# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=427

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 428

---

## [Synonym graph token filter backed by Elastic index](https://discuss.elastic.co/t/synonym-graph-token-filter-backed-by-elastic-index/326616)

<div class="topic-metadata">

**Author:** [@jnioche](https://discuss.elastic.co/u/jnioche)\
**Replies:** 0\
**Last updated:** [February 27, 2023, 4:35pm UTC](https://discuss.elastic.co/t/synonym-graph-token-filter-backed-by-elastic-index/326616 "2023-02-27T16:35:20Z")

</div>

Hi, I want to use the synonym graph token filter but ideally have the data stored in an Elasticsearch index so that it can be easily updated and modified. My understanding of the code is that it reads the data from a f…

---

## [Start elasticsearch that used to be in a cluster as a single-node or in a different cluster](https://discuss.elastic.co/t/start-elasticsearch-that-used-to-be-in-a-cluster-as-a-single-node-or-in-a-different-cluster/326568)

<div class="topic-metadata">

**Author:** [@lduvnjak](https://discuss.elastic.co/u/lduvnjak)\
**Replies:** 8\
**Last updated:** [February 27, 2023, 4:22pm UTC](https://discuss.elastic.co/t/start-elasticsearch-that-used-to-be-in-a-cluster-as-a-single-node-or-in-a-different-cluster/326568 "2023-02-27T16:22:24Z")

</div>

Hey Everyone, Due to some stuff that happened, I have an Elasticsearch node with a lot of data, that isn't up to date with the cluster. What I need to do is somehow start this node as a separate cluster, without it nee…

---

## [How to develop the Security Dashboard](https://discuss.elastic.co/t/how-to-develop-the-security-dashboard/326483)

<div class="topic-metadata">

**Author:** [@red-dragon](https://discuss.elastic.co/u/red-dragon)\
**Replies:** 1\
**Last updated:** [February 27, 2023, 4:14pm UTC](https://discuss.elastic.co/t/how-to-develop-the-security-dashboard/326483 "2023-02-27T16:14:19Z")

</div>

I wanted to review the security panel codes and develop them But I don't know in which part the codes of the security part are located

---

## [Agent for Endpoint is shown as unhealthy](https://discuss.elastic.co/t/agent-for-endpoint-is-shown-as-unhealthy/326485)

<div class="topic-metadata">

**Author:** [@Cosmic\_Season](https://discuss.elastic.co/u/Cosmic_Season)\
**Replies:** 1\
**Last updated:** [February 27, 2023, 3:41pm UTC](https://discuss.elastic.co/t/agent-for-endpoint-is-shown-as-unhealthy/326485 "2023-02-27T15:41:15Z")

</div>

I am unable to understand the issue. I tried to uninstall and install multiple times but the agent still shows as "Unhealthy". The agent is installed on windows and I am unable to open the file from GUI as it says "acce…

---

## [Monitoring of the private locations/Heartbeats](https://discuss.elastic.co/t/monitoring-of-the-private-locations-heartbeats/326601)

<div class="topic-metadata">

**Author:** [@Savva\_Morozov](https://discuss.elastic.co/u/Savva_Morozov)\
**Replies:** 1\
**Last updated:** [February 27, 2023, 3:03pm UTC](https://discuss.elastic.co/t/monitoring-of-the-private-locations-heartbeats/326601 "2023-02-27T15:03:09Z")

</div>

Hello! Are there any recommendations on how to monitor health of the private locations created with Elastic Agents and Heartbeats? For example, I would like to know that all the private locatons/Heartbeats are healthy an…

---

## [Elastic Agent Google Workspace module retrieves repeated events](https://discuss.elastic.co/t/elastic-agent-google-workspace-module-retrieves-repeated-events/323516)

<div class="topic-metadata">

**Author:** [@German\_Bravo](https://discuss.elastic.co/u/German_Bravo)\
**Replies:** 8\
**Last updated:** [February 27, 2023, 2:46pm UTC](https://discuss.elastic.co/t/elastic-agent-google-workspace-module-retrieves-repeated-events/323516 "2023-02-27T14:46:12Z")

</div>

Hi im using Elastic Agent version 8.6 installed on one host, applying a policy with Google Workspace module enabled retrieving all type of events from our Google Workspace tenant. It works perfectly as alert rules give …

---

## [Ingest issue during re-indexing/cloning?](https://discuss.elastic.co/t/ingest-issue-during-re-indexing-cloning/326466)

<div class="topic-metadata">

**Author:** [@GenSSC](https://discuss.elastic.co/u/GenSSC)\
**Replies:** 5\
**Last updated:** [February 27, 2023, 2:17pm UTC](https://discuss.elastic.co/t/ingest-issue-during-re-indexing-cloning/326466 "2023-02-27T14:17:29Z")

</div>

Hello ! I need to re-index multiple indices prior to an update of our stack. In order to test the reindexing process, I am cloning an index. However, the index needs to be read-only. My question is...what if data is in…

---

## [Elastic Search query](https://discuss.elastic.co/t/elastic-search-query/326430)

<div class="topic-metadata">

**Author:** [@ashish.akm](https://discuss.elastic.co/u/ashish.akm)\
**Replies:** 3\
**Last updated:** [February 27, 2023, 1:39pm UTC](https://discuss.elastic.co/t/elastic-search-query/326430 "2023-02-27T13:39:06Z")

</div>

how to create one query with match sort by newer report date and martch\_phrase sort by newer report and combine both result

---

## [Only one of the data nodes has a significantly higher cpu usage than other data nodes](https://discuss.elastic.co/t/only-one-of-the-data-nodes-has-a-significantly-higher-cpu-usage-than-other-data-nodes/326589)

<div class="topic-metadata">

**Author:** [@wangxr1985](https://discuss.elastic.co/u/wangxr1985)\
**Replies:** 0\
**Last updated:** [February 27, 2023, 1:07pm UTC](https://discuss.elastic.co/t/only-one-of-the-data-nodes-has-a-significantly-higher-cpu-usage-than-other-data-nodes/326589 "2023-02-27T13:07:23Z")

</div>

ES version: elasticsearch-5.6.3-1.noarch OS version: CentOS Linux release 7.6.1810 (Core) Linux version 3.10.0-1160.31.1.el7.x86\_64 (mockbuild@kbuilder.bsys.centos.org) (gcc version 4.8.5 20150623 (Red Hat 4.8.5-44) (…

---

## [Elastic security time zone issue](https://discuss.elastic.co/t/elastic-security-time-zone-issue/325915)

<div class="topic-metadata">

**Author:** [@frank\_rib](https://discuss.elastic.co/u/frank_rib)\
**Replies:** 4\
**Last updated:** [February 27, 2023, 12:43pm UTC](https://discuss.elastic.co/t/elastic-security-time-zone-issue/325915 "2023-02-27T12:43:34Z")

</div>

Hello Community, I have an issue with the TIMEZONE in the SECURITY – ALERTS section, the logs are received in UTC+1 in Discovery and in UTC+3 in SECURITY – ALERTS. Knowning that the timezone configured at the kibana i…

---

## [Two Node Cluster Failover did not work](https://discuss.elastic.co/t/two-node-cluster-failover-did-not-work/326583)

<div class="topic-metadata">

**Author:** [@sven\_begis](https://discuss.elastic.co/u/sven_begis)\
**Replies:** 2\
**Last updated:** [February 27, 2023, 12:32pm UTC](https://discuss.elastic.co/t/two-node-cluster-failover-did-not-work/326583 "2023-02-27T12:32:26Z")

</div>

Two Node Cluster Failover did not work Hello, I'm trying to set up a two node cluster. VST-ELA01 -- RAM = 8 GB -- CPU = 8 -- HD = 100 GB -- OS = Ubuntu 22.04 LTS VST-ELA02 -- RAM = 8 GB -- CPU = 8 -- HD = 1…

---

## [How to Ingest MultiLine Json file into ElasticSearch using Logstash Pipeline](https://discuss.elastic.co/t/how-to-ingest-multiline-json-file-into-elasticsearch-using-logstash-pipeline/326580)

<div class="topic-metadata">

**Author:** [@prabhakar\_kamath](https://discuss.elastic.co/u/prabhakar_kamath)\
**Replies:** 0\
**Last updated:** [February 27, 2023, 12:15pm UTC](https://discuss.elastic.co/t/how-to-ingest-multiline-json-file-into-elasticsearch-using-logstash-pipeline/326580 "2023-02-27T12:15:29Z")

</div>

I have a json file similar to following: { "Key1": "value1", "Key2": "value2" ....... } I want to ingest it as it is into logstash, The Keys should be fields and values should be values to the field, value can be a…

---

## [Kibana error connecting to package registry getaddrinfo EAI error](https://discuss.elastic.co/t/kibana-error-connecting-to-package-registry-getaddrinfo-eai-error/326579)

<div class="topic-metadata">

**Author:** [@Timo\_Anzalone](https://discuss.elastic.co/u/Timo_Anzalone)\
**Replies:** 0\
**Last updated:** [February 27, 2023, 12:14pm UTC](https://discuss.elastic.co/t/kibana-error-connecting-to-package-registry-getaddrinfo-eai-error/326579 "2023-02-27T12:14:15Z")

</div>

2023-02-27T12:01:09.365155555Z \[2023-02-27T12:01:09.364+00:00\]\[ERROR\]\[plugins.fleet\] Failed to fetch latest version of endpoint from registry: Error connecting to package registry: request to https://epr.elastic.co/searc…

---

## [Elasticsearch Engineer Lab 7.3: Index lifecycle management query](https://discuss.elastic.co/t/elasticsearch-engineer-lab-7-3-index-lifecycle-management-query/326512)

<div class="topic-metadata">

**Author:** [@Bryce\_Fernandes](https://discuss.elastic.co/u/Bryce_Fernandes)\
**Replies:** 1\
**Last updated:** [February 27, 2023, 12:12pm UTC](https://discuss.elastic.co/t/elasticsearch-engineer-lab-7-3-index-lifecycle-management-query/326512 "2023-02-27T12:12:51Z")

</div>

Course: Elasticsearch Engineer Lab 7.3: Index lifecycle management Version: 8.1 Question: Query regarding rollover duration Below is the lab question: the index is in the hot phase for 2 minutes when the index rolls…

---

## [Get sum of record count for inner bucket key in two level term aggregation](https://discuss.elastic.co/t/get-sum-of-record-count-for-inner-bucket-key-in-two-level-term-aggregation/326575)

<div class="topic-metadata">

**Author:** [@Baekjun-Kim](https://discuss.elastic.co/u/Baekjun-Kim)\
**Replies:** 0\
**Last updated:** [February 27, 2023, 12:01pm UTC](https://discuss.elastic.co/t/get-sum-of-record-count-for-inner-bucket-key-in-two-level-term-aggregation/326575 "2023-02-27T12:01:45Z")

</div>

I have records with two keyword type field user\_id: String that identifies individual user, result: String such as "success", "failure" or "pending" etc. These are what I want to do: Get record count for each result…

---

## [Compare two indexes based on more than two fields](https://discuss.elastic.co/t/compare-two-indexes-based-on-more-than-two-fields/325464)

<div class="topic-metadata">

**Author:** [@Prashant\_Pandey1](https://discuss.elastic.co/u/Prashant_Pandey1)\
**Replies:** 3\
**Last updated:** [February 27, 2023, 11:56am UTC](https://discuss.elastic.co/t/compare-two-indexes-based-on-more-than-two-fields/325464 "2023-02-27T11:56:24Z")

</div>

I have two Indexes. I want to get the list of matched and unmatched data based on field(s). I had tried to use Preview transform Api , but it's showing data only up to 100 records. Please let me know ,is there any oth…

---

## [\[ERROR\]\[elasticsearch-service\] Unable to retrieve version information from Elasticsearch nodes](https://discuss.elastic.co/t/error-elasticsearch-service-unable-to-retrieve-version-information-from-elasticsearch-nodes/325827)

<div class="topic-metadata">

**Author:** [@Mausam\_Singh](https://discuss.elastic.co/u/Mausam_Singh)\
**Replies:** 5\
**Last updated:** [February 27, 2023, 11:49am UTC](https://discuss.elastic.co/t/error-elasticsearch-service-unable-to-retrieve-version-information-from-elasticsearch-nodes/325827 "2023-02-27T11:49:21Z")

</div>

Hi Team, I have locally installed elasticsearch and kibana on Mac OS. it was working fine from last 1.5 months . However I am getting below error (while starting kibana) from last week: Below is elasticsearch detail : …

---

## [Improve indexing performance speed by routing to a specific shard](https://discuss.elastic.co/t/improve-indexing-performance-speed-by-routing-to-a-specific-shard/326552)

<div class="topic-metadata">

**Author:** [@Itay\_Bittan](https://discuss.elastic.co/u/Itay_Bittan)\
**Replies:** 7\
**Last updated:** [February 27, 2023, 10:16am UTC](https://discuss.elastic.co/t/improve-indexing-performance-speed-by-routing-to-a-specific-shard/326552 "2023-02-27T10:16:47Z")

</div>

Hi, Let's say I have a 100GB of data that need to be indexed into a specific index with 5 shards. I don't have reads during indexing time and I want to speed up the process as much as possible. I have 5 (python) worke…

---

## [Logstash input elasticsearch](https://discuss.elastic.co/t/logstash-input-elasticsearch/326561)

<div class="topic-metadata">

**Author:** [@almteref](https://discuss.elastic.co/u/almteref)\
**Replies:** 0\
**Last updated:** [February 27, 2023, 9:59am UTC](https://discuss.elastic.co/t/logstash-input-elasticsearch/326561 "2023-02-27T09:59:55Z")

</div>

Hi all I have question about the logstash in elasticsearch input plugin can I use the search template ID that I created in my cluster ? rether than pass query ?

---

## [Huge size for elastic endpoint (defend) integration indices?](https://discuss.elastic.co/t/huge-size-for-elastic-endpoint-defend-integration-indices/326344)

<div class="topic-metadata">

**Author:** [@rebug](https://discuss.elastic.co/u/rebug)\
**Replies:** 4\
**Last updated:** [February 27, 2023, 9:36am UTC](https://discuss.elastic.co/t/huge-size-for-elastic-endpoint-defend-integration-indices/326344 "2023-02-27T09:36:46Z")

</div>

Hello, Cluster information: 3 nodes with 1TB I have configured a fleet server with elastic defend integration to start using elastic security. Currently only 2 servers are enrolled with the agent. Here is the integra…

---

## [Question - Autoscaling on Kubernetes with ELK](https://discuss.elastic.co/t/question-autoscaling-on-kubernetes-with-elk/326421)

<div class="topic-metadata">

**Author:** [@dvp\_at](https://discuss.elastic.co/u/dvp_at)\
**Replies:** 1\
**Last updated:** [February 27, 2023, 9:36am UTC](https://discuss.elastic.co/t/question-autoscaling-on-kubernetes-with-elk/326421 "2023-02-27T09:36:44Z")

</div>

Hello all, I am new in the ECK and Kubernetes environement usage and I am currently working on a school project. We need to autoscale our kubernetes pods on 3 nodes, depending the workload of the pods on the nodes. On…

---

## [An index that inflates](https://discuss.elastic.co/t/an-index-that-inflates/326517)

<div class="topic-metadata">

**Author:** [@boazBD](https://discuss.elastic.co/u/boazBD)\
**Replies:** 4\
**Last updated:** [February 27, 2023, 9:27am UTC](https://discuss.elastic.co/t/an-index-that-inflates/326517 "2023-02-27T09:27:23Z")

</div>

Hello, I have an index that inflates more until the node crashes with a full disk error. For now, I delete the index directly from the VM because Elastic is unhealthy when it happens. It is helpful for a short period,…

---

## [Add a csv input for every batch](https://discuss.elastic.co/t/add-a-csv-input-for-every-batch/326553)

<div class="topic-metadata">

**Author:** [@Rakhshunda\_Noorein\_J](https://discuss.elastic.co/u/Rakhshunda_Noorein_J)\
**Replies:** 0\
**Last updated:** [February 27, 2023, 8:23am UTC](https://discuss.elastic.co/t/add-a-csv-input-for-every-batch/326553 "2023-02-27T08:23:19Z")

</div>

Hello, I am using http\_poller input plugin and elasticsearch output plugin.. I want to use CSV output plugin also for logging logstash success in a CSV file..But in my CSV all the events are noted but not only once. I …

---

## [Running \_forcemerge on an index that is being write on](https://discuss.elastic.co/t/running-forcemerge-on-an-index-that-is-being-write-on/326492)

<div class="topic-metadata">

**Author:** [@Tudor\_Plugaru](https://discuss.elastic.co/u/Tudor_Plugaru)\
**Replies:** 18\
**Last updated:** [February 27, 2023, 8:22am UTC](https://discuss.elastic.co/t/running-forcemerge-on-an-index-that-is-being-write-on/326492 "2023-02-27T08:22:27Z")

</div>

Hi, we are having an index with heavy updates on the documents. This leads us to having a lot of uncleaned deleted documents, for example, we can have around 400M searchable documents and around 150M of uncleaned docume…

---

## [How can I add field by a same field when across event](https://discuss.elastic.co/t/how-can-i-add-field-by-a-same-field-when-across-event/326551)

<div class="topic-metadata">

**Author:** [@OICAn](https://discuss.elastic.co/u/OICAn)\
**Replies:** 0\
**Last updated:** [February 27, 2023, 8:09am UTC](https://discuss.elastic.co/t/how-can-i-add-field-by-a-same-field-when-across-event/326551 "2023-02-27T08:09:02Z")

</div>

A user access our system will trigger many transcations. A transaction will generate some log, which are serval event in es and they have a same field called "globalNo". One event will log the name of the transaction and…

---

## [Syslog to elastic stack on kubernetes/openshift](https://discuss.elastic.co/t/syslog-to-elastic-stack-on-kubernetes-openshift/326068)

<div class="topic-metadata">

**Author:** [@splitmessage88](https://discuss.elastic.co/u/splitmessage88)\
**Replies:** 6\
**Last updated:** [February 27, 2023, 7:52am UTC](https://discuss.elastic.co/t/syslog-to-elastic-stack-on-kubernetes-openshift/326068 "2023-02-27T07:52:52Z")

</div>

Hi, We are almost in production and have one final function left, and it's fleet & elastic agent deployment so we can receive syslog from external source. For example CiscoFTD, Palo Alto etc. I have followed the docume…

---

## [Particular word count in particular file](https://discuss.elastic.co/t/particular-word-count-in-particular-file/326181)

<div class="topic-metadata">

**Author:** [@smitak](https://discuss.elastic.co/u/smitak)\
**Replies:** 5\
**Last updated:** [February 27, 2023, 7:10am UTC](https://discuss.elastic.co/t/particular-word-count-in-particular-file/326181 "2023-02-27T07:10:50Z")

</div>

Hello Sir, I want count of keyword occurance in a particular file in elaticsearch .

---

## [Too many tcp connection established issue](https://discuss.elastic.co/t/too-many-tcp-connection-established-issue/326545)

<div class="topic-metadata">

**Author:** [@manzoor77](https://discuss.elastic.co/u/manzoor77)\
**Replies:** 0\
**Last updated:** [February 27, 2023, 7:01am UTC](https://discuss.elastic.co/t/too-many-tcp-connection-established-issue/326545 "2023-02-27T07:01:56Z")

</div>

Hi, I have enable elasticsearch in my production chat application. There was total 500+ users that uses this application on daily bases for communication purpose. I have initialize ELS newclient once when server start …

---

## [Import kibana dashboard using ansible](https://discuss.elastic.co/t/import-kibana-dashboard-using-ansible/325685)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 2\
**Last updated:** [February 27, 2023, 6:04am UTC](https://discuss.elastic.co/t/import-kibana-dashboard-using-ansible/325685 "2023-02-27T06:04:01Z")

</div>

Hi, I have exported kibana dashboard in ndjson format. now i want to import it to another instance of kibana. I am doing this using ansible playbook. This is my command curl -X POST "\*Reverse\_PROXY\_IP/kibana\*/api/saved\_…

---

## [How to list all scripts/templates when GET \_cat/templates doesn't return them](https://discuss.elastic.co/t/how-to-list-all-scripts-templates-when-get-cat-templates-doesnt-return-them/326476)

<div class="topic-metadata">

**Author:** [@Cal\_L](https://discuss.elastic.co/u/Cal_L)\
**Replies:** 2\
**Last updated:** [February 27, 2023, 3:44am UTC](https://discuss.elastic.co/t/how-to-list-all-scripts-templates-when-get-cat-templates-doesnt-return-them/326476 "2023-02-27T03:44:16Z")

</div>

I am new to ES ... I am looking at the existing codes which my team is using es.put\_script("my\_custom\_template\_1\_id", my\_custom\_template\_1\_query) I can retrieve the the template info by using the SPECIFIC template id li…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=426)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=428)
