# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=428

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 429

---

## [My ela cluster failed to load metadata when running, but I can't see the other problem. If there is the same problem, please help to take a look](https://discuss.elastic.co/t/my-ela-cluster-failed-to-load-metadata-when-running-but-i-cant-see-the-other-problem-if-there-is-the-same-problem-please-help-to-take-a-look/326286)

<div class="topic-metadata">

**Author:** [@limedong1](https://discuss.elastic.co/u/limedong1)\
**Replies:** 8\
**Last updated:** [February 27, 2023, 3:17am UTC](https://discuss.elastic.co/t/my-ela-cluster-failed-to-load-metadata-when-running-but-i-cant-see-the-other-problem-if-there-is-the-same-problem-please-help-to-take-a-look/326286 "2023-02-27T03:17:01Z")

</div>

Here is the error message： {"@timestamp":"2023-02-23T08:43:40.767Z", "log.level":"ERROR", "message":"fatal exception while booting Elasticsearch", "ecs.version": "1.2.0","service.name":"ES\_ECS","event.dataset":"elastic…

---

## [Monitoring postgres y sql server on AWS with an elastic on premises](https://discuss.elastic.co/t/monitoring-postgres-y-sql-server-on-aws-with-an-elastic-on-premises/325660)

<div class="topic-metadata">

**Author:** [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Replies:** 2\
**Last updated:** [February 27, 2023, 3:00am UTC](https://discuss.elastic.co/t/monitoring-postgres-y-sql-server-on-aws-with-an-elastic-on-premises/325660 "2023-02-27T03:00:33Z")

</div>

It is posible to monitor postgres y sql server on aws? if it is, with wich tool? our elastic is on premises. thanks.

---

## [Update existing record shuffles the data](https://discuss.elastic.co/t/update-existing-record-shuffles-the-data/326400)

<div class="topic-metadata">

**Author:** [@srb.saurabhjain](https://discuss.elastic.co/u/srb.saurabhjain)\
**Replies:** 3\
**Last updated:** [February 26, 2023, 9:42pm UTC](https://discuss.elastic.co/t/update-existing-record-shuffles-the-data/326400 "2023-02-26T21:42:11Z")

</div>

Hi team, I am trying to update a field in the below data B.B1 but the result data is randomly shuffled when I fetch again. Original { "A": { "A1": "test" }, "B": { "B1": "approved" }, …

---

## [Grep-like results on elasticsearch index](https://discuss.elastic.co/t/grep-like-results-on-elasticsearch-index/326524)

<div class="topic-metadata">

**Author:** [@John10](https://discuss.elastic.co/u/John10)\
**Replies:** 1\
**Last updated:** [February 26, 2023, 7:42pm UTC](https://discuss.elastic.co/t/grep-like-results-on-elasticsearch-index/326524 "2023-02-26T19:42:45Z")

</div>

If you have 5,000 pdf documents and you want to return every instance of the word "dog" across all of those documents (including the context where it occurs -- page number, the line before and after the match, etc.), you…

---

## [Should I be copying the \`/etc/elasticsearch/service\_tokens\` to several elastic nodes?](https://discuss.elastic.co/t/should-i-be-copying-the-etc-elasticsearch-service-tokens-to-several-elastic-nodes/326185)

<div class="topic-metadata">

**Author:** [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Replies:** 1\
**Last updated:** [February 25, 2023, 8:37pm UTC](https://discuss.elastic.co/t/should-i-be-copying-the-etc-elasticsearch-service-tokens-to-several-elastic-nodes/326185 "2023-02-25T20:37:15Z")

</div>

I have an elastic cluster with three nodes: n1, n2 and n3. And I have a new kibana instance on a separate linux server. On n1, I ran this command /usr/share/elasticsearch/bin/elasticsearch-service-token elastic/kibana …

---

## [Logstash not shipping data to Elasticsearch](https://discuss.elastic.co/t/logstash-not-shipping-data-to-elasticsearch/326376)

<div class="topic-metadata">

**Author:** [@Technolust](https://discuss.elastic.co/u/Technolust)\
**Replies:** 2\
**Last updated:** [February 25, 2023, 7:50pm UTC](https://discuss.elastic.co/t/logstash-not-shipping-data-to-elasticsearch/326376 "2023-02-25T19:50:43Z")

</div>

How do I get logstash to ship data to Elasticsearch? I'm not sure what to change in the logstash.yml file or what section I should change for that matter. My pipelines.yml points to /etc/logstash/conf.d/syslog.conf... Th…

---

## [How load big data from database using Logstash in elasticsearch index?](https://discuss.elastic.co/t/how-load-big-data-from-database-using-logstash-in-elasticsearch-index/326489)

<div class="topic-metadata">

**Author:** [@boliwe](https://discuss.elastic.co/u/boliwe)\
**Replies:** 0\
**Last updated:** [February 25, 2023, 8:06am UTC](https://discuss.elastic.co/t/how-load-big-data-from-database-using-logstash-in-elasticsearch-index/326489 "2023-02-25T08:06:52Z")

</div>

I want to learn how to load big data from database to elasticsearch using logstash jdbc input plugin. I could not find my answer from other forums. I have 1billion data in databse. Logstash settings has 8 workers, 15000…

---

## [Querying data using script query with lang=expression for remainder operation](https://discuss.elastic.co/t/querying-data-using-script-query-with-lang-expression-for-remainder-operation/325895)

<div class="topic-metadata">

**Author:** [@Rachana\_Maniyar](https://discuss.elastic.co/u/Rachana_Maniyar)\
**Replies:** 16\
**Last updated:** [February 25, 2023, 7:20am UTC](https://discuss.elastic.co/t/querying-data-using-script-query-with-lang-expression-for-remainder-operation/325895 "2023-02-25T07:20:25Z")

</div>

hi Folks, We store a field of type "long" in elastic which has value of this nature = 9048716794795431 Need to retrieve these records based on modulus expression. So the query looks like this query: {'query': {'bool':…

---

## [Endpoint events dont contain process or file hash](https://discuss.elastic.co/t/endpoint-events-dont-contain-process-or-file-hash/324583)

<div class="topic-metadata">

**Author:** [@yak990](https://discuss.elastic.co/u/yak990)\
**Replies:** 2\
**Last updated:** [February 25, 2023, 1:51am UTC](https://discuss.elastic.co/t/endpoint-events-dont-contain-process-or-file-hash/324583 "2023-02-25T01:51:28Z")

</div>

I'm looking through a series of endpoint events, and do not see the hash of the process or file. The events are in endpoint.events.registry in this case. The hash is important, because its easy to cut and paste that in…

---

## [What is the difference between xpack.security.http.ssl.verification\_mode and xpack.http.ssl.verification\_mode](https://discuss.elastic.co/t/what-is-the-difference-between-xpack-security-http-ssl-verification-mode-and-xpack-http-ssl-verification-mode/326474)

<div class="topic-metadata">

**Author:** [@hiruni.insyncit.net](https://discuss.elastic.co/u/hiruni.insyncit.net)\
**Replies:** 0\
**Last updated:** [February 24, 2023, 9:39pm UTC](https://discuss.elastic.co/t/what-is-the-difference-between-xpack-security-http-ssl-verification-mode-and-xpack-http-ssl-verification-mode/326474 "2023-02-24T21:39:38Z")

</div>

I want to know what is the difference between xpack.security.http.ssl.verification\_mode: certificate and xpack.http.ssl.verification\_mode: certificate Also, can I use both setting at same time...? Thank you..! Hiruni

---

## [How to create many small separate indices](https://discuss.elastic.co/t/how-to-create-many-small-separate-indices/326459)

<div class="topic-metadata">

**Author:** [@tim28](https://discuss.elastic.co/u/tim28)\
**Replies:** 5\
**Last updated:** [February 24, 2023, 7:27pm UTC](https://discuss.elastic.co/t/how-to-create-many-small-separate-indices/326459 "2023-02-24T19:27:48Z")

</div>

Hi! I want to create many (~10k) indices each having a couple of hundred documents. I have read in other places that that's discouraged as it creates a shard per index which is a lot of overhead. However, I have the req…

---

## [Logs are not coming for every half n hour](https://discuss.elastic.co/t/logs-are-not-coming-for-every-half-n-hour/326402)

<div class="topic-metadata">

**Author:** [@Haneesha](https://discuss.elastic.co/u/Haneesha)\
**Replies:** 1\
**Last updated:** [February 24, 2023, 4:16pm UTC](https://discuss.elastic.co/t/logs-are-not-coming-for-every-half-n-hour/326402 "2023-02-24T16:16:20Z")

</div>

Hi Team, Since today morning logs in kibana are coming and then going off . This is the third time in a single day. Could anyone please help.

---

## [Why does aggregation contain ID's that don't exist in the query results?](https://discuss.elastic.co/t/why-does-aggregation-contain-ids-that-dont-exist-in-the-query-results/326445)

<div class="topic-metadata">

**Author:** [@A\_K3](https://discuss.elastic.co/u/A_K3)\
**Replies:** 1\
**Last updated:** [February 24, 2023, 4:08pm UTC](https://discuss.elastic.co/t/why-does-aggregation-contain-ids-that-dont-exist-in-the-query-results/326445 "2023-02-24T16:08:10Z")

</div>

To gather data on how many documents have been prepared by some employee in a given time period, I have written this query: { "from": 0, "size": 0, "sort": \[\], "query": { "bool": { "must": \[ { …

---

## [Alert rules requiring endpoint integration 8.2.0 when 8.6.1 is installed already](https://discuss.elastic.co/t/alert-rules-requiring-endpoint-integration-8-2-0-when-8-6-1-is-installed-already/326219)

<div class="topic-metadata">

**Author:** [@Kelly\_Slavens](https://discuss.elastic.co/u/Kelly_Slavens)\
**Replies:** 2\
**Last updated:** [February 24, 2023, 3:31pm UTC](https://discuss.elastic.co/t/alert-rules-requiring-endpoint-integration-8-2-0-when-8-6-1-is-installed-already/326219 "2023-02-24T15:31:10Z")

</div>

We're seeing an issue in the Rules section. Several rules indicate they require the Endpoint Integration to be installed. Endpoint is installed and deployed on thousands of devices. The link provided points to version 8…

---

## [Different values using date histogram](https://discuss.elastic.co/t/different-values-using-date-histogram/326453)

<div class="topic-metadata">

**Author:** [@bcamboim](https://discuss.elastic.co/u/bcamboim)\
**Replies:** 0\
**Last updated:** [February 24, 2023, 3:15pm UTC](https://discuss.elastic.co/t/different-values-using-date-histogram/326453 "2023-02-24T15:15:26Z")

</div>

Hi everyone. I'am using the package @elastic/elasticsearch (^7.9.1) to do queries in my cluster. I have a dashboard showing the concurrent users using my videos platform. My query is: { query: { bool: { …

---

## [New "Elastic Defend" integration not recognized by rules (8.6.2)](https://discuss.elastic.co/t/new-elastic-defend-integration-not-recognized-by-rules-8-6-2/326436)

<div class="topic-metadata">

**Author:** [@syk](https://discuss.elastic.co/u/syk)\
**Replies:** 2\
**Last updated:** [February 24, 2023, 3:06pm UTC](https://discuss.elastic.co/t/new-elastic-defend-integration-not-recognized-by-rules-8-6-2/326436 "2023-02-24T15:06:57Z")

</div>

Hi, I'm not able to satisfy the dependency of the "Prebuilt Security Detection Rules" on a fresh installation (on premises) of Elastic and Kibana version 8.6.2: Rules demand "Endpoint Security" integration being instal…

---

## [Unable to start elasticsearch 7.11.0](https://discuss.elastic.co/t/unable-to-start-elasticsearch-7-11-0/326342)

<div class="topic-metadata">

**Author:** [@anandgavai](https://discuss.elastic.co/u/anandgavai)\
**Replies:** 6\
**Last updated:** [February 24, 2023, 2:27pm UTC](https://discuss.elastic.co/t/unable-to-start-elasticsearch-7-11-0/326342 "2023-02-24T14:27:10Z")

</div>

Hi there, am getting an ElasticsearchUncaughtExceptionHandler error and not able to start elasticsearch. All I know was there was there was an abrupt shutdown of my server and since then am not able to start the elastic…

---

## [Aggregations: Getting accurate counts for filter panel](https://discuss.elastic.co/t/aggregations-getting-accurate-counts-for-filter-panel/326433)

<div class="topic-metadata">

**Author:** [@MonikaJ](https://discuss.elastic.co/u/MonikaJ)\
**Replies:** 0\
**Last updated:** [February 24, 2023, 11:23am UTC](https://discuss.elastic.co/t/aggregations-getting-accurate-counts-for-filter-panel/326433 "2023-02-24T11:23:09Z")

</div>

Many searches provide a standard filter panel on the left, that allows filtering by OR within a category and AND between categories. The logic the counts that are shown for every filter entry follows the following standa…

---

## [Configure Elasticsearch on Django App](https://discuss.elastic.co/t/configure-elasticsearch-on-django-app/326320)

<div class="topic-metadata">

**Author:** [@ekane3](https://discuss.elastic.co/u/ekane3)\
**Replies:** 8\
**Last updated:** [February 24, 2023, 1:31pm UTC](https://discuss.elastic.co/t/configure-elasticsearch-on-django-app/326320 "2023-02-24T13:31:52Z")

</div>

:wave: Hello everyone, I have been trying for weeks now to configure Elasticsearch/logstash on my Django app. But, all the tutorials i found are dealing with local elasticsearch meanwhile the one i’m dealing with is a…

---

## [Records Limits on upload](https://discuss.elastic.co/t/records-limits-on-upload/326442)

<div class="topic-metadata">

**Author:** [@IceF1reX](https://discuss.elastic.co/u/IceF1reX)\
**Replies:** 0\
**Last updated:** [February 24, 2023, 1:26pm UTC](https://discuss.elastic.co/t/records-limits-on-upload/326442 "2023-02-24T13:26:18Z")

</div>

How to increase or remove records limits from simultaneous upload in C# ?? For 300 000 and more

---

## [Logstash plugin had an unrecoverable error. Will restart this plugin](https://discuss.elastic.co/t/logstash-plugin-had-an-unrecoverable-error-will-restart-this-plugin/326220)

<div class="topic-metadata">

**Author:** [@Vinicius\_Carmo](https://discuss.elastic.co/u/Vinicius_Carmo)\
**Replies:** 6\
**Last updated:** [February 24, 2023, 12:39pm UTC](https://discuss.elastic.co/t/logstash-plugin-had-an-unrecoverable-error-will-restart-this-plugin/326220 "2023-02-24T12:39:56Z")

</div>

Hello everyone, I need help I tried using the Microsoft-sentinel plugin output logstash. but I get an error: A plugin had an unrecoverable error. Will restart this plugin Error: address already in use I used two outp…

---

## [Historic tomcat access logs transform historic timestamp to @timestamp](https://discuss.elastic.co/t/historic-tomcat-access-logs-transform-historic-timestamp-to-timestamp/325862)

<div class="topic-metadata">

**Author:** [@flomickl](https://discuss.elastic.co/u/flomickl)\
**Replies:** 6\
**Last updated:** [February 21, 2023, 11:57pm UTC](https://discuss.elastic.co/t/historic-tomcat-access-logs-transform-historic-timestamp-to-timestamp/325862 "2023-02-21T23:57:14Z")

</div>

Hi, I have some historic tomcat log files like 172.x.x.xx - - \[19/Dec/2022:23:59:58 +0100\] "POST /url/text/json HTTP/1.1" 200 348 I have already a Logstash grok pattern but I have a problem with the correct timestamp. …

---

## [Failed to clean async result](https://discuss.elastic.co/t/failed-to-clean-async-result/326347)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 3\
**Last updated:** [February 24, 2023, 10:13am UTC](https://discuss.elastic.co/t/failed-to-clean-async-result/326347 "2023-02-24T10:13:23Z")

</div>

Hi I met the case on transport transport\_worker in my workflow ingest node (mem capacity 36GB) received data from source and the next this data should be relocated on data nodes (16GB) Can we control bulk of data betw…

---

## [Where to find the generated CSV report](https://discuss.elastic.co/t/where-to-find-the-generated-csv-report/326395)

<div class="topic-metadata">

**Author:** [@ashd](https://discuss.elastic.co/u/ashd)\
**Replies:** 1\
**Last updated:** [February 24, 2023, 9:09am UTC](https://discuss.elastic.co/t/where-to-find-the-generated-csv-report/326395 "2023-02-24T09:09:43Z")

</div>

How can I access the CSV reports that were generated? What are the step to access them?!

---

## [Use the correct datatype fields](https://discuss.elastic.co/t/use-the-correct-datatype-fields/326290)

<div class="topic-metadata">

**Author:** [@rschirin](https://discuss.elastic.co/u/rschirin)\
**Replies:** 4\
**Last updated:** [February 24, 2023, 7:59am UTC](https://discuss.elastic.co/t/use-the-correct-datatype-fields/326290 "2023-02-24T07:59:01Z")

</div>

Hey there, I would like just to get a suggestion. If I have a field that contains only ip addresses and it is used for standard match query, should be better to map it with the ip datatype or is it not relevant? is the…

---

## [Get the matched and unmatched result based on fields inside an index](https://discuss.elastic.co/t/get-the-matched-and-unmatched-result-based-on-fields-inside-an-index/326397)

<div class="topic-metadata">

**Author:** [@Prashant\_Pandey1](https://discuss.elastic.co/u/Prashant_Pandey1)\
**Replies:** 0\
**Last updated:** [February 24, 2023, 4:06am UTC](https://discuss.elastic.co/t/get-the-matched-and-unmatched-result-based-on-fields-inside-an-index/326397 "2023-02-24T04:06:21Z")

</div>

Hi All , I'm new to Elasticsearch, please can someone help on this I want to matched and unmatched data based on fields from index. Sample of Data Schema of index : { "\_index": "comparebyid", "\_id": "MPGsra40AGzOIw1…

---

## [Lost Trial License on ECK After Creating LoadBalancer](https://discuss.elastic.co/t/lost-trial-license-on-eck-after-creating-loadbalancer/326396)

<div class="topic-metadata">

**Author:** [@tr78](https://discuss.elastic.co/u/tr78)\
**Replies:** 0\
**Last updated:** [February 24, 2023, 3:37am UTC](https://discuss.elastic.co/t/lost-trial-license-on-eck-after-creating-loadbalancer/326396 "2023-02-24T03:37:24Z")

</div>

Hi, I've been running a trial license on ECK for about a week now without issue. Today I created a LoadBalancer to expose the API on port 9200, and after applying my license had reverted back to basic. If I try the tr…

---

## [Autocomplete - Completion Suggester Or Search as you type filed type](https://discuss.elastic.co/t/autocomplete-completion-suggester-or-search-as-you-type-filed-type/326393)

<div class="topic-metadata">

**Author:** [@xef](https://discuss.elastic.co/u/xef)\
**Replies:** 0\
**Last updated:** [February 24, 2023, 3:18am UTC](https://discuss.elastic.co/t/autocomplete-completion-suggester-or-search-as-you-type-filed-type/326393 "2023-02-24T03:18:02Z")

</div>

We need to create an autocomplete functionality so that as the user is typing suggestions are shown from the backend elasticsearch indices. Which is the better option for indiex that has 10 million plus records and the …

---

## [Get request taking much time in elasticsearch](https://discuss.elastic.co/t/get-request-taking-much-time-in-elasticsearch/326391)

<div class="topic-metadata">

**Author:** [@Siva\_Karan](https://discuss.elastic.co/u/Siva_Karan)\
**Replies:** 1\
**Last updated:** [February 24, 2023, 2:12am UTC](https://discuss.elastic.co/t/get-request-taking-much-time-in-elasticsearch/326391 "2023-02-24T02:12:59Z")

</div>

Hi Team, For elasticsearch using transport client 9kb record it takes to 3 seconds. sometimes it will take the 100 ms.

---

## [Storing only pointer to source field?](https://discuss.elastic.co/t/storing-only-pointer-to-source-field/326368)

<div class="topic-metadata">

**Author:** [@XD\_Captain](https://discuss.elastic.co/u/XD_Captain)\
**Replies:** 3\
**Last updated:** [February 24, 2023, 12:21am UTC](https://discuss.elastic.co/t/storing-only-pointer-to-source-field/326368 "2023-02-24T00:21:19Z")

</div>

Hi, I'm new to Elasticsearch and am wondering about this: is there a handy way to not store the \_source field (original json file), but instead store just a pointer (ID) to the source field items? For instance if the …

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=427)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=429)
