# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=546

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 547

---

## [Recherche partielle d'un mot](https://discuss.elastic.co/t/recherche-partielle-dun-mot/311696)

<div class="topic-metadata">

**Author:** [@JoMod](https://discuss.elastic.co/u/JoMod)\
**Replies:** 2\
**Last updated:** [September 5, 2022, 12:51pm UTC](https://discuss.elastic.co/t/recherche-partielle-dun-mot/311696 "2022-09-05T12:51:17Z")

</div>

Bonjour, J'ai un document ayant pour titre "Quelle garantie choisir pour votre maison ?". Lors d'une recherche avec les mots "garantie", "garanti", tout fonctionne correctement mais avec la recherche "garant", plus rie…

---

## [Indexation ES](https://discuss.elastic.co/t/indexation-es/313345)

<div class="topic-metadata">

**Author:** [@ASRLO](https://discuss.elastic.co/u/ASRLO)\
**Replies:** 4\
**Last updated:** [September 5, 2022, 12:48pm UTC](https://discuss.elastic.co/t/indexation-es/313345 "2022-09-05T12:48:45Z")

</div>

Bonjour, J'utilise la suite ELK qui va reçoit ses données via un syslog. J'ai récemment coupé mon cluster ES de 2 nœuds pour finalement n'avoir qu'un seul noeud. Suite à cela, la volumétrie de mes index sur kibana/ES …

---

## [Can not bulk update with script on index have mapping strict dynamic?](https://discuss.elastic.co/t/can-not-bulk-update-with-script-on-index-have-mapping-strict-dynamic/313132)

<div class="topic-metadata">

**Author:** [@robocon20x](https://discuss.elastic.co/u/robocon20x)\
**Replies:** 4\
**Last updated:** [September 5, 2022, 11:32am UTC](https://discuss.elastic.co/t/can-not-bulk-update-with-script-on-index-have-mapping-strict-dynamic/313132 "2022-09-05T11:32:04Z")

</div>

Hi guys, i use bulk request with Http to ES, but the error strict\_dynamic\_mapping\_exception has appear. this error not happening when I use bulk request with index have no dynamic\_strict. in my case, bulk reques…

---

## [Working with messages with string format and split the fields of them in logstash](https://discuss.elastic.co/t/working-with-messages-with-string-format-and-split-the-fields-of-them-in-logstash/313645)

<div class="topic-metadata">

**Author:** [@f.haeri](https://discuss.elastic.co/u/f.haeri)\
**Replies:** 3\
**Last updated:** [September 5, 2022, 10:33am UTC](https://discuss.elastic.co/t/working-with-messages-with-string-format-and-split-the-fields-of-them-in-logstash/313645 "2022-09-05T10:33:05Z")

</div>

I have this message: \[ReadDockerQueue\] \[ReadMessageQueue\] message: {"requestType":"PortfolioResponse","parametersJson":"{"algorithmAccessSpecifications":{"dockerName":"D1","xxx":"xxx","userName":"xxx","instanceGuid":"95…

---

## [ElasticSearch Strange behavior](https://discuss.elastic.co/t/elasticsearch-strange-behavior/313650)

<div class="topic-metadata">

**Author:** [@lcui\_dxc](https://discuss.elastic.co/u/lcui_dxc)\
**Replies:** 1\
**Last updated:** [September 5, 2022, 9:10am UTC](https://discuss.elastic.co/t/elasticsearch-strange-behavior/313650 "2022-09-05T09:10:28Z")

</div>

Hello there: I use ELK v8.3.3, it worked fine without x-park. I activated x-pack and configured Elasticsearch by adding the following initially pack.security.enabled: true xpack.security.http.ssl.enabled: true xpack.…

---

## [Logstash centralized pipeline](https://discuss.elastic.co/t/logstash-centralized-pipeline/313625)

<div class="topic-metadata">

**Author:** [@vpolizki](https://discuss.elastic.co/u/vpolizki)\
**Replies:** 2\
**Last updated:** [September 5, 2022, 7:32am UTC](https://discuss.elastic.co/t/logstash-centralized-pipeline/313625 "2022-09-05T07:32:44Z")

</div>

Hi, I use Logstash centralized pipeline in my new cluster. I create pipeline for filebeat with: input/filter/output and it is work excellent. Now I want to add another pipeline from different filebeat that use same po…

---

## [Reason for brief cluster status RED](https://discuss.elastic.co/t/reason-for-brief-cluster-status-red/311719)

<div class="topic-metadata">

**Author:** [@nisow95612](https://discuss.elastic.co/u/nisow95612)\
**Replies:** 1\
**Last updated:** [September 5, 2022, 7:32am UTC](https://discuss.elastic.co/t/reason-for-brief-cluster-status-red/311719 "2022-09-05T07:32:43Z")

</div>

From time to time I see Cluster health API | Elasticsearch Guide \[8.3\] | Elastic return "status": "red" for a few seconds. This never lasts long, so simply running Cluster allocation explain API | Elasticsearch Guide \[8.…

---

## [Elasticsearch results doesn't highlight if a text is converted to raw datatype which is integer/double while searching](https://discuss.elastic.co/t/elasticsearch-results-doesnt-highlight-if-a-text-is-converted-to-raw-datatype-which-is-integer-double-while-searching/313632)

<div class="topic-metadata">

**Author:** [@Rathan\_K](https://discuss.elastic.co/u/Rathan_K)\
**Replies:** 0\
**Last updated:** [September 4, 2022, 8:38pm UTC](https://discuss.elastic.co/t/elasticsearch-results-doesnt-highlight-if-a-text-is-converted-to-raw-datatype-which-is-integer-double-while-searching/313632 "2022-09-04T20:38:33Z")

</div>

Currently im using ES 7.10 Creating a index and mapping PUT /rathan\_index PUT /rathan\_index/\_mappings { "properties" : { "Term\_\_kt" : { "type" : "nested", "include\_in\_root" : true, "properties" : { …

---

## [Filewatch.observingtail 단계에서 넘어가지 않습니다 도와주세요](https://discuss.elastic.co/t/filewatch-observingtail/313577)

<div class="topic-metadata">

**Author:** [@j3rsey](https://discuss.elastic.co/u/j3rsey)\
**Replies:** 1\
**Last updated:** [September 5, 2022, 12:32am UTC](https://discuss.elastic.co/t/filewatch-observingtail/313577 "2022-09-05T00:32:46Z")

</div>

자꾸 여기서 지진행이 되지 않습니다. sincedb라고 하길래 null 까지 지정했는데도 이유를 모르겠습니다.. 저의 conf는 이렇게 지정해주었습니다! 인덱스는 들어간거로 뜨는데 이유가 궁금합니다!!

---

## [Kibana server is not redy yet but the service running](https://discuss.elastic.co/t/kibana-server-is-not-redy-yet-but-the-service-running/313402)

<div class="topic-metadata">

**Author:** [@dvir8360](https://discuss.elastic.co/u/dvir8360)\
**Replies:** 6\
**Last updated:** [September 4, 2022, 11:33pm UTC](https://discuss.elastic.co/t/kibana-server-is-not-redy-yet-but-the-service-running/313402 "2022-09-04T23:33:40Z")

</div>

Hello everyone, i have a elastic cluster and i'm trying to setup kibana but i allways get this message "kibana server is not redy yet" and i configured the kibana.yaml and the elasticsearch.yaml, the status of the servi…

---

## [Need help adjusting elastic settings](https://discuss.elastic.co/t/need-help-adjusting-elastic-settings/313630)

<div class="topic-metadata">

**Author:** [@vortex\_444](https://discuss.elastic.co/u/vortex_444)\
**Replies:** 0\
**Last updated:** [September 4, 2022, 8:10pm UTC](https://discuss.elastic.co/t/need-help-adjusting-elastic-settings/313630 "2022-09-04T20:10:41Z")

</div>

Hello everyone, at the moment everything is almost fine, but there is a problem when the required string is not found through multi\_match and due to the filter selects the wrong result. If the occurrence of the string is…

---

## [Forcing shards synchronization](https://discuss.elastic.co/t/forcing-shards-synchronization/313549)

<div class="topic-metadata">

**Author:** [@cheshirecat](https://discuss.elastic.co/u/cheshirecat)\
**Replies:** 3\
**Last updated:** [September 4, 2022, 6:54pm UTC](https://discuss.elastic.co/t/forcing-shards-synchronization/313549 "2022-09-04T18:54:02Z")

</div>

Hello There! I know that shards are synchronized automatically but is there a way to force synchronization? I'm thinking of command/setting in Kibana/bash script to do fire and do it for me.

---

## [Bringing Elasticsearch node back online after being offline for a week](https://discuss.elastic.co/t/bringing-elasticsearch-node-back-online-after-being-offline-for-a-week/312497)

<div class="topic-metadata">

**Author:** [@kossde](https://discuss.elastic.co/u/kossde)\
**Replies:** 4\
**Last updated:** [September 4, 2022, 6:28pm UTC](https://discuss.elastic.co/t/bringing-elasticsearch-node-back-online-after-being-offline-for-a-week/312497 "2022-09-04T18:28:16Z")

</div>

We have an Elasticsearch data node that has been offline for a week. If we bring this node back online, will the cluster try to create new replica shards for the old primaries stored on that node or, because the shards …

---

## [\[LOGSTASH\] - Plugin input-udp and message charset](https://discuss.elastic.co/t/logstash-plugin-input-udp-and-message-charset/313617)

<div class="topic-metadata">

**Author:** [@manunc](https://discuss.elastic.co/u/manunc)\
**Replies:** 1\
**Last updated:** [September 4, 2022, 10:47am UTC](https://discuss.elastic.co/t/logstash-plugin-input-udp-and-message-charset/313617 "2022-09-04T10:47:18Z")

</div>

Hello, I have a an issue with the message charset received from the input-udp plugin. A raw trace taken using tcpdmp command on linux show the message of the UDP packat like this: Data: 8689630446410580020000001f46e00…

---

## [Cluster stats "Disk Available"](https://discuss.elastic.co/t/cluster-stats-disk-available/313604)

<div class="topic-metadata">

**Author:** [@ylasri](https://discuss.elastic.co/u/ylasri)\
**Replies:** 5\
**Last updated:** [September 4, 2022, 10:10am UTC](https://discuss.elastic.co/t/cluster-stats-disk-available/313604 "2022-09-04T10:10:38Z")

</div>

Dear, Does any one have an idea on how /\_cluster/stats computes total disk for the whole cluster ? any specific filter behind the scene on node.roles ? Bellow is the result of cluster stats API, it show disk space less…

---

## [收集思科交换机日志问题](https://discuss.elastic.co/t/topic/313614)

<div class="topic-metadata">

**Author:** [@xb\_11](https://discuss.elastic.co/u/xb_11)\
**Replies:** 0\
**Last updated:** [September 4, 2022, 3:54am UTC](https://discuss.elastic.co/t/topic/313614 "2022-09-04T03:54:53Z")

</div>

你好， 我正在测试将 IOS 交换机日志摄取到 Elasticsearch 中，但是一直不能成功。 我是安装的本地部署， Elastic&kibana 8.3.2 和 Fleet server ,并且已经安装 Cisco IOS 1.9.0 集成。 在服务器 A 上安装 Elastic Agent ，并启用Cisco IOS 集成策略 配置 Cisco 设备将 log 发送到服务器 A。 目前一直不能收取数据？ 我需要在服…

---

## [Managing large indices](https://discuss.elastic.co/t/managing-large-indices/313596)

<div class="topic-metadata">

**Author:** [@sssamant](https://discuss.elastic.co/u/sssamant)\
**Replies:** 5\
**Last updated:** [September 4, 2022, 3:15am UTC](https://discuss.elastic.co/t/managing-large-indices/313596 "2022-09-04T03:15:24Z")

</div>

I have question about how to manage large indices. The use case is this customer want to keep the data till 10 years for read and now the issue is this our index is keep growing and its size about 4 tb now and we are see…

---

## [No results match your search criteria](https://discuss.elastic.co/t/no-results-match-your-search-criteria/313581)

<div class="topic-metadata">

**Author:** [@kurdit](https://discuss.elastic.co/u/kurdit)\
**Replies:** 5\
**Last updated:** [September 4, 2022, 1:15am UTC](https://discuss.elastic.co/t/no-results-match-your-search-criteria/313581 "2022-09-04T01:15:45Z")

</div>

hi all! Maybe a stupid question, but I couldn't figure it out myself. inaccurate search in Kibana through the search bar in Discovery does not return anything ... if you search by fields, then the pots query works I…

---

## [Can't start elasticsearch service](https://discuss.elastic.co/t/cant-start-elasticsearch-service/313607)

<div class="topic-metadata">

**Author:** [@juancamiloll](https://discuss.elastic.co/u/juancamiloll)\
**Replies:** 8\
**Last updated:** [September 3, 2022, 11:36pm UTC](https://discuss.elastic.co/t/cant-start-elasticsearch-service/313607 "2022-09-03T23:36:43Z")

</div>

Hello, I am trying to start the elasticsearch service with the command systemctl start elasticsearch but I am getting this message Job for elasticsearch.service failed because the control process exited with error code…

---

## [How to calculate and present times between logs](https://discuss.elastic.co/t/how-to-calculate-and-present-times-between-logs/313324)

<div class="topic-metadata">

**Author:** [@amir\_Bialek](https://discuss.elastic.co/u/amir_Bialek)\
**Replies:** 4\
**Last updated:** [September 3, 2022, 10:06am UTC](https://discuss.elastic.co/t/how-to-calculate-and-present-times-between-logs/313324 "2022-09-03T10:06:59Z")

</div>

Hey, new user of elk with Logstash. I am using this as a confid: input { file { path =\> "/myapp/Logs/\*.slog" start\_position =\> "beginning" sincedb\_path =\> "/dev/null" } } filter { j…

---

## [Kibaba error while bootstraping](https://discuss.elastic.co/t/kibaba-error-while-bootstraping/313598)

<div class="topic-metadata">

**Author:** [@abak\_programmer](https://discuss.elastic.co/u/abak_programmer)\
**Replies:** 0\
**Last updated:** [September 3, 2022, 9:58am UTC](https://discuss.elastic.co/t/kibaba-error-while-bootstraping/313598 "2022-09-03T09:58:31Z")

</div>

hi, i have a problem when i try to bootstrap kibana, at first i ran " yarn kbn clean " then ran "yarn kbn bootstrap" but: succ 25 bootstrap builds are cached info \[@kbn/test\] running \[kbn:bootstrap\] script ERROR \[boots…

---

## [How to recover from split log messages](https://discuss.elastic.co/t/how-to-recover-from-split-log-messages/313579)

<div class="topic-metadata">

**Author:** [@bobus](https://discuss.elastic.co/u/bobus)\
**Replies:** 3\
**Last updated:** [September 2, 2022, 10:20pm UTC](https://discuss.elastic.co/t/how-to-recover-from-split-log-messages/313579 "2022-09-02T22:20:47Z")

</div>

There appears to be a years-long-standing issue with large ( longer than 16KB) messages getting split into parts and appearing on Kibana in multiple lines. Such long messages typically include Java exception stack traces…

---

## [Filebeat/Logstash Apache Access Logs timestamp issue](https://discuss.elastic.co/t/filebeat-logstash-apache-access-logs-timestamp-issue/313278)

<div class="topic-metadata">

**Author:** [@SirStephanikus](https://discuss.elastic.co/u/SirStephanikus)\
**Replies:** 8\
**Last updated:** [September 2, 2022, 8:24pm UTC](https://discuss.elastic.co/t/filebeat-logstash-apache-access-logs-timestamp-issue/313278 "2022-09-02T20:24:38Z")

</div>

Hello everyone I'm new to the ELK world and need some help with a basic Apache HTTP filebeat -\> logstash -\> Elasticsearch \<- Kibana filter/pipeline for learning purposes. Version: 8.3.3 Problem: A dummy apache acce…

---

## [Whether CCR and reindex from remote are same?](https://discuss.elastic.co/t/whether-ccr-and-reindex-from-remote-are-same/313106)

<div class="topic-metadata">

**Author:** [@mruthyu](https://discuss.elastic.co/u/mruthyu)\
**Replies:** 4\
**Last updated:** [September 2, 2022, 7:08pm UTC](https://discuss.elastic.co/t/whether-ccr-and-reindex-from-remote-are-same/313106 "2022-09-02T19:08:44Z")

</div>

Whether CCR and reindex from remote are same?

---

## [Upgrading from ECK 0.9.0](https://discuss.elastic.co/t/upgrading-from-eck-0-9-0/313580)

<div class="topic-metadata">

**Author:** [@charles3](https://discuss.elastic.co/u/charles3)\
**Replies:** 0\
**Last updated:** [September 2, 2022, 6:14pm UTC](https://discuss.elastic.co/t/upgrading-from-eck-0-9-0/313580 "2022-09-02T18:14:46Z")

</div>

Is there a guide for upgrading from ECK 0.9.0 to 1.0.0-beta1? I've followed the Upgrade Guide and it always results in the deletion of the persistent volumes and, ultimately, the loss of data. In the last test that I r…

---

## [CCR - 7.14 to 8.0/8.x version](https://discuss.elastic.co/t/ccr-7-14-to-8-0-8-x-version/312644)

<div class="topic-metadata">

**Author:** [@mruthyu](https://discuss.elastic.co/u/mruthyu)\
**Replies:** 2\
**Last updated:** [September 2, 2022, 5:45pm UTC](https://discuss.elastic.co/t/ccr-7-14-to-8-0-8-x-version/312644 "2022-09-02T17:45:52Z")

</div>

Is it possible to have a CCR to new 8.0 elasticsearch cluster from existing 7.14 version elasticsearch cluster (Remote Cluster)? or the existing 7.14 version cluster needs to be upgraded to 7.17 vesrion first?

---

## [Error starting Logstash](https://discuss.elastic.co/t/error-starting-logstash/313470)

<div class="topic-metadata">

**Author:** [@steevhise](https://discuss.elastic.co/u/steevhise)\
**Replies:** 6\
**Last updated:** [September 2, 2022, 4:06pm UTC](https://discuss.elastic.co/t/error-starting-logstash/313470 "2022-09-02T16:06:58Z")

</div>

Logstash is exiting with an error when starting up: \[ERROR\] 2022-09-01 17:35:32.473 \[Converge PipelineAction::Create\<main\>\] agent - Failed to execute action {:action=\>LogStash::PipelineAction::Create/pipeline\_id:main, :…

---

## [Logstash multiline codec do not read all lines](https://discuss.elastic.co/t/logstash-multiline-codec-do-not-read-all-lines/313542)

<div class="topic-metadata">

**Author:** [@alex\_96](https://discuss.elastic.co/u/alex_96)\
**Replies:** 2\
**Last updated:** [September 2, 2022, 1:33pm UTC](https://discuss.elastic.co/t/logstash-multiline-codec-do-not-read-all-lines/313542 "2022-09-02T13:33:33Z")

</div>

Hi I'm using multiline codec to concatenate lines into one event, here's an example of it: # Time: 2022-08-29T07:43:30.314166Z # User@Host: root\[root\] @ 1.1.1.1. \[\] Id: 111111 # Query\_time: 0.019870 Lock\_time: 0.00000…

---

## [Manipulate score by field integer value](https://discuss.elastic.co/t/manipulate-score-by-field-integer-value/313553)

<div class="topic-metadata">

**Author:** [@frankmehlhop.com](https://discuss.elastic.co/u/frankmehlhop.com)\
**Replies:** 0\
**Last updated:** [September 2, 2022, 12:21pm UTC](https://discuss.elastic.co/t/manipulate-score-by-field-integer-value/313553 "2022-09-02T12:21:57Z")

</div>

I use Elastic for searching pdf's. One of the fields apart of the pdf-content is doridat, what is a date as integer. The newest documents should get a higher score (higher ranking). This means that the higher the value i…

---

## [Disk Usage problem](https://discuss.elastic.co/t/disk-usage-problem/313543)

<div class="topic-metadata">

**Author:** [@Medel](https://discuss.elastic.co/u/Medel)\
**Replies:** 14\
**Last updated:** [September 2, 2022, 12:20pm UTC](https://discuss.elastic.co/t/disk-usage-problem/313543 "2022-09-02T12:20:48Z")

</div>

Hello! I have a strange issue in my elasticsearch cluster So I have 3 nodes, and each node server has 300gb disk space on it But it showed that only 20gb is available. How I can add more space to the nodes?

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=545)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=547)
