4:01am UTC](https://discuss.elastic.co/t/logstash/258800 "2020-12-16T04:01:59Z")

</div>

一般采用什么工具或者方法对logstash的吞吐量进行监控

---

## [No runner available for operation type \[composite\]](https://discuss.elastic.co/t/no-runner-available-for-operation-type-composite/258245)

<div class="topic-metadata">

**Author:** [@rose](https://discuss.elastic.co/u/rose)\
**Replies:** 2\
**Last updated:** [December 11, 2020, 12:22am UTC](https://discuss.elastic.co/t/no-runner-available-for-operation-type-composite/258245 "2020-12-11T00:22:45Z")

</div>

I use operation type is composite,esrally version is 2.0.2. \[ERROR\] Cannot race. Error in load generator \[0\] ('No runner available for operation type \[composite\]', None) The above is an error report. grep 'ERROR' .ra…

---

## [我使用我自己配置的文件启动logstash报错](https://discuss.elastic.co/t/logstash/257034)

<div class="topic-metadata">

**Author:** [@Tina\_Yang](https://discuss.elastic.co/u/Tina_Yang)\
**Replies:** 0\
**Last updated:** [November 30, 2020, 8:35am UTC](https://discuss.elastic.co/t/logstash/257034 "2020-11-30T08:35:32Z")

</div>

\*\* 启动 sh logstash -f ../config/mysql.conf \*\* Sending Logstash logs to /media/tina/UNTITLED/software/es/logstash-7.6.2/logs which is now configured via log4j2.properties \[2020-11-30T16:27:54,311\]\[WARN \]\[logstash.confi…

---

## [Cmd "Logstash-plugin list" raise unknown encoding error ms950](https://discuss.elastic.co/t/cmd-logstash-plugin-list-raise-unknown-encoding-error-ms950/252413)

<div class="topic-metadata">

**Author:** [@liu\_keli](https://discuss.elastic.co/u/liu_keli)\
**Replies:** 2\
**Last updated:** [October 21, 2020, 9:00am UTC](https://discuss.elastic.co/t/cmd-logstash-plugin-list-raise-unknown-encoding-error-ms950/252413 "2020-10-21T09:00:58Z")

</div>

Cmd "Logstash-plugin list" raise unknown encoding error ms950. I read alike topic, then try "chcp 65001" to correct it, but Cmd "Logstash-plugin list" still raise same error. Environment:Logstash v6.8.10 and win10 x64…

---

## [怎样使用QueryBuilders查询列表字段](https://discuss.elastic.co/t/querybuilders/240306)

<div class="topic-metadata">

**Author:** [@PeterZhao](https://discuss.elastic.co/u/PeterZhao)\
**Replies:** 2\
**Last updated:** [July 13, 2020, 8:17am UTC](https://discuss.elastic.co/t/querybuilders/240306 "2020-07-13T08:17:53Z")

</div>

新手 列表字段：docBuilder.field(FreeTextField, List freeTextFieldAsArray) 想用QueryBuilders做一个查询匹配列表中的一项，怎么做呢？

---

## [为什么我开启了doc value的binary field会花费这么多磁盘空间？或者还有别的更好的办法？](https://discuss.elastic.co/t/doc-value-binary-field/236615)

<div class="topic-metadata">

**Author:** [@nooneuse](https://discuss.elastic.co/u/nooneuse)\
**Replies:** 0\
**Last updated:** [June 11, 2020, 4:23am UTC](https://discuss.elastic.co/t/doc-value-binary-field/236615 "2020-06-11T04:23:18Z")

</div>

你好， （我的elasticsearch版本是6.8.0） 我有很多DataSketches序列化数据存储在索引中的一个binary字段中。我需要反序列化它们，然后将它们组合在一起以获得它们的总估算值。因此，我写了一个DataSketches的聚合插件供Elasticsearch组合并计算它们，效果还行，但是我发现binary字段占用了很大的磁盘空间。 我必须为binary field打开doc\_value，因为我需要聚合那些字段…

---

## [关于es聚合查询指标过滤并限制返回结果数量的问题](https://discuss.elastic.co/t/es/237379)

<div class="topic-metadata">

**Author:** [@NiFeng](https://discuss.elastic.co/u/NiFeng)\
**Replies:** 7\
**Last updated:** [June 30, 2020, 5:47am UTC](https://discuss.elastic.co/t/es/237379 "2020-06-30T05:47:29Z")

</div>

{ "size": 0, "query": { "bool": { "filter": } }, "track\_total\_hits": false, "aggregations": { "my\_buckets": { "composite": { "size": 5, "sources": \[ { "eventTime.keyword": { "terms": { "field": "eventTim…

---

## [7.5 Share the workpad on a websiteedit in a new html in not run success](https://discuss.elastic.co/t/7-5-share-the-workpad-on-a-websiteedit-in-a-new-html-in-not-run-success/238359)

<div class="topic-metadata">

**Author:** [@lily.guo](https://discuss.elastic.co/u/lily.guo)\
**Replies:** 0\
**Last updated:** [June 24, 2020, 2:20am UTC](https://discuss.elastic.co/t/7-5-share-the-workpad-on-a-websiteedit-in-a-new-html-in-not-run-success/238359 "2020-06-24T02:20:20Z")

</div>

---

## [Java 使用 RestHighLevelClient 调用慢](https://discuss.elastic.co/t/java-resthighlevelclient/233307)

<div class="topic-metadata">

**Author:** [@peiqing\_xu](https://discuss.elastic.co/u/peiqing_xu)\
**Replies:** 0\
**Last updated:** [May 19, 2020, 11:48am UTC](https://discuss.elastic.co/t/java-resthighlevelclient/233307 "2020-05-19T11:48:40Z")

</div>

直接使用 postman 调用 用时一秒 http://106.13.148.210:9200/\_search { "query": { "match": { "book\_id": { "query": 87, "operator": "OR", "prefix\_length": 0, "max\_expansions": 50, "…

---

## [Filebeat 7.6.x deb安装启动后不写运行日志到文件，发现是自动加了-e参数](https://discuss.elastic.co/t/filebeat-7-6-x-deb-e/233045)

<div class="topic-metadata">

**Author:** [@ttynet](https://discuss.elastic.co/u/ttynet)\
**Replies:** 0\
**Last updated:** [May 18, 2020, 6:56am UTC](https://discuss.elastic.co/t/filebeat-7-6-x-deb-e/233045 "2020-05-18T06:56:24Z")

</div>

filebeat7.6.1和7.6.2两个版本，deb包安装启动后不写运行日志到文件，通ps -ef 看filebeat的命令，发现里面有个-e参数，然后看了看/etc/init.d/filebeat还不知道怎么改能把-e去掉，不知道官方何时能修复这个bug，另外有没有临时解决方案

---

## [Getting an error when I use multiple processes with python](https://discuss.elastic.co/t/getting-an-error-when-i-use-multiple-processes-with-python/230128)

<div class="topic-metadata">

**Author:** [@KimTaenggu](https://discuss.elastic.co/u/KimTaenggu)\
**Replies:** 0\
**Last updated:** [April 28, 2020, 9:58am UTC](https://discuss.elastic.co/t/getting-an-error-when-i-use-multiple-processes-with-python/230128 "2020-04-28T09:58:55Z")

</div>

I get elasticsearch.exceptions.SerializationError when using multiple processes with python. The usual string result should be like {"took":3,"timed\_out":false.....}. But when I use multiple processes with python, the re…

---

## [Elasticsearch update by query problem](https://discuss.elastic.co/t/elasticsearch-update-by-query-problem/226611)

<div class="topic-metadata">

**Author:** [@111306](https://discuss.elastic.co/u/111306)\
**Replies:** 1\
**Last updated:** [April 6, 2020, 9:42am UTC](https://discuss.elastic.co/t/elasticsearch-update-by-query-problem/226611 "2020-04-06T09:42:45Z")

</div>

遇到一个问题，我的 elasticsearch 版本是 7.6.1 ，使用的系统是 Debian 9 。我们在线上运行 elasticsearch 时，发现使用 update\_by\_query 接口发现有时并没有更新，但单个请求又是成功的。什么情况下会显示更新成功，但并没有发生更新呢？请问这个是什么问题，困扰很久了。

---

## [Elasticsearch.js where to set Index max\_result\_window?](https://discuss.elastic.co/t/elasticsearch-js-where-to-set-index-max-result-window/226185)

<div class="topic-metadata">

**Author:** [@820465323](https://discuss.elastic.co/u/820465323)\
**Replies:** 0\
**Last updated:** [April 2, 2020, 9:15am UTC](https://discuss.elastic.co/t/elasticsearch-js-where-to-set-index-max-result-window/226185 "2020-04-02T09:15:46Z")

</div>

因为在elasticsearch.js我找不到可以设置的地方

---

## [Eshead 访问es](https://discuss.elastic.co/t/eshead-es/225482)

<div class="topic-metadata">

**Author:** [@qwer\_123](https://discuss.elastic.co/u/qwer_123)\
**Replies:** 0\
**Last updated:** [March 28, 2020, 10:10am UTC](https://discuss.elastic.co/t/eshead-es/225482 "2020-03-28T10:10:46Z")

</div>

阿里云部署es eshead无法链接到es \_stats报错 设置过可跨域 具体错误信息 {"error":{"root\_cause":\[{"type":"cluster\_block\_exception","reason":"blocked by: \[SERVICE\_UNAVAILABLE/1/state not recovered / initialized\];"}\],"type":"cluster\_block\_except…

---

## [单个文件大小对查询性能的影响](https://discuss.elastic.co/t/topic/221598)

<div class="topic-metadata">

**Author:** [@Zhengcong\_Yin](https://discuss.elastic.co/u/Zhengcong_Yin)\
**Replies:** 0\
**Last updated:** [March 1, 2020, 8:52pm UTC](https://discuss.elastic.co/t/topic/221598 "2020-03-01T20:52:13Z")

</div>

相同数量的文件， 如果减小每个文件的大小，文件数量不变，是否能提供search的性能

---

## [MSSQL 差異同步資料到Elasticsearch](https://discuss.elastic.co/t/mssql-elasticsearch/211971)

<div class="topic-metadata">

**Author:** [@111203](https://discuss.elastic.co/u/111203)\
**Replies:** 0\
**Last updated:** [December 16, 2019, 9:46am UTC](https://discuss.elastic.co/t/mssql-elasticsearch/211971 "2019-12-16T09:46:51Z")

</div>

請問要如何做MSSQL 差異同步資料到Elasticsearch? 如何定期對從上一次同步之後的新增或修改或刪除的資料同步到Elasticsearch?

---

## [ELK7.4.2版本多节点集群可以配置免费的Xpack吗](https://discuss.elastic.co/t/elk7-4-2-xpack/210469)

<div class="topic-metadata">

**Author:** [@wsy](https://discuss.elastic.co/u/wsy)\
**Replies:** 2\
**Last updated:** [December 4, 2019, 6:58am UTC](https://discuss.elastic.co/t/elk7-4-2-xpack/210469 "2019-12-04T06:58:51Z")

</div>

已有 : 我在CentOS上配置了版本号7.4.2的3个节点的elasticsearch 在节点master上配置了kibana 关闭安全验证时 服务是正常的 这两个web页面是可以正常访问的 目标 : 现在想给我的elasticsearch和kibana配置X-pack安全验证(登录web页面时设置成需要用户名密码才可访问 并且配置TLS验证) 操作 : 我按照https://www.elastic.co/guide/en/ela…

---

## [Elasticsearch 聚合加条件搜索一起检索](https://discuss.elastic.co/t/elasticsearch/205981)

<div class="topic-metadata">

**Author:** [@wwl1](https://discuss.elastic.co/u/wwl1)\
**Replies:** 1\
**Last updated:** [November 19, 2019, 9:49am UTC](https://discuss.elastic.co/t/elasticsearch/205981 "2019-11-19T09:49:09Z")

</div>

例如：根据一个产品名称查相关的产品信息，多个，页数为10，然后根据产品的公司再查公司信息，公司名称不能重复但返回的条数必须为10条，该怎么处理

---

## [ICU Analysis Plugin & 繁體中文分詞器相關詢問](https://discuss.elastic.co/t/icu-analysis-plugin/201882)

<div class="topic-metadata">

**Author:** [@111203](https://discuss.elastic.co/u/111203)\
**Replies:** 0\
**Last updated:** [October 2, 2019, 1:20am UTC](https://discuss.elastic.co/t/icu-analysis-plugin/201882 "2019-10-02T01:20:30Z")

</div>

請問ICU Analysis Plugin有提供客製擴展字典嗎? 類似IK Analysis plugin的 Dictionary Configuration? 另外想請問有沒有人有推薦的繁體中文分詞器? 目前覺得ICU Analysis Plugin的分詞效果不錯，但不確定有無支援客製擴展字典， 有試過Jieba但簡體跟繁體的分詞效果有差 謝謝

---

## [運行logstash-plugin list 命令失敗](https://discuss.elastic.co/t/logstash-plugin-list/198614)

<div class="topic-metadata">

**Author:** [@111203](https://discuss.elastic.co/u/111203)\
**Replies:** 1\
**Last updated:** [September 12, 2019, 3:03am UTC](https://discuss.elastic.co/t/logstash-plugin-list/198614 "2019-09-12T03:03:03Z")

</div>

我在Logstash folder 下運行logstash-plugin命令會出現 unknown encoding name - MS950 環境/版本: logstash: 6.8.1 OS : Win 10 請問有人知道如何解決嗎? 謝謝

---

## [如何提升es集群的搜索以及索引性能](https://discuss.elastic.co/t/es/198142)

<div class="topic-metadata">

**Author:** [@hyun\_wen](https://discuss.elastic.co/u/hyun_wen)\
**Replies:** 0\
**Last updated:** [September 5, 2019, 3:18am UTC](https://discuss.elastic.co/t/es/198142 "2019-09-05T03:18:45Z")

</div>

集群里有6台机子 (1 主节点 + 1 负载均衡 + 4 数据节点) 一水的dell r510 Xeon 5500 32G ssd（系统）+机械（数据） 之前纯索引数据的时候 4亿5千万多文档（1 Primary+ 1 Replica） ID是手动指定的 refresh = -1 总索引速度在8000/s左右 主分片在4000/s左右 虽然不是很快 但是还能接受 索引完成之后 1T data， 292 shards（主分…

[Previous page](https://discuss.elastic.co/c/in-your-native-tongue/chinese/46.md)

[Next page](https://discuss.elastic.co/c/in-your-native-tongue/chinese/46.md?page=2)
