# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=526

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 527

---

## [Parent/Child vs Nested. The real Performance difference](https://discuss.elastic.co/t/parent-child-vs-nested-the-real-performance-difference/315698)

<div class="topic-metadata">

**Author:** [@amirm](https://discuss.elastic.co/u/amirm)\
**Replies:** 0\
**Last updated:** [October 3, 2022, 3:11pm UTC](https://discuss.elastic.co/t/parent-child-vs-nested-the-real-performance-difference/315698 "2022-10-03T15:11:01Z")

</div>

Greeting. We all know that Elasticsearch is basically a NoSQL database. it means there is no relation between data and documents that need to be denormalized and flattened to index properly. In spite of all these thing…

---

## [Question regarding index stats - warmer](https://discuss.elastic.co/t/question-regarding-index-stats-warmer/315696)

<div class="topic-metadata">

**Author:** [@robbe482](https://discuss.elastic.co/u/robbe482)\
**Replies:** 0\
**Last updated:** [October 3, 2022, 3:03pm UTC](https://discuss.elastic.co/t/question-regarding-index-stats-warmer/315696 "2022-10-03T15:03:20Z")

</div>

Hello, we are running Elasticsearch 6.8.23. For one of our indices we are having performance problems. When checking the stats on that index one thing stands out, very high total\_time under the warmer section. Reading …

---

## [Crash of ECK Operator after disabling TLS on elastic agent in fleet mode](https://discuss.elastic.co/t/crash-of-eck-operator-after-disabling-tls-on-elastic-agent-in-fleet-mode/315679)

<div class="topic-metadata">

**Author:** [@p0sql](https://discuss.elastic.co/u/p0sql)\
**Replies:** 1\
**Last updated:** [October 3, 2022, 2:04pm UTC](https://discuss.elastic.co/t/crash-of-eck-operator-after-disabling-tls-on-elastic-agent-in-fleet-mode/315679 "2022-10-03T14:04:52Z")

</div>

Disable TLS on Fleet Server agent leads to panic runtime error (invalid memory address or nil pointer dereference) for the ECK Operator. I can't deploy anything after this crash until I delete the configuration. Moreove…

---

## [How to suggest queries to user](https://discuss.elastic.co/t/how-to-suggest-queries-to-user/315685)

<div class="topic-metadata">

**Author:** [@Guilherme\_Mello](https://discuss.elastic.co/u/Guilherme_Mello)\
**Replies:** 0\
**Last updated:** [October 3, 2022, 12:27pm UTC](https://discuss.elastic.co/t/how-to-suggest-queries-to-user/315685 "2022-10-03T12:27:16Z")

</div>

Hi, is there a way to suggest queries to the user based on terms? This feature is common in searches to suggest other queries to the user. I saw that there is appsearch, is that the only way to make it work?

---

## [Runtime field script String to Integer](https://discuss.elastic.co/t/runtime-field-script-string-to-integer/315678)

<div class="topic-metadata">

**Author:** [@kibanauser4](https://discuss.elastic.co/u/kibanauser4)\
**Replies:** 1\
**Last updated:** [October 3, 2022, 12:21pm UTC](https://discuss.elastic.co/t/runtime-field-script-string-to-integer/315678 "2022-10-03T12:21:15Z")

</div>

Hi. I want to create a runtime field using this script: if (doc.containsKey('price') ) { return Integer.parseInt(doc\['price.keyword'\].value) } but I'm getting this error: Cannot cast from \[int\] to \[void\]. What does i…

---

## [Palo-alto парсер логов](https://discuss.elastic.co/t/palo-alto/315684)

<div class="topic-metadata">

**Author:** [@beater228](https://discuss.elastic.co/u/beater228)\
**Replies:** 0\
**Last updated:** [October 3, 2022, 12:09pm UTC](https://discuss.elastic.co/t/palo-alto/315684 "2022-10-03T12:09:12Z")

</div>

Здравствуйте, я новичок, и не так хорошо ориентируюсь на сайте, потому прошу не судите строго. Ситуация следующая: Отправляю syslog с Paloalto в logstash, логи приходят но не обрабатываются, нашел пару вариантов парсер…

---

## [Kibana rollup / aggregation not working](https://discuss.elastic.co/t/kibana-rollup-aggregation-not-working/315663)

<div class="topic-metadata">

**Author:** [@thirty2](https://discuss.elastic.co/u/thirty2)\
**Replies:** 1\
**Last updated:** [October 3, 2022, 9:31am UTC](https://discuss.elastic.co/t/kibana-rollup-aggregation-not-working/315663 "2022-10-03T09:31:46Z")

</div>

Hi, does anyone use Rollup? When you are using AVG metric, is it working for you? On my side it is not as originally described in this post by me. Insted of AVG values i am getting MAX. I can't belive the problem is …

---

## [Endpoint security configuration](https://discuss.elastic.co/t/endpoint-security-configuration/315486)

<div class="topic-metadata">

**Author:** [@ttyser](https://discuss.elastic.co/u/ttyser)\
**Replies:** 7\
**Last updated:** [October 3, 2022, 9:13am UTC](https://discuss.elastic.co/t/endpoint-security-configuration/315486 "2022-10-03T09:13:38Z")

</div>

Hello all, I have an agent deployed via fleet on red hat server and I want to use the endpoint security there. I did add the endpoint security integration under the policy the red hat agent is bound to. Now it seems like…

---

## [How to read logs contineously from azure evnet hub](https://discuss.elastic.co/t/how-to-read-logs-contineously-from-azure-evnet-hub/315660)

<div class="topic-metadata">

**Author:** [@Anusha\_Kusanghi](https://discuss.elastic.co/u/Anusha_Kusanghi)\
**Replies:** 0\
**Last updated:** [October 3, 2022, 7:27am UTC](https://discuss.elastic.co/t/how-to-read-logs-contineously-from-azure-evnet-hub/315660 "2022-10-03T07:27:40Z")

</div>

Hie Everyone, I have an integration where I have to read logs that are generated/store in azure event hub. Will the below configuration will read logs as an when new log is generated in the hub ? If now what I'm loo…

---

## [Elastic cluster issue!](https://discuss.elastic.co/t/elastic-cluster-issue/314953)

<div class="topic-metadata">

**Author:** [@Shubham\_Singh](https://discuss.elastic.co/u/Shubham_Singh)\
**Replies:** 19\
**Last updated:** [October 2, 2022, 5:38pm UTC](https://discuss.elastic.co/t/elastic-cluster-issue/314953 "2022-10-02T17:38:41Z")

</div>

We are seeing CPU spikes for our Elastic cluster and in logs we see this error continuously. We also get a circuit breaker exception in kibana when CPU spikes up. What could be wrong with our cluster \[2022-09-22T13:40:3…

---

## [\_delete\_by\_query documentation suggestion](https://discuss.elastic.co/t/delete-by-query-documentation-suggestion/315642)

<div class="topic-metadata">

**Author:** [@MarcBT](https://discuss.elastic.co/u/MarcBT)\
**Replies:** 1\
**Last updated:** [October 3, 2022, 5:40am UTC](https://discuss.elastic.co/t/delete-by-query-documentation-suggestion/315642 "2022-10-03T05:40:48Z")

</div>

IMO, the \_delete\_by\_query page should mention that if an index is moved out of 'hot' phase by ILM, the delete will fail with "FORBIDDEN/8/index write (api)".

---

## [Custom Similarity for Percolate Query](https://discuss.elastic.co/t/custom-similarity-for-percolate-query/315654)

<div class="topic-metadata">

**Author:** [@aneeshkoya](https://discuss.elastic.co/u/aneeshkoya)\
**Replies:** 0\
**Last updated:** [October 3, 2022, 5:37am UTC](https://discuss.elastic.co/t/custom-similarity-for-percolate-query/315654 "2022-10-03T05:37:12Z")

</div>

I created a percolation index with a custom similarity in its settings and a mapping to use this custom similarity: { "my-index": { "settings": { "index": { "similarity": { "idfless": { …

---

## [Saved Objects / API](https://discuss.elastic.co/t/saved-objects-api/315639)

<div class="topic-metadata">

**Author:** [@cyberzlo](https://discuss.elastic.co/u/cyberzlo)\
**Replies:** 1\
**Last updated:** [October 2, 2022, 11:32pm UTC](https://discuss.elastic.co/t/saved-objects-api/315639 "2022-10-02T23:32:37Z")

</div>

Hi, is this possible to perform Kibana " Saved Objects" (export all objects) via curl etc? It whould be great for backup purposes.

---

## [What's the cause of this problem and what's the solution?](https://discuss.elastic.co/t/whats-the-cause-of-this-problem-and-whats-the-solution/315641)

<div class="topic-metadata">

**Author:** [@morad\_della3](https://discuss.elastic.co/u/morad_della3)\
**Replies:** 0\
**Last updated:** [October 2, 2022, 8:59pm UTC](https://discuss.elastic.co/t/whats-the-cause-of-this-problem-and-whats-the-solution/315641 "2022-10-02T20:59:57Z")

</div>

i installed elastic and kibana 8.4.1 in ubuntu 22.04 and when i try to do sudo apt update or sudo apt install unzip i get this error E: Conflicting values set for option Signed-By regarding source https://artif…

---

## [Problems with installing/starting current Elasticsearch on ubuntu](https://discuss.elastic.co/t/problems-with-installing-starting-current-elasticsearch-on-ubuntu/315632)

<div class="topic-metadata">

**Author:** [@besucher80](https://discuss.elastic.co/u/besucher80)\
**Replies:** 3\
**Last updated:** [October 2, 2022, 3:22pm UTC](https://discuss.elastic.co/t/problems-with-installing-starting-current-elasticsearch-on-ubuntu/315632 "2022-10-02T15:22:10Z")

</div>

hi, i have installed elasticsearch like here: https://www.elastic.co/guide/en/elasticsearch/reference/current/deb.html Now i want to start it with: sudo systemctl start elasticsearch.service But this always fail. In t…

---

## [How match indexof in query?](https://discuss.elastic.co/t/how-match-indexof-in-query/315615)

<div class="topic-metadata">

**Author:** [@Nikolas1306](https://discuss.elastic.co/u/Nikolas1306)\
**Replies:** 1\
**Last updated:** [October 2, 2022, 12:20pm UTC](https://discuss.elastic.co/t/how-match-indexof-in-query/315615 "2022-10-02T12:20:30Z")

</div>

i've used this GET /myindex/\_search { "query": { "match\_phrase\_prefix": { "message": "my text\*" } } } but not have results i' ve always #! Elasticsearch built-in security features are not enabled. …

---

## [Pushing data through python to elastic search](https://discuss.elastic.co/t/pushing-data-through-python-to-elastic-search/315489)

<div class="topic-metadata">

**Author:** [@Shashank02](https://discuss.elastic.co/u/Shashank02)\
**Replies:** 6\
**Last updated:** [October 2, 2022, 3:06am UTC](https://discuss.elastic.co/t/pushing-data-through-python-to-elastic-search/315489 "2022-10-02T03:06:33Z")

</div>

I'm trying to push some data that I've collected through Python into Elasticsearch but it's showing this error:- "ValueError: Can't specify the options 'http\_auth' via a dictionary in 'hosts', only 'host', 'path\_prefix',…

---

## [How to connect Google Colab to Elasticsearch](https://discuss.elastic.co/t/how-to-connect-google-colab-to-elasticsearch/315618)

<div class="topic-metadata">

**Author:** [@shivang.ahd](https://discuss.elastic.co/u/shivang.ahd)\
**Replies:** 2\
**Last updated:** [October 1, 2022, 6:21pm UTC](https://discuss.elastic.co/t/how-to-connect-google-colab-to-elasticsearch/315618 "2022-10-01T18:21:29Z")

</div>

Hi, How to connect Google Colab to Elasticsearch. I have followed few ways, but getting error for all the ways. One of the code is as below:- !pip install Elasticsearch -q # download elasticsearch !wget https://arti…

---

## [Can Replica shards be used for Disaster Recovery](https://discuss.elastic.co/t/can-replica-shards-be-used-for-disaster-recovery/315620)

<div class="topic-metadata">

**Author:** [@hiruni.insyncit.net](https://discuss.elastic.co/u/hiruni.insyncit.net)\
**Replies:** 1\
**Last updated:** [October 1, 2022, 3:14pm UTC](https://discuss.elastic.co/t/can-replica-shards-be-used-for-disaster-recovery/315620 "2022-10-01T15:14:48Z")

</div>

Hi, We don't have backup in our cluster. Can we you replicas for disaster recovery purpose..? Elasticsearch version: 8.12 Thank you...!

---

## [Additional java process in ES8.4](https://discuss.elastic.co/t/additional-java-process-in-es8-4/315619)

<div class="topic-metadata">

**Author:** [@frankshad](https://discuss.elastic.co/u/frankshad)\
**Replies:** 0\
**Last updated:** [October 1, 2022, 2:25pm UTC](https://discuss.elastic.co/t/additional-java-process-in-es8-4/315619 "2022-10-01T14:25:41Z")

</div>

I'm trying a fresh install of ES8.4 on Debian 11, starting using systemctl start elasticsearch. I notice that there are now two Java processes permanently running, where on all previous versions I have used (up to 8.2) t…

---

## [Filtered Log messages show up as empty fields in Kibana](https://discuss.elastic.co/t/filtered-log-messages-show-up-as-empty-fields-in-kibana/315399)

<div class="topic-metadata">

**Author:** [@Chma](https://discuss.elastic.co/u/Chma)\
**Replies:** 1\
**Last updated:** [October 1, 2022, 2:02am UTC](https://discuss.elastic.co/t/filtered-log-messages-show-up-as-empty-fields-in-kibana/315399 "2022-10-01T02:02:28Z")

</div>

I have filtered my log message using grok. But when I check Kibana, I find the new fields on the left side of the page, but they are empty. I am also getting the \_grokparsefailure tag. Here's an example of my log messag…

---

## [Unable to deploy elastic/eck-operator on RedHat OpenShift 4.11](https://discuss.elastic.co/t/unable-to-deploy-elastic-eck-operator-on-redhat-openshift-4-11/314534)

<div class="topic-metadata">

**Author:** [@Uzi\_Cohen](https://discuss.elastic.co/u/Uzi_Cohen)\
**Replies:** 1\
**Last updated:** [September 30, 2022, 5:31pm UTC](https://discuss.elastic.co/t/unable-to-deploy-elastic-eck-operator-on-redhat-openshift-4-11/314534 "2022-09-30T17:31:35Z")

</div>

When deploying elastic/eck-operator helm chart on OpenShift 4.11, deployment fails, getting: msg="runc create failed: unable to start container process: exec: "./elastic-operator": stat ./elastic-operator: permission de…

---

## [Elastic agent install failing](https://discuss.elastic.co/t/elastic-agent-install-failing/315501)

<div class="topic-metadata">

**Author:** [@Cyrax002](https://discuss.elastic.co/u/Cyrax002)\
**Replies:** 1\
**Last updated:** [September 30, 2022, 5:10pm UTC](https://discuss.elastic.co/t/elastic-agent-install-failing/315501 "2022-09-30T17:10:46Z")

</div>

When installing elastic agent on one host I am receiving the following error message: panic: EvalSymlinks: too many links goroutine 1 \[running\]: github.com/elastic/elastic-agent/internal/pkg/agent/application/paths.ret…

---

## [How create 2 different indexs with same file source?](https://discuss.elastic.co/t/how-create-2-different-indexs-with-same-file-source/315594)

<div class="topic-metadata">

**Author:** [@Nikolas1306](https://discuss.elastic.co/u/Nikolas1306)\
**Replies:** 3\
**Last updated:** [September 30, 2022, 5:07pm UTC](https://discuss.elastic.co/t/how-create-2-different-indexs-with-same-file-source/315594 "2022-09-30T17:07:56Z")

</div>

this is my conf file and it's ok i've created an index with only errors match but now it's possible create a second indexs with file warning or custom? code =\> "event.cancel if not event.get('message').include? 'WARN' …

---

## [Watcher, how to create and compare arrays](https://discuss.elastic.co/t/watcher-how-to-create-and-compare-arrays/315597)

<div class="topic-metadata">

**Author:** [@sguerrero](https://discuss.elastic.co/u/sguerrero)\
**Replies:** 0\
**Last updated:** [September 30, 2022, 4:46pm UTC](https://discuss.elastic.co/t/watcher-how-to-create-and-compare-arrays/315597 "2022-09-30T16:46:14Z")

</div>

Hi. We're trying to perform an alarm with a watcher alarm but we don't know how. We have two different indices, index-1 and index-2, we need to search all events of index-1 and find all unique values of a field called f…

---

## [Custom Term Vectors](https://discuss.elastic.co/t/custom-term-vectors/315593)

<div class="topic-metadata">

**Author:** [@Tobias\_Fink](https://discuss.elastic.co/u/Tobias_Fink)\
**Replies:** 0\
**Last updated:** [September 30, 2022, 3:54pm UTC](https://discuss.elastic.co/t/custom-term-vectors/315593 "2022-09-30T15:54:22Z")

</div>

Hello, I'm trying to create custom term frequencies for terms in my documents, independent of the actual term frequencies in the document and including expansion terms that are not in the original document. Position and…

---

## [Custom filter in ruby?](https://discuss.elastic.co/t/custom-filter-in-ruby/315567)

<div class="topic-metadata">

**Author:** [@Nikolas1306](https://discuss.elastic.co/u/Nikolas1306)\
**Replies:** 2\
**Last updated:** [September 30, 2022, 3:49pm UTC](https://discuss.elastic.co/t/custom-filter-in-ruby/315567 "2022-09-30T15:49:39Z")

</div>

hello i've used this config but have error when executed filter { ruby { code =\> ' if event.get("message").include? ' INFO ' event.cancel end ' …

---

## [Not able to install Elasticsearch 8.4.1](https://discuss.elastic.co/t/not-able-to-install-elasticsearch-8-4-1/314650)

<div class="topic-metadata">

**Author:** [@shivang.ahd](https://discuss.elastic.co/u/shivang.ahd)\
**Replies:** 17\
**Last updated:** [September 30, 2022, 3:10pm UTC](https://discuss.elastic.co/t/not-able-to-install-elasticsearch-8-4-1/314650 "2022-09-30T15:10:39Z")

</div>

Hi, I am not able to install elasticsearch 8.4.1 I am getting the below mentioned error. will not overwrite keystore at \[C:\\ProgramData\\Elastic\\Elasticsearch\\config\\elasticsearch.keystore\], because this incurs changi…

---

## [ELK 8.x Logstash creates index with variable name instead variable value](https://discuss.elastic.co/t/elk-8-x-logstash-creates-index-with-variable-name-instead-variable-value/315365)

<div class="topic-metadata">

**Author:** [@Cezary](https://discuss.elastic.co/u/Cezary)\
**Replies:** 1\
**Last updated:** [September 30, 2022, 12:31pm UTC](https://discuss.elastic.co/t/elk-8-x-logstash-creates-index-with-variable-name-instead-variable-value/315365 "2022-09-30T12:31:24Z")

</div>

Hello Guys, I have an issue with Logstash, it creates index in elasticsearch and archive filename with variable name instead variable value and next creates index and archive filename with correct name. My logstash co…

---

## [Elastic SearchSearch API - default\_allow\_partial\_results parameter](https://discuss.elastic.co/t/elastic-searchsearch-api-default-allow-partial-results-parameter/315553)

<div class="topic-metadata">

**Author:** [@edsonma](https://discuss.elastic.co/u/edsonma)\
**Replies:** 0\
**Last updated:** [September 30, 2022, 12:30pm UTC](https://discuss.elastic.co/t/elastic-searchsearch-api-default-allow-partial-results-parameter/315553 "2022-09-30T12:30:22Z")

</div>

I am working on a project and looking at ES documentation I found a query parameter allow\_partial\_search\_results. (Optional, Boolean) If true, returns partial results if there are shard request timeouts or shard failur…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=525)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=527)
