# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=508

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 509

---

## [Parsed Multi Object in Json](https://discuss.elastic.co/t/parsed-multi-object-in-json/317705)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 7\
**Last updated:** [October 31, 2022, 4:42pm UTC](https://discuss.elastic.co/t/parsed-multi-object-in-json/317705 "2022-10-31T16:42:38Z")

</div>

Hi there, so i have a log look like this: 2022-10-27 08:39:02 \[https-jsse-nio-9078-exec-7\] INFO i.c.p.va.security.LoggerFilter - Response Body : {"responseCode":"00","responseDesc":"Approved","data":"{"vaNumber":"111…

---

## [Error uploading data from PostgresQL to Elasticsearch via logstash](https://discuss.elastic.co/t/error-uploading-data-from-postgresql-to-elasticsearch-via-logstash/317832)

<div class="topic-metadata">

**Author:** [@Evgen\_G](https://discuss.elastic.co/u/Evgen_G)\
**Replies:** 0\
**Last updated:** [October 31, 2022, 4:21pm UTC](https://discuss.elastic.co/t/error-uploading-data-from-postgresql-to-elasticsearch-via-logstash/317832 "2022-10-31T16:21:34Z")

</div>

Tell me, please, can anyone come across such a problem: when unloading data from the database in elasticsearch, an error occurs \[ERROR\] 2022-10-31 16:02:14.628 \[\[main\]\>worker1\] elasticsearch - Encountered a retryable er…

---

## [Concatenation of two fields](https://discuss.elastic.co/t/concatenation-of-two-fields/317691)

<div class="topic-metadata">

**Author:** [@prashantreddy](https://discuss.elastic.co/u/prashantreddy)\
**Replies:** 2\
**Last updated:** [October 31, 2022, 3:20pm UTC](https://discuss.elastic.co/t/concatenation-of-two-fields/317691 "2022-10-31T15:20:16Z")

</div>

Hello, I want to concatenate/combine/merge two or three fields and assign this combined value to new field (mapping created for new field) after indexing. could you please suggest how to do this? Thanks!

---

## [Set role for cluster-member node](https://discuss.elastic.co/t/set-role-for-cluster-member-node/317785)

<div class="topic-metadata">

**Author:** [@g.le](https://discuss.elastic.co/u/g.le)\
**Replies:** 3\
**Last updated:** [October 31, 2022, 8:50am UTC](https://discuss.elastic.co/t/set-role-for-cluster-member-node/317785 "2022-10-31T08:50:43Z")

</div>

We 've been using ELK v7.10 in a cluster setup with several nodes. For the time being, all nodes have the same roles. According to the documentation, we could specify that a given node (member of the cluster) can have …

---

## [How to grok a certain fields from a log file](https://discuss.elastic.co/t/how-to-grok-a-certain-fields-from-a-log-file/315996)

<div class="topic-metadata">

**Author:** [@anupvtr](https://discuss.elastic.co/u/anupvtr)\
**Replies:** 1\
**Last updated:** [October 31, 2022, 6:43am UTC](https://discuss.elastic.co/t/how-to-grok-a-certain-fields-from-a-log-file/315996 "2022-10-31T06:43:42Z")

</div>

Preformatted textHi All, I am quite new to the magic world of Grok. Any help will be thankful. I need to apply filter for the following file. 2022-08-22 22:18:59 , 666 INFO @ (blockurcolumn-11) \[rbbit\_MQ\_Versa.appa…

---

## [Fresh ELK install 8.4.3. Logstash problem](https://discuss.elastic.co/t/fresh-elk-install-8-4-3-logstash-problem/317670)

<div class="topic-metadata">

**Author:** [@Xgraver1](https://discuss.elastic.co/u/Xgraver1)\
**Replies:** 2\
**Last updated:** [October 31, 2022, 6:06am UTC](https://discuss.elastic.co/t/fresh-elk-install-8-4-3-logstash-problem/317670 "2022-10-31T06:06:50Z")

</div>

Hello Could use some help with fresh ELK installation on premises. I installed Elasticstack and Kibana with mostly default configuration. In Elasticstack conf i changed Data path and uncommented host and port settings. …

---

## [While ingesting a log file from source system to Kibana through Filebeat, getting "End Of File reached" message in Filebeat logs](https://discuss.elastic.co/t/while-ingesting-a-log-file-from-source-system-to-kibana-through-filebeat-getting-end-of-file-reached-message-in-filebeat-logs/317777)

<div class="topic-metadata">

**Author:** [@cadrija](https://discuss.elastic.co/u/cadrija)\
**Replies:** 0\
**Last updated:** [October 31, 2022, 5:55am UTC](https://discuss.elastic.co/t/while-ingesting-a-log-file-from-source-system-to-kibana-through-filebeat-getting-end-of-file-reached-message-in-filebeat-logs/317777 "2022-10-31T05:55:37Z")

</div>

Hi experts! I am new to elastic. I have installed ELK (8.4) on a Ubuntu system (suppose u.u.u.u). Now I am trying to fetch/ingest a log file from a windows system (suppose w.w.w.w). Steps I followed leaning from tutori…

---

## [Pagination, sorted and aggregation on data](https://discuss.elastic.co/t/pagination-sorted-and-aggregation-on-data/317291)

<div class="topic-metadata">

**Author:** [@StephenGuo](https://discuss.elastic.co/u/StephenGuo)\
**Replies:** 4\
**Last updated:** [October 31, 2022, 2:54am UTC](https://discuss.elastic.co/t/pagination-sorted-and-aggregation-on-data/317291 "2022-10-31T02:54:53Z")

</div>

Hi I have a group of user access data which contain the user name, access timestamp, and some of other info. There will be multiple records with the same username but different access timestamp. What I want is to do i…

---

## [ElasticSearch Failed to build \[request\] after last required field arrived](https://discuss.elastic.co/t/elasticsearch-failed-to-build-request-after-last-required-field-arrived/317364)

<div class="topic-metadata">

**Author:** [@akshay-atam](https://discuss.elastic.co/u/akshay-atam)\
**Replies:** 1\
**Last updated:** [October 31, 2022, 2:25am UTC](https://discuss.elastic.co/t/elasticsearch-failed-to-build-request-after-last-required-field-arrived/317364 "2022-10-31T02:25:33Z")

</div>

---

## [Elastic Agent Might Not Be Running](https://discuss.elastic.co/t/elastic-agent-might-not-be-running/317535)

<div class="topic-metadata">

**Author:** [@bigverm23](https://discuss.elastic.co/u/bigverm23)\
**Replies:** 1\
**Last updated:** [October 31, 2022, 2:21am UTC](https://discuss.elastic.co/t/elastic-agent-might-not-be-running/317535 "2022-10-31T02:21:45Z")

</div>

{"log.level":"info","@timestamp":"2022-10-26T10:03:34.190-0400","log.origin":{"file.name":"cmd/enroll\_cmd.go","file.line":271},"message":"Elastic Agent might not be running; unable to trigger restart","ecs.version":"1.6.…

---

## [Error: Could not create the Java Virtual Machine. ES won't start](https://discuss.elastic.co/t/error-could-not-create-the-java-virtual-machine-es-wont-start/317581)

<div class="topic-metadata">

**Author:** [@rrrrrrrrrrr](https://discuss.elastic.co/u/rrrrrrrrrrr)\
**Replies:** 2\
**Last updated:** [October 31, 2022, 2:20am UTC](https://discuss.elastic.co/t/error-could-not-create-the-java-virtual-machine-es-wont-start/317581 "2022-10-31T02:20:44Z")

</div>

Hello, I've tried to follow this step https://discuss.elastic.co/t/elasticsearch-logs-are-getting-piled-up-in-var-log-elasticsearch-path-how-to-cater-to-this-problem/186039 to do the log rotation but when I tried to res…

---

## [Accidental force merge](https://discuss.elastic.co/t/accidental-force-merge/317539)

<div class="topic-metadata">

**Author:** [@h0llym0lly](https://discuss.elastic.co/u/h0llym0lly)\
**Replies:** 1\
**Last updated:** [October 31, 2022, 2:17am UTC](https://discuss.elastic.co/t/accidental-force-merge/317539 "2022-10-31T02:17:08Z")

</div>

Hi, I executed force merge and forgot to add index name which I want to merge... Now the task is ongoing for some time and it has description: "Force-merge indices \[\], maxSegments\[4\], onlyExpungeDeletes\[false\], flush…

---

## [Indices deleted as a result of unauthorised access – how to restore?](https://discuss.elastic.co/t/indices-deleted-as-a-result-of-unauthorised-access-how-to-restore/317637)

<div class="topic-metadata">

**Author:** [@Drept](https://discuss.elastic.co/u/Drept)\
**Replies:** 2\
**Last updated:** [October 31, 2022, 1:41am UTC](https://discuss.elastic.co/t/indices-deleted-as-a-result-of-unauthorised-access-how-to-restore/317637 "2022-10-31T01:41:23Z")

</div>

As a result of compromised security, my ES server was accessed by a third party that deleted all the indices. While I can easily recreate and repopulate my own indices, there are a few that I don't know how to deal with.…

---

## [How to visualize process RAM consumption](https://discuss.elastic.co/t/how-to-visualize-process-ram-consumption/317667)

<div class="topic-metadata">

**Author:** [@augandi](https://discuss.elastic.co/u/augandi)\
**Replies:** 0\
**Last updated:** [October 28, 2022, 8:29am UTC](https://discuss.elastic.co/t/how-to-visualize-process-ram-consumption/317667 "2022-10-28T08:29:35Z")

</div>

Hi, I hope someone can help :slight\_smile: We have an use case to visualize the process RAM consumption in relation to the overall consumption. In Obeservability I can search for hosts and process.name. Example: The ov…

---

## [Can i use "date type field" more than two?](https://discuss.elastic.co/t/can-i-use-date-type-field-more-than-two/317671)

<div class="topic-metadata">

**Author:** [@hellocomputer](https://discuss.elastic.co/u/hellocomputer)\
**Replies:** 1\
**Last updated:** [October 31, 2022, 1:40am UTC](https://discuss.elastic.co/t/can-i-use-date-type-field-more-than-two/317671 "2022-10-31T01:40:11Z")

</div>

Hello I want to use a field called "timestamp" as time series data. I'm using monstache to connect mongoDB and Elasticsearch. In mostache mapping file, I set type of timestamp to "date". But, in elastic index, type of…

---

## [What's the solution of this error please?](https://discuss.elastic.co/t/whats-the-solution-of-this-error-please/317485)

<div class="topic-metadata">

**Author:** [@morad\_della3](https://discuss.elastic.co/u/morad_della3)\
**Replies:** 12\
**Last updated:** [October 30, 2022, 8:59pm UTC](https://discuss.elastic.co/t/whats-the-solution-of-this-error-please/317485 "2022-10-30T20:59:42Z")

</div>

I don't find a solution for this error anyone help me please when I try to start elasticsearch. \[ 2022-10-26T08:13:00,690\]\[WARN \]\[i.n.u.i.PlatformDependent\] \[elastic\] Failed to get the temporary directory; falling back…

---

## [Why did Elastic release Elasticsearch Java API Client to replace the old High Level Client?](https://discuss.elastic.co/t/why-did-elastic-release-elasticsearch-java-api-client-to-replace-the-old-high-level-client/317749)

<div class="topic-metadata">

**Author:** [@Michael\_Gattinger](https://discuss.elastic.co/u/Michael_Gattinger)\
**Replies:** 2\
**Last updated:** [October 30, 2022, 5:59pm UTC](https://discuss.elastic.co/t/why-did-elastic-release-elasticsearch-java-api-client-to-replace-the-old-high-level-client/317749 "2022-10-30T17:59:49Z")

</div>

Did Elastic release the ESJAC to replace the old High Level Client because of the dispute with amazon about the Amazon Elasticsearch Service to make Elasticsearch in any matter incompatible with AES? Thanks - Enomine

---

## [Performance problem with custom sort](https://discuss.elastic.co/t/performance-problem-with-custom-sort/317435)

<div class="topic-metadata">

**Author:** [@Guilherme\_Mello](https://discuss.elastic.co/u/Guilherme_Mello)\
**Replies:** 5\
**Last updated:** [October 30, 2022, 2:51pm UTC](https://discuss.elastic.co/t/performance-problem-with-custom-sort/317435 "2022-10-30T14:51:57Z")

</div>

Hello! My search page needs to have a custom sorting type. To do this sorting i need to return about 5k items from elasticsearch The problem is that this causes a serious performance problem, the application ends up c…

---

## [New indices on elastic.com](https://discuss.elastic.co/t/new-indices-on-elastic-com/317711)

<div class="topic-metadata">

**Author:** [@sportys](https://discuss.elastic.co/u/sportys)\
**Replies:** 4\
**Last updated:** [October 30, 2022, 2:32pm UTC](https://discuss.elastic.co/t/new-indices-on-elastic-com/317711 "2022-10-30T14:32:22Z")

</div>

Hello, I set up a new indices on elastic.co, I'm just trying it out, I only see connectivity through port 443 with a api key. I'm using java and spring and usually connect via port 9300. So I'm having a hard time trans…

---

## [Grokparse failure seen with tcp input plugin in logstash pipeline](https://discuss.elastic.co/t/grokparse-failure-seen-with-tcp-input-plugin-in-logstash-pipeline/317447)

<div class="topic-metadata">

**Author:** [@Arinjay\_Jain](https://discuss.elastic.co/u/Arinjay_Jain)\
**Replies:** 5\
**Last updated:** [October 30, 2022, 11:52am UTC](https://discuss.elastic.co/t/grokparse-failure-seen-with-tcp-input-plugin-in-logstash-pipeline/317447 "2022-10-30T11:52:14Z")

</div>

Hi, I have the following logstash pipeline configuration. input { tcp { port =\> 5102 codec =\> plain } } filter { grok { match =\> {"message" =\> "%{SYSLOGTIMESTAMP:time} %{DATA:trace\_n…

---

## [Index rollover not working](https://discuss.elastic.co/t/index-rollover-not-working/317750)

<div class="topic-metadata">

**Author:** [@Eran\_Hadad](https://discuss.elastic.co/u/Eran_Hadad)\
**Replies:** 2\
**Last updated:** [October 30, 2022, 11:08am UTC](https://discuss.elastic.co/t/index-rollover-not-working/317750 "2022-10-30T11:08:37Z")

</div>

I have an index, let's call it index-name-000001, current size 30gb. Aliases index-name Current action rollover under phase definition: "actions": { "rollover": { "max\_primary\_shard\_size": "20gb" …

---

## [Output Batch Sizes](https://discuss.elastic.co/t/output-batch-sizes/317486)

<div class="topic-metadata">

**Author:** [@dawiro](https://discuss.elastic.co/u/dawiro)\
**Replies:** 3\
**Last updated:** [October 30, 2022, 9:39am UTC](https://discuss.elastic.co/t/output-batch-sizes/317486 "2022-10-30T09:39:55Z")

</div>

Hi, How can we see the size of the batches logstash is pushing to elasticsearch? Thx D

---

## [Phrase search with fuzziness](https://discuss.elastic.co/t/phrase-search-with-fuzziness/317725)

<div class="topic-metadata">

**Author:** [@Davood1659](https://discuss.elastic.co/u/Davood1659)\
**Replies:** 0\
**Last updated:** [October 29, 2022, 12:24pm UTC](https://discuss.elastic.co/t/phrase-search-with-fuzziness/317725 "2022-10-29T12:24:34Z")

</div>

Hi all, A while ago, I needed to find documents that a certain term(word) is repeated twice or more in a certain field of those documents. Some queries like Match query doesn't work in such situations as they just check…

---

## [How to disable score calculation to improve performance (fuzzy queries)](https://discuss.elastic.co/t/how-to-disable-score-calculation-to-improve-performance-fuzzy-queries/317729)

<div class="topic-metadata">

**Author:** [@Giorgos\_Katiforis](https://discuss.elastic.co/u/Giorgos_Katiforis)\
**Replies:** 0\
**Last updated:** [October 29, 2022, 1:20pm UTC](https://discuss.elastic.co/t/how-to-disable-score-calculation-to-improve-performance-fuzzy-queries/317729 "2022-10-29T13:20:50Z")

</div>

Hello, I would like to know if there is a way to disable the score calculation in Elasticsearch. I am running match queries with fuzziness 2 and I have noticed (using profile )it consumes a lot of time in build\_scorer. …

---

## [Does forcing/manually setting the id of the document makes the shards unevenly distributed?](https://discuss.elastic.co/t/does-forcing-manually-setting-the-id-of-the-document-makes-the-shards-unevenly-distributed/317372)

<div class="topic-metadata">

**Author:** [@Java2avaj](https://discuss.elastic.co/u/Java2avaj)\
**Replies:** 7\
**Last updated:** [October 29, 2022, 5:32am UTC](https://discuss.elastic.co/t/does-forcing-manually-setting-the-id-of-the-document-makes-the-shards-unevenly-distributed/317372 "2022-10-29T05:32:29Z")

</div>

Does forcing/manually setting the id of the document makes the shards unevenly distributed? Currently, we are forcing the values of id when storing documents in the index. Is this a bad practice? Does it make the shar…

---

## [Multi\_match phrase\_prefix is giving different results for Elastic versions 6.6 and 8.4](https://discuss.elastic.co/t/multi-match-phrase-prefix-is-giving-different-results-for-elastic-versions-6-6-and-8-4/315979)

<div class="topic-metadata">

**Author:** [@Hariprasad4118](https://discuss.elastic.co/u/Hariprasad4118)\
**Replies:** 1\
**Last updated:** [October 29, 2022, 5:03am UTC](https://discuss.elastic.co/t/multi-match-phrase-prefix-is-giving-different-results-for-elastic-versions-6-6-and-8-4/315979 "2022-10-29T05:03:04Z")

</div>

Team, Please help me, I am using same max expansion and same ES Query on Elastic versions 6.6 and 8.4, with same set of data. but giving different results. so, can some one clearly confirms what is the major differenc…

---

## [Metric aggregation on composite buckets not working with nested fields](https://discuss.elastic.co/t/metric-aggregation-on-composite-buckets-not-working-with-nested-fields/317712)

<div class="topic-metadata">

**Author:** [@Ahmed\_Syed](https://discuss.elastic.co/u/Ahmed_Syed)\
**Replies:** 0\
**Last updated:** [October 28, 2022, 8:30pm UTC](https://discuss.elastic.co/t/metric-aggregation-on-composite-buckets-not-working-with-nested-fields/317712 "2022-10-28T20:30:02Z")

</div>

I am able to create buckets from different sources (one of them being a nested field) successfully. However when I do a metric aggregation, the metric aggregation is not applied on the composite bucket. For example: I c…

---

## [Ignore\_case doesn't work for elastic search stop token filter](https://discuss.elastic.co/t/ignore-case-doesnt-work-for-elastic-search-stop-token-filter/317706)

<div class="topic-metadata">

**Author:** [@taugusti](https://discuss.elastic.co/u/taugusti)\
**Replies:** 0\
**Last updated:** [October 28, 2022, 6:23pm UTC](https://discuss.elastic.co/t/ignore-case-doesnt-work-for-elastic-search-stop-token-filter/317706 "2022-10-28T18:23:22Z")

</div>

Trying to follow the example from the URL below to ignore case for stop words. However it doesn't seem to stop case insensitive stop words. for eg it stop "the", but not "The" PUT /my-index-000001 { "settings": { …

---

## [Elastic Search Query performance when source is disabled](https://discuss.elastic.co/t/elastic-search-query-performance-when-source-is-disabled/317348)

<div class="topic-metadata">

**Author:** [@prateek\_shekhar](https://discuss.elastic.co/u/prateek_shekhar)\
**Replies:** 11\
**Last updated:** [October 28, 2022, 6:14pm UTC](https://discuss.elastic.co/t/elastic-search-query-performance-when-source-is-disabled/317348 "2022-10-28T18:14:40Z")

</div>

Hi Everyone, we have an Elasticsearch index with 100 million documents (with replicas it's about 400 million). The index contains nested documents as well. We have a use case where we have to boost the score of the docu…

---

## [Elastic Agent vs Logstash/Elasticsearch output](https://discuss.elastic.co/t/elastic-agent-vs-logstash-elasticsearch-output/316345)

<div class="topic-metadata">

**Author:** [@djkprojects](https://discuss.elastic.co/u/djkprojects)\
**Replies:** 1\
**Last updated:** [October 28, 2022, 3:46pm UTC](https://discuss.elastic.co/t/elastic-agent-vs-logstash-elasticsearch-output/316345 "2022-10-28T15:46:46Z")

</div>

Hello, We are thinking of replacing Beats with Elastic Agent and would like to send metrics to Elasticsearch directly and custom logs via Logstash. Is this even possible with Elastic Agent? Looking at Fleet settings the…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=507)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=509)
