# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=555

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 556

---

## [500 - Internal Server : ErrorRepository\_verification\_exception, nested: RepositoryVerificationException\[\[backup\] a file written by master to the store \[C:\\\\Updates\\\\Backups\\\\ElasticSearch\] cannot be accessed on the node](https://discuss.elastic.co/t/500-internal-server-errorrepository-verification-exception-nested-repositoryverificationexception-backup-a-file-written-by-master-to-the-store-c-updates-backups-elasticsearch-cannot-be-accessed-on-the-node/311106)

<div class="topic-metadata">

**Author:** [@mujtabah](https://discuss.elastic.co/u/mujtabah)\
**Replies:** 9\
**Last updated:** [August 24, 2022, 6:07am UTC](https://discuss.elastic.co/t/500-internal-server-errorrepository-verification-exception-nested-repositoryverificationexception-backup-a-file-written-by-master-to-the-store-c-updates-backups-elasticsearch-cannot-be-accessed-on-the-node/311106 "2022-08-24T06:07:40Z")

</div>

I have a cluster of 5 nodes(3master,2 data), i have created directory in each node and included its path as path.repo in all of its yml's. then when i take snapshot its giving this error. command i used PUT \_snapshot/b…

---

## [Merge two Json arrays in logstash+ruby](https://discuss.elastic.co/t/merge-two-json-arrays-in-logstash-ruby/312759)

<div class="topic-metadata">

**Author:** [@deep08](https://discuss.elastic.co/u/deep08)\
**Replies:** 0\
**Last updated:** [August 24, 2022, 5:54am UTC](https://discuss.elastic.co/t/merge-two-json-arrays-in-logstash-ruby/312759 "2022-08-24T05:54:56Z")

</div>

Hello , I want to merge two json array based on one id matching fields and create an new array in logstash , I have two Json array data1,data2 below - "data1 "{ "tenant":"0", "city":"FLORENCE", "id":"AXY798", "stat…

---

## [Connect to elasticsearch cluster](https://discuss.elastic.co/t/connect-to-elasticsearch-cluster/312684)

<div class="topic-metadata">

**Author:** [@skyle52](https://discuss.elastic.co/u/skyle52)\
**Replies:** 2\
**Last updated:** [August 24, 2022, 3:33am UTC](https://discuss.elastic.co/t/connect-to-elasticsearch-cluster/312684 "2022-08-24T03:33:07Z")

</div>

Hello all, I have a question about elasticsearch cluster, please advise: I setup 3 nodes elasticsearch cluster with each node have all the default roles. But I don't know how my filebeat or logstash can push log to ela…

---

## [Elasticsearch 8.x installation and configuration problem and elasticsearch service not able to start](https://discuss.elastic.co/t/elasticsearch-8-x-installation-and-configuration-problem-and-elasticsearch-service-not-able-to-start/312745)

<div class="topic-metadata">

**Author:** [@rjoshi28](https://discuss.elastic.co/u/rjoshi28)\
**Replies:** 1\
**Last updated:** [August 23, 2022, 10:48pm UTC](https://discuss.elastic.co/t/elasticsearch-8-x-installation-and-configuration-problem-and-elasticsearch-service-not-able-to-start/312745 "2022-08-23T22:48:18Z")

</div>

Hello guys, I have trouble installing and configuring my elasticsearch 8.x on Ubuntu 20.04 with ansible role. I am getting an error of Could not create auto-configuration directory with main ERROR Unable to create file…

---

## [How to count two different message and put the value in an email in Watcher](https://discuss.elastic.co/t/how-to-count-two-different-message-and-put-the-value-in-an-email-in-watcher/312743)

<div class="topic-metadata">

**Author:** [@pshada](https://discuss.elastic.co/u/pshada)\
**Replies:** 0\
**Last updated:** [August 23, 2022, 9:09pm UTC](https://discuss.elastic.co/t/how-to-count-two-different-message-and-put-the-value-in-an-email-in-watcher/312743 "2022-08-23T21:09:06Z")

</div>

I have a watcher with query like this { "match\_phrase": { "message": { "query": "INITIAL" } } …

---

## [How do I get Kibana credentials for On-Demand?](https://discuss.elastic.co/t/how-do-i-get-kibana-credentials-for-on-demand/312724)

<div class="topic-metadata">

**Author:** [@Adebayo](https://discuss.elastic.co/u/Adebayo)\
**Replies:** 4\
**Last updated:** [August 23, 2022, 8:49pm UTC](https://discuss.elastic.co/t/how-do-i-get-kibana-credentials-for-on-demand/312724 "2022-08-23T20:49:02Z")

</div>

Hi, Just signed up for the Elasticsearch Engineer (On-Demand) course. I went through the lab setup and also created a Strigo account. I have access to the terminal and Kibana1 & Kibana2, but through this process, I didn…

---

## [GeoIP working strange after update](https://discuss.elastic.co/t/geoip-working-strange-after-update/312505)

<div class="topic-metadata">

**Author:** [@Alexander\_A](https://discuss.elastic.co/u/Alexander_A)\
**Replies:** 2\
**Last updated:** [August 23, 2022, 6:10pm UTC](https://discuss.elastic.co/t/geoip-working-strange-after-update/312505 "2022-08-23T18:10:48Z")

</div>

After GeoIP Update using geoip.elastic.co we see strange behavior country for ip 1.1.1.1 not detected and organization\_name became "CLOUDFLARENET" instead of "Cloudflare, Inc". When we use simulate API we get old data (…

---

## [Search sas you type working great, but I need fuzziness / misspell correction](https://discuss.elastic.co/t/search-sas-you-type-working-great-but-i-need-fuzziness-misspell-correction/312729)

<div class="topic-metadata">

**Author:** [@pthreat](https://discuss.elastic.co/u/pthreat)\
**Replies:** 1\
**Last updated:** [August 23, 2022, 6:04pm UTC](https://discuss.elastic.co/t/search-sas-you-type-working-great-but-i-need-fuzziness-misspell-correction/312729 "2022-08-23T18:04:20Z")

</div>

This works great, however, I want to also be able to handle mistypes such as pish or fish, should match phish: My Query: { "from": 0, "size": 5, "sort": \[ { "date": { "o…

---

## [Problem logstash runner](https://discuss.elastic.co/t/problem-logstash-runner/312730)

<div class="topic-metadata">

**Author:** [@Vitoria\_De\_Lara](https://discuss.elastic.co/u/Vitoria_De_Lara)\
**Replies:** 0\
**Last updated:** [August 23, 2022, 6:00pm UTC](https://discuss.elastic.co/t/problem-logstash-runner/312730 "2022-08-23T18:00:58Z")

</div>

I'm trying to run logstash with this command, I would like to know if the syntax is right, and if not what would be the rule to run logstash. command /usr/share/logstash/bin/logstash --config.test\_and\_exit -f /etc/logs…

---

## [Filter range on array of object](https://discuss.elastic.co/t/filter-range-on-array-of-object/312669)

<div class="topic-metadata">

**Author:** [@Jake\_Wong](https://discuss.elastic.co/u/Jake_Wong)\
**Replies:** 10\
**Last updated:** [August 23, 2022, 4:21pm UTC](https://discuss.elastic.co/t/filter-range-on-array-of-object/312669 "2022-08-23T16:21:10Z")

</div>

I have a documents with many nested fields and array of objects inside them. So when I perform search, how can I get the age range between 20 to 35? { "company\_name": "abc company", "detail": { "staff": …

---

## [How to disable the default index mapping and index documents based on explicit mapping](https://discuss.elastic.co/t/how-to-disable-the-default-index-mapping-and-index-documents-based-on-explicit-mapping/312719)

<div class="topic-metadata">

**Author:** [@Kishan\_Singh](https://discuss.elastic.co/u/Kishan_Singh)\
**Replies:** 0\
**Last updated:** [August 23, 2022, 3:07pm UTC](https://discuss.elastic.co/t/how-to-disable-the-default-index-mapping-and-index-documents-based-on-explicit-mapping/312719 "2022-08-23T15:07:00Z")

</div>

The problem statement is this: i want to index documents based only on the fields that i define in my explicit mapping configuration while creating an index. i can see that even if i pass my own index mapping for speci…

---

## [Kibana is now available (was degraded)"](https://discuss.elastic.co/t/kibana-is-now-available-was-degraded/312610)

<div class="topic-metadata">

**Author:** [@sanjay\_kumar\_chahar](https://discuss.elastic.co/u/sanjay_kumar_chahar)\
**Replies:** 2\
**Last updated:** [August 23, 2022, 2:00pm UTC](https://discuss.elastic.co/t/kibana-is-now-available-was-degraded/312610 "2022-08-23T14:00:57Z")

</div>

Hi All I have configured elasticsearch, kibana and fileebeat Kibana version number: "8.3.3" Elasticsearch version number : "8.3.3" Filebeat version number : "8.3.3" I am able to login in Kibana Web UI and not able…

---

## [Question About Field order in Discover](https://discuss.elastic.co/t/question-about-field-order-in-discover/312439)

<div class="topic-metadata">

**Author:** [@Paul\_Chen](https://discuss.elastic.co/u/Paul_Chen)\
**Replies:** 1\
**Last updated:** [August 23, 2022, 1:38pm UTC](https://discuss.elastic.co/t/question-about-field-order-in-discover/312439 "2022-08-23T13:38:25Z")

</div>

I use Logstash to output data to ES from database, and in the Kibana discover, the field always sort in a-z Is there any way to make the field order follow the database field order? note: My SQL statement already has t…

---

## [Kibana Email Alerting Connector](https://discuss.elastic.co/t/kibana-email-alerting-connector/312587)

<div class="topic-metadata">

**Author:** [@Ayushi\_bhardwaj](https://discuss.elastic.co/u/Ayushi_bhardwaj)\
**Replies:** 1\
**Last updated:** [August 23, 2022, 1:18pm UTC](https://discuss.elastic.co/t/kibana-email-alerting-connector/312587 "2022-08-23T13:18:17Z")

</div>

How to setup Email Connector once the rule is created in kibana Rules & Connectors? what Username and password inside email connector option we need to give.

---

## [Missing rsyslog/logstash data: rescan?](https://discuss.elastic.co/t/missing-rsyslog-logstash-data-rescan/312706)

<div class="topic-metadata">

**Author:** [@cvcv](https://discuss.elastic.co/u/cvcv)\
**Replies:** 0\
**Last updated:** [August 23, 2022, 12:46pm UTC](https://discuss.elastic.co/t/missing-rsyslog-logstash-data-rescan/312706 "2022-08-23T12:46:55Z")

</div>

Hi, I'm an ELK newbie. I configured rsyslogd and sending logs via the json template into logstash. Things worked fine for awhile but my index got "full". I lost a few days of logs. The rsyslog data/files are still t…

---

## [Kibana Dashboard Refresh takes too long](https://discuss.elastic.co/t/kibana-dashboard-refresh-takes-too-long/312683)

<div class="topic-metadata">

**Author:** [@Scorpion21](https://discuss.elastic.co/u/Scorpion21)\
**Replies:** 1\
**Last updated:** [August 23, 2022, 11:56am UTC](https://discuss.elastic.co/t/kibana-dashboard-refresh-takes-too-long/312683 "2022-08-23T11:56:46Z")

</div>

I deploy an ELK platform using kubernetes. For a quick test, I just create a simple dashboard including one map and two bars, based on a small index including less than 4000 docs. However, it will take around 20 sec…

---

## [Monitoring Request Failed in Stack Monitoring in Kibana 8.3.3](https://discuss.elastic.co/t/monitoring-request-failed-in-stack-monitoring-in-kibana-8-3-3/312698)

<div class="topic-metadata">

**Author:** [@sumitpramanik](https://discuss.elastic.co/u/sumitpramanik)\
**Replies:** 0\
**Last updated:** [August 23, 2022, 11:27am UTC](https://discuss.elastic.co/t/monitoring-request-failed-in-stack-monitoring-in-kibana-8-3-3/312698 "2022-08-23T11:27:25Z")

</div>

Hi, I am facing below issue after updating kibana to 8.2 and in 8.3.3 its not fixed yet. How to solve this? {"ecs":{"version":"8.0.0"},"@timestamp":"2022-08-23T17:24:52.715+06:00","message":"Saved object \[task/e3353…

---

## [Set new value in controls-visualisation after pipeline execution/index creation](https://discuss.elastic.co/t/set-new-value-in-controls-visualisation-after-pipeline-execution-index-creation/312679)

<div class="topic-metadata">

**Author:** [@Jonas\_S](https://discuss.elastic.co/u/Jonas_S)\
**Replies:** 2\
**Last updated:** [August 23, 2022, 10:43am UTC](https://discuss.elastic.co/t/set-new-value-in-controls-visualisation-after-pipeline-execution-index-creation/312679 "2022-08-23T10:43:32Z")

</div>

Hello, i have a kibana dashboard with an index pattern where every month a new index is created by a logstash pipeline within the same index pattern. The data contains a field "month", which is selectable in a controls …

---

## [Multi match query or any search query is not working when field data is in Json string format](https://discuss.elastic.co/t/multi-match-query-or-any-search-query-is-not-working-when-field-data-is-in-json-string-format/311527)

<div class="topic-metadata">

**Author:** [@sona](https://discuss.elastic.co/u/sona)\
**Replies:** 1\
**Last updated:** [August 23, 2022, 11:01am UTC](https://discuss.elastic.co/t/multi-match-query-or-any-search-query-is-not-working-when-field-data-is-in-json-string-format/311527 "2022-08-23T11:01:53Z")

</div>

Hi, One of the field in my index is in json string format but I am not able to perform multi match search query on this. For example if I am passing query as my\_full\_name I am not getting any output. Below is the query …

---

## [Download CSV file name with visualization Name](https://discuss.elastic.co/t/download-csv-file-name-with-visualization-name/312372)

<div class="topic-metadata">

**Author:** [@Sandeep\_Raju](https://discuss.elastic.co/u/Sandeep_Raju)\
**Replies:** 3\
**Last updated:** [August 23, 2022, 10:53am UTC](https://discuss.elastic.co/t/download-csv-file-name-with-visualization-name/312372 "2022-08-23T10:53:59Z")

</div>

Hi all, I'm using Kibana 7.4.1. I create a data table and include it in my dashboard. When i try to download CSV on formatted button I'm only able to download filename table.CSV. For all visualizations, name of file …

---

## [Processors in elastic agent integrations](https://discuss.elastic.co/t/processors-in-elastic-agent-integrations/312692)

<div class="topic-metadata">

**Author:** [@Serhii\_Chebonenko](https://discuss.elastic.co/u/Serhii_Chebonenko)\
**Replies:** 0\
**Last updated:** [August 23, 2022, 10:34am UTC](https://discuss.elastic.co/t/processors-in-elastic-agent-integrations/312692 "2022-08-23T10:34:51Z")

</div>

Hi Everyone. I'm trying to add a field (user\_principal\_name) with processors to have common point of reference while searching different indexes (ftd, ad logs, azure logs etc.) I tried adding this processor to cisco ft…

---

## [Do aarch64-architecture support x-pack？](https://discuss.elastic.co/t/do-aarch64-architecture-support-x-pack/311985)

<div class="topic-metadata">

**Author:** [@calvin\_zhang1206](https://discuss.elastic.co/u/calvin_zhang1206)\
**Replies:** 11\
**Last updated:** [August 23, 2022, 9:41am UTC](https://discuss.elastic.co/t/do-aarch64-architecture-support-x-pack/311985 "2022-08-23T09:41:52Z")

</div>

Hi: My server CPU architecture is aarch64, my elasticsearch version is 6.2.4，now I want to use x-pack for security, Do aarch64-architecture support x-pack？ please help me ,thank you

---

## [Error: Index pattern does not contain any geospatial fields](https://discuss.elastic.co/t/error-index-pattern-does-not-contain-any-geospatial-fields/312686)

<div class="topic-metadata">

**Author:** [@Ricard-CT](https://discuss.elastic.co/u/Ricard-CT)\
**Replies:** 0\
**Last updated:** [August 23, 2022, 8:34am UTC](https://discuss.elastic.co/t/error-index-pattern-does-not-contain-any-geospatial-fields/312686 "2022-08-23T08:34:32Z")

</div>

Hello everyone, I'm trying to use the geo\_ip filter on my logstash, but it is not working. When I try to create the map, this error appears: "Index pattern does not contain any geospatial fields" The problem is tha…

---

## [How to restart data nodes with outdated data?](https://discuss.elastic.co/t/how-to-restart-data-nodes-with-outdated-data/312363)

<div class="topic-metadata">

**Author:** [@Sylmarch](https://discuss.elastic.co/u/Sylmarch)\
**Replies:** 2\
**Last updated:** [August 23, 2022, 7:55am UTC](https://discuss.elastic.co/t/how-to-restart-data-nodes-with-outdated-data/312363 "2022-08-23T07:55:09Z")

</div>

Hi, we have an Elasticsearch 7 cluster in production with 3 physical machines. Each machines hosts 3 nodes: 1 node: master-eligible + data 2 nodes: data only Cluster is configured so that replica shards are copied o…

---

## [Can I create two or more clusters in ElasticSearch](https://discuss.elastic.co/t/can-i-create-two-or-more-clusters-in-elasticsearch/312681)

<div class="topic-metadata">

**Author:** [@Rakhshunda\_Noorein\_J](https://discuss.elastic.co/u/Rakhshunda_Noorein_J)\
**Replies:** 0\
**Last updated:** [August 23, 2022, 7:37am UTC](https://discuss.elastic.co/t/can-i-create-two-or-more-clusters-in-elasticsearch/312681 "2022-08-23T07:37:38Z")

</div>

Hi, I want to create two clusters in elasticsearch. 1 cluster will hold different indices and another cluster will hold different indices. Can I do that in Elasticsearch and if yes then how to do that??

---

## [Elastic best Practice](https://discuss.elastic.co/t/elastic-best-practice/312671)

<div class="topic-metadata">

**Author:** [@vnovotny98](https://discuss.elastic.co/u/vnovotny98)\
**Replies:** 7\
**Last updated:** [August 23, 2022, 7:03am UTC](https://discuss.elastic.co/t/elastic-best-practice/312671 "2022-08-23T07:03:15Z")

</div>

Hello, I am indexing 1mil logs per 15 minutes in one index and I need about 10 000 of them to visualize in Grafana and make reports on it. Is it good practice to separate these 10 000/15 mins to another index? Will sear…

---

## [Eck-operator error logs](https://discuss.elastic.co/t/eck-operator-error-logs/312459)

<div class="topic-metadata">

**Author:** [@x00m](https://discuss.elastic.co/u/x00m)\
**Replies:** 4\
**Last updated:** [August 23, 2022, 6:00am UTC](https://discuss.elastic.co/t/eck-operator-error-logs/312459 "2022-08-23T06:00:34Z")

</div>

I see a lot of errors coming out of eck operator : This is one instance: E0819 10:51:42.525350 1 leaderelection.go:330\] error retrieving resource lock elastic-system/elastic-operator-leader: leases.coordination.k…

---

## [Prometheus integration](https://discuss.elastic.co/t/prometheus-integration/310946)

<div class="topic-metadata">

**Author:** [@tgkumarmca](https://discuss.elastic.co/u/tgkumarmca)\
**Replies:** 1\
**Last updated:** [August 23, 2022, 4:45am UTC](https://discuss.elastic.co/t/prometheus-integration/310946 "2022-08-23T04:45:49Z")

</div>

Continuing the discussion from Configuration Prometheus data in ElasticSearch via Metricbeats:

---

## [Update Reindex Data](https://discuss.elastic.co/t/update-reindex-data/312667)

<div class="topic-metadata">

**Author:** [@xynobob](https://discuss.elastic.co/u/xynobob)\
**Replies:** 0\
**Last updated:** [August 23, 2022, 3:28am UTC](https://discuss.elastic.co/t/update-reindex-data/312667 "2022-08-23T03:28:56Z")

</div>

So I reindex one of my ".kibana" index to a new index called "kibana-detections" as shown below POST \_reindex { "source": { "index": ".kibana", "query": { "bool": { "must": \[\], "filter": …

---

## [Bucket size control for sub-aggregation](https://discuss.elastic.co/t/bucket-size-control-for-sub-aggregation/312193)

<div class="topic-metadata">

**Author:** [@lzz118](https://discuss.elastic.co/u/lzz118)\
**Replies:** 2\
**Last updated:** [August 23, 2022, 3:21am UTC](https://discuss.elastic.co/t/bucket-size-control-for-sub-aggregation/312193 "2022-08-23T03:21:49Z")

</div>

Hi there, I am using multi-level sub-aggregations in my application and I noticed that the size/shard size parameter does not seems to be used during the runtime to control the bucket size of the secondary or deeper lev…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=554)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=556)
