# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=535

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 536

---

## [How to find or query duplicate offsets?](https://discuss.elastic.co/t/how-to-find-or-query-duplicate-offsets/314456)

<div class="topic-metadata">

**Author:** [@connectgeeks](https://discuss.elastic.co/u/connectgeeks)\
**Replies:** 6\
**Last updated:** [September 19, 2022, 1:04pm UTC](https://discuss.elastic.co/t/how-to-find-or-query-duplicate-offsets/314456 "2022-09-19T13:04:33Z")

</div>

I’m having duplicate records in my indexes. How can I find list of duplicate records ? Duplicate records have same offset, can you suggest the query to find list of offset with more than one count ? Or any other way to…

---

## [Sorting by Fields After Text Score](https://discuss.elastic.co/t/sorting-by-fields-after-text-score/314673)

<div class="topic-metadata">

**Author:** [@AymanHamdoun](https://discuss.elastic.co/u/AymanHamdoun)\
**Replies:** 1\
**Last updated:** [September 19, 2022, 12:37pm UTC](https://discuss.elastic.co/t/sorting-by-fields-after-text-score/314673 "2022-09-19T12:37:35Z")

</div>

Hello, I was wondering if elastic has the ability to sort by certain indexed fields in a document but not prioritize them over the textual match... For instance, lets say i have an index of products that has the follow…

---

## [KV filter on ugly json log](https://discuss.elastic.co/t/kv-filter-on-ugly-json-log/314575)

<div class="topic-metadata">

**Author:** [@stanley783](https://discuss.elastic.co/u/stanley783)\
**Replies:** 4\
**Last updated:** [September 19, 2022, 10:43am UTC](https://discuss.elastic.co/t/kv-filter-on-ugly-json-log/314575 "2022-09-19T10:43:07Z")

</div>

Hi, received log in json format, json filter parsed correctly but one field, "details", is in a unfinished/incorrect format lets say and json cant handle it, therefore i applied kv but cant get desired outcome - correct…

---

## [How to store documents (word/ppt/excel/pdf) and search its content using elastic search](https://discuss.elastic.co/t/how-to-store-documents-word-ppt-excel-pdf-and-search-its-content-using-elastic-search/314674)

<div class="topic-metadata">

**Author:** [@avinash.parameswaran](https://discuss.elastic.co/u/avinash.parameswaran)\
**Replies:** 1\
**Last updated:** [September 19, 2022, 10:26am UTC](https://discuss.elastic.co/t/how-to-store-documents-word-ppt-excel-pdf-and-search-its-content-using-elastic-search/314674 "2022-09-19T10:26:15Z")

</div>

How to store document as blob to create indexes and search document content as full text search?Any suggestion on above approach to proceed would be helpful Thanks.

---

## [Show number as percentile in elasticsearch DSL](https://discuss.elastic.co/t/show-number-as-percentile-in-elasticsearch-dsl/314506)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 5\
**Last updated:** [September 19, 2022, 9:01am UTC](https://discuss.elastic.co/t/show-number-as-percentile-in-elasticsearch-dsl/314506 "2022-09-19T09:01:38Z")

</div>

Sample data Name response\_code abc 6780 abc2 9999 abc3 1000 abc4 3456 . . . abc20 9700 I want two perform following task Show those response\_code whoes value is greater than 3000 Sh…

---

## [Post\_filter on aggregated results](https://discuss.elastic.co/t/post-filter-on-aggregated-results/314671)

<div class="topic-metadata">

**Author:** [@Emna\_Jaoua](https://discuss.elastic.co/u/Emna_Jaoua)\
**Replies:** 0\
**Last updated:** [September 19, 2022, 7:58am UTC](https://discuss.elastic.co/t/post-filter-on-aggregated-results/314671 "2022-09-19T07:58:18Z")

</div>

Hello everyone, I have some trouble filtering on aggregated results although the post\_filter is applied on the nested path. To give some context, I m aggregating on nested path aggregationTr.subField.countryId using thi…

---

## [Saved object not found & cannot delete it](https://discuss.elastic.co/t/saved-object-not-found-cannot-delete-it/314164)

<div class="topic-metadata">

**Author:** [@uae\_user](https://discuss.elastic.co/u/uae_user)\
**Replies:** 4\
**Last updated:** [September 19, 2022, 5:50am UTC](https://discuss.elastic.co/t/saved-object-not-found-cannot-delete-it/314164 "2022-09-19T05:50:50Z")

</div>

Hello, I re-indexed my data and created a new data view after deleting the old one. There are some visualization objects linked to the old data view which I managed to create again and remove the old one however there a…

---

## [Specify the naming space](https://discuss.elastic.co/t/specify-the-naming-space/314619)

<div class="topic-metadata">

**Author:** [@aluopy](https://discuss.elastic.co/u/aluopy)\
**Replies:** 1\
**Last updated:** [September 19, 2022, 4:28am UTC](https://discuss.elastic.co/t/specify-the-naming-space/314619 "2022-09-19T04:28:31Z")

</div>

HI, Use ECK to deploy ES and Kibana, how to specify the naming space running ES and Kibana Thanks

---

## [Elastic Cluster change to applyingphase after receiving data stream and logs](https://discuss.elastic.co/t/elastic-cluster-change-to-applyingphase-after-receiving-data-stream-and-logs/313120)

<div class="topic-metadata">

**Author:** [@steveytam](https://discuss.elastic.co/u/steveytam)\
**Replies:** 12\
**Last updated:** [September 19, 2022, 3:10am UTC](https://discuss.elastic.co/t/elastic-cluster-change-to-applyingphase-after-receiving-data-stream-and-logs/313120 "2022-09-19T03:10:12Z")

</div>

My elastic cluster is just crashing after I installed one elastic agent, I use ECK 2.4 and deploy Elasticsearch 8.3.3 apiVersion: elasticsearch.k8s.elastic.co/v1 kind: Elasticsearch metadata: name: elasticsearch spec:…

---

## [Adding new data nodes to busy ingesting cluster](https://discuss.elastic.co/t/adding-new-data-nodes-to-busy-ingesting-cluster/314614)

<div class="topic-metadata">

**Author:** [@Todd\_Lyons](https://discuss.elastic.co/u/Todd_Lyons)\
**Replies:** 2\
**Last updated:** [September 19, 2022, 12:26am UTC](https://discuss.elastic.co/t/adding-new-data-nodes-to-busy-ingesting-cluster/314614 "2022-09-19T00:26:10Z")

</div>

We have a 7.17.4 cluster with 10 data nodes. Our main index is 10 shards with 1 replica, and it rolls over at 500 GB. I added 2 data nodes, expecting the incoming shards to spread out over the 12 nodes, maybe 2 per new…

---

## [What's the cause of This Error and how to fix It?](https://discuss.elastic.co/t/whats-the-cause-of-this-error-and-how-to-fix-it/314507)

<div class="topic-metadata">

**Author:** [@morad\_della3](https://discuss.elastic.co/u/morad_della3)\
**Replies:** 1\
**Last updated:** [September 18, 2022, 11:15pm UTC](https://discuss.elastic.co/t/whats-the-cause-of-this-error-and-how-to-fix-it/314507 "2022-09-18T23:15:36Z")

</div>

I installed Elasticsearch and Kibana 8.4.1 in VM ubuntu 22.04 ad I give this VM 2G RAM, 50 G disk, and 2 CPU, i try in the first time to browze kibana , it's work i can access kibana GUI and relate it to elasticsearch bu…

---

## [What's the cause of this Eroor and how to fix it?](https://discuss.elastic.co/t/whats-the-cause-of-this-eroor-and-how-to-fix-it/314505)

<div class="topic-metadata">

**Author:** [@morad\_della3](https://discuss.elastic.co/u/morad_della3)\
**Replies:** 1\
**Last updated:** [September 18, 2022, 11:15pm UTC](https://discuss.elastic.co/t/whats-the-cause-of-this-eroor-and-how-to-fix-it/314505 "2022-09-18T23:15:12Z")

</div>

I installed elasticsearch and kibana 8.4.1 in VM ubuntu 22.04 ad i give to this VM 2G RAM , 50 G disk and 2 cpu Caused by: java.io.IOException: No space left on device elastic@elqstic:~$ sudo systemctl status elasticse…

---

## [Elasticsearch: find closest/nearest docs in reference to one (calculated from known date)](https://discuss.elastic.co/t/elasticsearch-find-closest-nearest-docs-in-reference-to-one-calculated-from-known-date/314648)

<div class="topic-metadata">

**Author:** [@err](https://discuss.elastic.co/u/err)\
**Replies:** 0\
**Last updated:** [September 18, 2022, 4:52pm UTC](https://discuss.elastic.co/t/elasticsearch-find-closest-nearest-docs-in-reference-to-one-calculated-from-known-date/314648 "2022-09-18T16:52:14Z")

</div>

Is there a standard seach possibility to find closest docs to one reference doc by date criteria (if I don not know range yet) Example dataset index “person” - doc : name=\>Alice birthday=\>01.01.1991 - doc : name=\>Bob…

---

## [Unable to access kibana dashboard](https://discuss.elastic.co/t/unable-to-access-kibana-dashboard/314637)

<div class="topic-metadata">

**Author:** [@Cipta\_Daffa](https://discuss.elastic.co/u/Cipta_Daffa)\
**Replies:** 1\
**Last updated:** [September 18, 2022, 2:59pm UTC](https://discuss.elastic.co/t/unable-to-access-kibana-dashboard/314637 "2022-09-18T14:59:39Z")

</div>

With this configuration, i can't access kibana dashboard? there's anybody can help me? thank you

---

## [Aggregations on \_routing](https://discuss.elastic.co/t/aggregations-on-routing/314640)

<div class="topic-metadata">

**Author:** [@Alexandr\_Maximov](https://discuss.elastic.co/u/Alexandr_Maximov)\
**Replies:** 0\
**Last updated:** [September 18, 2022, 11:24am UTC](https://discuss.elastic.co/t/aggregations-on-routing/314640 "2022-09-18T11:24:50Z")

</div>

Hey folks, is there any way how to aggregate on \_routing meta field? I'd like to do an aggregation on \_routing to make sure we don't have any stale data in our indices.

---

## [Very large index , delete and recreate replica](https://discuss.elastic.co/t/very-large-index-delete-and-recreate-replica/314608)

<div class="topic-metadata">

**Author:** [@Paul-Ayo](https://discuss.elastic.co/u/Paul-Ayo)\
**Replies:** 8\
**Last updated:** [September 18, 2022, 10:03am UTC](https://discuss.elastic.co/t/very-large-index-delete-and-recreate-replica/314608 "2022-09-18T10:03:26Z")

</div>

I have a huge index which i want to split or reindex , the index has one primary and one replica shard both 118gb . I need to create a new index from the current to be able to use ILM as the index name does not fulfill t…

---

## [Elastic security](https://discuss.elastic.co/t/elastic-security/314297)

<div class="topic-metadata">

**Author:** [@dockerdeploys](https://discuss.elastic.co/u/dockerdeploys)\
**Replies:** 2\
**Last updated:** [September 18, 2022, 3:39am UTC](https://discuss.elastic.co/t/elastic-security/314297 "2022-09-18T03:39:19Z")

</div>

Continuing the discussion from ERROR: Failed to set password for user \[apm\_system\] yet again: Hello good time I encountered the following security error in Elasticsearch Thank you for your guidance

---

## [ElasticSearch-6.8 - querying with hyphens in fields does not get results](https://discuss.elastic.co/t/elasticsearch-6-8-querying-with-hyphens-in-fields-does-not-get-results/314467)

<div class="topic-metadata">

**Author:** [@spp125](https://discuss.elastic.co/u/spp125)\
**Replies:** 7\
**Last updated:** [September 18, 2022, 2:08am UTC](https://discuss.elastic.co/t/elasticsearch-6-8-querying-with-hyphens-in-fields-does-not-get-results/314467 "2022-09-18T02:08:17Z")

</div>

I have a users index in that there is a field called groupName that have value like "ad-users" when I query to match how many users belong to "ad-users" groupName. Upon querying to match on groupName I got no results. He…

---

## [Can't index new docs due to type error; sending to old indices still works](https://discuss.elastic.co/t/cant-index-new-docs-due-to-type-error-sending-to-old-indices-still-works/314628)

<div class="topic-metadata">

**Author:** [@emw](https://discuss.elastic.co/u/emw)\
**Replies:** 2\
**Last updated:** [September 18, 2022, 12:23am UTC](https://discuss.elastic.co/t/cant-index-new-docs-due-to-type-error-sending-to-old-indices-still-works/314628 "2022-09-18T00:23:13Z")

</div>

In my ES 7.17 cluster, I'm using index templates to create a new weekly index where I send log data. The index names are generated by my application, not by ES; the template handles index patterns, field limits, and alia…

---

## [How to config OpenTelemetry Log](https://discuss.elastic.co/t/how-to-config-opentelemetry-log/314622)

<div class="topic-metadata">

**Author:** [@yingziisme](https://discuss.elastic.co/u/yingziisme)\
**Replies:** 1\
**Last updated:** [September 17, 2022, 2:56pm UTC](https://discuss.elastic.co/t/how-to-config-opentelemetry-log/314622 "2022-09-17T14:56:02Z")

</div>

In Observability Page, find the error "Expected ")", ":", "\<", "\<=", "\>", "\>=", AND, OR, whitespace but end of input found." like below picture. but I can find Log from Trace details By Trace logs

---

## [Looking for some assistance with rsyslog-\>ES adding custom field, solvee will get 50$ 100%](https://discuss.elastic.co/t/looking-for-some-assistance-with-rsyslog-es-adding-custom-field-solvee-will-get-50-100/314422)

<div class="topic-metadata">

**Author:** [@PlospRawrs](https://discuss.elastic.co/u/PlospRawrs)\
**Replies:** 2\
**Last updated:** [September 17, 2022, 4:35am UTC](https://discuss.elastic.co/t/looking-for-some-assistance-with-rsyslog-es-adding-custom-field-solvee-will-get-50-100/314422 "2022-09-17T04:35:00Z")

</div>

Hi All, Looking for some guidance, per the subject, I will give the solvee 50$ to show my appreciation. I will share solution on thread I don't care, but I will compensate. Setup: Rsyslog version 8.20 ES version 7.10 …

---

## [Elasticsearch won’t start after upgrade to 8.4.1](https://discuss.elastic.co/t/elasticsearch-won-t-start-after-upgrade-to-8-4-1/314583)

<div class="topic-metadata">

**Author:** [@Ubuxa](https://discuss.elastic.co/u/Ubuxa)\
**Replies:** 4\
**Last updated:** [September 17, 2022, 2:12am UTC](https://discuss.elastic.co/t/elasticsearch-won-t-start-after-upgrade-to-8-4-1/314583 "2022-09-17T02:12:40Z")

</div>

Similar issue, but this ticket has since been closed: I upgraded Elasticsearch from 7.17.5 to 8.4.1, and unfortunately I did not check for any incompatibilities. I am now unable to start Elasticsearch, and downgrading …

---

## [Mapping question](https://discuss.elastic.co/t/mapping-question/314528)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 10\
**Last updated:** [September 16, 2022, 9:35pm UTC](https://discuss.elastic.co/t/mapping-question/314528 "2022-09-16T21:35:30Z")

</div>

I have old index hundreds of them which has following in pattern. I have another index created on different test cluster. which had this place dynamically. What I want is to add this host.name.keyword in previous…

---

## [Query DSL in kibana discover](https://discuss.elastic.co/t/query-dsl-in-kibana-discover/314526)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 2\
**Last updated:** [September 16, 2022, 6:58pm UTC](https://discuss.elastic.co/t/query-dsl-in-kibana-discover/314526 "2022-09-16T18:58:46Z")

</div>

I want to run this below query in kibana discover filter "aggs": { "response\_term": { "terms": { "field": "ResponseCode.keyword", "size": 100000 }, "aggs": { "response": { "…

---

## [Break down log messages to keywords](https://discuss.elastic.co/t/break-down-log-messages-to-keywords/314588)

<div class="topic-metadata">

**Author:** [@Mark\_S](https://discuss.elastic.co/u/Mark_S)\
**Replies:** 0\
**Last updated:** [September 16, 2022, 3:39pm UTC](https://discuss.elastic.co/t/break-down-log-messages-to-keywords/314588 "2022-09-16T15:39:40Z")

</div>

I want to index logs from different applications in one index. However some applications don't use exactly the same log format.... How can I use a grok pattern in the input section of the config file to break down the …

---

## [Kibana Dashboard Enlarge image on click](https://discuss.elastic.co/t/kibana-dashboard-enlarge-image-on-click/314404)

<div class="topic-metadata">

**Author:** [@mirokrastev](https://discuss.elastic.co/u/mirokrastev)\
**Replies:** 5\
**Last updated:** [September 16, 2022, 3:24pm UTC](https://discuss.elastic.co/t/kibana-dashboard-enlarge-image-on-click/314404 "2022-09-16T15:24:28Z")

</div>

Hello, Please take a look at the attached snippet. Basically we have a table, which has images into it. My goal here is to be able to enlarge the image, when I click on it. Can you let me know if there is such functiona…

---

## [Logstash from SQL Server to Elasticsearch character encoding problem](https://discuss.elastic.co/t/logstash-from-sql-server-to-elasticsearch-character-encoding-problem/314587)

<div class="topic-metadata">

**Author:** [@Startech](https://discuss.elastic.co/u/Startech)\
**Replies:** 0\
**Last updated:** [September 16, 2022, 3:23pm UTC](https://discuss.elastic.co/t/logstash-from-sql-server-to-elasticsearch-character-encoding-problem/314587 "2022-09-16T15:23:25Z")

</div>

Hi, I am using ELK stack v8.4.1 and trying to integrate data between SQL Server and Elasticsearch via Logstash. My source table includes Turkish characters (collation SQL\_Latin1\_General\_CP1\_CI\_AS). When Logstash writes …

---

## [How to run a pipeline from a pipeline](https://discuss.elastic.co/t/how-to-run-a-pipeline-from-a-pipeline/314562)

<div class="topic-metadata">

**Author:** [@reed](https://discuss.elastic.co/u/reed)\
**Replies:** 4\
**Last updated:** [September 16, 2022, 2:37pm UTC](https://discuss.elastic.co/t/how-to-run-a-pipeline-from-a-pipeline/314562 "2022-09-16T14:37:30Z")

</div>

Hi All, in my project I have 3 pipelines, I know that a pipeline can be scheduled but in my case I need to run the third one at the end of other two. There is a way to do this? run the pipelines in order: pipeline1 -\>…

---

## [UDP Listener died, address already in use](https://discuss.elastic.co/t/udp-listener-died-address-already-in-use/314281)

<div class="topic-metadata">

**Author:** [@sirineb](https://discuss.elastic.co/u/sirineb)\
**Replies:** 4\
**Last updated:** [September 16, 2022, 2:24pm UTC](https://discuss.elastic.co/t/udp-listener-died-address-already-in-use/314281 "2022-09-16T14:24:49Z")

</div>

Hi, I have two pipeline configurations located in /etc/logstash/conf.d. I can make work both seperately by running /usr/share/logstash/bin/logstash -f /etc/logstash/conf.d/\*\*.conf -r, and it sends data to elasticsearch …

---

## [How to handle inconsistent field types](https://discuss.elastic.co/t/how-to-handle-inconsistent-field-types/314064)

<div class="topic-metadata">

**Author:** [@elastimatic](https://discuss.elastic.co/u/elastimatic)\
**Replies:** 3\
**Last updated:** [September 16, 2022, 2:12pm UTC](https://discuss.elastic.co/t/how-to-handle-inconsistent-field-types/314064 "2022-09-16T14:12:51Z")

</div>

I am trying to index a JSON object (comes from Postgres) that has sometimes-inconsistent types that is tripping me up. an example would be: { "financials": { "amount": "100" } }, { "financials": { …

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=534)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=536)
