# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=373

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 374

---

## [The analyser in mapping is not getting applied to field](https://discuss.elastic.co/t/the-analyser-in-mapping-is-not-getting-applied-to-field/334286)

<div class="topic-metadata">

**Author:** [@Sheereen](https://discuss.elastic.co/u/Sheereen)\
**Replies:** 2\
**Last updated:** [May 25, 2023, 9:38am UTC](https://discuss.elastic.co/t/the-analyser-in-mapping-is-not-getting-applied-to-field/334286 "2023-05-25T09:38:44Z")

</div>

This is the mapping and settings { "blogs\_fixed2": { "aliases": {}, "mappings": { "\_meta": { "created\_by": "Sheereen Hamza KV" }, "properties": { "@timestamp": { "t…

---

## [Manage Multiple instances of Elasticsearch cluster with different version by ECK](https://discuss.elastic.co/t/manage-multiple-instances-of-elasticsearch-cluster-with-different-version-by-eck/332894)

<div class="topic-metadata">

**Author:** [@HadarPeeran](https://discuss.elastic.co/u/HadarPeeran)\
**Replies:** 3\
**Last updated:** [May 25, 2023, 9:02am UTC](https://discuss.elastic.co/t/manage-multiple-instances-of-elasticsearch-cluster-with-different-version-by-eck/332894 "2023-05-25T09:02:00Z")

</div>

I should deploy Elasticsearch 8 and Elasticsearch 7 on the same AKS cluster. Is it possible to upgrade the ECK operator to the latest 2.7.0 and deploy Elasticsearch 7 and 8 by this one operator? thanks

---

## [Search\_phase\_execution\_exception error with all\_shared failes](https://discuss.elastic.co/t/search-phase-execution-exception-error-with-all-shared-failes/334169)

<div class="topic-metadata">

**Author:** [@Kapildev](https://discuss.elastic.co/u/Kapildev)\
**Replies:** 15\
**Last updated:** [May 25, 2023, 6:18am UTC](https://discuss.elastic.co/t/search-phase-execution-exception-error-with-all-shared-failes/334169 "2023-05-25T06:18:32Z")

</div>

hi team i am facing this search\_phase\_execution\_exception Please find the details. curl -X GET "localhost:9200/\_cluster/health?filter\_path=status,\*\_shards&pretty" { "status" : "red", "active\_primary\_shards" : 0, "…

---

## [How to view inner IP packet detail](https://discuss.elastic.co/t/how-to-view-inner-ip-packet-detail/334267)

<div class="topic-metadata">

**Author:** [@a\_techie](https://discuss.elastic.co/u/a_techie)\
**Replies:** 0\
**Last updated:** [May 25, 2023, 4:50am UTC](https://discuss.elastic.co/t/how-to-view-inner-ip-packet-detail/334267 "2023-05-25T04:50:21Z")

</div>

Hello, We send flow data from network gears to Elasticsearch. There are packets that are encapsulated in another IP header. For example, please refer: CS Enterprise on cloudshark.org In the flow data search using Kiban…

---

## [I am getting the error in elasticsearch Rollup jobs](https://discuss.elastic.co/t/i-am-getting-the-error-in-elasticsearch-rollup-jobs/334262)

<div class="topic-metadata">

**Author:** [@daemon](https://discuss.elastic.co/u/daemon)\
**Replies:** 0\
**Last updated:** [May 25, 2023, 12:32am UTC](https://discuss.elastic.co/t/i-am-getting-the-error-in-elasticsearch-rollup-jobs/334262 "2023-05-25T00:32:24Z")

</div>

I am getting the error in Kibana Rollup Jobs screen as shown in the image. Is there any solution?

---

## [Logstash plugin is installed and not listed and found by logstash](https://discuss.elastic.co/t/logstash-plugin-is-installed-and-not-listed-and-found-by-logstash/333595)

<div class="topic-metadata">

**Author:** [@SAMY-ELK](https://discuss.elastic.co/u/SAMY-ELK)\
**Replies:** 5\
**Last updated:** [May 23, 2023, 9:24pm UTC](https://discuss.elastic.co/t/logstash-plugin-is-installed-and-not-listed-and-found-by-logstash/333595 "2023-05-23T21:24:34Z")

</div>

Hi Team, Microsoft-sentinel-logstash-output-plugin is installed on logstash (7.15.1) server Linux but is not listed and found by logstash : /usr/share/logstash/bin #./logstash-plugin list Plugin successfully install…

---

## [COPY - PASTE from KIBANA without “ROW” and “COLUMN” information - 2](https://discuss.elastic.co/t/copy-paste-from-kibana-without-row-and-column-information-2/334026)

<div class="topic-metadata">

**Author:** [@mch](https://discuss.elastic.co/u/mch)\
**Replies:** 3\
**Last updated:** [May 24, 2023, 2:57pm UTC](https://discuss.elastic.co/t/copy-paste-from-kibana-without-row-and-column-information-2/334026 "2023-05-24T14:57:41Z")

</div>

Hello everyone, I have the same problem as described in the following ticket: COPY - PASTE from KIBANA without "ROW" and "COLUMN" information It's a real pain to export the selection we're interested in every time, whe…

---

## [How can I handle typos in synonyms?](https://discuss.elastic.co/t/how-can-i-handle-typos-in-synonyms/334141)

<div class="topic-metadata">

**Author:** [@gennadii](https://discuss.elastic.co/u/gennadii)\
**Replies:** 12\
**Last updated:** [May 24, 2023, 2:54pm UTC](https://discuss.elastic.co/t/how-can-i-handle-typos-in-synonyms/334141 "2023-05-24T14:54:38Z")

</div>

I have synonyms in synonyms.txt - "auto, vehicle =\> car". In index I have a document with string "car" and an analyzer to handle synonyms. When you use "auto", for example, it will also return you results for "car". B…

---

## [Not able to stop the tasks in devtool (Kibana)](https://discuss.elastic.co/t/not-able-to-stop-the-tasks-in-devtool-kibana/333857)

<div class="topic-metadata">

**Author:** [@sanjeevtomar](https://discuss.elastic.co/u/sanjeevtomar)\
**Replies:** 1\
**Last updated:** [May 24, 2023, 2:36pm UTC](https://discuss.elastic.co/t/not-able-to-stop-the-tasks-in-devtool-kibana/333857 "2023-05-24T14:36:43Z")

</div>

1.Firstly, "delete by query" was run. it exhausted 100 % of disk space, then I tried POST /\_forcemerge after adding more disk space but this space is also getting consumed rapidly can I cancel the tasks which are …

---

## [Corrupt index in Logstash causing primary shard is not active](https://discuss.elastic.co/t/corrupt-index-in-logstash-causing-primary-shard-is-not-active/334229)

<div class="topic-metadata">

**Author:** [@Vaibhav\_Aher](https://discuss.elastic.co/u/Vaibhav_Aher)\
**Replies:** 2\
**Last updated:** [May 24, 2023, 2:34pm UTC](https://discuss.elastic.co/t/corrupt-index-in-logstash-causing-primary-shard-is-not-active/334229 "2023-05-24T14:34:19Z")

</div>

Elasticsearch Version- opendistroforelasticsearch-1.4.0 Logstash Version - logstash-7.4.2 Error on Logstash: retrying failed action with response code: 503 ({"type"=\>"unavailable\_shards\_exception", "reason"=\>"\[ABC-20…

---

## [Elasticsearch Get All data which has specified value for some of the field](https://discuss.elastic.co/t/elasticsearch-get-all-data-which-has-specified-value-for-some-of-the-field/334201)

<div class="topic-metadata">

**Author:** [@Mustafa\_AYDOGDU](https://discuss.elastic.co/u/Mustafa_AYDOGDU)\
**Replies:** 1\
**Last updated:** [May 24, 2023, 2:22pm UTC](https://discuss.elastic.co/t/elasticsearch-get-all-data-which-has-specified-value-for-some-of-the-field/334201 "2023-05-24T14:22:57Z")

</div>

Hello, I have a query which gets data with project\_id=1 and project\_user\_id=1: GET /tweet\_user\_id\_index/\_search { "query": { "bool": { "should": \[ { "term": { "project\_id": { …

---

## ['\_source' filtering is slower than query without '\_source' field](https://discuss.elastic.co/t/source-filtering-is-slower-than-query-without-source-field/333556)

<div class="topic-metadata">

**Author:** [@nadeem.akhter](https://discuss.elastic.co/u/nadeem.akhter)\
**Replies:** 7\
**Last updated:** [May 24, 2023, 2:17pm UTC](https://discuss.elastic.co/t/source-filtering-is-slower-than-query-without-source-field/333556 "2023-05-24T14:17:17Z")

</div>

I have an elasticsearch instance with some data on it, and when trying queries on the data, it is slower to filter '\_source' in query than not mentioning the '\_source' key at all. Is there any specific reason for this? P…

---

## [.kibana\_task\_manager UNASSIGNED ALLOCATION\_FAILED](https://discuss.elastic.co/t/kibana-task-manager-unassigned-allocation-failed/334211)

<div class="topic-metadata">

**Author:** [@cyberzlo](https://discuss.elastic.co/u/cyberzlo)\
**Replies:** 0\
**Last updated:** [May 24, 2023, 11:44am UTC](https://discuss.elastic.co/t/kibana-task-manager-unassigned-allocation-failed/334211 "2023-05-24T11:44:27Z")

</div>

I have a single node (without a cluster of several machines) that had an uncontrolled reboot due to power failure. How can I fix this problem? kibana\[4428\]: no\_shard\_available\_action\_exception: null'. Re…

---

## [Kibana Error - Failed to open PIT](https://discuss.elastic.co/t/kibana-error-failed-to-open-pit/334166)

<div class="topic-metadata">

**Author:** [@Yos](https://discuss.elastic.co/u/Yos)\
**Replies:** 1\
**Last updated:** [May 24, 2023, 12:16pm UTC](https://discuss.elastic.co/t/kibana-error-failed-to-open-pit/334166 "2023-05-24T12:16:39Z")

</div>

Kibana Version : 8.5.3 Hello The following error is intermittently logged in Kibana's logs Please let me know the cause of this and how to address it. Best Regards \[2023-05-24T11:30:54.572+09:00\]\[ERROR\]\[savedobject…

---

## [Sending all elasticsearch logs to a diode](https://discuss.elastic.co/t/sending-all-elasticsearch-logs-to-a-diode/334207)

<div class="topic-metadata">

**Author:** [@willsy](https://discuss.elastic.co/u/willsy)\
**Replies:** 0\
**Last updated:** [May 24, 2023, 10:49am UTC](https://discuss.elastic.co/t/sending-all-elasticsearch-logs-to-a-diode/334207 "2023-05-24T10:49:57Z")

</div>

Hi there, I am completing some dev work and trying to input all of the ingested elasticsearch data from my system, into logstash (on the same server as elasticsearch) and output this to a one way data diode to allow the…

---

## [Cluster State Yellow: 2 shards initializing with multiple failed attempts: IllegalArgumentException \[ReleasableBytesStreamOutput cannot hold more than 2GB of data](https://discuss.elastic.co/t/cluster-state-yellow-2-shards-initializing-with-multiple-failed-attempts-illegalargumentexception-releasablebytesstreamoutput-cannot-hold-more-than-2gb-of-data/334008)

<div class="topic-metadata">

**Author:** [@Sarit\_Ghosh](https://discuss.elastic.co/u/Sarit_Ghosh)\
**Replies:** 5\
**Last updated:** [May 24, 2023, 9:43am UTC](https://discuss.elastic.co/t/cluster-state-yellow-2-shards-initializing-with-multiple-failed-attempts-illegalargumentexception-releasablebytesstreamoutput-cannot-hold-more-than-2gb-of-data/334008 "2023-05-24T09:43:51Z")

</div>

For about a week, we are seeing the following error and cluster state yellow. On checking the \_cluster/state we get this - Elastic Search Version - 7.17 (Please let me know if more data is needed) {"state":"INITIALIZIN…

---

## [Service unavailable error code 503 all shard failed](https://discuss.elastic.co/t/service-unavailable-error-code-503-all-shard-failed/333976)

<div class="topic-metadata">

**Author:** [@target\_test](https://discuss.elastic.co/u/target_test)\
**Replies:** 11\
**Last updated:** [May 24, 2023, 9:30am UTC](https://discuss.elastic.co/t/service-unavailable-error-code-503-all-shard-failed/333976 "2023-05-24T09:30:24Z")

</div>

Hello all, I got this problem showing that service unavailable {"statusCode":503,"error":"Service Unavailable","message":"\[all shards failed: search\_phase\_execution\_exception\\n\\tRoot causes:\\n\\t\\tno\_shard\_available\_act…

---

## [当调用ElasticsearchClient的query方法时, static字段丢失或者改变, 这是为什么呀](https://discuss.elastic.co/t/elasticsearchclient-query-static/334181)

<div class="topic-metadata">

**Author:** [@xiaochunyong](https://discuss.elastic.co/u/xiaochunyong)\
**Replies:** 2\
**Last updated:** [May 24, 2023, 9:24am UTC](https://discuss.elastic.co/t/elasticsearchclient-query-static/334181 "2023-05-24T09:24:28Z")

</div>

Java API client version: 7.17.10 Java version: jdk-17.0.3.1 Elasticsearch Version: 7.17 我有个代码仓库可以复现这个问题: GitHub - xiaochunyong/elasticsearch-threadlocal-reference-changed 有一个类UserHolder, 里面有个ThreadLocal变量 public cla…

---

## [How to show several docs with the same field?](https://discuss.elastic.co/t/how-to-show-several-docs-with-the-same-field/334198)

<div class="topic-metadata">

**Author:** [@asebalo98](https://discuss.elastic.co/u/asebalo98)\
**Replies:** 0\
**Last updated:** [May 24, 2023, 9:20am UTC](https://discuss.elastic.co/t/how-to-show-several-docs-with-the-same-field/334198 "2023-05-24T09:20:52Z")

</div>

I have documents that have a ”CompanyId” field that can be the same for multiple documents. I want Elasticsearch to take up to 3 documents with the same “CompanyId” and the highest score, and then rank them in the overa…

---

## [Warm tier shards being allocated to data nodes](https://discuss.elastic.co/t/warm-tier-shards-being-allocated-to-data-nodes/334136)

<div class="topic-metadata">

**Author:** [@Mirko\_Katunar](https://discuss.elastic.co/u/Mirko_Katunar)\
**Replies:** 1\
**Last updated:** [May 24, 2023, 8:18am UTC](https://discuss.elastic.co/t/warm-tier-shards-being-allocated-to-data-nodes/334136 "2023-05-24T08:18:29Z")

</div>

Hello, I have a hot, warm architecture and 3 master nodes that are also data nodes. At some point Elastic started to allocate data stream shards that are in warm tier to master/data nodes. As plain data node can fill a…

---

## [How to find openssl Version](https://discuss.elastic.co/t/how-to-find-openssl-version/334038)

<div class="topic-metadata">

**Author:** [@kannan\_raj](https://discuss.elastic.co/u/kannan_raj)\
**Replies:** 1\
**Last updated:** [May 24, 2023, 8:08am UTC](https://discuss.elastic.co/t/how-to-find-openssl-version/334038 "2023-05-24T08:08:43Z")

</div>

Hello Team, Does Elasticsearch use openssl when using the SSL / TLS protocol? If so, where can I find the version of openssl? Regards Kannan P

---

## [Sending logs from Filebeat(windows) to Logstash(Linux)](https://discuss.elastic.co/t/sending-logs-from-filebeat-windows-to-logstash-linux/334112)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 2\
**Last updated:** [May 24, 2023, 6:18am UTC](https://discuss.elastic.co/t/sending-logs-from-filebeat-windows-to-logstash-linux/334112 "2023-05-24T06:18:57Z")

</div>

Hi, I have installed filebeat on windows machine and configured it to send logs to logstash. Here is my filebeat config filebeat.inputs: # Each - is an input. Most options can be set at the input level, so # you can …

---

## [Should clause within nested query not giving results](https://discuss.elastic.co/t/should-clause-within-nested-query-not-giving-results/334167)

<div class="topic-metadata">

**Author:** [@discuss\_lipak](https://discuss.elastic.co/u/discuss_lipak)\
**Replies:** 0\
**Last updated:** [May 24, 2023, 5:07am UTC](https://discuss.elastic.co/t/should-clause-within-nested-query-not-giving-results/334167 "2023-05-24T05:07:40Z")

</div>

I am trying to retrieve a specific document with nested query on the identityLinks element. My requirement: either identityLinks.userId should match specific userid when identityLinks.type is "assignee" OR identityLin…

---

## [Using value from the returned documents and recalculating the score of the documents](https://discuss.elastic.co/t/using-value-from-the-returned-documents-and-recalculating-the-score-of-the-documents/334154)

<div class="topic-metadata">

**Author:** [@akhil\_reddy](https://discuss.elastic.co/u/akhil_reddy)\
**Replies:** 2\
**Last updated:** [May 24, 2023, 4:10am UTC](https://discuss.elastic.co/t/using-value-from-the-returned-documents-and-recalculating-the-score-of-the-documents/334154 "2023-05-24T04:10:01Z")

</div>

Hi, I have a use case where I need to perform a search request, then use a value from the returned documents in recalculating the score. Below is the example of returned documents for my search request { \_score: 1.7, \_…

---

## [How to resolve failed requests to ES database after rebuilding the site](https://discuss.elastic.co/t/how-to-resolve-failed-requests-to-es-database-after-rebuilding-the-site/333365)

<div class="topic-metadata">

**Author:** [@stan4o](https://discuss.elastic.co/u/stan4o)\
**Replies:** 4\
**Last updated:** [May 24, 2023, 1:54am UTC](https://discuss.elastic.co/t/how-to-resolve-failed-requests-to-es-database-after-rebuilding-the-site/333365 "2023-05-24T01:54:11Z")

</div>

After our website (system) was rebuilt on a new server (Digital Ocean) all the requests to the Elastic search are failing = we cannot access the Elastic search. How to resolve this issue? I am not a programmer. This is w…

---

## [Elasticsearch memory data ratio recommendations for logging use case](https://discuss.elastic.co/t/elasticsearch-memory-data-ratio-recommendations-for-logging-use-case/334076)

<div class="topic-metadata">

**Author:** [@Farah\_Bhr](https://discuss.elastic.co/u/Farah_Bhr)\
**Replies:** 0\
**Last updated:** [May 23, 2023, 6:15am UTC](https://discuss.elastic.co/t/elasticsearch-memory-data-ratio-recommendations-for-logging-use-case/334076 "2023-05-23T06:15:43Z")

</div>

Hello , I am planning to create an Elasticsearch Cluster for logging and metrics purpose I am using time-based indexes I want to calculate the optimal data nodes and shards this cluster requires The logs reach a maxi…

---

## [Write a RegEx to match the event pattern in log file](https://discuss.elastic.co/t/write-a-regex-to-match-the-event-pattern-in-log-file/334048)

<div class="topic-metadata">

**Author:** [@hamzeha](https://discuss.elastic.co/u/hamzeha)\
**Replies:** 1\
**Last updated:** [May 23, 2023, 9:31pm UTC](https://discuss.elastic.co/t/write-a-regex-to-match-the-event-pattern-in-log-file/334048 "2023-05-23T21:31:33Z")

</div>

Hi Everyone, I have application log file which contains the application requests and responses, the complete request and response looks like the below, I tried different patterns using RegEx but unfortunately without an…

---

## [Pipeline is running but index is not created at elasticsearch](https://discuss.elastic.co/t/pipeline-is-running-but-index-is-not-created-at-elasticsearch/333940)

<div class="topic-metadata">

**Author:** [@Yasser\_Alsawy](https://discuss.elastic.co/u/Yasser_Alsawy)\
**Replies:** 30\
**Last updated:** [May 23, 2023, 7:49pm UTC](https://discuss.elastic.co/t/pipeline-is-running-but-index-is-not-created-at-elasticsearch/333940 "2023-05-23T19:49:21Z")

</div>

I'm trying to create an index and loading one log file to Elasticsearch using logstash using below config: input { file { path =\> \["/mnt/c/databalanceInfo\_0.log"\] start\_position =\> "beginning" sincedb\_path =\> "…

---

## [How to increase queue capacity from 200 to 400?](https://discuss.elastic.co/t/how-to-increase-queue-capacity-from-200-to-400/333947)

<div class="topic-metadata">

**Author:** [@mpniel](https://discuss.elastic.co/u/mpniel)\
**Replies:** 11\
**Last updated:** [May 23, 2023, 5:40pm UTC](https://discuss.elastic.co/t/how-to-increase-queue-capacity-from-200-to-400/333947 "2023-05-23T17:40:44Z")

</div>

How to increase queue capacity from 200 to 400?

---

## [Ruby API call when parser hit specific field](https://discuss.elastic.co/t/ruby-api-call-when-parser-hit-specific-field/334107)

<div class="topic-metadata">

**Author:** [@Jirka\_Liska](https://discuss.elastic.co/u/Jirka_Liska)\
**Replies:** 8\
**Last updated:** [May 23, 2023, 5:42pm UTC](https://discuss.elastic.co/t/ruby-api-call-when-parser-hit-specific-field/334107 "2023-05-23T17:42:03Z")

</div>

Hi, I'm trying to have Logstash make API call when it hits specific field using Ruby code but I'm unable to do so. Could someone smarter than me check what I'm doing wrong please? Ruby code: require 'uri' require 'net…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=372)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=374)
