# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=382

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 383

---

## [ElasticSearch does not see indices](https://discuss.elastic.co/t/elasticsearch-does-not-see-indices/332960)

<div class="topic-metadata">

**Author:** [@not\_correct](https://discuss.elastic.co/u/not_correct)\
**Replies:** 6\
**Last updated:** [May 11, 2023, 9:23am UTC](https://discuss.elastic.co/t/elasticsearch-does-not-see-indices/332960 "2023-05-11T09:23:11Z")

</div>

Hi, I had to reboot EC2 instances that hosts 5-node cluster. The data stored on corresponding EBS volumes. Once I have rebooted the instance and started the Elasticsearch my cluster got into status red. \_cat/indices m…

---

## [Поиск по ключу + 2 символа](https://discuss.elastic.co/t/topic/333177)

<div class="topic-metadata">

**Author:** [@cia](https://discuss.elastic.co/u/cia)\
**Replies:** 0\
**Last updated:** [May 11, 2023, 9:18am UTC](https://discuss.elastic.co/t/topic/333177 "2023-05-11T09:18:28Z")

</div>

Добрый день. Мне нужно организовать поиск по началу слова, но не больше "ключ + 2 символа". То есть если проиндексировали фразу "Каждый охотник желает знать", то результат должен находиться по "охотн", но НЕ должен по "…

---

## [My index write api request blocked by status 403 after adding index lifecycle policy](https://discuss.elastic.co/t/my-index-write-api-request-blocked-by-status-403-after-adding-index-lifecycle-policy/333174)

<div class="topic-metadata">

**Author:** [@jeyong.oh](https://discuss.elastic.co/u/jeyong.oh)\
**Replies:** 0\
**Last updated:** [May 11, 2023, 9:01am UTC](https://discuss.elastic.co/t/my-index-write-api-request-blocked-by-status-403-after-adding-index-lifecycle-policy/333174 "2023-05-11T09:01:46Z")

</div>

This is what happened today. I'm using index without life cycle management. The index name is "vehicle-iot-coordinate", it's size is about 280GB and it grow with rate of 1GB/day. I'm adding lifecycle management. (disab…

---

## [Some info does not get shipped with MetricsBeat from AWS EKS](https://discuss.elastic.co/t/some-info-does-not-get-shipped-with-metricsbeat-from-aws-eks/332528)

<div class="topic-metadata">

**Author:** [@jeffpang](https://discuss.elastic.co/u/jeffpang)\
**Replies:** 5\
**Last updated:** [May 11, 2023, 8:15am UTC](https://discuss.elastic.co/t/some-info-does-not-get-shipped-with-metricsbeat-from-aws-eks/332528 "2023-05-11T08:15:28Z")

</div>

Hello there, As we would have the EKS to be monitored by Elastic, we deploy DaemonSet following this url. Metricbeat However some of the metrics cannot be shipped nor displayed on dashboards. apiVersion: v1 kind: …

---

## [Elasticsearch high latency](https://discuss.elastic.co/t/elasticsearch-high-latency/328911)

<div class="topic-metadata">

**Author:** [@jaykb77](https://discuss.elastic.co/u/jaykb77)\
**Replies:** 15\
**Last updated:** [May 11, 2023, 7:49am UTC](https://discuss.elastic.co/t/elasticsearch-high-latency/328911 "2023-05-11T07:49:47Z")

</div>

Hi all, We noticed some high request latency for searches on our elasticsearch cluster(7.17) and while checking the metrics, it was seen that there was spike in search\_fetch\_time for many indices which were configured 1…

---

## [Can we use kibana without ES?](https://discuss.elastic.co/t/can-we-use-kibana-without-es/333151)

<div class="topic-metadata">

**Author:** [@j\_lim](https://discuss.elastic.co/u/j_lim)\
**Replies:** 2\
**Last updated:** [May 11, 2023, 6:53am UTC](https://discuss.elastic.co/t/can-we-use-kibana-without-es/333151 "2023-05-11T06:53:57Z")

</div>

is there any way use Kibana without ES?

---

## [Curriculum Vitae using ES](https://discuss.elastic.co/t/curriculum-vitae-using-es/333108)

<div class="topic-metadata">

**Author:** [@Kirtash](https://discuss.elastic.co/u/Kirtash)\
**Replies:** 2\
**Last updated:** [May 11, 2023, 6:15am UTC](https://discuss.elastic.co/t/curriculum-vitae-using-es/333108 "2023-05-11T06:15:57Z")

</div>

Good morning, I would like use elastic to search in CV perfect matchings and I have this question. Is it possible that with the text of CV get a list of tags? Like a tag cloud. My idea is get this tags and simply sav…

---

## [Fetching filtered and unfiltered count in a single request](https://discuss.elastic.co/t/fetching-filtered-and-unfiltered-count-in-a-single-request/333160)

<div class="topic-metadata">

**Author:** [@\_baba](https://discuss.elastic.co/u/_baba)\
**Replies:** 0\
**Last updated:** [May 11, 2023, 6:11am UTC](https://discuss.elastic.co/t/fetching-filtered-and-unfiltered-count-in-a-single-request/333160 "2023-05-11T06:11:51Z")

</div>

Hi, I have a use case where a user\_id has multiple records in Elasticsearch. I'm using a bool query on user\_id and additional filters on top of it. I'm able to fetch the count of filtered records using track\_total\_hits…

---

## [Timestamp attribute mapping as text(this existing mapping not working for newly created indices )](https://discuss.elastic.co/t/timestamp-attribute-mapping-as-text-this-existing-mapping-not-working-for-newly-created-indices/333156)

<div class="topic-metadata">

**Author:** [@Dnyaneshwar\_Chavan](https://discuss.elastic.co/u/Dnyaneshwar_Chavan)\
**Replies:** 0\
**Last updated:** [May 11, 2023, 5:46am UTC](https://discuss.elastic.co/t/timestamp-attribute-mapping-as-text-this-existing-mapping-not-working-for-newly-created-indices/333156 "2023-05-11T05:46:36Z")

</div>

I am using dynamic indices creation with template { "base\_index\_dev" : { "order" : 0, "index\_patterns" : \[ "dev\_shipments", "dev\_shipment\_legs\_", "dev\_transport\_orders\_\*" \], "settings" : { "index" : { "default…

---

## [Logstash jdbc Illegal instant due to time zone offset transition (daylight savings time 'gap'): 1979-03-21](https://discuss.elastic.co/t/logstash-jdbc-illegal-instant-due-to-time-zone-offset-transition-daylight-savings-time-gap-1979-03-21/332902)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 1\
**Last updated:** [May 11, 2023, 5:59am UTC](https://discuss.elastic.co/t/logstash-jdbc-illegal-instant-due-to-time-zone-offset-transition-daylight-savings-time-gap-1979-03-21/332902 "2023-05-11T05:59:11Z")

</div>

Hi Here is the logstash jdbc input config: Logstash conf: input { jdbc { jdbc\_driver\_library =\> "/opt/jdbc/ifxjdbc.jar" jdbc\_driver\_class =\> "com.informix.jdbc.IfxDriver" jdbc\_connection\_string =\> "jdbc:…

---

## [Can filebeat recognize .gz log files?](https://discuss.elastic.co/t/can-filebeat-recognize-gz-log-files/332961)

<div class="topic-metadata">

**Author:** [@talka](https://discuss.elastic.co/u/talka)\
**Replies:** 1\
**Last updated:** [May 11, 2023, 2:49am UTC](https://discuss.elastic.co/t/can-filebeat-recognize-gz-log-files/332961 "2023-05-11T02:49:18Z")

</div>

Hi, I'm using filebeat version 8.7.0. /var/log list the following files: -rwxrwxrwx 1 1000 1000 244631 Mar 21 06:30 cron -rwxrwxrwx 1 1000 1000 48940 Feb 26 03:37 cron-20230226.gz -rwxrwxrwx 1 1000 1000 48766 Mar …

---

## [Elasticsearch](https://discuss.elastic.co/t/elasticsearch/332956)

<div class="topic-metadata">

**Author:** [@Ali\_Trache](https://discuss.elastic.co/u/Ali_Trache)\
**Replies:** 1\
**Last updated:** [May 11, 2023, 1:13am UTC](https://discuss.elastic.co/t/elasticsearch/332956 "2023-05-11T01:13:16Z")

</div>

hello ; please i want somme repense for me . thank you 1-How to size ELk storage? 2-How to check storage status and detect possible saturation? Can it be integrated into an “ELK” Dashboard? 3- how can we expand the s…

---

## [Read after write consistency (test refresh interval)](https://discuss.elastic.co/t/read-after-write-consistency-test-refresh-interval/332809)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 1\
**Last updated:** [May 11, 2023, 1:05am UTC](https://discuss.elastic.co/t/read-after-write-consistency-test-refresh-interval/332809 "2023-05-11T01:05:33Z")

</div>

I have a refresh interval of 1 s. I want to confirm that this is actually happening. Is there a test to validate the item getting indexed is getting searchable in a second? If so, How do I do that? I am ingesting documen…

---

## [Legend of a map](https://discuss.elastic.co/t/legend-of-a-map/332999)

<div class="topic-metadata">

**Author:** [@Phildefer](https://discuss.elastic.co/u/Phildefer)\
**Replies:** 4\
**Last updated:** [May 11, 2023, 1:04am UTC](https://discuss.elastic.co/t/legend-of-a-map/332999 "2023-05-11T01:04:59Z")

</div>

Hi, Just a question : For the moment it's impossible to change the label in the legend of a map. Do you know if this feature is expected or not? t would be very useful because sometimes the legend is not very meaningfu…

---

## [Aliases Error in Ingest pipeline Index](https://discuss.elastic.co/t/aliases-error-in-ingest-pipeline-index/332814)

<div class="topic-metadata">

**Author:** [@anushyaadam](https://discuss.elastic.co/u/anushyaadam)\
**Replies:** 1\
**Last updated:** [May 11, 2023, 12:54am UTC](https://discuss.elastic.co/t/aliases-error-in-ingest-pipeline-index/332814 "2023-05-11T00:54:29Z")

</div>

Hi Team, We are processing the logs using API key from below path. C# -\> ingest pipeline -\> Elasticsearch -\> kibana We ran the below template but Aliases not working, it shows none. Please find the snapshot attached. …

---

## [Import data csv/json](https://discuss.elastic.co/t/import-data-csv-json/333090)

<div class="topic-metadata">

**Author:** [@Haitem\_Touiss](https://discuss.elastic.co/u/Haitem_Touiss)\
**Replies:** 2\
**Last updated:** [May 11, 2023, 12:03am UTC](https://discuss.elastic.co/t/import-data-csv-json/333090 "2023-05-11T00:03:01Z")

</div>

Hello, I am having difficulty importing data into Elasticsearch version 7.17, but it is working fine in the latest version. I have tried several methods, including using Logstash and Beats, but none of them seem to be w…

---

## [Disabling the \_size mapping?](https://discuss.elastic.co/t/disabling-the-size-mapping/332831)

<div class="topic-metadata">

**Author:** [@shani\_angarkadu](https://discuss.elastic.co/u/shani_angarkadu)\
**Replies:** 1\
**Last updated:** [May 10, 2023, 11:57pm UTC](https://discuss.elastic.co/t/disabling-the-size-mapping/332831 "2023-05-10T23:57:28Z")

</div>

I want to enable and disable the size mapping. Enable worked fine after the index refreshed and I disable the \_size set to false but I still able to query the \_size. How can I disable so no one can query?

---

## [Unable to recover my cluster](https://discuss.elastic.co/t/unable-to-recover-my-cluster/333000)

<div class="topic-metadata">

**Author:** [@Ashu\_Mahajan](https://discuss.elastic.co/u/Ashu_Mahajan)\
**Replies:** 12\
**Last updated:** [May 10, 2023, 10:58pm UTC](https://discuss.elastic.co/t/unable-to-recover-my-cluster/333000 "2023-05-10T22:58:56Z")

</div>

We moved our data to new version of elasticsearch. The new cluster have 3 master, 3 hot and 3 warm nodes. Everything was working fine till this morning and all of a cluster health went red. After looking at it further, I…

---

## [Issue regarding setup and local host](https://discuss.elastic.co/t/issue-regarding-setup-and-local-host/333017)

<div class="topic-metadata">

**Author:** [@Tushar25](https://discuss.elastic.co/u/Tushar25)\
**Replies:** 1\
**Last updated:** [May 10, 2023, 9:16pm UTC](https://discuss.elastic.co/t/issue-regarding-setup-and-local-host/333017 "2023-05-10T21:16:45Z")

</div>

Hello there, I'm having an issue doing the setup of the version 8.7.1, (http:// localhost:9200/) this link requires a password to which the default USERNAME('elastic') and PASSWORD('changeme') is not working or giving a…

---

## [ elastic SIEM vs elastic Security](https://discuss.elastic.co/t/elastic-siem-vs-elastic-security/332846)

<div class="topic-metadata">

**Author:** [@THOR\_EL\_PODEROSO\_TEC](https://discuss.elastic.co/u/THOR_EL_PODEROSO_TEC)\
**Replies:** 1\
**Last updated:** [May 10, 2023, 8:40pm UTC](https://discuss.elastic.co/t/elastic-siem-vs-elastic-security/332846 "2023-05-10T20:40:08Z")

</div>

What is the difference between elastic SIEM and elastic Security? Is there a manual to install it in HyperV in onpremise?

---

## [Duplicating Event To Multiple Indices](https://discuss.elastic.co/t/duplicating-event-to-multiple-indices/332955)

<div class="topic-metadata">

**Author:** [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Replies:** 3\
**Last updated:** [May 10, 2023, 4:18pm UTC](https://discuss.elastic.co/t/duplicating-event-to-multiple-indices/332955 "2023-05-10T16:18:40Z")

</div>

I have events coming in with an ID of 123. Is it possible to have this event indexed into two different indices by doing something like below? output { if \[log\] == 123 { elasticsearch { index =\> "123logs" …

---

## [Ukrainian analyzer](https://discuss.elastic.co/t/ukrainian-analyzer/333062)

<div class="topic-metadata">

**Author:** [@Vladimir\_Talabko](https://discuss.elastic.co/u/Vladimir_Talabko)\
**Replies:** 16\
**Last updated:** [May 10, 2023, 3:46pm UTC](https://discuss.elastic.co/t/ukrainian-analyzer/333062 "2023-05-10T15:46:35Z")

</div>

Hello! I have a hosting with installed the Ukrainian plugin from this page Ukrainian analysis plugin | Elasticsearch Plugins and Integrations \[8.7\] | Elastic . It's proven by this command: bin/elasticsearch-plugin list …

---

## [Kibana - Automatizar login acceso a kibana](https://discuss.elastic.co/t/kibana-automatizar-login-acceso-a-kibana/333032)

<div class="topic-metadata">

**Author:** [@Javier\_Garcia\_Alvare](https://discuss.elastic.co/u/Javier_Garcia_Alvare)\
**Replies:** 1\
**Last updated:** [May 10, 2023, 3:15pm UTC](https://discuss.elastic.co/t/kibana-automatizar-login-acceso-a-kibana/333032 "2023-05-10T15:15:55Z")

</div>

Buenos días, versión 6.8.3 Es posible el automatizar el login de acceso a kibana y en la url de acceso pasar las credenciales y que apunten a un dashboard. Gracias, un saludo Javier.

---

## [Elasticsearch not updating data from Logstash](https://discuss.elastic.co/t/elasticsearch-not-updating-data-from-logstash/333097)

<div class="topic-metadata">

**Author:** [@VVlad23](https://discuss.elastic.co/u/VVlad23)\
**Replies:** 0\
**Last updated:** [May 10, 2023, 2:51pm UTC](https://discuss.elastic.co/t/elasticsearch-not-updating-data-from-logstash/333097 "2023-05-10T14:51:09Z")

</div>

Hello! So it's been some time I've spent trying to figure out what exactly is happening and why there is a problem. We're sending information from a server through Filebeat to Logstash. Logstash is installed on one of …

---

## [Suggestions response doesnt contain index information or information about document where the suggestion was found](https://discuss.elastic.co/t/suggestions-response-doesnt-contain-index-information-or-information-about-document-where-the-suggestion-was-found/332543)

<div class="topic-metadata">

**Author:** [@schawla](https://discuss.elastic.co/u/schawla)\
**Replies:** 3\
**Last updated:** [May 10, 2023, 2:18pm UTC](https://discuss.elastic.co/t/suggestions-response-doesnt-contain-index-information-or-information-about-document-where-the-suggestion-was-found/332543 "2023-05-10T14:18:57Z")

</div>

Hi, I am trying to trace a suggestion to its source document returned by my search suggestion query in Elasticsearch 7.9 It seems the suggest Options only returns the suggested text , frequency and score. I see that the…

---

## [OSQuery Integration user.id is \[long\] but ECS is \[keyword\]](https://discuss.elastic.co/t/osquery-integration-user-id-is-long-but-ecs-is-keyword/332700)

<div class="topic-metadata">

**Author:** [@oloughlinp](https://discuss.elastic.co/u/oloughlinp)\
**Replies:** 2\
**Last updated:** [May 10, 2023, 1:33pm UTC](https://discuss.elastic.co/t/osquery-integration-user-id-is-long-but-ecs-is-keyword/332700 "2023-05-10T13:33:50Z")

</div>

Hi all, I am trying to use some of the Windows prebuilt rules that rely on user.id in the eql query, but they are erroring out because my OSQuery manager indexes have user.id set to long, but the ECS standard (and what …

---

## [Search Query Based on Nested Fields](https://discuss.elastic.co/t/search-query-based-on-nested-fields/333084)

<div class="topic-metadata">

**Author:** [@Mustafa\_AYDOGDU](https://discuss.elastic.co/u/Mustafa_AYDOGDU)\
**Replies:** 4\
**Last updated:** [May 10, 2023, 1:04pm UTC](https://discuss.elastic.co/t/search-query-based-on-nested-fields/333084 "2023-05-10T13:04:01Z")

</div>

I have this kind of data: "1655184519597531137": { "reply\_depth": 1, "gather\_likes": false, "gather\_user\_data": "false", "keyword": "galatasaray", "gather\_retw…

---

## [Elasticsearch / logstash Log time shift](https://discuss.elastic.co/t/elasticsearch-logstash-log-time-shift/332898)

<div class="topic-metadata">

**Author:** [@JackieLaFrite](https://discuss.elastic.co/u/JackieLaFrite)\
**Replies:** 6\
**Last updated:** [May 10, 2023, 12:28pm UTC](https://discuss.elastic.co/t/elasticsearch-logstash-log-time-shift/332898 "2023-05-10T12:28:54Z")

</div>

I currently have a small problem and I don't know why it happens. I have my log 2023-05-09 09:20:11 \[DEBUG\] org.apache.activemq.transport.AbstractInactivityMonitor:150 -\> WriteChecker: 10000ms elapsed since last write …

---

## [Term suggester returning correct suggestions for misspelled words outside of suggester data source](https://discuss.elastic.co/t/term-suggester-returning-correct-suggestions-for-misspelled-words-outside-of-suggester-data-source/333083)

<div class="topic-metadata">

**Author:** [@MilanGatyas](https://discuss.elastic.co/u/MilanGatyas)\
**Replies:** 0\
**Last updated:** [May 10, 2023, 12:26pm UTC](https://discuss.elastic.co/t/term-suggester-returning-correct-suggestions-for-misspelled-words-outside-of-suggester-data-source/333083 "2023-05-10T12:26:07Z")

</div>

Please help me understand why this happens. We use Elasticsearch 7.10 term suggester. The field didYouMean.trigram we use for the suggestions has the following mapping "didYouMean" : { "type" : "text", "fields" : { …

---

## [Elastic 8.7\_\_enrollement-token\_\_"failed to establish trust with server "](https://discuss.elastic.co/t/elastic-8-7-enrollement-token-failed-to-establish-trust-with-server/330856)

<div class="topic-metadata">

**Author:** [@Julien069](https://discuss.elastic.co/u/Julien069)\
**Replies:** 6\
**Last updated:** [May 10, 2023, 12:06pm UTC](https://discuss.elastic.co/t/elastic-8-7-enrollement-token-failed-to-establish-trust-with-server/330856 "2023-05-10T12:06:09Z")

</div>

Hi , I have a kibana server and an elastic server with differents IP address . When I want to create a token for kibana with command : sudo bin/elasticsearch-create-enrollement-token -s kibana OR sudo bin/elasticse…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=381)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=383)
