# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=531

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 532

---

## [Elasticsearch does not start](https://discuss.elastic.co/t/elasticsearch-does-not-start/315156)

<div class="topic-metadata">

**Author:** [@KermitSZ](https://discuss.elastic.co/u/KermitSZ)\
**Replies:** 1\
**Last updated:** [September 26, 2022, 10:07am UTC](https://discuss.elastic.co/t/elasticsearch-does-not-start/315156 "2022-09-26T10:07:22Z")

</div>

Hello community, We installed elasticsearch following this tutorial Install Elasticsearch with Debian Package | Elasticsearch Guide \[6.8\] | Elastic but the service crashes immediately after running the start command. T…

---

## [Dashboards based on a subquery](https://discuss.elastic.co/t/dashboards-based-on-a-subquery/315153)

<div class="topic-metadata">

**Author:** [@shinobu](https://discuss.elastic.co/u/shinobu)\
**Replies:** 2\
**Last updated:** [September 26, 2022, 9:40am UTC](https://discuss.elastic.co/t/dashboards-based-on-a-subquery/315153 "2022-09-26T09:40:06Z")

</div>

Hello, I would like to aggregate data into a pie chart based on the newest data for a specific type id. In other words something like category | type\_id | @timestamp category1 | abcd | 2022-08-26 category1 | abcd |…

---

## [Kibana is now available (was degraded), No ML saved objects in need of synchronization](https://discuss.elastic.co/t/kibana-is-now-available-was-degraded-no-ml-saved-objects-in-need-of-synchronization/315121)

<div class="topic-metadata">

**Author:** [@Tushar\_Singh1](https://discuss.elastic.co/u/Tushar_Singh1)\
**Replies:** 5\
**Last updated:** [September 26, 2022, 9:26am UTC](https://discuss.elastic.co/t/kibana-is-now-available-was-degraded-no-ml-saved-objects-in-need-of-synchronization/315121 "2022-09-26T09:26:53Z")

</div>

I am not able to open kibana GUI , It is continuously throwing error as \[2022-09-25T22:39:48.677+00:00\]\[INFO \]\[plugins.monitoring.monitoring\] config sourced from: production cluster \[2022-09-25T22:39:50.434+00:00\]\[INF…

---

## [Multiple Kibana on multiple cluster with same data](https://discuss.elastic.co/t/multiple-kibana-on-multiple-cluster-with-same-data/313550)

<div class="topic-metadata">

**Author:** [@baneinc](https://discuss.elastic.co/u/baneinc)\
**Replies:** 1\
**Last updated:** [September 26, 2022, 9:10am UTC](https://discuss.elastic.co/t/multiple-kibana-on-multiple-cluster-with-same-data/313550 "2022-09-26T09:10:19Z")

</div>

Hi forum, I have multiple (two) elasticsearch clusters, with kafka in front, so both clusters have identical data. How to setup HA kibana (two kibana, one on eachcluster) with loadbalancer in front, so all kibana setti…

---

## [Field \[gcp.audit.response.status.conditions.lastHeartbeatTime\] of type \[flattened\] doesn't support formats](https://discuss.elastic.co/t/field-gcp-audit-response-status-conditions-lastheartbeattime-of-type-flattened-doesnt-support-formats/315028)

<div class="topic-metadata">

**Author:** [@AndreiRD](https://discuss.elastic.co/u/AndreiRD)\
**Replies:** 2\
**Last updated:** [September 26, 2022, 9:08am UTC](https://discuss.elastic.co/t/field-gcp-audit-response-status-conditions-lastheartbeattime-of-type-flattened-doesnt-support-formats/315028 "2022-09-26T09:08:46Z")

</div>

So, I have enabled GCP Audit logs collection using the GCP integration from Elastic Agent 8.3.3. I've had no problems so far running searches in this dataset, but as of today the next error keeps appearing, and now I ca…

---

## [How to acheive multiple filter in elastic search using API](https://discuss.elastic.co/t/how-to-acheive-multiple-filter-in-elastic-search-using-api/315131)

<div class="topic-metadata">

**Author:** [@Azhar\_Uddin1](https://discuss.elastic.co/u/Azhar_Uddin1)\
**Replies:** 0\
**Last updated:** [September 26, 2022, 6:45am UTC](https://discuss.elastic.co/t/how-to-acheive-multiple-filter-in-elastic-search-using-api/315131 "2022-09-26T06:45:29Z")

</div>

How could I be able to add multiple filters on my index like in an image I have filtered that result by first\_name and then by category using elasticsearch client @app.route('/get-data') @login\_required def get\_permiss…

---

## [Unhealthy Deployment](https://discuss.elastic.co/t/unhealthy-deployment/315114)

<div class="topic-metadata">

**Author:** [@wijamw](https://discuss.elastic.co/u/wijamw)\
**Replies:** 3\
**Last updated:** [September 26, 2022, 2:41am UTC](https://discuss.elastic.co/t/unhealthy-deployment/315114 "2022-09-26T02:41:53Z")

</div>

Hi everyone, I have cloud deployment which today went unhealthy. But when I checked the cluster all is healthy. I have 1 Master, 2 Hot and 1 Warm. I checked the status of the index and it going through rollover …

---

## [How does Elasticsearch Splitting an Index Work?](https://discuss.elastic.co/t/how-does-elasticsearch-splitting-an-index-work/313319)

<div class="topic-metadata">

**Author:** [@Hao\_Yellow](https://discuss.elastic.co/u/Hao_Yellow)\
**Replies:** 17\
**Last updated:** [September 26, 2022, 1:37am UTC](https://discuss.elastic.co/t/how-does-elasticsearch-splitting-an-index-work/313319 "2022-09-26T01:37:54Z")

</div>

Hello, recently I've been working on splitting some indices with too large shards (not too many), so that the cluster's free disk space is more balanced among the multiple nodes. I read a discussion (see the discussion …

---

## [Installing Heartbeat on Oracle Solaris 11.4](https://discuss.elastic.co/t/installing-heartbeat-on-oracle-solaris-11-4/315069)

<div class="topic-metadata">

**Author:** [@idegia](https://discuss.elastic.co/u/idegia)\
**Replies:** 2\
**Last updated:** [September 25, 2022, 7:48pm UTC](https://discuss.elastic.co/t/installing-heartbeat-on-oracle-solaris-11-4/315069 "2022-09-25T19:48:33Z")

</div>

Dear Elastic Community, Can anyone please let me know if it possible to install Heartbeat on Oracle Solaris 11.4. I have tried various combinations but not able to install. If anyone could provide a step-by-step guide o…

---

## [Error when creating a kibana token](https://discuss.elastic.co/t/error-when-creating-a-kibana-token/315090)

<div class="topic-metadata">

**Author:** [@morad\_della3](https://discuss.elastic.co/u/morad_della3)\
**Replies:** 3\
**Last updated:** [September 25, 2022, 3:58pm UTC](https://discuss.elastic.co/t/error-when-creating-a-kibana-token/315090 "2022-09-25T15:58:39Z")

</div>

ubuntu 22.04 elastic 8.4.1 kibana 8.4.1 filebeat 8.4.1 auditbeat suricata elastic and kibana were working well with an old IP and when now i changed the IP to both of them i try to create a token it doesn't work ..…

---

## [Tf-idf custom similarity and bm25 gives same scores and identical results along with a minor problem](https://discuss.elastic.co/t/tf-idf-custom-similarity-and-bm25-gives-same-scores-and-identical-results-along-with-a-minor-problem/314814)

<div class="topic-metadata">

**Author:** [@dayzero](https://discuss.elastic.co/u/dayzero)\
**Replies:** 2\
**Last updated:** [September 25, 2022, 11:08am UTC](https://discuss.elastic.co/t/tf-idf-custom-similarity-and-bm25-gives-same-scores-and-identical-results-along-with-a-minor-problem/314814 "2022-09-25T11:08:40Z")

</div>

\#custom\_similarity #\_ignored #search\_problem #bm25 #tfidf Hi guys, First doubt: while indexing a field with large text along with other lightweight fields, the field gets ignored. But searching works in that field. how…

---

## [Extract query result in csv file](https://discuss.elastic.co/t/extract-query-result-in-csv-file/315095)

<div class="topic-metadata">

**Author:** [@Shubh](https://discuss.elastic.co/u/Shubh)\
**Replies:** 0\
**Last updated:** [September 25, 2022, 8:18am UTC](https://discuss.elastic.co/t/extract-query-result-in-csv-file/315095 "2022-09-25T08:18:49Z")

</div>

Hi all, can you help me how would i extract the java query output in csv file my code is given below. try { RangeQueryBuilder rangeQ = QueryBuilders .rangeQuery("@timestamp") …

---

## [Bucket aggregation with java api](https://discuss.elastic.co/t/bucket-aggregation-with-java-api/315074)

<div class="topic-metadata">

**Author:** [@Shubh](https://discuss.elastic.co/u/Shubh)\
**Replies:** 6\
**Last updated:** [September 25, 2022, 8:12am UTC](https://discuss.elastic.co/t/bucket-aggregation-with-java-api/315074 "2022-09-25T08:12:17Z")

</div>

Hi all can anyone pls help me convert below query in java i have been stuck to this from very long and frustrated.. pls help here GET /\_search { "query": { "bool": { "filter": \[ { "range": …

---

## [Подключение к кластеру по https из php](https://discuss.elastic.co/t/https-php/314692)

<div class="topic-metadata">

**Author:** [@Jenya87](https://discuss.elastic.co/u/Jenya87)\
**Replies:** 1\
**Last updated:** [September 24, 2022, 7:40pm UTC](https://discuss.elastic.co/t/https-php/314692 "2022-09-24T19:40:03Z")

</div>

Доброго времени суток. Подключаюсь к ноде Elastic (версия 8.4) с помощью официального php клиента ( версия 7.3) таким образом $hosts = \['host' =\>'https://XXX.XXX.XXX.XXX'\]; $client2 = ClientBuilder::create()-\>set…

---

## [Match\_phrase with exact substring without space](https://discuss.elastic.co/t/match-phrase-with-exact-substring-without-space/315064)

<div class="topic-metadata">

**Author:** [@ansamHox](https://discuss.elastic.co/u/ansamHox)\
**Replies:** 2\
**Last updated:** [September 24, 2022, 6:59pm UTC](https://discuss.elastic.co/t/match-phrase-with-exact-substring-without-space/315064 "2022-09-24T18:59:55Z")

</div>

I have a dataset like Text: a==b==c== Text: a==b== c== Text: a== b==c== And my own analyzer to create tokens for each letter "analysis": { "analyzer": { "my\_analyzer": { "char\_filter": \[ "my\_char\_filter" …

---

## [Kibana / ajout données csv à un index existant](https://discuss.elastic.co/t/kibana-ajout-donnees-csv-a-un-index-existant/314970)

<div class="topic-metadata">

**Author:** [@Phildefer](https://discuss.elastic.co/u/Phildefer)\
**Replies:** 6\
**Last updated:** [September 24, 2022, 4:46pm UTC](https://discuss.elastic.co/t/kibana-ajout-donnees-csv-a-un-index-existant/314970 "2022-09-24T16:46:55Z")

</div>

Bonjour, Je suis sans doute stupide mais je ne trouve pas le moyen d'ajouter des données (un fichier csv) à un index existant et mappé grâce à l'import via Kibana d'un fichier CSV équivalent. En gros le premier fichier …

---

## [Parsing a list of lists with logstash filter](https://discuss.elastic.co/t/parsing-a-list-of-lists-with-logstash-filter/314747)

<div class="topic-metadata">

**Author:** [@amirfarsi](https://discuss.elastic.co/u/amirfarsi)\
**Replies:** 2\
**Last updated:** [September 24, 2022, 12:52pm UTC](https://discuss.elastic.co/t/parsing-a-list-of-lists-with-logstash-filter/314747 "2022-09-24T12:52:49Z")

</div>

Hello friends. I have a list of lists in the form below: doc 1: \[\[40004, 10\], \[40005, 12\]\] doc 2: \[\[40004, 8\], \[40006, 12\], \[20002, 3\]\] I want to change them to the following form: doc 1: { "40004": 10, "…

---

## [Persian synonyms](https://discuss.elastic.co/t/persian-synonyms/315079)

<div class="topic-metadata">

**Author:** [@Mahdi\_Abbasi](https://discuss.elastic.co/u/Mahdi_Abbasi)\
**Replies:** 0\
**Last updated:** [September 24, 2022, 10:06am UTC](https://discuss.elastic.co/t/persian-synonyms/315079 "2022-09-24T10:06:59Z")

</div>

Hey, I was wondering if there is a dataset of persian synonym words for my analyzer. I expect the dataset to contain at least same words with different spacings. for example: "اسید لاکتیک" and "اسیدلاکتیک". Thank you …

---

## [Preparing Logs analytics with Logstash (for kibana)](https://discuss.elastic.co/t/preparing-logs-analytics-with-logstash-for-kibana/314834)

<div class="topic-metadata">

**Author:** [@Mark\_S](https://discuss.elastic.co/u/Mark_S)\
**Replies:** 8\
**Last updated:** [September 24, 2022, 8:35am UTC](https://discuss.elastic.co/t/preparing-logs-analytics-with-logstash-for-kibana/314834 "2022-09-24T08:35:18Z")

</div>

When creating analytics (for kibana) I need to create keywords Because unfortunately simple text cannot be analyzed in kibana Dashboards. So I am trying to break up the logs. Grok constructor works fine when the logs …

---

## [Cannot Start .\\elasticsearch.bat on windows](https://discuss.elastic.co/t/cannot-start-elasticsearch-bat-on-windows/315037)

<div class="topic-metadata">

**Author:** [@miawu8](https://discuss.elastic.co/u/miawu8)\
**Replies:** 4\
**Last updated:** [September 24, 2022, 5:17am UTC](https://discuss.elastic.co/t/cannot-start-elasticsearch-bat-on-windows/315037 "2022-09-24T05:17:02Z")

</div>

Last month I installed V8.3.2 on windows 2022, everything was ok, but today I stop and deleted V8.3.2, and downloaded 8.4.2 from the official website, use the same config, the system reported an error and could not start…

---

## [Puzzling Scoring situation using multi\_match](https://discuss.elastic.co/t/puzzling-scoring-situation-using-multi-match/315065)

<div class="topic-metadata">

**Author:** [@terzano](https://discuss.elastic.co/u/terzano)\
**Replies:** 1\
**Last updated:** [September 24, 2022, 2:57am UTC](https://discuss.elastic.co/t/puzzling-scoring-situation-using-multi-match/315065 "2022-09-24T02:57:56Z")

</div>

I am having a hard time understading why the scoring of record #1 is higher than #2. The one on #2 has more matches (see Highlight entry). Both terms are found on fields with higher boosting criteria ss\_categories\_full …

---

## [Field with different types on same index](https://discuss.elastic.co/t/field-with-different-types-on-same-index/315047)

<div class="topic-metadata">

**Author:** [@prabello](https://discuss.elastic.co/u/prabello)\
**Replies:** 5\
**Last updated:** [September 23, 2022, 11:41pm UTC](https://discuss.elastic.co/t/field-with-different-types-on-same-index/315047 "2022-09-23T23:41:33Z")

</div>

Currently, we are indexing information on elastic for each business that is our customer (B2B), this is causing us to have too many indexes, some with very small shards (500mb shards) But due to the nature of the data, …

---

## [Elasticsearch: \[Python Client\] Search does not return documents](https://discuss.elastic.co/t/elasticsearch-python-client-search-does-not-return-documents/315066)

<div class="topic-metadata">

**Author:** [@Ivo\_Tavares](https://discuss.elastic.co/u/Ivo_Tavares)\
**Replies:** 0\
**Last updated:** [September 23, 2022, 10:41pm UTC](https://discuss.elastic.co/t/elasticsearch-python-client-search-does-not-return-documents/315066 "2022-09-23T22:41:48Z")

</div>

When I run the following: search\_doc = Document.search( using=client, index=custom\_index ) search\_doc = search\_doc.query("term", doc\_field = f"string\_{num}") and then use .scan() I get Hit objects. So…

---

## [Logstash Error Failed to Execute action](https://discuss.elastic.co/t/logstash-error-failed-to-execute-action/315051)

<div class="topic-metadata">

**Author:** [@Technolust](https://discuss.elastic.co/u/Technolust)\
**Replies:** 7\
**Last updated:** [September 23, 2022, 9:38pm UTC](https://discuss.elastic.co/t/logstash-error-failed-to-execute-action/315051 "2022-09-23T21:38:01Z")

</div>

Team, I've lost all my hair... For whatever reason, I can't figure this out. \[2022-09-23T15:09:46,265\]\[ERROR\]\[logstash.agent \] Failed to execute action {:action=\>LogStash::PipelineAction::Create/pipeline\_id:m…

---

## [VMWare NSX Parsing](https://discuss.elastic.co/t/vmware-nsx-parsing/315054)

<div class="topic-metadata">

**Author:** [@groth](https://discuss.elastic.co/u/groth)\
**Replies:** 2\
**Last updated:** [September 23, 2022, 9:18pm UTC](https://discuss.elastic.co/t/vmware-nsx-parsing/315054 "2022-09-23T21:18:42Z")

</div>

I'm currently working on a Logstash pipeline for VMWare NSX firewall logs coming in over syslog forwarding. Some of the ICMP logs have a couple numbers between the protocol name and the source and destination IPs that VM…

---

## [Error when starting elasticsearch](https://discuss.elastic.co/t/error-when-starting-elasticsearch/315026)

<div class="topic-metadata">

**Author:** [@morad\_della3](https://discuss.elastic.co/u/morad_della3)\
**Replies:** 5\
**Last updated:** [September 23, 2022, 9:18pm UTC](https://discuss.elastic.co/t/error-when-starting-elasticsearch/315026 "2022-09-23T21:18:21Z")

</div>

I HAVE elastic 8.4.1 in ubuntu 22.04 and when i make this cmd "discovery.type: single-node" in elasticsearch.yml because i installed elastic ad kibana in the same server i have this error \[2022-09-23T14:30:10,954\]\[ERRO…

---

## [Visualize inequality with a Lorenz Curve](https://discuss.elastic.co/t/visualize-inequality-with-a-lorenz-curve/315048)

<div class="topic-metadata">

**Author:** [@Andreas\_Schennings](https://discuss.elastic.co/u/Andreas_Schennings)\
**Replies:** 0\
**Last updated:** [September 23, 2022, 6:41pm UTC](https://discuss.elastic.co/t/visualize-inequality-with-a-lorenz-curve/315048 "2022-09-23T18:41:21Z")

</div>

Hi! I am quite new to Kibana. But I must say I really like its diversity and possibilites. Lets say I would like to visualize inequalities e.g. income over population. I have heard that this could be achieved by using …

---

## [How to achieve semantic search with ElasticSearch 8.4.2?](https://discuss.elastic.co/t/how-to-achieve-semantic-search-with-elasticsearch-8-4-2/315038)

<div class="topic-metadata">

**Author:** [@Dinesh\_Sonachalam](https://discuss.elastic.co/u/Dinesh_Sonachalam)\
**Replies:** 1\
**Last updated:** [September 23, 2022, 4:48pm UTC](https://discuss.elastic.co/t/how-to-achieve-semantic-search-with-elasticsearch-8-4-2/315038 "2022-09-23T16:48:13Z")

</div>

How to achieve semantic search with Elasticsearch 8.4.2? Hi guys, I have a basic understanding of adding semantic search support for ES and added them below. It would be beneficial if you guys share some working examp…

---

## [Detect sessions via timestamp and threshold](https://discuss.elastic.co/t/detect-sessions-via-timestamp-and-threshold/315019)

<div class="topic-metadata">

**Author:** [@SKiD](https://discuss.elastic.co/u/SKiD)\
**Replies:** 0\
**Last updated:** [September 23, 2022, 1:46pm UTC](https://discuss.elastic.co/t/detect-sessions-via-timestamp-and-threshold/315019 "2022-09-23T13:46:53Z")

</div>

Hey, I'm not sure if this is the right area to post it, maybe it might be Kibana, but I just give it a try. I'm currently having firewall logs in my indices with timestamp, IP adresses, sent and received bytes and sess…

---

## [Throttled merge](https://discuss.elastic.co/t/throttled-merge/314963)

<div class="topic-metadata">

**Author:** [@Ariel\_Zach](https://discuss.elastic.co/u/Ariel_Zach)\
**Replies:** 3\
**Last updated:** [September 23, 2022, 12:47pm UTC](https://discuss.elastic.co/t/throttled-merge/314963 "2022-09-23T12:47:18Z")

</div>

Hello, Currently we have an index of 33TB (ES 7.8), 48 shards (16 primary, 32 replicas), two months ago we deleted a lot of documents and we noticed that one of the shards (the primary and the 2 replicas) has a very lar…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=530)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=532)
