# 中文提问与讨论

**URL:** https://discuss.elastic.co/c/in-your-native-tongue/chinese/46.md?page=2

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 3

---

## [解壓縮kibana-7.2.0-windows-x86\_64失敗](https://discuss.elastic.co/t/kibana-7-2-0-windows-x86-64/197842)

<div class="topic-metadata">

**Author:** [@111203](https://discuss.elastic.co/u/111203)\
**Replies:** 0\
**Last updated:** [September 3, 2019, 11:49am UTC](https://discuss.elastic.co/t/kibana-7-2-0-windows-x86-64/197842 "2019-09-03T11:49:23Z")

</div>

解壓縮kibana-7.2.0-windows-x86\_64發生以下失敗畫面 似乎是防毒Symantec不允許.mirco結尾的folder， 想請問有人也遇過此問題嗎? 我把防毒關閉了，也還是不行。

---

## [隐藏侧边栏某些功能，该怎么做？](https://discuss.elastic.co/t/topic/177048)

<div class="topic-metadata">

**Author:** [@hanyongsheng](https://discuss.elastic.co/u/hanyongsheng)\
**Replies:** 0\
**Last updated:** [April 16, 2019, 9:48am UTC](https://discuss.elastic.co/t/topic/177048 "2019-04-16T09:48:09Z")

</div>

Machine Learning,Maps,Canvas,Stack Monitoring, 以上这几个侧边栏功能如何让它消失，我找了很久都没有找到解决的办法，希望可以得到你们的帮助，谢谢你

---

## [使用RestHighLevelClient时单个索引速度很慢](https://discuss.elastic.co/t/resthighlevelclient/170293)

<div class="topic-metadata">

**Author:** [@PearceDuan](https://discuss.elastic.co/u/PearceDuan)\
**Replies:** 2\
**Last updated:** [March 15, 2019, 7:19am UTC](https://discuss.elastic.co/t/resthighlevelclient/170293 "2019-03-15T07:19:31Z")

</div>

Elastic版本： 6.6.1 本地（4核,16G）运行单个节点的ES（启动时参数基本都是默认的），同时使用RestHighLevelClient循环写入1000条（每条\<1K）数据，无论是SyncIndex，还是AsyncIndex，发现耗时50s左右，相当于每秒才写入20条 问题： 不考虑bulk操作，这种速度是否正常（感觉太慢）？有没有优化办法？

---

## [Elastic 里面有数据，但是无法拆解](https://discuss.elastic.co/t/elastic/170837)

<div class="topic-metadata">

**Author:** [@mytea003](https://discuss.elastic.co/u/mytea003)\
**Replies:** 2\
**Last updated:** [March 5, 2019, 9:51am UTC](https://discuss.elastic.co/t/elastic/170837 "2019-03-05T09:51:16Z")

</div>

如图所示，数据已经在Elastic里面了。但是无法拆解出来按照规定的字段进行查看相应的信息。 这个如何处理呀？ 怎么把原来不能拆解出来的记录，重新匹配拆解呢？

---

## [Elasticsearch6.3，how to use sql to appoint Routing value](https://discuss.elastic.co/t/elasticsearch6-3-how-to-use-sql-to-appoint-routing-value/170746)

<div class="topic-metadata">

**Author:** [@ZQbd](https://discuss.elastic.co/u/ZQbd)\
**Replies:** 1\
**Last updated:** [March 4, 2019, 3:12pm UTC](https://discuss.elastic.co/t/elasticsearch6-3-how-to-use-sql-to-appoint-routing-value/170746 "2019-03-04T15:12:11Z")

</div>

\`GET website/article/\_search?routing=user123\` 这样指定routing value的查询，如何用es6.3以上版本内置的sql实现同样的功能

---

## [Sum\_bucket cardinality 多层 aggregation](https://discuss.elastic.co/t/sum-bucket-cardinality-aggregation/170714)

<div class="topic-metadata">

**Author:** [@Kristen\_Chang](https://discuss.elastic.co/u/Kristen_Chang)\
**Replies:** 0\
**Last updated:** [March 4, 2019, 11:13am UTC](https://discuss.elastic.co/t/sum-bucket-cardinality-aggregation/170714 "2019-03-04T11:13:19Z")

</div>

Elasticsearch版本为5.5 以下方法1可以得到user里面cardinality的value加总，但是方法2却会得到以下错误讯息， buckets\_path must reference either a number value or a single value numeric metric aggregation 请问是哪里出错？或是其他方法可以统计数据？ 方法1： { "size": 0, "aggs"…

---

## [Elk cluster其中一个node启动提示failed to send join request to master](https://discuss.elastic.co/t/elk-cluster-node-failed-to-send-join-request-to-master/170268)

<div class="topic-metadata">

**Author:** [@jayshi1985](https://discuss.elastic.co/u/jayshi1985)\
**Replies:** 0\
**Last updated:** [February 28, 2019, 3:35am UTC](https://discuss.elastic.co/t/elk-cluster-node-failed-to-send-join-request-to-master/170268 "2019-02-28T03:35:35Z")

</div>

如题，elasticsearch cluster中，其中一个node无法正常启动elasticsearch，提示: \[2019-02-28T10:55:58,243\]\[INFO \]\[o.e.d.z.ZenDiscovery \] \[es-node-1\] failed to send join request to master \[{es-node-2}{THbImmRcQ7WdREIQcG4ndg}{cFtkVn3IRr-P\_g…

---

## [filebeat往Central Management 注册失败后第二次注册会提示empty access\_token](https://discuss.elastic.co/t/filebeat-central-management-empty-access-token/170103)

<div class="topic-metadata">

**Author:** [@wajika](https://discuss.elastic.co/u/wajika)\
**Replies:** 0\
**Last updated:** [February 27, 2019, 5:47am UTC](https://discuss.elastic.co/t/filebeat-central-management-empty-access-token/170103 "2019-02-27T05:47:55Z")

</div>

filebeat enroll http://192.168.10.161:5601 --username elastic --password stdin Enter password: Error while enrolling: empty access\_token 不管是用kibana生成的token url注册还是以用户密码的方式注册，后面都会提示Error while enrolling: empty access\_t…

---

## [使用 RestHighLevelClient 连接 es 集群报错 Request cannot be executed; I/O reactor status: STOPPED](https://discuss.elastic.co/t/resthighlevelclient-es-request-cannot-be-executed-i-o-reactor-status-stopped/165009)

<div class="topic-metadata">

**Author:** [@corleone](https://discuss.elastic.co/u/corleone)\
**Replies:** 0\
**Last updated:** [January 21, 2019, 8:44am UTC](https://discuss.elastic.co/t/resthighlevelclient-es-request-cannot-be-executed-i-o-reactor-status-stopped/165009 "2019-01-21T08:44:52Z")

</div>

连接集群的代码如下： 在启动完成之后，查询某索引就会报错，查询的关键代码如下： SearchResponse searchResponse = client.search(searchRequest, RequestOptions.DEFAULT); 这是报错：

---

## [请问ElasticSearch时序性存储，官方文档在哪里啊？](https://discuss.elastic.co/t/elasticsearch/163847)

<div class="topic-metadata">

**Author:** [@ennian001](https://discuss.elastic.co/u/ennian001)\
**Replies:** 0\
**Last updated:** [January 11, 2019, 6:10am UTC](https://discuss.elastic.co/t/elasticsearch/163847 "2019-01-11T06:10:28Z")

</div>

:grinning:

---

## [\[logstash-filter-multiline\]安装使用](https://discuss.elastic.co/t/logstash-filter-multiline/162038)

<div class="topic-metadata">

**Author:** [@haoyun](https://discuss.elastic.co/u/haoyun)\
**Replies:** 1\
**Last updated:** [January 7, 2019, 2:35am UTC](https://discuss.elastic.co/t/logstash-filter-multiline/162038 "2019-01-07T02:35:04Z")

</div>

logstash 插件 \[logstash-filter-multiline\]要怎么安装？ 我在这个页面看到 ，但是不明白怎么装上去（最好是可以离线安装）~ https://rubygems.org/gems/logstash-filter-multiline/versions/3.0.4

---

## [Logstash日志里频繁出现报错""undefined method \`sanitized' "](https://discuss.elastic.co/t/logstash-undefined-method-sanitized/160079)

<div class="topic-metadata">

**Author:** [@haoyun](https://discuss.elastic.co/u/haoyun)\
**Replies:** 7\
**Last updated:** [December 24, 2018, 3:01am UTC](https://discuss.elastic.co/t/logstash-undefined-method-sanitized/160079 "2018-12-24T03:01:22Z")

</div>

你好， 我的elk版本是5.6，logstash日志里频繁出现报错""undefined method \`sanitized' " 每次，刚开始启动的时候是一切正常的，然后慢慢就会出现下面这种报错，积攒到某一天，就会发现不往elastic里写索引数据了。这时候产看日志每天会有7 、 8 M都是刷这个错误。 然后我重启logstash就看似又恢复正常了！ 有没有什么好的解决办法？日志内容如下： \[2018-12-07T06:02…

---

## [怎么在java代码里使用sum\_bucket聚合操作](https://discuss.elastic.co/t/java-sum-bucket/161295)

<div class="topic-metadata">

**Author:** [@fengyuning](https://discuss.elastic.co/u/fengyuning)\
**Replies:** 2\
**Last updated:** [December 20, 2018, 6:17am UTC](https://discuss.elastic.co/t/java-sum-bucket/161295 "2018-12-20T06:17:03Z")

</div>

---

## [Elasticsearch突然崩溃，日志相关报错如下。](https://discuss.elastic.co/t/elasticsearch/156335)

<div class="topic-metadata">

**Author:** [@kdu\_fdj](https://discuss.elastic.co/u/kdu_fdj)\
**Replies:** 1\
**Last updated:** [December 3, 2018, 7:23am UTC](https://discuss.elastic.co/t/elasticsearch/156335 "2018-12-03T07:23:44Z")

</div>

相关报错已经搜索结果如下。 不知道限制fielddata上限能否解决这个问题。

---

## [为什么筛选条件api参数不是list?](https://discuss.elastic.co/t/api-list/153088)

<div class="topic-metadata">

**Author:** [@taoli](https://discuss.elastic.co/u/taoli)\
**Replies:** 1\
**Last updated:** [November 8, 2018, 8:34am UTC](https://discuss.elastic.co/t/api-list/153088 "2018-11-08T08:34:34Z")

</div>

如题， QueryBuilder queryBuilder = QueryBuilders.boolQuery() .filter(BuildTerm("regionid", searchEstate.getRegionId())) .filter(BuildTerm("gscopeid", searchEstate.getGscopeId())) .filter(BuildTerm("showinweb", searchEstate…

---

## [在Mac上编译启动es 6.4，报ClassNotFoundException ～ GenericAction](https://discuss.elastic.co/t/mac-es-6-4-classnotfoundexception-genericaction/155286)

<div class="topic-metadata">

**Author:** [@chen\_steven](https://discuss.elastic.co/u/chen_steven)\
**Replies:** 0\
**Last updated:** [November 4, 2018, 4:52am UTC](https://discuss.elastic.co/t/mac-es-6-4-classnotfoundexception-genericaction/155286 "2018-11-04T04:52:27Z")

</div>

JDK 11 gradle 4.8 es branch 6.4 idea 最新社区版 有人遇到过吗？

---

## [如何修改 dashboard 上方的導航欄?](https://discuss.elastic.co/t/dashboard/154160)

<div class="topic-metadata">

**Author:** [@harutsuki](https://discuss.elastic.co/u/harutsuki)\
**Replies:** 0\
**Last updated:** [October 26, 2018, 9:19am UTC](https://discuss.elastic.co/t/dashboard/154160 "2018-10-26T09:19:08Z")

</div>

各位好, 想請教一下各位，要如何修改Dashboard裡的上方導航欄，像是要增加連結和修改文字，是否有方法用 hack plugin 達成? 如果有是不是有一些 hack api document 可以參考? 還是說只能修改 kibana 的 core ?

---

## [使用javaAPI查询的Aggregations结果怎么解析](https://discuss.elastic.co/t/javaapi-aggregations/150317)

<div class="topic-metadata">

**Author:** [@fengyuning](https://discuss.elastic.co/u/fengyuning)\
**Replies:** 0\
**Last updated:** [September 28, 2018, 10:03am UTC](https://discuss.elastic.co/t/javaapi-aggregations/150317 "2018-09-28T10:03:40Z")

</div>

如上图所示，我在java API里使用了2个addAggregation，但是发现该结果不能转成json格式的数据，不知道怎么取值。有大神帮帮忙吗？

---

## [Elastic-logstash huawei netstream error](https://discuss.elastic.co/t/elastic-logstash-huawei-netstream-error/149097)

<div class="topic-metadata">

**Author:** [@tigerofcn](https://discuss.elastic.co/u/tigerofcn)\
**Replies:** 0\
**Last updated:** [September 19, 2018, 10:00am UTC](https://discuss.elastic.co/t/elastic-logstash-huawei-netstream-error/149097 "2018-09-19T10:00:10Z")

</div>

• Version:6.3.0 • Operating System: Centos 7.5 • Config File (if you have sensitive info, please remove it): Settings file in YAML Settings can be specified either in hierarchical form, e.g.: pipeline: batch: size…

---

## [Elasticsearch 节点数据盘数量不一致导致数据分布异常](https://discuss.elastic.co/t/elasticsearch/148550)

<div class="topic-metadata">

**Author:** [@79bcf509ed50dc69709a](https://discuss.elastic.co/u/79bcf509ed50dc69709a)\
**Replies:** 1\
**Last updated:** [September 19, 2018, 1:47am UTC](https://discuss.elastic.co/t/elasticsearch/148550 "2018-09-19T01:47:26Z")

</div>

你好，我的elasticsearch集群有20个节点，其中19个节点，每个节点有3块数据盘，单磁盘使用量在60%左右，剩下的一个节点有1块数据盘，然后发现这个节点磁盘使用量将近90%，请问如何解决类似的问题？

---

## [请问重置安全选项这个 post 是不是有问题](https://discuss.elastic.co/t/post/146129)

<div class="topic-metadata">

**Author:** [@Imr](https://discuss.elastic.co/u/Imr)\
**Replies:** 1\
**Last updated:** [August 29, 2018, 6:40am UTC](https://discuss.elastic.co/t/post/146129 "2018-08-29T06:40:18Z")

</div>

文档地址在： https://www.elastic.co/guide/en/elasticsearch/reference/current/secure-settings.html#secure-settings 最下面有方法： POST \_nodes/reload\_secure\_settings 但是我 POST 返回信息是 ： {"error":"Incorrect HTTP method for uri \[/\_node…

---

## [Logstash6.3 grok mysql slow日志](https://discuss.elastic.co/t/logstash6-3-grok-mysql-slow/142667)

<div class="topic-metadata">

**Author:** [@hjfeng1988](https://discuss.elastic.co/u/hjfeng1988)\
**Replies:** 1\
**Last updated:** [August 2, 2018, 2:11am UTC](https://discuss.elastic.co/t/logstash6-3-grok-mysql-slow/142667 "2018-08-02T02:11:39Z")

</div>

官方参考页：https://www.elastic.co/guide/en/logstash/current/logstash-config-for-filebeat-modules.html grok { match =\> { "message" =\> \["^# User@Host: %{USER:\[mysql\]\[slowlog\]\[user\]}(\\\[\[^\\\]\]+\\\])? @ %{HOSTNAME:\[mys…

---

## [Docker composer elc 6.2.4 Caused by: java.lang.IllegalStateException: Failed to create node environment](https://discuss.elastic.co/t/docker-composer-elc-6-2-4-caused-by-java-lang-illegalstateexception-failed-to-create-node-environment/141778)

<div class="topic-metadata">

**Author:** [@yang2306](https://discuss.elastic.co/u/yang2306)\
**Replies:** 0\
**Last updated:** [July 26, 2018, 1:23pm UTC](https://discuss.elastic.co/t/docker-composer-elc-6-2-4-caused-by-java-lang-illegalstateexception-failed-to-create-node-environment/141778 "2018-07-26T13:23:01Z")

</div>

openapi\_elc: image: docker.elastic.co/elasticsearch/elasticsearch:6.2.4 ports: - 9200:9200 - 9300:9300 environment: discovery.zen.ping.unicast.hosts: elasticsearch #discovery.zen.minimum\_master\_nodes: 1 cluster.n…

---

## [在线等：histogram 按时间 聚合 的 时区 问题](https://discuss.elastic.co/t/histogram/141473)

<div class="topic-metadata">

**Author:** [@kklingjie](https://discuss.elastic.co/u/kklingjie)\
**Replies:** 5\
**Last updated:** [July 25, 2018, 10:09am UTC](https://discuss.elastic.co/t/histogram/141473 "2018-07-25T10:09:02Z")

</div>

ES 插入的 数据 : "hits": \[{ "\_index": "log", "\_type": "accesslog", "\_id": "5b2977e843644c8a7e8b4582", "\_score": 1, "\_source": { "id": { "$id": "5b2977e843644c8a7e8b4582" }, "ip": "117.30.209.86", "source\_url": "www", "…

---

## [如何处理iis日志中出现中文路径的情况](https://discuss.elastic.co/t/iis/140857)

<div class="topic-metadata">

**Author:** [@heimao](https://discuss.elastic.co/u/heimao)\
**Replies:** 1\
**Last updated:** [July 25, 2018, 6:52am UTC](https://discuss.elastic.co/t/iis/140857 "2018-07-25T06:52:52Z")

</div>

我的是iis7.5版本，日志默认w3c格式。 2018-07-11 08:27:41 1.1.1.1 HEAD /安装说明书.txt - 80 - 2.2.2.2 - 404 0 2 124 然后grok的规则是 %{TIMESTAMP\_ISO8601:timestamp} %{IP:sourceip} %{WORD:method} %{URIPATH:uristem} (?:-|%{NOTSPACE:uriquery}) %{P…

---

## [Kibana的安装](https://discuss.elastic.co/t/kibana/141272)

<div class="topic-metadata">

**Author:** [@xiaolou](https://discuss.elastic.co/u/xiaolou)\
**Replies:** 1\
**Last updated:** [July 24, 2018, 3:06am UTC](https://discuss.elastic.co/t/kibana/141272 "2018-07-24T03:06:48Z")

</div>

Uploading... 我在安装的shi时候出现这个问题？请问是什么插件没装呢？有详细的kibana安装部署文档么？

---

## [Kibana 匯出 csv](https://discuss.elastic.co/t/kibana-csv/140680)

<div class="topic-metadata">

**Author:** [@ricky94511](https://discuss.elastic.co/u/ricky94511)\
**Replies:** 0\
**Last updated:** [July 19, 2018, 7:52am UTC](https://discuss.elastic.co/t/kibana-csv/140680 "2018-07-19T07:52:03Z")

</div>

想請問一下，最近在匯出csv的時候，在有些時間區間下載成formatted格式，點選buttom都沒反應，但是如果是下載成raw就都沒問題。 感謝

---

## [如何在Kibana中使用自定义的分析器](https://discuss.elastic.co/t/kibana/140658)

<div class="topic-metadata">

**Author:** [@wuwenjie\_cn](https://discuss.elastic.co/u/wuwenjie_cn)\
**Replies:** 0\
**Last updated:** [July 19, 2018, 6:28am UTC](https://discuss.elastic.co/t/kibana/140658 "2018-07-19T06:28:48Z")

</div>

如何在Kibana中使用自定义的分析器

---

## [采集信息重复](https://discuss.elastic.co/t/topic/140322)

<div class="topic-metadata">

**Author:** [@wuwenjie\_cn](https://discuss.elastic.co/u/wuwenjie_cn)\
**Replies:** 0\
**Last updated:** [July 17, 2018, 11:45am UTC](https://discuss.elastic.co/t/topic/140322 "2018-07-17T11:45:53Z")

</div>

日志背景描述： 日志是java程序的日志，每天按天自动分割成一个单独的日志文件。 用filebeat采集日志信息到elasticsearch后，在Kibana端查看时，发现采集上来的日志信息条数和日志源文件里的条数不一致（有重复的）， 查看filebeat采集日志，发现只采集了一次，并非重复采集，但是不知道为什么到elasticsearch里面，日志信息就重复了？ kibana端截图 linux 命令过滤后的行数信息 f…

---

## [How to compress \_source in elastic 5.6.1](https://discuss.elastic.co/t/how-to-compress-source-in-elastic-5-6-1/139858)

<div class="topic-metadata">

**Author:** [@haoyun](https://discuss.elastic.co/u/haoyun)\
**Replies:** 0\
**Last updated:** [July 13, 2018, 2:31am UTC](https://discuss.elastic.co/t/how-to-compress-source-in-elastic-5-6-1/139858 "2018-07-13T02:31:31Z")

</div>

Hello, In the web,I see "If disk space is a concern, rather increase the compression level instead of disabling the \_source." But I how to set this parameter ? Or jion this parameter to templates? Thanks! HAOYUN E\_m…

[Previous page](https://discuss.elastic.co/c/in-your-native-tongue/chinese/46.md?page=1)

[Next page](https://discuss.elastic.co/c/in-your-native-tongue/chinese/46.md?page=3)
