# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=507

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 508

---

## [Cluster is yellow and 3 shards are unassigned](https://discuss.elastic.co/t/cluster-is-yellow-and-3-shards-are-unassigned/317892)

<div class="topic-metadata">

**Author:** [@fribse](https://discuss.elastic.co/u/fribse)\
**Replies:** 2\
**Last updated:** [November 2, 2022, 8:32am UTC](https://discuss.elastic.co/t/cluster-is-yellow-and-3-shards-are-unassigned/317892 "2022-11-02T08:32:13Z")

</div>

I had a Elastic search stack crash due to disk almost full, after enabling extra winlogbeat, which took me a bit with surprise, so I added some policies to reduce them a bit. But after doing that and expanding the disk,…

---

## [一台主机安装两个版本的Elastic Search可以区分输入输出接口同时运行吗？](https://discuss.elastic.co/t/elastic-search/317940)

<div class="topic-metadata">

**Author:** [@Shadow\_CHN](https://discuss.elastic.co/u/Shadow_CHN)\
**Replies:** 2\
**Last updated:** [November 2, 2022, 8:17am UTC](https://discuss.elastic.co/t/elastic-search/317940 "2022-11-02T08:17:39Z")

</div>

我在一台CentOS7.8上同时安装了ES7.x和8.x希望服务于不同的应用，请问可以让这两个版本的ES不冲突地同时运行吗？

---

## [Grok pattern](https://discuss.elastic.co/t/grok-pattern/317891)

<div class="topic-metadata">

**Author:** [@abkonred1](https://discuss.elastic.co/u/abkonred1)\
**Replies:** 4\
**Last updated:** [November 2, 2022, 7:25am UTC](https://discuss.elastic.co/t/grok-pattern/317891 "2022-11-02T07:25:06Z")

</div>

Hi Team, I need to ingest the below log file, and i required all the fields without pipe. In order to create visualization and dashboards for the same. kindly any one please help, how to split the fields with this log e…

---

## [Split index failed](https://discuss.elastic.co/t/split-index-failed/317744)

<div class="topic-metadata">

**Author:** [@tonycongjie](https://discuss.elastic.co/u/tonycongjie)\
**Replies:** 2\
**Last updated:** [November 2, 2022, 5:09am UTC](https://discuss.elastic.co/t/split-index-failed/317744 "2022-11-02T05:09:21Z")

</div>

Hello, I tried to split my index to more shard. My cluster has 3 node, the index currently have 1 shard and 1 replicas. I tried to split the shard, but I got a return with “shards\_acknowledged : false” PUT /my\_source\_i…

---

## [Is Elasticsearch suitable for efficient retrieval of large number of docs?](https://discuss.elastic.co/t/is-elasticsearch-suitable-for-efficient-retrieval-of-large-number-of-docs/317845)

<div class="topic-metadata">

**Author:** [@David\_Yu](https://discuss.elastic.co/u/David_Yu)\
**Replies:** 14\
**Last updated:** [November 1, 2022, 4:13pm UTC](https://discuss.elastic.co/t/is-elasticsearch-suitable-for-efficient-retrieval-of-large-number-of-docs/317845 "2022-11-01T16:13:17Z")

</div>

How do we use ES? Our team is using ES to index ads metadata. When we need to show a user ads, we query ES for a list of ads that satisfy certain criteria (e.g. geo, queries, campaign date range, etc). Upon fetching the…

---

## [Need advice for my small ElasticSearch cluster](https://discuss.elastic.co/t/need-advice-for-my-small-elasticsearch-cluster/317881)

<div class="topic-metadata">

**Author:** [@tomboy](https://discuss.elastic.co/u/tomboy)\
**Replies:** 2\
**Last updated:** [November 1, 2022, 11:56pm UTC](https://discuss.elastic.co/t/need-advice-for-my-small-elasticsearch-cluster/317881 "2022-11-01T23:56:39Z")

</div>

Hi all, We have a 3-node cluster in production in the past, and recently we added an independent DC for backup usage. For simplicity, I want to deploy a single ES instance in the backup DC, and keep data in sync with 3…

---

## [Monitor indicies and shards](https://discuss.elastic.co/t/monitor-indicies-and-shards/317920)

<div class="topic-metadata">

**Author:** [@Saeedeh\_Moghimi](https://discuss.elastic.co/u/Saeedeh_Moghimi)\
**Replies:** 1\
**Last updated:** [November 1, 2022, 7:59pm UTC](https://discuss.elastic.co/t/monitor-indicies-and-shards/317920 "2022-11-01T19:59:49Z")

</div>

I'm looking for a way to monitor inside of the cluster like: how many indices are available on my cluster, how many shards each index has and ... I know we can do it manually by GET \_cluster/... commands but I'm looki…

---

## [Convert within Ingest Pipeline not outputting Target field](https://discuss.elastic.co/t/convert-within-ingest-pipeline-not-outputting-target-field/317918)

<div class="topic-metadata">

**Author:** [@Jmc](https://discuss.elastic.co/u/Jmc)\
**Replies:** 0\
**Last updated:** [November 1, 2022, 7:02pm UTC](https://discuss.elastic.co/t/convert-within-ingest-pipeline-not-outputting-target-field/317918 "2022-11-01T19:02:05Z")

</div>

I am using a Convert processor in an Ingest Pipeline, attempting to convert a field from a Keyword type to a Double type. No error is thrown when I test a document through my pipeline. However, I have opted to direct the…

---

## [Does new OpenSSL Vulnerability effect Elasticsearch/Kibana/ECE](https://discuss.elastic.co/t/does-new-openssl-vulnerability-effect-elasticsearch-kibana-ece/317768)

<div class="topic-metadata">

**Author:** [@Jugsofbeer](https://discuss.elastic.co/u/Jugsofbeer)\
**Replies:** 2\
**Last updated:** [November 1, 2022, 5:52pm UTC](https://discuss.elastic.co/t/does-new-openssl-vulnerability-effect-elasticsearch-kibana-ece/317768 "2022-11-01T17:52:28Z")

</div>

Hi, Can someone please advise if the mentioned OpenSSL vulnerabiity effects Elasticsearch/Kibana/E.C.E ?

---

## [Logstash - Adding http\_poller meta data into document](https://discuss.elastic.co/t/logstash-adding-http-poller-meta-data-into-document/317863)

<div class="topic-metadata">

**Author:** [@zx8086](https://discuss.elastic.co/u/zx8086)\
**Replies:** 2\
**Last updated:** [November 1, 2022, 4:48pm UTC](https://discuss.elastic.co/t/logstash-adding-http-poller-meta-data-into-document/317863 "2022-11-01T16:48:36Z")

</div>

The value in this field is what i require -\> http\_poller\_metadata.input.http\_poller.request.name mutate { add\_field =\> { "metric" =\> "\[http\_poller\_metadata\]\[request\]\[name\]" } } Not sure the notation when the …

---

## [Does Elasticsearch provide an equivalent of IN (SELECT...)?](https://discuss.elastic.co/t/does-elasticsearch-provide-an-equivalent-of-in-select/317910)

<div class="topic-metadata">

**Author:** [@Luis95](https://discuss.elastic.co/u/Luis95)\
**Replies:** 0\
**Last updated:** [November 1, 2022, 4:16pm UTC](https://discuss.elastic.co/t/does-elasticsearch-provide-an-equivalent-of-in-select/317910 "2022-11-01T16:16:17Z")

</div>

We are saving one item for each user, show, and episode. We save everything on the same index. The ERD would look something like this: ┌────┐ ┌────────────┐ ┌────┐ │User├─────\<┤Subscription├\>────┤Show│ └───…

---

## [How to use environment variable for logstash output elasticsearch plugin for multiple elasticsearch hosts?](https://discuss.elastic.co/t/how-to-use-environment-variable-for-logstash-output-elasticsearch-plugin-for-multiple-elasticsearch-hosts/317169)

<div class="topic-metadata">

**Author:** [@asp](https://discuss.elastic.co/u/asp)\
**Replies:** 4\
**Last updated:** [November 1, 2022, 3:07pm UTC](https://discuss.elastic.co/t/how-to-use-environment-variable-for-logstash-output-elasticsearch-plugin-for-multiple-elasticsearch-hosts/317169 "2022-11-01T15:07:54Z")

</div>

Hi, I am deploying logstash and its pipelines via ansible. I want to use the same pipeline on different installations. So I don't want to modify the elasticsearch output plugin in each pipeline. I want to use an environ…

---

## [Curling ElasticSearch API using logstash keystore credentials](https://discuss.elastic.co/t/curling-elasticsearch-api-using-logstash-keystore-credentials/317647)

<div class="topic-metadata">

**Author:** [@Broken08](https://discuss.elastic.co/u/Broken08)\
**Replies:** 2\
**Last updated:** [November 1, 2022, 12:49pm UTC](https://discuss.elastic.co/t/curling-elasticsearch-api-using-logstash-keystore-credentials/317647 "2022-11-01T12:49:16Z")

</div>

Is it possible to call Elasticsearch API requests with the Logstash Keystore credentials that are stored (If they obviously are the right username/password/etc...). I know API/curl calls can be done utilizing Username p…

---

## [Fleet Server Not healthy](https://discuss.elastic.co/t/fleet-server-not-healthy/317877)

<div class="topic-metadata">

**Author:** [@shuuny-matrix](https://discuss.elastic.co/u/shuuny-matrix)\
**Replies:** 1\
**Last updated:** [November 1, 2022, 11:40am UTC](https://discuss.elastic.co/t/fleet-server-not-healthy/317877 "2022-11-01T11:40:22Z")

</div>

Hi, I tried to update the fleet server from 8.3.2 to 8.3.3 and now my fleet server is unhealthy. I t was working fine before that but somewhere I messed up. I reinstalled elastic agent but to no avail. I am running elast…

---

## ['\[bool\] malformed query, expected \[END\_OBJECT\] but found \[FIELD\_NAME\]'](https://discuss.elastic.co/t/bool-malformed-query-expected-end-object-but-found-field-name/317862)

<div class="topic-metadata">

**Author:** [@Shobhit\_Jain1](https://discuss.elastic.co/u/Shobhit_Jain1)\
**Replies:** 1\
**Last updated:** [November 1, 2022, 11:26am UTC](https://discuss.elastic.co/t/bool-malformed-query-expected-end-object-but-found-field-name/317862 "2022-11-01T11:26:11Z")

</div>

I am running the following query in Elasticsearch and for some reason I am getting an error: elasticsearch.exceptions.RequestError: RequestError(400, 'x\_content\_parse\_exception', '\[bool\] malformed query, expected \[END\_O…

---

## [Centralized list of values for queries filter](https://discuss.elastic.co/t/centralized-list-of-values-for-queries-filter/317595)

<div class="topic-metadata">

**Author:** [@Volodymyr\_Komarynsky](https://discuss.elastic.co/u/Volodymyr_Komarynsky)\
**Replies:** 2\
**Last updated:** [November 1, 2022, 11:11am UTC](https://discuss.elastic.co/t/centralized-list-of-values-for-queries-filter/317595 "2022-11-01T11:11:47Z")

</div>

Hello. Can Elasticsearch use a value from an external list or other index to filter queries? This is necessary to store the same filtering values for different requests and not to make changes in each request.

---

## [Elastic search as statefulset in kubernetes cluster](https://discuss.elastic.co/t/elastic-search-as-statefulset-in-kubernetes-cluster/317882)

<div class="topic-metadata">

**Author:** [@gsingh20](https://discuss.elastic.co/u/gsingh20)\
**Replies:** 0\
**Last updated:** [November 1, 2022, 10:33am UTC](https://discuss.elastic.co/t/elastic-search-as-statefulset-in-kubernetes-cluster/317882 "2022-11-01T10:33:53Z")

</div>

how can we sync the data between 2 persistent volume when Elasticsearch is deployed as statefulset in kubernetes cluster. when we are scaling up pods then new pv is created and data is not sync. How can we sync the data…

---

## [Nested document full text query with filter capability](https://discuss.elastic.co/t/nested-document-full-text-query-with-filter-capability/317843)

<div class="topic-metadata">

**Author:** [@john2022](https://discuss.elastic.co/u/john2022)\
**Replies:** 1\
**Last updated:** [November 1, 2022, 10:22am UTC](https://discuss.elastic.co/t/nested-document-full-text-query-with-filter-capability/317843 "2022-11-01T10:22:16Z")

</div>

Hi dear My index mappings and sample data as follows I need full text search on these type of documents with following criteria: country is one input of this search If I search "Alex 4455" and country is "xxx"…

---

## [Should i use emit() when using runtime field](https://discuss.elastic.co/t/should-i-use-emit-when-using-runtime-field/317861)

<div class="topic-metadata">

**Author:** [@mikhatanu](https://discuss.elastic.co/u/mikhatanu)\
**Replies:** 1\
**Last updated:** [November 1, 2022, 9:42am UTC](https://discuss.elastic.co/t/should-i-use-emit-when-using-runtime-field/317861 "2022-11-01T09:42:00Z")

</div>

Hello, i'm trying to sum 2 fields in index template using runtime field. Currently, my script is like this: doc\['a'\].value + doc\['b'\].value. Do i need to emit like this: emit(doc\['a'\].value + doc\['b'\].value) so that the …

---

## [Synonym\_graph token filter and synonyms including comma's](https://discuss.elastic.co/t/synonym-graph-token-filter-and-synonyms-including-commas/316219)

<div class="topic-metadata">

**Author:** [@erikNL](https://discuss.elastic.co/u/erikNL)\
**Replies:** 5\
**Last updated:** [November 1, 2022, 8:52am UTC](https://discuss.elastic.co/t/synonym-graph-token-filter-and-synonyms-including-commas/316219 "2022-11-01T08:52:42Z")

</div>

I am trying to create a index that uses a synonym\_graph token filter to search for synonyms of chemical compound. For instance, when I search for "benzene", I also want to find sentences containing the following: "benz…

---

## [Elasticsearch service getting failed on Ubuntu 20.4](https://discuss.elastic.co/t/elasticsearch-service-getting-failed-on-ubuntu-20-4/317677)

<div class="topic-metadata">

**Author:** [@BJawaid](https://discuss.elastic.co/u/BJawaid)\
**Replies:** 37\
**Last updated:** [November 1, 2022, 7:07am UTC](https://discuss.elastic.co/t/elasticsearch-service-getting-failed-on-ubuntu-20-4/317677 "2022-11-01T07:07:59Z")

</div>

Hi, I have installed elasticsearch 7.1.0 on Ubuntu 20.4 with java-11-openjdk-amd64. Since I am not a developer hence I expect respect for this post. Elasticsearch service is getting started successfully whenever I run; …

---

## [Sort query in Java](https://discuss.elastic.co/t/sort-query-in-java/317864)

<div class="topic-metadata">

**Author:** [@Apurba](https://discuss.elastic.co/u/Apurba)\
**Replies:** 1\
**Last updated:** [November 1, 2022, 6:20am UTC](https://discuss.elastic.co/t/sort-query-in-java/317864 "2022-11-01T06:20:35Z")

</div>

How can I write the below sort query in java - "sort": \[ { "fieldName1": { "order": "desc" }, "fieldName2": { "order": "desc" } } \] I can do that if the query like - "sort": \[ { "…

---

## [When to use Coordinating only node](https://discuss.elastic.co/t/when-to-use-coordinating-only-node/317774)

<div class="topic-metadata">

**Author:** [@Balesh\_Kumar](https://discuss.elastic.co/u/Balesh_Kumar)\
**Replies:** 6\
**Last updated:** [November 1, 2022, 1:39am UTC](https://discuss.elastic.co/t/when-to-use-coordinating-only-node/317774 "2022-11-01T01:39:19Z")

</div>

Hi All, I have read this recommendation Coordinating only nodes can benefit large clusters by offloading the coordinating node role from data and master-eligible nodes.. What is considered a "large cluster"? Do you hav…

---

## [How to re-run cluster with different cluster uuid](https://discuss.elastic.co/t/how-to-re-run-cluster-with-different-cluster-uuid/317431)

<div class="topic-metadata">

**Author:** [@qksjdhi1212](https://discuss.elastic.co/u/qksjdhi1212)\
**Replies:** 3\
**Last updated:** [October 31, 2022, 11:57pm UTC](https://discuss.elastic.co/t/how-to-re-run-cluster-with-different-cluster-uuid/317431 "2022-10-31T23:57:57Z")

</div>

using version 8.4 When I ran es in single-node-cluster on ec2 instance I got this message Fully-formed clusters do not attempt to discover other nodes, and nodes with different cluster UUIDs cannot belong to the same c…

---

## [Reroute API](https://discuss.elastic.co/t/reroute-api/316832)

<div class="topic-metadata">

**Author:** [@wijamw](https://discuss.elastic.co/u/wijamw)\
**Replies:** 20\
**Last updated:** [October 31, 2022, 11:55pm UTC](https://discuss.elastic.co/t/reroute-api/316832 "2022-10-31T23:55:13Z")

</div>

I tried to move indices from one node to another using reroute API but I had the following error. type: illegal\_argument\_exception reason: "can't move from node-1 to node-2, , since its not allowed, reason: .. \[NO(the n…

---

## [Elastic/Kibana Maintenance](https://discuss.elastic.co/t/elastic-kibana-maintenance/317420)

<div class="topic-metadata">

**Author:** [@tifty](https://discuss.elastic.co/u/tifty)\
**Replies:** 6\
**Last updated:** [October 31, 2022, 11:38pm UTC](https://discuss.elastic.co/t/elastic-kibana-maintenance/317420 "2022-10-31T23:38:07Z")

</div>

Hi everyone, I was wondering what steps I should follow for production-grade Elasticsearch maintenance for on-premises deployment. Any resources/idea would be highly appreciated. TIA

---

## [Understanding Young vs Survivor vs Old in JVM Nodes Stats](https://discuss.elastic.co/t/understanding-young-vs-survivor-vs-old-in-jvm-nodes-stats/317844)

<div class="topic-metadata">

**Author:** [@nola](https://discuss.elastic.co/u/nola)\
**Replies:** 0\
**Last updated:** [October 31, 2022, 7:10pm UTC](https://discuss.elastic.co/t/understanding-young-vs-survivor-vs-old-in-jvm-nodes-stats/317844 "2022-10-31T19:10:10Z")

</div>

I have a basic understanding of young vs old, vs permanent in general context of the JVM heap. But I was told when I want to monitor JVM heap pressure and gc, I should run GET \_nodes/stats?filter\_path=nodes.\*.jvm.mem.p…

---

## [Help with conditionals in logstash](https://discuss.elastic.co/t/help-with-conditionals-in-logstash/317836)

<div class="topic-metadata">

**Author:** [@RaonyO](https://discuss.elastic.co/u/RaonyO)\
**Replies:** 2\
**Last updated:** [October 31, 2022, 5:31pm UTC](https://discuss.elastic.co/t/help-with-conditionals-in-logstash/317836 "2022-10-31T17:31:34Z")

</div>

hello, I'm trying to perform a filter with some conditions, but when performing as follows, it doesn't work. if "dns\_server\_process\_query\_send" or "Not authoritative" in \[message\] { drop {} } but if I use the followin…

---

## [Index boosting and how the exact matches can rank higher than fuzzy match and phrase match in the elastic search?](https://discuss.elastic.co/t/index-boosting-and-how-the-exact-matches-can-rank-higher-than-fuzzy-match-and-phrase-match-in-the-elastic-search/317835)

<div class="topic-metadata">

**Author:** [@paris1](https://discuss.elastic.co/u/paris1)\
**Replies:** 0\
**Last updated:** [October 31, 2022, 5:07pm UTC](https://discuss.elastic.co/t/index-boosting-and-how-the-exact-matches-can-rank-higher-than-fuzzy-match-and-phrase-match-in-the-elastic-search/317835 "2022-10-31T17:07:02Z")

</div>

0 I'm trying to configure Elasticsearch to give me both exact matches and fuzzy matches, and also phrase matches. I'm using Elasticsearch to search names of foods in a database, and I want it to be fuzzy to allow for mi…

---

## [Whitelist nested field](https://discuss.elastic.co/t/whitelist-nested-field/317773)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 5\
**Last updated:** [October 31, 2022, 4:53pm UTC](https://discuss.elastic.co/t/whitelist-nested-field/317773 "2022-10-31T16:53:07Z")

</div>

Hi everyone, i plan to whitelist some fields, but they are nested field. i already tried prune to whitelist them and it didn't work. for example: Request Body : {"tipe":"FF","nama":"ABC","nik":"","handphone":"00012","…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=506)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=508)
