# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=485

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 486

---

## [Node is disconnected from cluster and does not join existing cluster (ES 7.16.2)](https://discuss.elastic.co/t/node-is-disconnected-from-cluster-and-does-not-join-existing-cluster-es-7-16-2/320357)

<div class="topic-metadata">

**Author:** [@Pooja2](https://discuss.elastic.co/u/Pooja2)\
**Replies:** 1\
**Last updated:** [December 4, 2022, 9:15pm UTC](https://discuss.elastic.co/t/node-is-disconnected-from-cluster-and-does-not-join-existing-cluster-es-7-16-2/320357 "2022-12-04T21:15:10Z")

</div>

Hi Team, We have an elasticsearch(ES 7.16.2) cluster of 3 nodes in which one node(node-3) is randomly disconnected from the cluster. Node info: node-1 = master, data (currently master) node-2 = master, data node-3 =…

---

## [How to properly monitor containerized databases?](https://discuss.elastic.co/t/how-to-properly-monitor-containerized-databases/320401)

<div class="topic-metadata">

**Author:** [@jerrac](https://discuss.elastic.co/u/jerrac)\
**Replies:** 0\
**Last updated:** [December 3, 2022, 12:50am UTC](https://discuss.elastic.co/t/how-to-properly-monitor-containerized-databases/320401 "2022-12-03T00:50:21Z")

</div>

I'm in the the middle of testing how well deploying a MariaDB Galera cluster per app works in a Docker Swarm stack. The idea being that we can tweak each Galera cluster to fit each individual apps needs, have them be hi…

---

## [Retrieve records and update a field at the same time](https://discuss.elastic.co/t/retrieve-records-and-update-a-field-at-the-same-time/320432)

<div class="topic-metadata">

**Author:** [@xef](https://discuss.elastic.co/u/xef)\
**Replies:** 1\
**Last updated:** [December 4, 2022, 7:12pm UTC](https://discuss.elastic.co/t/retrieve-records-and-update-a-field-at-the-same-time/320432 "2022-12-04T19:12:44Z")

</div>

We did not get a response the first time. Hopefully someone can give us some guidance this time. Is there anyway when making a query in Elasticsearch, to update a field (such as say a counter++) in each record that is s…

---

## [Issues in scalling elastic search, version conflicts](https://discuss.elastic.co/t/issues-in-scalling-elastic-search-version-conflicts/320424)

<div class="topic-metadata">

**Author:** [@Manav\_Motwani](https://discuss.elastic.co/u/Manav_Motwani)\
**Replies:** 6\
**Last updated:** [December 4, 2022, 10:31am UTC](https://discuss.elastic.co/t/issues-in-scalling-elastic-search-version-conflicts/320424 "2022-12-04T10:31:15Z")

</div>

I will describe my problem as simple as possible, so we have a index which stores product details, but we have 2 primary keys one is product id (unique for every product) and other is city id (we need city id because we …

---

## [Dec 4th 2022: \[PT\] Coletando JSON logs com Elastic-Agent (e/ou Filebeat)](https://discuss.elastic.co/t/dec-4th-2022-pt-coletando-json-logs-com-elastic-agent-e-ou-filebeat/320030)

<div class="topic-metadata">

**Author:** [@TiagoQueiroz](https://discuss.elastic.co/u/TiagoQueiroz)\
**Replies:** 0\
**Last updated:** [December 4, 2022, 8:00am UTC](https://discuss.elastic.co/t/dec-4th-2022-pt-coletando-json-logs-com-elastic-agent-e-ou-filebeat/320030 "2022-12-04T08:00:03Z")

</div>

Este artigo também está disponível em inglês. Logs estruturados particamente se tornaram um padrão na industria de software, permitindo um fácil entendimento e processamento dos dados. O Elastic-Agent oferece um gran…

---

## [Elasticsearch best\_compression](https://discuss.elastic.co/t/elasticsearch-best-compression/320397)

<div class="topic-metadata">

**Author:** [@VamPikmin](https://discuss.elastic.co/u/VamPikmin)\
**Replies:** 4\
**Last updated:** [December 4, 2022, 3:05am UTC](https://discuss.elastic.co/t/elasticsearch-best-compression/320397 "2022-12-04T03:05:55Z")

</div>

Hello, I have a bunch of indices that I've remotely re-indexed into a single node as a sort of a backup, these won't need to be written to anymore so I'd like to make them smaller, if possible. What would be the correc…

---

## [Ruby logstash filter](https://discuss.elastic.co/t/ruby-logstash-filter/320408)

<div class="topic-metadata">

**Author:** [@tienld](https://discuss.elastic.co/u/tienld)\
**Replies:** 1\
**Last updated:** [December 3, 2022, 6:07pm UTC](https://discuss.elastic.co/t/ruby-logstash-filter/320408 "2022-12-03T18:07:25Z")

</div>

I have a message contains Unicode Escape Sequence I want convert it to UTF-8 character with my country language (VIetnamese) Input is from filebeat filestream I use logstash to parse the message: \\u0043\\u1ea3\\u006d\\u…

---

## [Kibana / Map / Custom Color Palette](https://discuss.elastic.co/t/kibana-map-custom-color-palette/320415)

<div class="topic-metadata">

**Author:** [@Phildefer](https://discuss.elastic.co/u/Phildefer)\
**Replies:** 0\
**Last updated:** [December 3, 2022, 5:11pm UTC](https://discuss.elastic.co/t/kibana-map-custom-color-palette/320415 "2022-12-03T17:11:53Z")

</div>

Bonjour, Je souhaiterais savoir s'il était possible lors de la validation d'une custom Palette Color par valeur au lieu d'un classement automatique d'attribuer plusieurs valeurs à une seule couleur facilement. Je m'expl…

---

## [Dec 3rd, 2022: \[EN\] Get insights from your webmapping application with Ingest Pipelines and Elastic Observability](https://discuss.elastic.co/t/dec-3rd-2022-en-get-insights-from-your-webmapping-application-with-ingest-pipelines-and-elastic-observability/316864)

<div class="topic-metadata">

**Author:** [@jsanz](https://discuss.elastic.co/u/jsanz)\
**Replies:** 0\
**Last updated:** [December 3, 2022, 8:00am UTC](https://discuss.elastic.co/t/dec-3rd-2022-en-get-insights-from-your-webmapping-application-with-ingest-pipelines-and-elastic-observability/316864 "2022-12-03T08:00:57Z")

</div>

Introduction Imagine you have an application that offers a map interface that should render thousands of elements, so you learn you must go through the modern route of generating tiles. But what are those tiles? Well,…

---

## [ElasticSearch 8: is there a "conf.d" folder to change settings without editing elasticsearch.yml?](https://discuss.elastic.co/t/elasticsearch-8-is-there-a-conf-d-folder-to-change-settings-without-editing-elasticsearch-yml/320076)

<div class="topic-metadata">

**Author:** [@ZaneCEO](https://discuss.elastic.co/u/ZaneCEO)\
**Replies:** 6\
**Last updated:** [December 3, 2022, 7:15am UTC](https://discuss.elastic.co/t/elasticsearch-8-is-there-a-conf-d-folder-to-change-settings-without-editing-elasticsearch-yml/320076 "2022-12-03T07:15:10Z")

</div>

I'd like to edit a few Elasticsearch 8 settings (for example: network.host), but I don't want to edit /etc/elasticsearch/elasticsearch.yml directly. What I'd like to do is to add my settings to my own file and put it in …

---

## [Connect logstash to elasticsearch](https://discuss.elastic.co/t/connect-logstash-to-elasticsearch/320298)

<div class="topic-metadata">

**Author:** [@vassiliy.vins](https://discuss.elastic.co/u/vassiliy.vins)\
**Replies:** 4\
**Last updated:** [December 2, 2022, 8:57pm UTC](https://discuss.elastic.co/t/connect-logstash-to-elasticsearch/320298 "2022-12-02T20:57:41Z")

</div>

Hello! I can see in logstash logs that it is not able to connect to elasticsearch to provide data The ELK documentation says: Copy the self-signed CA certificate from the Elasticsearch config/certs directory. Save it…

---

## [COPY - PASTE from KIBANA without "ROW" and "COLUMN" information](https://discuss.elastic.co/t/copy-paste-from-kibana-without-row-and-column-information/320048)

<div class="topic-metadata">

**Author:** [@Marian\_Ovidiu\_Pistol](https://discuss.elastic.co/u/Marian_Ovidiu_Pistol)\
**Replies:** 7\
**Last updated:** [December 2, 2022, 6:02pm UTC](https://discuss.elastic.co/t/copy-paste-from-kibana-without-row-and-column-information/320048 "2022-12-02T18:02:17Z")

</div>

Hello everybody, Has anyone encountered the following "issue" let's say? I want to copy some info from Kibana, and when I paste it in my notebook for example, it copy-pastes the info with the "row and column" also. It…

---

## [Kibana 6.8.23 CSV reporting is always failing](https://discuss.elastic.co/t/kibana-6-8-23-csv-reporting-is-always-failing/316626)

<div class="topic-metadata">

**Author:** [@Sarat\_Khilar](https://discuss.elastic.co/u/Sarat_Khilar)\
**Replies:** 3\
**Last updated:** [December 2, 2022, 5:26pm UTC](https://discuss.elastic.co/t/kibana-6-8-23-csv-reporting-is-always-failing/316626 "2022-12-02T17:26:09Z")

</div>

I am running two instances of Kibana. When I generate CSV report it is always failing and giving message "failed to generate report maximum 3 attempt reached". if anybody has idea please suggest what could be the reason …

---

## [Fingerprint filter questions: is fingerprint source sensitive to different data types? does it include the field name when calculating fingerprint?](https://discuss.elastic.co/t/fingerprint-filter-questions-is-fingerprint-source-sensitive-to-different-data-types-does-it-include-the-field-name-when-calculating-fingerprint/320326)

<div class="topic-metadata">

**Author:** [@mikhatanu](https://discuss.elastic.co/u/mikhatanu)\
**Replies:** 1\
**Last updated:** [December 2, 2022, 4:58pm UTC](https://discuss.elastic.co/t/fingerprint-filter-questions-is-fingerprint-source-sensitive-to-different-data-types-does-it-include-the-field-name-when-calculating-fingerprint/320326 "2022-12-02T16:58:03Z")

</div>

first question: If I use a source with 2 field value of different data type (1 string field and 1 integer field) and a source with 2 string field value but same content, will it output different fingerprint? second qu…

---

## [Fingerprint filter concatenate\_all\_fields vs concatenate\_sources](https://discuss.elastic.co/t/fingerprint-filter-concatenate-all-fields-vs-concatenate-sources/320318)

<div class="topic-metadata">

**Author:** [@mikhatanu](https://discuss.elastic.co/u/mikhatanu)\
**Replies:** 1\
**Last updated:** [December 2, 2022, 4:44pm UTC](https://discuss.elastic.co/t/fingerprint-filter-concatenate-all-fields-vs-concatenate-sources/320318 "2022-12-02T16:44:15Z")

</div>

Hello, does concatenate\_sources only concat field in the source option and concatenate\_all\_fields concat all the fields from the input, e.g.: i have a log with a,b,c,d,e fields. If i use this, fingerprint{ concaten…

---

## [I want to pin down Elasticsearch during Ubuntu 18.04 to 20.04 upgrade](https://discuss.elastic.co/t/i-want-to-pin-down-elasticsearch-during-ubuntu-18-04-to-20-04-upgrade/320383)

<div class="topic-metadata">

**Author:** [@menabulele](https://discuss.elastic.co/u/menabulele)\
**Replies:** 0\
**Last updated:** [December 2, 2022, 3:12pm UTC](https://discuss.elastic.co/t/i-want-to-pin-down-elasticsearch-during-ubuntu-18-04-to-20-04-upgrade/320383 "2022-12-02T15:12:47Z")

</div>

I'm trying to upgrade from ubuntu 18.04 to ubuntu 20.04 and I don't want my Elasticsearch version to change. We presently run on Elasticsearch 7.17.5 version and the upgrade is forcing a version change to 7.17.7 . We wa…

---

## [Do we need to avoid using Elastic Search as primary DB?](https://discuss.elastic.co/t/do-we-need-to-avoid-using-elastic-search-as-primary-db/320233)

<div class="topic-metadata">

**Author:** [@aswin1906](https://discuss.elastic.co/u/aswin1906)\
**Replies:** 5\
**Last updated:** [December 2, 2022, 2:55pm UTC](https://discuss.elastic.co/t/do-we-need-to-avoid-using-elastic-search-as-primary-db/320233 "2022-12-02T14:55:31Z")

</div>

We are using Elasticsearch as primary db which includes entire ELK, unfortunately last week we lost huge data from Elasticsearch during server restart. 1) Do we need to avoid using Elastic Search as primary DB? If Yes, …

---

## [Setting Env Variables in logstash configuration files](https://discuss.elastic.co/t/setting-env-variables-in-logstash-configuration-files/320341)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 3\
**Last updated:** [December 2, 2022, 2:52pm UTC](https://discuss.elastic.co/t/setting-env-variables-in-logstash-configuration-files/320341 "2022-12-02T14:52:17Z")

</div>

Hello All, I would like to know how can I set up Env Variable in logstash pipleline.yml to read config files from particular folder when logstash startup. Directory structure: C-\>Logstash-\>cfg-\>Different config files …

---

## [Multiple Indice Search With Filters Applied Per Indice](https://discuss.elastic.co/t/multiple-indice-search-with-filters-applied-per-indice/320297)

<div class="topic-metadata">

**Author:** [@sbattGM](https://discuss.elastic.co/u/sbattGM)\
**Replies:** 3\
**Last updated:** [December 2, 2022, 2:34pm UTC](https://discuss.elastic.co/t/multiple-indice-search-with-filters-applied-per-indice/320297 "2022-12-02T14:34:17Z")

</div>

I want to perform a multiple indice search with a term search for all indices but I want to add filters for a particular indice. For example a term query like: http://0.0.0.0:9200/index\_a,index\_b/type1,type2,typ3/\_sear…

---

## [Rate document by term offset or location](https://discuss.elastic.co/t/rate-document-by-term-offset-or-location/320364)

<div class="topic-metadata">

**Author:** [@Ostr1969](https://discuss.elastic.co/u/Ostr1969)\
**Replies:** 0\
**Last updated:** [December 2, 2022, 11:45am UTC](https://discuss.elastic.co/t/rate-document-by-term-offset-or-location/320364 "2022-12-02T11:45:32Z")

</div>

I know that text search can show the location or offset of a term found. can I build a function that can rate or boost the doc by the offset location? for example if searching fox: "brown fox jumping over yellow fenc…

---

## [Delete old logs files](https://discuss.elastic.co/t/delete-old-logs-files/318317)

<div class="topic-metadata">

**Author:** [@Ludovic9](https://discuss.elastic.co/u/Ludovic9)\
**Replies:** 3\
**Last updated:** [December 2, 2022, 11:14am UTC](https://discuss.elastic.co/t/delete-old-logs-files/318317 "2022-12-02T11:14:52Z")

</div>

Hi I'm using an old version of elasticsearch (6.4.1). In /var/log/elasticsearch I have a lot of logs file since 2018 with log.gz extension. It seems using logrotate is not a good option, but instead, using the paramet…

---

## [Logstash ConfigurationError - Expect character](https://discuss.elastic.co/t/logstash-configurationerror-expect-character/320355)

<div class="topic-metadata">

**Author:** [@stefanocog](https://discuss.elastic.co/u/stefanocog)\
**Replies:** 1\
**Last updated:** [December 2, 2022, 10:47am UTC](https://discuss.elastic.co/t/logstash-configurationerror-expect-character/320355 "2022-12-02T10:47:23Z")

</div>

Hi, I've this pattern that match correctly on https://grokconstructor.appspot.com "%{TIMESTAMP\_ISO8601:timestamp}"\\|"%{DATA:tz}"\\|"%{GREEDYDATA:trans}\\: %{GREEDYDATA:transId}"\\|"%{GREEDYDATA:req}\\: %{GREEDYDATA:reqId}"\\…

---

## [Elasticsearch instability using ECK operator on openshift cluster](https://discuss.elastic.co/t/elasticsearch-instability-using-eck-operator-on-openshift-cluster/320349)

<div class="topic-metadata">

**Author:** [@brpedromaia](https://discuss.elastic.co/u/brpedromaia)\
**Replies:** 0\
**Last updated:** [December 2, 2022, 10:10am UTC](https://discuss.elastic.co/t/elasticsearch-instability-using-eck-operator-on-openshift-cluster/320349 "2022-12-02T10:10:29Z")

</div>

We are getting issues with elasticsearch pods, the pods become in a pending state twice in 4 months. sometimes, when it's loading a few dashboards on kibana the pods are restarting, we have added the ILM policy but froz…

---

## [Multiline logs into one event using logstash?](https://discuss.elastic.co/t/multiline-logs-into-one-event-using-logstash/320005)

<div class="topic-metadata">

**Author:** [@kurdit](https://discuss.elastic.co/u/kurdit)\
**Replies:** 9\
**Last updated:** [December 2, 2022, 10:14am UTC](https://discuss.elastic.co/t/multiline-logs-into-one-event-using-logstash/320005 "2022-12-02T10:14:08Z")

</div>

hi all! I have these logs: Nov 23 18:57:14 mx.host.cloud 18:57:14.756 2 SIPS-072111 SIPDATA-124634 REGISTER sip:111.222.333.444:65110 from udp\[555.666.777.888\]:65111 Nov 23 18:57:14 mx.host.cloud 18:57:14.756 2 SIPS-072…

---

## [Usually data are not enriched](https://discuss.elastic.co/t/usually-data-are-not-enriched/316435)

<div class="topic-metadata">

**Author:** [@Marcin\_Frankiewicz](https://discuss.elastic.co/u/Marcin_Frankiewicz)\
**Replies:** 10\
**Last updated:** [December 2, 2022, 10:04am UTC](https://discuss.elastic.co/t/usually-data-are-not-enriched/316435 "2022-12-02T10:04:59Z")

</div>

Hi, Does exists some situactions, when data are not enriched ? (i'm excluding scenario when there are no matching data) Example : Can be skipped for perfomance reasons? It is possible that enrich processor in pipeline…

---

## [Need help for creating filter pattern based on custom logs](https://discuss.elastic.co/t/need-help-for-creating-filter-pattern-based-on-custom-logs/320347)

<div class="topic-metadata">

**Author:** [@Shrikant\_Dhawale](https://discuss.elastic.co/u/Shrikant_Dhawale)\
**Replies:** 0\
**Last updated:** [December 2, 2022, 10:02am UTC](https://discuss.elastic.co/t/need-help-for-creating-filter-pattern-based-on-custom-logs/320347 "2022-12-02T10:02:55Z")

</div>

Hi All, I am new to this technology started learning, need help in writing filter plugin which will parse custom logs from the server. External User(dummy-user) is Mapped to Temp User(dummy-user) with Role(s): role1 ro…

---

## [BadRequestError(400, 'search\_phase\_execution\_exception', 'runtime error')](https://discuss.elastic.co/t/badrequesterror-400-search-phase-execution-exception-runtime-error/320340)

<div class="topic-metadata">

**Author:** [@sanjayk1241](https://discuss.elastic.co/u/sanjayk1241)\
**Replies:** 0\
**Last updated:** [December 2, 2022, 8:40am UTC](https://discuss.elastic.co/t/badrequesterror-400-search-phase-execution-exception-runtime-error/320340 "2022-12-02T08:40:20Z")

</div>

I am trying to implement the search functionality using the elasticsearch concept. I am getting the following error: BadRequestError(400, 'search\_phase\_execution\_exception', 'runtime error') I am not sure where I am d…

---

## [Dec 2nd 2022: \[EN\] The no-data user experience in Kibana](https://discuss.elastic.co/t/dec-2nd-2022-en-the-no-data-user-experience-in-kibana/319322)

<div class="topic-metadata">

**Author:** [@majagrubic](https://discuss.elastic.co/u/majagrubic)\
**Replies:** 0\
**Last updated:** [December 2, 2022, 8:00am UTC](https://discuss.elastic.co/t/dec-2nd-2022-en-the-no-data-user-experience-in-kibana/319322 "2022-12-02T08:00:17Z")

</div>

Over the past few years, Kibana grew both as a product and a codebase. We have added more apps and more solutions. Inadvertently, this led to a situation where multiple teams were building the same thing in a differen…

---

## [Linux Fundamentals course - Networking part is locked](https://discuss.elastic.co/t/linux-fundamentals-course-networking-part-is-locked/320236)

<div class="topic-metadata">

**Author:** [@sl3vin](https://discuss.elastic.co/u/sl3vin)\
**Replies:** 4\
**Last updated:** [December 2, 2022, 7:52am UTC](https://discuss.elastic.co/t/linux-fundamentals-course-networking-part-is-locked/320236 "2022-12-02T07:52:03Z")

</div>

Hello Training-Team, I just completed your Linux Fundamentals course and I have some problems accessing the challenge 6 – Networking. I couldn’t find the necessary flag to unlock this section. Not in the Linux I Fundame…

---

## [Is this a bug of Elasticsearch sorting?](https://discuss.elastic.co/t/is-this-a-bug-of-elasticsearch-sorting/320317)

<div class="topic-metadata">

**Author:** [@howe\_xiao](https://discuss.elastic.co/u/howe_xiao)\
**Replies:** 3\
**Last updated:** [December 2, 2022, 7:25am UTC](https://discuss.elastic.co/t/is-this-a-bug-of-elasticsearch-sorting/320317 "2022-12-02T07:25:46Z")

</div>

Problem Description: A field of keyword type causes a shard retrieval failure with differernt size and from value. Environment：Node-4, Shard-8, Version-8.0 This is my query DSL on Kibana: POST myIndex/\_search { "fro…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=484)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=486)
