# 中文提问与讨论

**URL:** https://discuss.elastic.co/c/in-your-native-tongue/chinese/46.md?page=4

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 5

---

## [Elastic6.1报错 java.lang.ClassNotFoundException: org.elasticsearch.common.transport.InetSocketTransportAddress](https://discuss.elastic.co/t/elastic6-1-java-lang-classnotfoundexception-org-elasticsearch-common-transport-inetsockettransportaddress/114079)

<div class="topic-metadata">

**Author:** [@b7e5eceffd46f9453deb](https://discuss.elastic.co/u/b7e5eceffd46f9453deb)\
**Replies:** 4\
**Last updated:** [January 29, 2018, 11:45am UTC](https://discuss.elastic.co/t/elastic6-1-java-lang-classnotfoundexception-org-elasticsearch-common-transport-inetsockettransportaddress/114079 "2018-01-29T11:45:35Z")

</div>

新手学习elasticsearch 6.1.0，使用gradle来构建项目 build.gradle： dependencies { compile 'org.springframework.boot:spring-boot-starter-actuator' compile 'org.elasticsearch:elasticsearch:6.1.0' compile 'org.elasticsearch.…

---

## [集群查询变慢](https://discuss.elastic.co/t/topic/110732)

<div class="topic-metadata">

**Author:** [@Zhengcong\_Yin](https://discuss.elastic.co/u/Zhengcong_Yin)\
**Replies:** 3\
**Last updated:** [January 15, 2018, 2:50am UTC](https://discuss.elastic.co/t/topic/110732 "2018-01-15T02:50:18Z")

</div>

43G数据， 4个主分片，没有副本。 集群1： 单节点 集群2： 3个主节点，4个数据节点，1个客户节点。 2种查询： sort by distance; match query 同步发送请求，计算平均的took值。 发现集群2 took值大于集群1. 如何测试水平扩展性？用什么指标及工具？ 谢谢

---

## [Elasticsearch可以对历史数据汇总计算吗？](https://discuss.elastic.co/t/elasticsearch/110658)

<div class="topic-metadata">

**Author:** [@longqinsi](https://discuss.elastic.co/u/longqinsi)\
**Replies:** 1\
**Last updated:** [December 15, 2017, 3:01am UTC](https://discuss.elastic.co/t/elasticsearch/110658 "2017-12-15T03:01:41Z")

</div>

我需要为公司的Web服务网关开发日志组件 功能：记录通过网关发生的所有web服务调用的日志，包括调用时间、调用人、被调用服务名称、被调用服务所属应用名称、调用是否成功、调用成功时web服务执行时长 要求：能查看过去某个时间段内全部服务、某应用所含服务、单个服务的总调用次数、成功调用次数及平均响应时长、失败调用次数。 背景：服务调用次数会很大，所以实时计算较长时间段的服务调用统计数据不可行，我们计划定期对调用日志进行汇总计算，查询时…

---

## [Adding custom pattern failed!](https://discuss.elastic.co/t/adding-custom-pattern-failed/108812)

<div class="topic-metadata">

**Author:** [@dominicdeng](https://discuss.elastic.co/u/dominicdeng)\
**Replies:** 0\
**Last updated:** [November 23, 2017, 1:26am UTC](https://discuss.elastic.co/t/adding-custom-pattern-failed/108812 "2017-11-23T01:26:08Z")

</div>

Hi experts I am a newer to Kibana(6.x) , when I tried to add custom patterns with the instruction 'https://www.elastic.co/guide/en/kibana/current/grokdebugger-getting-started.html1' but failed. \[1\] Can anyone help me…

---

## [Logstash 對於 postgresql log的filter 問題](https://discuss.elastic.co/t/logstash-postgresql-log-filter/102816)

<div class="topic-metadata">

**Author:** [@stephen\_luan](https://discuss.elastic.co/u/stephen_luan)\
**Replies:** 3\
**Last updated:** [November 12, 2017, 1:50am UTC](https://discuss.elastic.co/t/logstash-postgresql-log-filter/102816 "2017-11-12T01:50:13Z")

</div>

Hi All, 不知道這裡有沒有人使用logstash , 把postgresql log 做fileter, 找了很多方法，都無法實現，postgresql log 大致如下， 不知道各位有沒有比較好的解決方法 2017-10-02 16:00:06 CST\[2017-10-02 15:59:13 CST\]59d1f1d1.61ad\[25005\]10.0.10.\* username || LOG: duration: 9904.…

---

## [SSD对于es的优势](https://discuss.elastic.co/t/ssd-es/98074)

<div class="topic-metadata">

**Author:** [@Gongruixiao](https://discuss.elastic.co/u/Gongruixiao)\
**Replies:** 1\
**Last updated:** [September 11, 2017, 4:55am UTC](https://discuss.elastic.co/t/ssd-es/98074 "2017-09-11T04:55:40Z")

</div>

ES 单节点，5.4.2版本 每秒4万写入量，ssd和普通硬盘的qps无差距，想咨询ssd对于ES的优势体现在哪里

---

## [Logstash-input-jdbc 如何对 statement 设置时间变量](https://discuss.elastic.co/t/logstash-input-jdbc-statement/98821)

<div class="topic-metadata">

**Author:** [@Moln](https://discuss.elastic.co/u/Moln)\
**Replies:** 0\
**Last updated:** [August 30, 2017, 8:51am UTC](https://discuss.elastic.co/t/logstash-input-jdbc-statement/98821 "2017-08-30T08:51:09Z")

</div>

怎么设置让 input-jdbc 支持时间变量呢？ input { jdbc { #... statement =\> "select \* from table\_name\_%{+yyyyMM}" #... } }

---

## [Ik分词器对"中国人民银行"分词后无法命中问题](https://discuss.elastic.co/t/ik/96732)

<div class="topic-metadata">

**Author:** [@James\_Kelvin](https://discuss.elastic.co/u/James_Kelvin)\
**Replies:** 0\
**Last updated:** [August 11, 2017, 8:48am UTC](https://discuss.elastic.co/t/ik/96732 "2017-08-11T08:48:27Z")

</div>

doc内容： {“content”:“中国人民银行”} ik\_max\_word分词。 分词结果如下： 中国人民银行|中国人民|中国人|中国|国人|人民银行|人民|银行 执行以下查询： curl -XGET ‘localhost:9200/chineseindex/\_search?pretty’ -d ‘{“explain”:true,“query”:{“query\_string”:{“fields”:\[“content”\],…

---

## [自定义分词器后，如何才能进行词干提取](https://discuss.elastic.co/t/topic/96573)

<div class="topic-metadata">

**Author:** [@DimonHo](https://discuss.elastic.co/u/DimonHo)\
**Replies:** 0\
**Last updated:** [August 10, 2017, 8:43am UTC](https://discuss.elastic.co/t/topic/96573 "2017-08-10T08:43:55Z")

</div>

假设我又这样一个索引： PUT myindex { "settings": { "analysis": { "analyzer": { "my\_analyzer": { "tokenizer": "my\_tokenizer", "filter": \[ "lowercase", "my\_stemmer" …

---

## [None of the configured nodes are available（5.5.0）](https://discuss.elastic.co/t/none-of-the-configured-nodes-are-available-5-5-0/94951)

<div class="topic-metadata">

**Author:** [@felayman](https://discuss.elastic.co/u/felayman)\
**Replies:** 4\
**Last updated:** [August 10, 2017, 4:07am UTC](https://discuss.elastic.co/t/none-of-the-configured-nodes-are-available-5-5-0/94951 "2017-08-10T04:07:15Z")

</div>

在使用官方Elasticsearch5.5.0版本的java客户端来连接启动在本地的ES的时候会出现如下错误: NoNodeAvailableException\[None of the configured nodes are available: \[{#transport#-1}{RtE8nzE9RMSz6nsPf28R8w}{localhost}{127.0.0.1:9300}\] \] at org.elasticsearch.c…

---

## [Filebeat 的 logstash output 是否可以設定二個hosts](https://discuss.elastic.co/t/filebeat-logstash-output-hosts/94563)

<div class="topic-metadata">

**Author:** [@stephen\_luan](https://discuss.elastic.co/u/stephen_luan)\
**Replies:** 5\
**Last updated:** [August 10, 2017, 1:04am UTC](https://discuss.elastic.co/t/filebeat-logstash-output-hosts/94563 "2017-08-10T01:04:46Z")

</div>

Hi all, 有一個問題請教，filebeat 在設定檔內是否可以設定在logstash output的hosts 為兩個以上的logstash hosts, 並且是每個logstash host, 都能收到一模一樣的資料，如果不行，是否可以一台client 啟動兩個filebeat呢？ 在麻煩大家的幫助，謝謝。

---

## [Iis日志分段格式和映射](https://discuss.elastic.co/t/iis/92006)

<div class="topic-metadata">

**Author:** [@dog](https://discuss.elastic.co/u/dog)\
**Replies:** 3\
**Last updated:** [August 1, 2017, 2:47am UTC](https://discuss.elastic.co/t/iis/92006 "2017-08-01T02:47:34Z")

</div>

我需要解析IIS的日志文件，，我想它在Kibana里得日志看起来是这样的格式，我看了文档，做了一些尝试之后，现在毫无进展，有人可以帮助我吗 我希望在Kibana显示的日志模板大致为 "date"：2017-07-06 02:09:01 "serverIP": 127.0.0.1 "method": GET

---

## [使用curl测试 Elasticsearch 是否启动成功----失败](https://discuss.elastic.co/t/curl-elasticsearch/93916)

<div class="topic-metadata">

**Author:** [@eboy](https://discuss.elastic.co/u/eboy)\
**Replies:** 7\
**Last updated:** [August 1, 2017, 2:46am UTC](https://discuss.elastic.co/t/curl-elasticsearch/93916 "2017-08-01T02:46:57Z")

</div>

今天刚学elastic，跟着看到这里： https://www.elastic.co/guide/cn/elasticsearch/guide/current/running-elasticsearch.html 我的 elastic在 localhost:9200 打开是有数据的，就是显示名字的那些数据。 但是使用curl在cmd输入curl 'http://localhost:9200/?pretty'，显示报错的{error:..…

---

## [使用logstash的kafka input plugin插件，进程重启后offset能否指定具体的数值？](https://discuss.elastic.co/t/logstash-kafka-input-plugin-offset/93884)

<div class="topic-metadata">

**Author:** [@kai\_fu](https://discuss.elastic.co/u/kai_fu)\
**Replies:** 1\
**Last updated:** [July 26, 2017, 7:44am UTC](https://discuss.elastic.co/t/logstash-kafka-input-plugin-offset/93884 "2017-07-26T07:44:10Z")

</div>

如果logstash重启，如何保证读取kafka的offset继续上次重启的地方开始，auto\_offset\_reset只是支持earliest/lastest，可能导致数据读取缺少或重复，旧版的zk\_connect方式，应该可以把offset维护在zookeeper上，新版bootstrap\_servers方式，没有考虑offset的维护？

---

## [More\_like\_this使用分词器后居然查不出来](https://discuss.elastic.co/t/more-like-this/93328)

<div class="topic-metadata">

**Author:** [@401825317](https://discuss.elastic.co/u/401825317)\
**Replies:** 2\
**Last updated:** [July 26, 2017, 2:19am UTC](https://discuss.elastic.co/t/more-like-this/93328 "2017-07-26T02:19:54Z")

</div>

elasticsearch版本：5.4.0 插件：ik,pinyin jvm:1.8 setting： PUT /testcar/ { "index": { "analysis": { "analyzer": { "ik\_pinyin\_analyzer": { "type": "custom", "tokenizer": "ik\_smart", …

---

## [Elasticsearch有配置可以保护正在重启的节点吗？](https://discuss.elastic.co/t/elasticsearch/88680)

<div class="topic-metadata">

**Author:** [@BrickXu](https://discuss.elastic.co/u/BrickXu)\
**Replies:** 2\
**Last updated:** [July 5, 2017, 7:57am UTC](https://discuss.elastic.co/t/elasticsearch/88680 "2017-07-05T07:57:46Z")

</div>

Hi 各位， 我的Elasticsearch版本是2.4.2，最近有一个问题想请教下： 如果节点突然宕机了，用程序/手工启动后，recovery过程中，如何保证外部的请求不会路由到这个节点呢？ 感谢！

---

## [PF\_RING on Packetbeat error chinese](https://discuss.elastic.co/t/pf-ring-on-packetbeat-error-chinese/91365)

<div class="topic-metadata">

**Author:** [@pgyggi](https://discuss.elastic.co/u/pgyggi)\
**Replies:** 1\
**Last updated:** [July 4, 2017, 9:21am UTC](https://discuss.elastic.co/t/pf-ring-on-packetbeat-error-chinese/91365 "2017-07-04T09:21:09Z")

</div>

everybody, 1、I want to use PF\_RING for Packetbeat and then install PF\_RING on my CentOS(1161 min),PF\_RING is work. see: \[root@packetbeat packetbeat\]# lsmod |grep pf\_ring pf\_ring 1234205 0 2、 I clone the latest version b…

---

## [Flume 关于 X-Pack认证的写法？](https://discuss.elastic.co/t/flume-x-pack/90046)

<div class="topic-metadata">

**Author:** [@lapertem4](https://discuss.elastic.co/u/lapertem4)\
**Replies:** 1\
**Last updated:** [July 4, 2017, 9:14am UTC](https://discuss.elastic.co/t/flume-x-pack/90046 "2017-07-04T09:14:01Z")

</div>

Hi, 请问谁有FLume 在认证X-pack配置方法实例，谢谢。 I'm using Flume+ES+Kibana ES and Kibana works fine, but log can't transfer through, On Flume side, 20:29:54.061 INFO org.elasticsearch.client.transport.TransportClientNodesService…

---

## [服务莫名断开链接，然后报：None of the configured nodes are available: \[{#transport#-1](https://discuss.elastic.co/t/none-of-the-configured-nodes-are-available-transport-1/89488)

<div class="topic-metadata">

**Author:** [@maoli](https://discuss.elastic.co/u/maoli)\
**Replies:** 1\
**Last updated:** [July 4, 2017, 9:13am UTC](https://discuss.elastic.co/t/none-of-the-configured-nodes-are-available-transport-1/89488 "2017-07-04T09:13:08Z")

</div>

版本5.4.1 如果我链接本机服务没有任何问题，但是如果我链接远程服务，运行一段时间后，服务器和客户端莫名断掉，然后就抛标题那个异常了。很奇怪，注意：是正常运行一段时间后，链接就断掉了，不是链接不上，而且索引和数据都有写进去。 这是个什么鬼问题。。。。。。。

---

## [为什么相同的文本搜索结果的\_score不同？](https://discuss.elastic.co/t/-score/78135)

<div class="topic-metadata">

**Author:** [@watson](https://discuss.elastic.co/u/watson)\
**Replies:** 3\
**Last updated:** [May 29, 2017, 3:35pm UTC](https://discuss.elastic.co/t/-score/78135 "2017-05-29T15:35:15Z")

</div>

\*\*Elasticsearch version2.3.3: Plugins installed: \[head,ik\] \*\*JVM versionopenjdk version "1.8.0\_111": \*\*OS versionCentOS release 6.8 (Final): +++++++++++++++++++++++++++++++++++++++++ my mapping： "mappings": { "we…

---

## [Filebeats @timestamp 可也删除或者更改格式？](https://discuss.elastic.co/t/filebeats-timestamp/77100)

<div class="topic-metadata">

**Author:** [@zhenxing914](https://discuss.elastic.co/u/zhenxing914)\
**Replies:** 3\
**Last updated:** [May 29, 2017, 3:06pm UTC](https://discuss.elastic.co/t/filebeats-timestamp/77100 "2017-05-29T15:06:45Z")

</div>

我想通过filebeats收集日志，然后发送给eagle进行处理， 但是eagle不能处理filebeats @timestamp这个字段（2017-03-01T02:30:30.558Z） 我需要将2017-03-01T02:30:30.558Z 转换成 2017-03-01 02:30:30,558 filebeats @timestamp 可也删除或者更改格式？

---

## [Logstash处理数据延时问题？](https://discuss.elastic.co/t/logstash/86593)

<div class="topic-metadata">

**Author:** [@can.zhang](https://discuss.elastic.co/u/can.zhang)\
**Replies:** 1\
**Last updated:** [May 29, 2017, 3:05pm UTC](https://discuss.elastic.co/t/logstash/86593 "2017-05-29T15:05:32Z")

</div>

我们部署的ELK结构是filbeat+logstash+ES服务。 filebeat采集数据，通过logstash处理后，存入ES服务。 想咨询下，logstash有处理能力的限制吗？logstash能同时接受多少filebeat上传的数据？

---

## [Elasticsearch单节点写入并发多少算是正常的?](https://discuss.elastic.co/t/elasticsearch/86550)

<div class="topic-metadata">

**Author:** [@willdx](https://discuss.elastic.co/u/willdx)\
**Replies:** 1\
**Last updated:** [May 29, 2017, 3:02pm UTC](https://discuss.elastic.co/t/elasticsearch/86550 "2017-05-29T15:02:52Z")

</div>

环境 ELK 5 机器性能: 4核/16GB/SSD硬盘 问题1: Elasticsearch单节点写入速度(并发量)多少算是正常的? 我先把日志写到redis, 再用logstash转存到Elasticsearch, 并发量大概在1500-2000每秒的样子, 感觉单节点的Elasticsearch支持的并发量并不是很大, 这样是正常的么? 问题2: 另外, 如果我要提升写入Elastic的性能, 是否只能用集群的方式…

---

## [Filebeat 不释放文件句柄问题？求助](https://discuss.elastic.co/t/filebeat/85982)

<div class="topic-metadata">

**Author:** [@can.zhang](https://discuss.elastic.co/u/can.zhang)\
**Replies:** 2\
**Last updated:** [May 29, 2017, 2:51pm UTC](https://discuss.elastic.co/t/filebeat/85982 "2017-05-29T14:51:29Z")

</div>

我的环境是使用filebeat收集应用日志，上传到logstash-indexer，然后存入ES， filebeat版本是 1.3.1(amd64)，大概的配置是： - paths: - /opt/mateinfo/logs/app/app.log input\_type: log fields: log\_format: wfm\_log4j fields\_under\_root: true ignore\_older: 1m close\_o…

---

## [如何确定es集群需要增加节点了](https://discuss.elastic.co/t/es/84690)

<div class="topic-metadata">

**Author:** [@zhaochl](https://discuss.elastic.co/u/zhaochl)\
**Replies:** 3\
**Last updated:** [May 29, 2017, 2:47pm UTC](https://discuss.elastic.co/t/es/84690 "2017-05-29T14:47:22Z")

</div>

现有集群2个节点，CPU和内存都很高，想增加一个节点，不知道是不是会降低原来2台机器的负载了， 还有如何知道集群该扩展了，一般的机器节点数与文档总量关系是如何对应的了 多谢

---

## [Logstash可以生成全局唯一且自增的id吗？](https://discuss.elastic.co/t/logstash-id/83010)

<div class="topic-metadata">

**Author:** [@elastic\_johnson\_yi](https://discuss.elastic.co/u/elastic_johnson_yi)\
**Replies:** 1\
**Last updated:** [May 3, 2017, 4:12am UTC](https://discuss.elastic.co/t/logstash-id/83010 "2017-05-03T04:12:46Z")

</div>

我想要的其实和uuid插件提供的uuid类似，但是uuid太长，而且我不需要universal唯一，只要在我的logstash服务器范围内唯一即可。 请问有没有类似uuid插件的，能返回一个自增的，且服务器内唯一的id的插件？ 或者有什么其他方法能得到这样的id。 我需要在后续的filter中使用这个id。 谢谢。

---

## [紧急求助(ebc71b)](https://discuss.elastic.co/t/ebc71b/84107)

<div class="topic-metadata">

**Author:** [@yxd777](https://discuss.elastic.co/u/yxd777)\
**Replies:** 1\
**Last updated:** [May 3, 2017, 4:00am UTC](https://discuss.elastic.co/t/ebc71b/84107 "2017-05-03T04:00:23Z")

</div>

我的elastic cloud ID是ebc71b，在重新启动cluster后我连不上ES和kibana服务器了，请帮忙查看一下。 不知是否与我设置了IP过滤有关。 谢谢！

---

## [Logstash tcp input插件 keepalive 的问题](https://discuss.elastic.co/t/logstash-tcp-input-keepalive/82403)

<div class="topic-metadata">

**Author:** [@qin](https://discuss.elastic.co/u/qin)\
**Replies:** 0\
**Last updated:** [April 14, 2017, 10:50am UTC](https://discuss.elastic.co/t/logstash-tcp-input-keepalive/82403 "2017-04-14T10:50:45Z")

</div>

我使用logstash的tcp input插件,它是server端，在使用的过程中,client异常断开连接,但是server没有断开, 所以服务器的TCP连接数一直在增加; 我试着修改OS tcp\_keepalive参数,但是不起作用 logstash version 5.0.1 tcp config: input { tcp { host =\> "0.0.0.0" port =\> 4561 mode =\> "server" …

---

## [ES5.X 在只有两个nodes时查询性能还不如一个node](https://discuss.elastic.co/t/es5-x-nodes-node/73780)

<div class="topic-metadata">

**Author:** [@kevin-tang-rs](https://discuss.elastic.co/u/kevin-tang-rs)\
**Replies:** 1\
**Last updated:** [March 20, 2017, 11:27pm UTC](https://discuss.elastic.co/t/es5-x-nodes-node/73780 "2017-03-20T23:27:49Z")

</div>

配置信息： 版本：ES 5.0.1 或者ES5.1.2 ; replic: 1; shard:3; index:30，每个index的大小是4G左右，总共约120G数据量。 操作： 创建两个nodes的集群，通过kibana进行查询的时候，发现两个nodes主机上的IO是先从其中一个节点不固定的查询，然后过了几分钟后，另一个节点上才会有相应的IO查询。 结果： 导致两个节点的集群查询能力不如一个节点的时候…

---

## [使用docker-compose创建的es集群，怎么使用Java连接进行查询？](https://discuss.elastic.co/t/docker-compose-es-java/78089)

<div class="topic-metadata">

**Author:** [@silence](https://discuss.elastic.co/u/silence)\
**Replies:** 2\
**Last updated:** [March 20, 2017, 11:26pm UTC](https://discuss.elastic.co/t/docker-compose-es-java/78089 "2017-03-20T23:26:59Z")

</div>

我采用官方文档中说明的，使用了docker-compose搭建了一个es集群。 采用curl 方式访问都没有任何问题，使用elasticsearch-head工具监控也是正常的。 但是使用Java编写代码链接集群出现异常，由于搭建es集群默认使用的是docker-compose中指定的网络链接方式，IP也是docker-compose自动分配的。与当前机器都不再同一个网段内，因此不知道怎么访问这个docker搭建的es集群？ 亲们有…

[Previous page](https://discuss.elastic.co/c/in-your-native-tongue/chinese/46.md?page=3)

[Next page](https://discuss.elastic.co/c/in-your-native-tongue/chinese/46.md?page=5)
