# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=480

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 481

---

## [Dec 10th, 2022: \[EN\] Asking top notch technical questions to get you help quicker!](https://discuss.elastic.co/t/dec-10th-2022-en-asking-top-notch-technical-questions-to-get-you-help-quicker/320300)

<div class="topic-metadata">

**Author:** [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Replies:** 0\
**Last updated:** [December 10, 2022, 8:05am UTC](https://discuss.elastic.co/t/dec-10th-2022-en-asking-top-notch-technical-questions-to-get-you-help-quicker/320300 "2022-12-10T08:05:20Z")

</div>

The quickest way to get help for any technical questions you have on our forums is to provide as much information as possible, as the details you do and don't provide make a big impact on the ability for us to help yo…

---

## [ElasticSearch 8.5 and Java Client Error ""com.fasterxml.jackson.core.JsonParseException: Unrecognized token 'Client'](https://discuss.elastic.co/t/elasticsearch-8-5-and-java-client-error-com-fasterxml-jackson-core-jsonparseexception-unrecognized-token-client/319700)

<div class="topic-metadata">

**Author:** [@AlwaysBatMan](https://discuss.elastic.co/u/AlwaysBatMan)\
**Replies:** 3\
**Last updated:** [December 10, 2022, 10:34am UTC](https://discuss.elastic.co/t/elasticsearch-8-5-and-java-client-error-com-fasterxml-jackson-core-jsonparseexception-unrecognized-token-client/319700 "2022-12-10T10:34:05Z")

</div>

I am trying to use Elasticsearch 8.5 and its associated RestClient.I am having some difficulties using it and I am not able to make sense of this as to why this error message will be thrown.Looking for some guidance on h…

---

## [Different same-field highlighting with alias fields and highlight queries broken](https://discuss.elastic.co/t/different-same-field-highlighting-with-alias-fields-and-highlight-queries-broken/320940)

<div class="topic-metadata">

**Author:** [@Erik\_Fassler](https://discuss.elastic.co/u/Erik_Fassler)\
**Replies:** 1\
**Last updated:** [December 10, 2022, 9:35am UTC](https://discuss.elastic.co/t/different-same-field-highlighting-with-alias-fields-and-highlight-queries-broken/320940 "2022-12-10T09:35:18Z")

</div>

I am using alias fields to do different highlighting on basically the same field. I use highlight\_queries to highlight different parts of the same field. This worked fine in ES up to 7.9.1 but changed its behaviour in ne…

---

## [Problem with range search with datetime field](https://discuss.elastic.co/t/problem-with-range-search-with-datetime-field/320878)

<div class="topic-metadata">

**Author:** [@abkrim](https://discuss.elastic.co/u/abkrim)\
**Replies:** 4\
**Last updated:** [December 10, 2022, 9:33am UTC](https://discuss.elastic.co/t/problem-with-range-search-with-datetime-field/320878 "2022-12-10T09:33:36Z")

</div>

I have a strange problem when I make queries in date range Mapping index . . . "datetime": { "type": "date", "format": "epoch\_second||yyyy-MM-dd HH:mm:ss", "ignore\_malformed": true …

---

## [Degrading search performance and old recods](https://discuss.elastic.co/t/degrading-search-performance-and-old-recods/320892)

<div class="topic-metadata">

**Author:** [@rvallel](https://discuss.elastic.co/u/rvallel)\
**Replies:** 3\
**Last updated:** [December 10, 2022, 9:02am UTC](https://discuss.elastic.co/t/degrading-search-performance-and-old-recods/320892 "2022-12-10T09:02:41Z")

</div>

Hi! My searches become slower and slower as the number of indexed documents grow. However, we only query the documents that happen to be produced in the last 3 months. I wonder if it is possible to have an alias or an…

---

## [How to configure 'ls.cgroup.cpu.path.override' in the Logstash JAVA\_OPTS environment variable](https://discuss.elastic.co/t/how-to-configure-ls-cgroup-cpu-path-override-in-the-logstash-java-opts-environment-variable/320880)

<div class="topic-metadata">

**Author:** [@jijesh\_vu](https://discuss.elastic.co/u/jijesh_vu)\
**Replies:** 2\
**Last updated:** [December 10, 2022, 5:46am UTC](https://discuss.elastic.co/t/how-to-configure-ls-cgroup-cpu-path-override-in-the-logstash-java-opts-environment-variable/320880 "2022-12-10T05:46:44Z")

</div>

I would like to know how to configure ls.cgroup.cpu.path.override and what this is means actaully? \[DEBUG\] 2022-12-09 12:27:37.592 \[pool-6-thread-1\] cpuresource - File /sys/fs/cgroup/cpu/kubepods.slice/kubepods-burstabl…

---

## [Missing required fields in duplicated rules](https://discuss.elastic.co/t/missing-required-fields-in-duplicated-rules/320874)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 1\
**Last updated:** [December 9, 2022, 10:22pm UTC](https://discuss.elastic.co/t/missing-required-fields-in-duplicated-rules/320874 "2022-12-09T22:22:09Z")

</div>

When I duplicate a rule, I don't immediately see an option to select required fields? (I could be looking over it?)

---

## [Logstash Aggregate filter inside Elasticsearch](https://discuss.elastic.co/t/logstash-aggregate-filter-inside-elasticsearch/320934)

<div class="topic-metadata">

**Author:** [@watercannons](https://discuss.elastic.co/u/watercannons)\
**Replies:** 0\
**Last updated:** [December 9, 2022, 9:53pm UTC](https://discuss.elastic.co/t/logstash-aggregate-filter-inside-elasticsearch/320934 "2022-12-09T21:53:11Z")

</div>

Hi, first time on this forum, sorry if this is a duplicate. I'm running into some weird hardware-specific issues running LogStash that's causing the aggregate plugin to not apply on certain events. However, all of the da…

---

## [Where is Logstash installed by default?](https://discuss.elastic.co/t/where-is-logstash-installed-by-default/320913)

<div class="topic-metadata">

**Author:** [@timer5764](https://discuss.elastic.co/u/timer5764)\
**Replies:** 2\
**Last updated:** [December 9, 2022, 8:42pm UTC](https://discuss.elastic.co/t/where-is-logstash-installed-by-default/320913 "2022-12-09T20:42:47Z")

</div>

I have a CentOS machine that I recently installed Logstash on, using the following command: sudo yum install logstash The command executed successfully and Logstash was installed, as shown in the screenshot below: H…

---

## [ES Field Capabilities API does not return non-indexed/disabled fields when include\_unmapped=true](https://discuss.elastic.co/t/es-field-capabilities-api-does-not-return-non-indexed-disabled-fields-when-include-unmapped-true/320810)

<div class="topic-metadata">

**Author:** [@Alsheh](https://discuss.elastic.co/u/Alsheh)\
**Replies:** 3\
**Last updated:** [December 9, 2022, 8:07pm UTC](https://discuss.elastic.co/t/es-field-capabilities-api-does-not-return-non-indexed-disabled-fields-when-include-unmapped-true/320810 "2022-12-09T20:07:21Z")

</div>

Hi, I'm trying to list all fields in a certain index, indexed and non-indexed fields. I'm using the ES Field capabilities API: GET \<index-name\>/\_field\_caps?fields=\*&include\_unmapped=true. However, the API is not returni…

---

## [Aggregate logs of different grok matches](https://discuss.elastic.co/t/aggregate-logs-of-different-grok-matches/320901)

<div class="topic-metadata">

**Author:** [@stefanocog](https://discuss.elastic.co/u/stefanocog)\
**Replies:** 1\
**Last updated:** [December 9, 2022, 7:51pm UTC](https://discuss.elastic.co/t/aggregate-logs-of-different-grok-matches/320901 "2022-12-09T19:51:43Z")

</div>

Hi, I apologize in advance if the request appears incorrect I need calculate the time difference between a request and response of a REST service, this service produce two logs, one for request e and one for response an…

---

## [Elastic Deployment on minukube cluster Failing](https://discuss.elastic.co/t/elastic-deployment-on-minukube-cluster-failing/320924)

<div class="topic-metadata">

**Author:** [@akansha.agarwal1](https://discuss.elastic.co/u/akansha.agarwal1)\
**Replies:** 0\
**Last updated:** [December 9, 2022, 7:42pm UTC](https://discuss.elastic.co/t/elastic-deployment-on-minukube-cluster-failing/320924 "2022-12-09T19:42:04Z")

</div>

Hi, I am trying to deploy Elastic 8.5.2 on minukube cluster using: Helm, Statefulset & simple Elasticsearch cluster specification. But all deployments are failing with error: CrashLoopBackOff Although, deployment for…

---

## [authorizeIndexAction never gets called for custom AuthorizationEngine plugin](https://discuss.elastic.co/t/authorizeindexaction-never-gets-called-for-custom-authorizationengine-plugin/320921)

<div class="topic-metadata">

**Author:** [@adamsandor](https://discuss.elastic.co/u/adamsandor)\
**Replies:** 0\
**Last updated:** [December 9, 2022, 7:23pm UTC](https://discuss.elastic.co/t/authorizeindexaction-never-gets-called-for-custom-authorizationengine-plugin/320921 "2022-12-09T19:23:16Z")

</div>

I'm building a plugin that would execute some custom authorization logic, namely integrating the OpenPolicyAgent into the authorization flow of ES. I have implemented the org.elasticsearch.xpack.core.security.authz.Autho…

---

## [Centerlized Dashboard](https://discuss.elastic.co/t/centerlized-dashboard/316518)

<div class="topic-metadata">

**Author:** [@Milan\_Dangol](https://discuss.elastic.co/u/Milan_Dangol)\
**Replies:** 3\
**Last updated:** [October 16, 2022, 10:27pm UTC](https://discuss.elastic.co/t/centerlized-dashboard/316518 "2022-10-16T22:27:10Z")

</div>

Hello team, I have a query about the centralized dashboard. I am planning to integrate 60 VMs into my Kibana and I want to view all those individual 60 VM's graphs in a single dashboard. Thank you in advance \<3

---

## [Enable soundex level search](https://discuss.elastic.co/t/enable-soundex-level-search/320904)

<div class="topic-metadata">

**Author:** [@ryendluri](https://discuss.elastic.co/u/ryendluri)\
**Replies:** 2\
**Last updated:** [December 9, 2022, 5:17pm UTC](https://discuss.elastic.co/t/enable-soundex-level-search/320904 "2022-12-09T17:17:32Z")

</div>

how to enable soundex search in querying data from Elastic search DB? thanks

---

## [Можно ли кастомизировать ukrainian\_analyzer с пощью shingle filter?](https://discuss.elastic.co/t/ukrainian-analyzer-shingle-filter/320887)

<div class="topic-metadata">

**Author:** [@va2dim](https://discuss.elastic.co/u/va2dim)\
**Replies:** 0\
**Last updated:** [December 9, 2022, 1:38pm UTC](https://discuss.elastic.co/t/ukrainian-analyzer-shingle-filter/320887 "2022-12-09T13:38:54Z")

</div>

Необходима комбинация ukrainian\_analyzer с shingle filter. С русским языком проблем нет - можно собрать кастомный анализатор: есть russian\_stemmer который можем передать как фильтр в кастомный анализатор. В реализаци…

---

## [Is it possible to reimplemented ukrainian build-in analyzer as a custom analyzer (extend ukrainian\_analyzer with shingle filter)?](https://discuss.elastic.co/t/is-it-possible-to-reimplemented-ukrainian-build-in-analyzer-as-a-custom-analyzer-extend-ukrainian-analyzer-with-shingle-filter/320888)

<div class="topic-metadata">

**Author:** [@va2dim](https://discuss.elastic.co/u/va2dim)\
**Replies:** 0\
**Last updated:** [December 9, 2022, 1:46pm UTC](https://discuss.elastic.co/t/is-it-possible-to-reimplemented-ukrainian-build-in-analyzer-as-a-custom-analyzer-extend-ukrainian-analyzer-with-shingle-filter/320888 "2022-12-09T13:46:27Z")

</div>

Need to reimplemented ukrainian build-in language analyzer as a custom analyzer (extend ukrainian analyzer with shingle filter). In russian we have russian\_stemmer that could be passed to custom analyzer. In ukrainian…

---

## [Kibana Can't store an async search response larger than?](https://discuss.elastic.co/t/kibana-cant-store-an-async-search-response-larger-than/316677)

<div class="topic-metadata">

**Author:** [@Nikolas1306](https://discuss.elastic.co/u/Nikolas1306)\
**Replies:** 0\
**Last updated:** [October 15, 2022, 9:53am UTC](https://discuss.elastic.co/t/kibana-cant-store-an-async-search-response-larger-than/316677 "2022-10-15T09:53:13Z")

</div>

Can't store an async search response larger than \[10485760\] bytes. This limit can be set by changing the \[search.max\_async\_search\_response\_size\] setting.

---

## [Reindex vs Split index speeds](https://discuss.elastic.co/t/reindex-vs-split-index-speeds/320779)

<div class="topic-metadata">

**Author:** [@Daithi\_O\_Conchobhair](https://discuss.elastic.co/u/Daithi_O_Conchobhair)\
**Replies:** 8\
**Last updated:** [December 9, 2022, 1:23pm UTC](https://discuss.elastic.co/t/reindex-vs-split-index-speeds/320779 "2022-12-09T13:23:46Z")

</div>

Hi there, I have a relatively large index, 1.1TB, which currently has one shard due to a misconfiguration. I would like to keep my shard size around 50GB. I have two options I guess Split the index into a new index wi…

---

## [Percolator issue, matching queries](https://discuss.elastic.co/t/percolator-issue-matching-queries/320884)

<div class="topic-metadata">

**Author:** [@Mahesh\_Hegde](https://discuss.elastic.co/u/Mahesh_Hegde)\
**Replies:** 0\
**Last updated:** [December 9, 2022, 1:02pm UTC](https://discuss.elastic.co/t/percolator-issue-matching-queries/320884 "2022-12-09T13:02:43Z")

</div>

Hi Team, Issue module - percolator Issue Version - 8.3 & 8.4 Configuration Number of shards of percolator index - 2 Total documents indexed - 78000 approximate Index size = 30MB Details - We have about 78000 quer…

---

## [How can i display string on yaxis of timelion?](https://discuss.elastic.co/t/how-can-i-display-string-on-yaxis-of-timelion/320879)

<div class="topic-metadata">

**Author:** [@Cusis\_Eel](https://discuss.elastic.co/u/Cusis_Eel)\
**Replies:** 0\
**Last updated:** [December 9, 2022, 12:06pm UTC](https://discuss.elastic.co/t/how-can-i-display-string-on-yaxis-of-timelion/320879 "2022-12-09T12:06:50Z")

</div>

i did use this code .es(index=timelion\_01, timefield=input\_date,metric='max:value').fit(carry).lines(fill=5) { "input\_date" : "2022-12-09T03:00:00.00", "value" : 2 (type is maybe long) } value is only 0 to 2 …

---

## [Composant output jdbc dans logstash](https://discuss.elastic.co/t/composant-output-jdbc-dans-logstash/320806)

<div class="topic-metadata">

**Author:** [@yannt](https://discuss.elastic.co/u/yannt)\
**Replies:** 4\
**Last updated:** [December 9, 2022, 11:31am UTC](https://discuss.elastic.co/t/composant-output-jdbc-dans-logstash/320806 "2022-12-09T11:31:48Z")

</div>

Bonjour nous avons installé logstash au droit d'un serveur postgresql que nous interrogeons via le composant input jdbc pour alimenter en ligne un cloud elastic. Nous cherchons maintenant à faire une opération de mise à…

---

## [How to get average number of samples for time series data with DSL query?](https://discuss.elastic.co/t/how-to-get-average-number-of-samples-for-time-series-data-with-dsl-query/320841)

<div class="topic-metadata">

**Author:** [@bgyomorei\_c](https://discuss.elastic.co/u/bgyomorei_c)\
**Replies:** 2\
**Last updated:** [December 9, 2022, 11:26am UTC](https://discuss.elastic.co/t/how-to-get-average-number-of-samples-for-time-series-data-with-dsl-query/320841 "2022-12-09T11:26:28Z")

</div>

I want to get the average number of request per second(or minute) for performance testing data, but the basic aggregation possibilities i've found so far doesn't cover this. I could only do a count on a field, but that …

---

## [Logstash and elasticsearch bundled java update](https://discuss.elastic.co/t/logstash-and-elasticsearch-bundled-java-update/320853)

<div class="topic-metadata">

**Author:** [@Ravi\_Vishwakarma](https://discuss.elastic.co/u/Ravi_Vishwakarma)\
**Replies:** 2\
**Last updated:** [December 9, 2022, 11:01am UTC](https://discuss.elastic.co/t/logstash-and-elasticsearch-bundled-java-update/320853 "2022-12-09T11:01:43Z")

</div>

Hi, We are using ELK stack 7.17.2 in our environment. We have found vulnerability on Logstash and Elasticsearch for JDK. We have used jdk bundled one. Below is the VA snap. Please let me know how i can update the JDK …

---

## [Clone cluster with Logstash](https://discuss.elastic.co/t/clone-cluster-with-logstash/320551)

<div class="topic-metadata">

**Author:** [@lduvnjak](https://discuss.elastic.co/u/lduvnjak)\
**Replies:** 19\
**Last updated:** [December 9, 2022, 9:44am UTC](https://discuss.elastic.co/t/clone-cluster-with-logstash/320551 "2022-12-09T09:44:25Z")

</div>

Hey Everyone, We're trying to figure out the best way to clone a cluster completely, and Logstash seems to be the best option on a large scale as there's no need to use a custom solution. An example configuration of wh…

---

## [Kibana Query Taking too long](https://discuss.elastic.co/t/kibana-query-taking-too-long/320865)

<div class="topic-metadata">

**Author:** [@Arjun\_Meena](https://discuss.elastic.co/u/Arjun_Meena)\
**Replies:** 3\
**Last updated:** [December 9, 2022, 9:24am UTC](https://discuss.elastic.co/t/kibana-query-taking-too-long/320865 "2022-12-09T09:24:37Z")

</div>

We have a visualisation that uses the below given query to fetch the data. GET commerce-access-console-logs-\*/\_search { "aggs": { "3": { "filters": { "filters": { "LUX-SearchProducts": { …

---

## [Set Static Master Node in Elasticsearch Cluster](https://discuss.elastic.co/t/set-static-master-node-in-elasticsearch-cluster/320858)

<div class="topic-metadata">

**Author:** [@hjsroldan](https://discuss.elastic.co/u/hjsroldan)\
**Replies:** 5\
**Last updated:** [December 9, 2022, 9:22am UTC](https://discuss.elastic.co/t/set-static-master-node-in-elasticsearch-cluster/320858 "2022-12-09T09:22:08Z")

</div>

Hi, I have a 3 Node Elasticsearch. I have set the discovery.seed\_hosts: \["Node1", "Node2", "Node3"\] and cluster.initial\_master\_nodes: \["Node1"\]. What is the configuration if I want the master node " Node1" to be re-ele…

---

## [Howto to visualize/map latest state of a string value of multiple docs](https://discuss.elastic.co/t/howto-to-visualize-map-latest-state-of-a-string-value-of-multiple-docs/318735)

<div class="topic-metadata">

**Author:** [@stefws](https://discuss.elastic.co/u/stefws)\
**Replies:** 0\
**Last updated:** [November 11, 2022, 11:25am UTC](https://discuss.elastic.co/t/howto-to-visualize-map-latest-state-of-a-string-value-of-multiple-docs/318735 "2022-11-11T11:25:29Z")

</div>

Got metricbeat fetching jolokia values of the state of several instances of Jboss servers of several linux boxes. I tinkering with howto best create a visualization that'll show an overview of each expected instances sta…

---

## [Elasticsearch bootstrap check](https://discuss.elastic.co/t/elasticsearch-bootstrap-check/320812)

<div class="topic-metadata">

**Author:** [@imdroid](https://discuss.elastic.co/u/imdroid)\
**Replies:** 3\
**Last updated:** [December 9, 2022, 8:32am UTC](https://discuss.elastic.co/t/elasticsearch-bootstrap-check/320812 "2022-12-09T08:32:59Z")

</div>

I'm trying to create an elasticcluster. the nodes are setup in two seperate servers. my network and transport details are as follows: network.host: 10.198.22.161 http.port: 9200 transport.host: 10.198.22.161 transport.t…

---

## [Deleting / editing existing analyzer in elastic index](https://discuss.elastic.co/t/deleting-editing-existing-analyzer-in-elastic-index/320838)

<div class="topic-metadata">

**Author:** [@Leonid\_P](https://discuss.elastic.co/u/Leonid_P)\
**Replies:** 3\
**Last updated:** [December 9, 2022, 8:17am UTC](https://discuss.elastic.co/t/deleting-editing-existing-analyzer-in-elastic-index/320838 "2022-12-09T08:17:27Z")

</div>

Hello! Is it safe to delete or change an analyzer in an existing index? Surfing through Stackoverflow and experimenting on my own I've found ways for both operations, i.e. curl -X PUT "localhost:9200/index\_name/\_setti…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=479)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=481)
