# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=586

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 587

---

## [How to return exact match result first then other matches?](https://discuss.elastic.co/t/how-to-return-exact-match-result-first-then-other-matches/309452)

<div class="topic-metadata">

**Author:** [@Jake\_Wong](https://discuss.elastic.co/u/Jake_Wong)\
**Replies:** 1\
**Last updated:** [July 13, 2022, 2:06pm UTC](https://discuss.elastic.co/t/how-to-return-exact-match-result-first-then-other-matches/309452 "2022-07-13T14:06:09Z")

</div>

I am newbie to elastic. I have data in elasticsearch, with field post\_title : Chocolate Hot Homemade I expect to get 'ho' (exact match) as first result when I search 'ho' like this: Homemade Hot chocolate I have t…

---

## [Elasticsearch Data nodes](https://discuss.elastic.co/t/elasticsearch-data-nodes/309517)

<div class="topic-metadata">

**Author:** [@Farah\_Bhr](https://discuss.elastic.co/u/Farah_Bhr)\
**Replies:** 2\
**Last updated:** [July 13, 2022, 2:05pm UTC](https://discuss.elastic.co/t/elasticsearch-data-nodes/309517 "2022-07-13T14:05:27Z")

</div>

Hello I am a beginner in elastic, I want to create an elasticsearch cluster with 3 data nodes, I want to ask can I specify for each data node, the type of logs meaning if I can specify for each data node what is the ty…

---

## [Why do we need logstash](https://discuss.elastic.co/t/why-do-we-need-logstash/309379)

<div class="topic-metadata">

**Author:** [@yugeeklab](https://discuss.elastic.co/u/yugeeklab)\
**Replies:** 2\
**Last updated:** [July 13, 2022, 1:43pm UTC](https://discuss.elastic.co/t/why-do-we-need-logstash/309379 "2022-07-13T13:43:12Z")

</div>

I found out my Logstash has no logic except for forwarding log to Elasticsearch. Filebeat has many logic instead of Logstash(filtering etc.) In my case, Still do i need Logstash?? Why??

---

## [Query for values not present for the last 90 days](https://discuss.elastic.co/t/query-for-values-not-present-for-the-last-90-days/309308)

<div class="topic-metadata">

**Author:** [@ChristianOelsner](https://discuss.elastic.co/u/ChristianOelsner)\
**Replies:** 2\
**Last updated:** [July 13, 2022, 1:37pm UTC](https://discuss.elastic.co/t/query-for-values-not-present-for-the-last-90-days/309308 "2022-07-13T13:37:05Z")

</div>

Hello forum, I am trying to wrap my head around a query. In order to weed out some users i need to search for values in field "data.authenticationInfo.metadata.identifier.keyword" not present in the last 90 days. Coul…

---

## [Kibana outputs integer values with commas](https://discuss.elastic.co/t/kibana-outputs-integer-values-with-commas/309522)

<div class="topic-metadata">

**Author:** [@Aleksei](https://discuss.elastic.co/u/Aleksei)\
**Replies:** 2\
**Last updated:** [July 13, 2022, 1:27pm UTC](https://discuss.elastic.co/t/kibana-outputs-integer-values-with-commas/309522 "2022-07-13T13:27:21Z")

</div>

Hi. I don’t remember with which version of elastic, but they began to notice in kibana on graphs or tables the output of integer values with commas. This is data from the database. Why does kibana do this? Has anyone …

---

## [Avoid reinventing a reindexing toolbox](https://discuss.elastic.co/t/avoid-reinventing-a-reindexing-toolbox/309273)

<div class="topic-metadata">

**Author:** [@stefws](https://discuss.elastic.co/u/stefws)\
**Replies:** 0\
**Last updated:** [July 10, 2022, 8:43pm UTC](https://discuss.elastic.co/t/avoid-reinventing-a-reindexing-toolbox/309273 "2022-07-10T20:43:05Z")

</div>

Anyone know of a good CLI toolbox for doing reindexing to save #shards? Or should I create my own set of REST API scripts for this from scratch, surely someone else should have had the same issue before :slight\_smile: E…

---

## [Optimizing storage with fleet integrations](https://discuss.elastic.co/t/optimizing-storage-with-fleet-integrations/309532)

<div class="topic-metadata">

**Author:** [@tsbayne](https://discuss.elastic.co/u/tsbayne)\
**Replies:** 0\
**Last updated:** [July 13, 2022, 1:02pm UTC](https://discuss.elastic.co/t/optimizing-storage-with-fleet-integrations/309532 "2022-07-13T13:02:20Z")

</div>

Our log storage is through the roof with the new elasticstack with fleet set up. How/where can I configure compression options for this?

---

## [Java SearchResponse\<ObjectNode\> serialization](https://discuss.elastic.co/t/java-searchresponse-objectnode-serialization/309523)

<div class="topic-metadata">

**Author:** [@3xil3](https://discuss.elastic.co/u/3xil3)\
**Replies:** 0\
**Last updated:** [July 13, 2022, 11:12am UTC](https://discuss.elastic.co/t/java-searchresponse-objectnode-serialization/309523 "2022-07-13T11:12:36Z")

</div>

it's a simple question, but I can't seem to serialize the SearchResponse back to a json string. What I've tried: final SearchResponse\<ObjectNode\> search1 = client.search( e -\> e.index("myindex") …

---

## [Search query not returning result data](https://discuss.elastic.co/t/search-query-not-returning-result-data/309488)

<div class="topic-metadata">

**Author:** [@jsr](https://discuss.elastic.co/u/jsr)\
**Replies:** 6\
**Last updated:** [July 13, 2022, 11:10am UTC](https://discuss.elastic.co/t/search-query-not-returning-result-data/309488 "2022-07-13T11:10:29Z")

</div>

I tried to fetch data via search query api through postman /\_search if I search through without filter { "query": { "match": { "message": { "query": "matching\_data" } } } } I'm getting…

---

## [Count emails that have more than 10 documents (buckets count)](https://discuss.elastic.co/t/count-emails-that-have-more-than-10-documents-buckets-count/307477)

<div class="topic-metadata">

**Author:** [@jack\_daniels00](https://discuss.elastic.co/u/jack_daniels00)\
**Replies:** 3\
**Last updated:** [July 13, 2022, 8:58am UTC](https://discuss.elastic.co/t/count-emails-that-have-more-than-10-documents-buckets-count/307477 "2022-07-13T08:58:07Z")

</div>

Hi! I have documents in elastic like: { "email": "user@example.com", "subject": "Email subject", "body": "Email body" } And I'm trying to count all unique emails that have more than 10 documents. I can re…

---

## [Failed to start Elasticsearch(/usr/lib/systemd/system/elasticsearch.service; disabled; vendor preset: disabled)](https://discuss.elastic.co/t/failed-to-start-elasticsearch-usr-lib-systemd-system-elasticsearch-service-disabled-vendor-preset-disabled/309514)

<div class="topic-metadata">

**Author:** [@sagar\_hukre](https://discuss.elastic.co/u/sagar_hukre)\
**Replies:** 1\
**Last updated:** [July 13, 2022, 8:43am UTC](https://discuss.elastic.co/t/failed-to-start-elasticsearch-usr-lib-systemd-system-elasticsearch-service-disabled-vendor-preset-disabled/309514 "2022-07-13T08:43:08Z")

</div>

● elasticsearch.service - Elasticsearch Loaded: loaded \`(/usr/lib/systemd/system/elasticsearch.service; disabled; vendor preset: disabled)\` Active: failed (Result: exit-code) since Wed 2022-07-13 14:05:42 IST; 1min…

---

## [Is combined\_script required or not in scripted\_metric?](https://discuss.elastic.co/t/is-combined-script-required-or-not-in-scripted-metric/309502)

<div class="topic-metadata">

**Author:** [@angelo\_c](https://discuss.elastic.co/u/angelo_c)\
**Replies:** 0\
**Last updated:** [July 13, 2022, 7:54am UTC](https://discuss.elastic.co/t/is-combined-script-required-or-not-in-scripted-metric/309502 "2022-07-13T07:54:54Z")

</div>

Hi there, I was reading the documentation for scripted\_metric aggregation here, but I feel it is a bit confusing. I report what written there: map\_script Executed once per document collected. This is a required scrip…

---

## [Failed to process cluster event (index-aliases) within 30s](https://discuss.elastic.co/t/failed-to-process-cluster-event-index-aliases-within-30s/309504)

<div class="topic-metadata">

**Author:** [@Anca\_Muresan](https://discuss.elastic.co/u/Anca_Muresan)\
**Replies:** 0\
**Last updated:** [July 13, 2022, 8:09am UTC](https://discuss.elastic.co/t/failed-to-process-cluster-event-index-aliases-within-30s/309504 "2022-07-13T08:09:54Z")

</div>

Hello everyone , I get this error very frequently Elasticsearch\\Common\\Exceptions\\ServerErrorResponseException: {"error":{"root\_cause":\[{"type":"process\_cluster\_event\_timeout\_exception","reason":"failed to process clus…

---

## [Error Install APM-Agent M1](https://discuss.elastic.co/t/error-install-apm-agent-m1/308805)

<div class="topic-metadata">

**Author:** [@sefhi](https://discuss.elastic.co/u/sefhi)\
**Replies:** 0\
**Last updated:** [July 4, 2022, 10:18am UTC](https://discuss.elastic.co/t/error-install-apm-agent-m1/308805 "2022-07-04T10:18:24Z")

</div>

I'm having some trouble installing Fleet Server in Kibana on an m1 pro. When I run the command sudo ./elastic-agent install -v \\ --fleet-server-es=http://localhost:9200 \\ --fleet-server-service-token=AAEAAWVsYXN…

---

## [Filebeat cannt connect to kibana](https://discuss.elastic.co/t/filebeat-cannt-connect-to-kibana/309433)

<div class="topic-metadata">

**Author:** [@matin44](https://discuss.elastic.co/u/matin44)\
**Replies:** 2\
**Last updated:** [July 13, 2022, 7:29am UTC](https://discuss.elastic.co/t/filebeat-cannt-connect-to-kibana/309433 "2022-07-13T07:29:39Z")

</div>

i try to setup filebeat on redhat when i run the command "filebeat setup -e" i get error message "Exiting: error connecting to Kibana: fail to get the Kibana version ....." i changed the kibana host name at filebeat.y…

---

## [Error on starting elasticsearch](https://discuss.elastic.co/t/error-on-starting-elasticsearch/309493)

<div class="topic-metadata">

**Author:** [@fransrampai](https://discuss.elastic.co/u/fransrampai)\
**Replies:** 0\
**Last updated:** [July 13, 2022, 7:13am UTC](https://discuss.elastic.co/t/error-on-starting-elasticsearch/309493 "2022-07-13T07:13:05Z")

</div>

Hi I am having error when start elasticsearch.8.3.2, please see my logs: Jul 13 09:06:22 rnb03-sbices1 systemd-entrypoint\[22381\]: /usr/share/elasticsearch/bin/systemd-entrypoint: line 7: my\_pwd\_file.tmp: No such file or…

---

## [Query two Indexes, only get results which match in both indexes](https://discuss.elastic.co/t/query-two-indexes-only-get-results-which-match-in-both-indexes/309480)

<div class="topic-metadata">

**Author:** [@manoj-manoharan](https://discuss.elastic.co/u/manoj-manoharan)\
**Replies:** 0\
**Last updated:** [July 13, 2022, 6:41am UTC](https://discuss.elastic.co/t/query-two-indexes-only-get-results-which-match-in-both-indexes/309480 "2022-07-13T06:41:07Z")

</div>

I have a use case in Elasticsearch. I want to search two indexes containing different schemas and get result which matches the query An example of what i want to achieve is here : Query Multiple Indexes, but apply queri…

---

## [Event filter for Elastict Agent and Endpoint Security](https://discuss.elastic.co/t/event-filter-for-elastict-agent-and-endpoint-security/309429)

<div class="topic-metadata">

**Author:** [@Axel\_zendata](https://discuss.elastic.co/u/Axel_zendata)\
**Replies:** 2\
**Last updated:** [July 13, 2022, 5:48am UTC](https://discuss.elastic.co/t/event-filter-for-elastict-agent-and-endpoint-security/309429 "2022-07-13T05:48:08Z")

</div>

Dear all, I created lot of event filter in Security -\> Event Filter for the Elastic Endpoint Agent, but it 's still impossible to use regular expression to exclude event (except for file.path.text). Do you have an id…

---

## [Mapper\_parsing\_Exception\\", \\"reason\\"=\>\\"failed to parse field \[service\] of type \[text\] in document](https://discuss.elastic.co/t/mapper-parsing-exception-reason-failed-to-parse-field-service-of-type-text-in-document/309476)

<div class="topic-metadata">

**Author:** [@skumarp7](https://discuss.elastic.co/u/skumarp7)\
**Replies:** 0\
**Last updated:** [July 13, 2022, 5:47am UTC](https://discuss.elastic.co/t/mapper-parsing-exception-reason-failed-to-parse-field-service-of-type-text-in-document/309476 "2022-07-13T05:47:28Z")

</div>

Hi Team, Elasticsearch is throwing mapper\_parsing\_exception when we try to push logs to an index from different applications. As different applications generates logs with same field \[whose type might differ\], there are…

---

## [How many Log's supports Elasticsearch version Free](https://discuss.elastic.co/t/how-many-logs-supports-elasticsearch-version-free/309466)

<div class="topic-metadata">

**Author:** [@Javier\_Alberto\_Ameli](https://discuss.elastic.co/u/Javier_Alberto_Ameli)\
**Replies:** 1\
**Last updated:** [July 12, 2022, 11:38pm UTC](https://discuss.elastic.co/t/how-many-logs-supports-elasticsearch-version-free/309466 "2022-07-12T23:38:57Z")

</div>

How many machines sending log's simultaneously, does Elasticksearch Stack support the Free version, not licensed?

---

## [Elasticsearch.service failing on Debian](https://discuss.elastic.co/t/elasticsearch-service-failing-on-debian/309366)

<div class="topic-metadata">

**Author:** [@kamie](https://discuss.elastic.co/u/kamie)\
**Replies:** 21\
**Last updated:** [July 12, 2022, 9:25pm UTC](https://discuss.elastic.co/t/elasticsearch-service-failing-on-debian/309366 "2022-07-12T21:25:07Z")

</div>

My operating system is Debian 11 (Bullseye), it runs on a Pentium E5800 I've installed JDK/Java 11 (and set the path), apt-transport-https, the Elasticsearch keys and repo, and have updated my system multiple times. I'v…

---

## [Failed to filter using following grok pattern](https://discuss.elastic.co/t/failed-to-filter-using-following-grok-pattern/309116)

<div class="topic-metadata">

**Author:** [@Rao\_Nelakurti](https://discuss.elastic.co/u/Rao_Nelakurti)\
**Replies:** 2\
**Last updated:** [July 12, 2022, 8:06pm UTC](https://discuss.elastic.co/t/failed-to-filter-using-following-grok-pattern/309116 "2022-07-12T20:06:15Z")

</div>

Hi Team, I'm trying filter following log message, \[2022-07-06T20:54:20.471-0700\] \[LogLevel:INFO\] \[ServerName:xyz.vcn.com\] \[IP:10.x.x.66\]\[AppName:IoT\] \[FlowName: updateDevice\] \[ID:2022-07-06 20:54:20.471\] \[ECID:yja\_Y1eg…

---

## [LogStash::Json::ParserError: Unexpected character ('(' (code 40))](https://discuss.elastic.co/t/logstash-unexpected-character-code-40/309438)

<div class="topic-metadata">

**Author:** [@John\_snow](https://discuss.elastic.co/u/John_snow)\
**Replies:** 9\
**Last updated:** [July 12, 2022, 7:59pm UTC](https://discuss.elastic.co/t/logstash-unexpected-character-code-40/309438 "2022-07-12T19:59:26Z")

</div>

I'm getting following error Error: :exception=\>#\<LogStash::Json::ParserError: Unexpected character ('(' (code 40)): expected a valid value (number, String, array, object, 'true', 'false' or 'null') my conf file looks l…

---

## [Do applications need login info in config to log to Elasticsearch in 7.17 and later](https://discuss.elastic.co/t/do-applications-need-login-info-in-config-to-log-to-elasticsearch-in-7-17-and-later/309457)

<div class="topic-metadata">

**Author:** [@wes.campbell](https://discuss.elastic.co/u/wes.campbell)\
**Replies:** 0\
**Last updated:** [July 12, 2022, 7:57pm UTC](https://discuss.elastic.co/t/do-applications-need-login-info-in-config-to-log-to-elasticsearch-in-7-17-and-later/309457 "2022-07-12T19:57:19Z")

</div>

Do applications need login info in config to log to Elasticsearch in 7.17 and later

---

## [Network Drive connector package](https://discuss.elastic.co/t/network-drive-connector-package/303775)

<div class="topic-metadata">

**Author:** [@Serena\_Chou](https://discuss.elastic.co/u/Serena_Chou)\
**Replies:** 1\
**Last updated:** [July 12, 2022, 7:37pm UTC](https://discuss.elastic.co/t/network-drive-connector-package/303775 "2022-07-12T19:37:00Z")

</div>

Starting in the 8.2 Enterprise Search release, we have a new Elastic Network Drive connector package available for beta. This connector package extends the existing Workplace Search content source catalog, with a fully …

---

## [Downsize Elastic Cluster](https://discuss.elastic.co/t/downsize-elastic-cluster/309454)

<div class="topic-metadata">

**Author:** [@marshall99](https://discuss.elastic.co/u/marshall99)\
**Replies:** 0\
**Last updated:** [July 12, 2022, 6:44pm UTC](https://discuss.elastic.co/t/downsize-elastic-cluster/309454 "2022-07-12T18:44:10Z")

</div>

We have a 6 node elastic cluster on bare metal that was installed by way of helm 7.10.0 We are looking to downsize the cluster from 6 nodes to 3. The 3 that are being decommissioned have the master pods on them along wi…

---

## [How to force a node to become master?](https://discuss.elastic.co/t/how-to-force-a-node-to-become-master/309444)

<div class="topic-metadata">

**Author:** [@pushshift](https://discuss.elastic.co/u/pushshift)\
**Replies:** 0\
**Last updated:** [July 12, 2022, 5:44pm UTC](https://discuss.elastic.co/t/how-to-force-a-node-to-become-master/309444 "2022-07-12T17:44:47Z")

</div>

I upgrades a cluster from version 7.17.5 to 8.3.2 and I'm having issues with master discovery. The node that is set to be the master continues to log this: \[2022-07-12T17:39:00,115\]\[WARN \]\[o.e.c.c.ClusterFormationFailur…

---

## [Using cosineSimilarity function inside aggregation scripts](https://discuss.elastic.co/t/using-cosinesimilarity-function-inside-aggregation-scripts/308046)

<div class="topic-metadata">

**Author:** [@lonewolf](https://discuss.elastic.co/u/lonewolf)\
**Replies:** 2\
**Last updated:** [July 12, 2022, 5:10pm UTC](https://discuss.elastic.co/t/using-cosinesimilarity-function-inside-aggregation-scripts/308046 "2022-07-12T17:10:16Z")

</div>

I am trying to use cosineSimilarity function inside in aggregation script but getting Unknown call \[cosine Similarity\] with \[2\] arguments { "query": { "match\_all": {} }, "aggs": { "group":…

---

## [CodeFirst Implementation For Synthetics Beta TLS, ICMP, HTTP?](https://discuss.elastic.co/t/codefirst-implementation-for-synthetics-beta-tls-icmp-http/309434)

<div class="topic-metadata">

**Author:** [@MarcomPrintable](https://discuss.elastic.co/u/MarcomPrintable)\
**Replies:** 0\
**Last updated:** [July 12, 2022, 3:13pm UTC](https://discuss.elastic.co/t/codefirst-implementation-for-synthetics-beta-tls-icmp-http/309434 "2022-07-12T15:13:41Z")

</div>

First off really enjoying the beta its really nice when things just work and the amount of work that one has to do to get something just works out of the box is nil. But i have a question I understand that the npx packag…

---

## [How to increase/decrease the number count via API on K8s instead of kubectl apply -f?](https://discuss.elastic.co/t/how-to-increase-decrease-the-number-count-via-api-on-k8s-instead-of-kubectl-apply-f/238228)

<div class="topic-metadata">

**Author:** [@longlnk](https://discuss.elastic.co/u/longlnk)\
**Replies:** 3\
**Last updated:** [July 12, 2022, 3:09pm UTC](https://discuss.elastic.co/t/how-to-increase-decrease-the-number-count-via-api-on-k8s-instead-of-kubectl-apply-f/238228 "2022-07-12T15:09:18Z")

</div>

Now, I only increase/decrease in the number count by kubectl apply -f Example: I create with count is 1 cat \<\<EOF | kubectl apply -f - apiVersion: elasticsearch.k8s.elastic.co/v1 kind: Elasticsearch metadata: name: …

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=585)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=587)
