# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=588

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 589

---

## [Masking ecs logs](https://discuss.elastic.co/t/masking-ecs-logs/309324)

<div class="topic-metadata">

**Author:** [@chiragnighut](https://discuss.elastic.co/u/chiragnighut)\
**Replies:** 0\
**Last updated:** [July 11, 2022, 1:24pm UTC](https://discuss.elastic.co/t/masking-ecs-logs/309324 "2022-07-11T13:24:28Z")

</div>

How do I mask Ecslayout based logs based on regex based logic? I am using log4j2 for logging purposes and the layout I am using is EcsLayout. Consider following JSON object which I would be logging using log4j2 ecslayou…

---

## [Question About Removing A Node From A Production ELK Stack](https://discuss.elastic.co/t/question-about-removing-a-node-from-a-production-elk-stack/308589)

<div class="topic-metadata">

**Author:** [@NJMitchell](https://discuss.elastic.co/u/NJMitchell)\
**Replies:** 2\
**Last updated:** [July 11, 2022, 1:23pm UTC](https://discuss.elastic.co/t/question-about-removing-a-node-from-a-production-elk-stack/308589 "2022-07-11T13:23:30Z")

</div>

Hello, I have a question about removing a node from a production ELK Stack. We are removing a server from the stack to repurpose it for another use. After moving shards from the node that we are targeting for removal fr…

---

## [Transform for predefined fields](https://discuss.elastic.co/t/transform-for-predefined-fields/309261)

<div class="topic-metadata">

**Author:** [@Robina\_Dhingra1](https://discuss.elastic.co/u/Robina_Dhingra1)\
**Replies:** 8\
**Last updated:** [July 11, 2022, 11:27am UTC](https://discuss.elastic.co/t/transform-for-predefined-fields/309261 "2022-07-11T11:27:22Z")

</div>

Hi Team elastic, We have a use case, where we created a continuous pivot transform on a source index to get count of status of transactions. If status of any of the transaction changes, the same document appears in dest…

---

## [Logstach configuration](https://discuss.elastic.co/t/logstach-configuration/309306)

<div class="topic-metadata">

**Author:** [@escanor\_sama](https://discuss.elastic.co/u/escanor_sama)\
**Replies:** 1\
**Last updated:** [July 11, 2022, 11:19am UTC](https://discuss.elastic.co/t/logstach-configuration/309306 "2022-07-11T11:19:14Z")

</div>

Hello, Hope everyone is doing well I installed ELK on a Debian recently and I want Logstash to receive logs from another machine (windows) that is in the same network. Can I achieve that without using Filebeat? Can I …

---

## [Elastic8 java client allocation.max\_retries exception](https://discuss.elastic.co/t/elastic8-java-client-allocation-max-retries-exception/308868)

<div class="topic-metadata">

**Author:** [@Idorasi\_Paul](https://discuss.elastic.co/u/Idorasi_Paul)\
**Replies:** 5\
**Last updated:** [July 11, 2022, 10:30am UTC](https://discuss.elastic.co/t/elastic8-java-client-allocation-max-retries-exception/308868 "2022-07-11T10:30:04Z")

</div>

Hello, currently using elasticsearch-java 8.1.3 client to communicate with my es cluster. Index settings looks like this: "settings": { "index": { "number\_of\_shards": 1, "number\_of\_replicas": 7, "…

---

## [Unable to install a specific version of Elastic Stack software (Ubuntu 20.04 LTS)](https://discuss.elastic.co/t/unable-to-install-a-specific-version-of-elastic-stack-software-ubuntu-20-04-lts/309305)

<div class="topic-metadata">

**Author:** [@Rysiu](https://discuss.elastic.co/u/Rysiu)\
**Replies:** 0\
**Last updated:** [July 11, 2022, 9:28am UTC](https://discuss.elastic.co/t/unable-to-install-a-specific-version-of-elastic-stack-software-ubuntu-20-04-lts/309305 "2022-07-11T09:28:39Z")

</div>

Hi, I have Ubuntu 20.04 LTS with the latest updates. root@pk-elk1:/etc/kibana# uname -a Linux pk-elk1 5.13.0-1028-azure #33~20.04.1-Ubuntu SMP Fri Jun 3 15:13:34 UTC 2022 x86\_64 x86\_64 x86\_64 GNU/Linux On this Ubuntu,…

---

## [Cluster in two data centers](https://discuss.elastic.co/t/cluster-in-two-data-centers/309302)

<div class="topic-metadata">

**Author:** [@pszemesy](https://discuss.elastic.co/u/pszemesy)\
**Replies:** 1\
**Last updated:** [July 11, 2022, 9:25am UTC](https://discuss.elastic.co/t/cluster-in-two-data-centers/309302 "2022-07-11T09:25:42Z")

</div>

Hi All, I do have an Elasticsearch cluster where some of the nodes are in an east-US datacenter (the master nodes are located here) and some of them are in a west-US datacenter. I have requested the connections 9200 an…

---

## [Kibana map function](https://discuss.elastic.co/t/kibana-map-function/309259)

<div class="topic-metadata">

**Author:** [@Jathurshan\_Sumandira](https://discuss.elastic.co/u/Jathurshan_Sumandira)\
**Replies:** 1\
**Last updated:** [July 10, 2022, 3:47pm UTC](https://discuss.elastic.co/t/kibana-map-function/309259 "2022-07-10T15:47:52Z")

</div>

I am using the kibana map visualization for visualizing my elastic data. I have data on shopping mall locations. So I use the latitude and the longitude of those locations as geo-points and I created a layer on the map a…

---

## [Heap memory overflow master nodes (continuous GC)](https://discuss.elastic.co/t/heap-memory-overflow-master-nodes-continuous-gc/308465)

<div class="topic-metadata">

**Author:** [@Balaji\_Arun](https://discuss.elastic.co/u/Balaji_Arun)\
**Replies:** 3\
**Last updated:** [July 11, 2022, 8:25am UTC](https://discuss.elastic.co/t/heap-memory-overflow-master-nodes-continuous-gc/308465 "2022-07-11T08:25:25Z")

</div>

Hi everyone, Recently, encountered increases in the heap memory usage in the master nodes (heap memory overflow master nodes continuous garbage collection). I try to debug the root cause using the heap dump saved in the…

---

## [Logstash not working, if installed in a location where the path contains parentheses (on windows)](https://discuss.elastic.co/t/logstash-not-working-if-installed-in-a-location-where-the-path-contains-parentheses-on-windows/309291)

<div class="topic-metadata">

**Author:** [@simon137](https://discuss.elastic.co/u/simon137)\
**Replies:** 0\
**Last updated:** [July 11, 2022, 6:57am UTC](https://discuss.elastic.co/t/logstash-not-working-if-installed-in-a-location-where-the-path-contains-parentheses-on-windows/309291 "2022-07-11T06:57:03Z")

</div>

Hello together, As the title suggests, with a sample path of "C:\\ProgramData\\Test)Test\\logstash", the call to ".\\bin\\logstash.bat" fails with the message: "Test\\logstash\\jdk\\bin\\java.exe" cannot be processed syntactical…

---

## [Multi Match Phrase query](https://discuss.elastic.co/t/multi-match-phrase-query/309290)

<div class="topic-metadata">

**Author:** [@Sahil5](https://discuss.elastic.co/u/Sahil5)\
**Replies:** 0\
**Last updated:** [July 11, 2022, 6:47am UTC](https://discuss.elastic.co/t/multi-match-phrase-query/309290 "2022-07-11T06:47:33Z")

</div>

Hi Team, Does elasticsearch multi\_match phrase query supports custom synonyms in search time? Below is the query { "multi\_match": { "query": "add new document", …

---

## [Feasibility to upsert the documents using Bulk operation](https://discuss.elastic.co/t/feasibility-to-upsert-the-documents-using-bulk-operation/309289)

<div class="topic-metadata">

**Author:** [@bkantu](https://discuss.elastic.co/u/bkantu)\
**Replies:** 0\
**Last updated:** [July 11, 2022, 6:35am UTC](https://discuss.elastic.co/t/feasibility-to-upsert-the-documents-using-bulk-operation/309289 "2022-07-11T06:35:36Z")

</div>

Hi Team, Is there a way to insert a document if the document doesn't exist or else update the document in Elasticsearch using BulkAll? How can we handle not duplicating the records if we do the import twice?

---

## [How to split an existing index based on number of documents](https://discuss.elastic.co/t/how-to-split-an-existing-index-based-on-number-of-documents/309287)

<div class="topic-metadata">

**Author:** [@Aurovindo\_Sahu](https://discuss.elastic.co/u/Aurovindo_Sahu)\
**Replies:** 4\
**Last updated:** [July 11, 2022, 6:18am UTC](https://discuss.elastic.co/t/how-to-split-an-existing-index-based-on-number-of-documents/309287 "2022-07-11T06:18:51Z")

</div>

We have an index of size 70GB which contains 73 million documents and we want to split this index based on number of documents. Is there any way we can divide the current index by taking number of documents into conside…

---

## [OCR integration](https://discuss.elastic.co/t/ocr-integration/308781)

<div class="topic-metadata">

**Author:** [@kanavsha](https://discuss.elastic.co/u/kanavsha)\
**Replies:** 1\
**Last updated:** [July 11, 2022, 6:16am UTC](https://discuss.elastic.co/t/ocr-integration/308781 "2022-07-11T06:16:40Z")

</div>

Hi, We have a requirement where we receive pdf/jpg documents having log content. We need to read those documents and convert them to text and index them. We have been guided to use OCR libraries and then index the cont…

---

## [Analyzer-ik Can we support the 祖-10 participle?](https://discuss.elastic.co/t/analyzer-ik-can-we-support-the-10-participle/309062)

<div class="topic-metadata">

**Author:** [@zhilong](https://discuss.elastic.co/u/zhilong)\
**Replies:** 0\
**Last updated:** [July 7, 2022, 1:46am UTC](https://discuss.elastic.co/t/analyzer-ik-can-we-support-the-10-participle/309062 "2022-07-07T01:46:24Z")

</div>

Can we support the 祖-10 participle? I was unable to support the 祖-10 participle after using the Analyzer - IK test

---

## [About the Elastic Agent category](https://discuss.elastic.co/t/about-the-elastic-agent-category/309279)

<div class="topic-metadata">

**Author:** [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Replies:** 0

</div>

This category is for any questions relating to our Elastic Agent.

---

## [Query\_string with wildcard does not return an explanation (explain=true)](https://discuss.elastic.co/t/query-string-with-wildcard-does-not-return-an-explanation-explain-true/309278)

<div class="topic-metadata">

**Author:** [@Alberto\_Calvo\_Rubio](https://discuss.elastic.co/u/Alberto_Calvo_Rubio)\
**Replies:** 0\
**Last updated:** [July 10, 2022, 9:18pm UTC](https://discuss.elastic.co/t/query-string-with-wildcard-does-not-return-an-explanation-explain-true/309278 "2022-07-10T21:18:49Z")

</div>

Hello, The following query\_string does not return the explanation of the matching (explain=true) GET myindex/\_search?explain=true { "query": { "nested": { "path": "entity", "query": { …

---

## [Issue with Embed Kibana Dashboard](https://discuss.elastic.co/t/issue-with-embed-kibana-dashboard/309275)

<div class="topic-metadata">

**Author:** [@soumilshah1995](https://discuss.elastic.co/u/soumilshah1995)\
**Replies:** 0\
**Last updated:** [July 10, 2022, 9:00pm UTC](https://discuss.elastic.co/t/issue-with-embed-kibana-dashboard/309275 "2022-07-10T21:00:10Z")

</div>

Hello all i have spent almost more than 4 hours reading and resolving this issue I have a dashboard which I am trying top embed on the website I went and created a role and assigned the role to the user and added chan…

---

## [Wondering about REST API difference between \_cat/count vs \_stats](https://discuss.elastic.co/t/wondering-about-rest-api-difference-between-cat-count-vs-stats/309272)

<div class="topic-metadata">

**Author:** [@stefws](https://discuss.elastic.co/u/stefws)\
**Replies:** 0\
**Last updated:** [July 10, 2022, 8:38pm UTC](https://discuss.elastic.co/t/wondering-about-rest-api-difference-between-cat-count-vs-stats/309272 "2022-07-10T20:38:32Z")

</div>

Trying to understand why it seems that indicies/\_stats doesn't return the proper numbers of docs as \_cat/count/index and kibana discover does? eg. finding these samples from a sample index with a simple REST API CLI wra…

---

## [ElasticSearch on NAS](https://discuss.elastic.co/t/elasticsearch-on-nas/309156)

<div class="topic-metadata">

**Author:** [@akassabi](https://discuss.elastic.co/u/akassabi)\
**Replies:** 17\
**Last updated:** [July 10, 2022, 6:48pm UTC](https://discuss.elastic.co/t/elasticsearch-on-nas/309156 "2022-07-10T18:48:23Z")

</div>

We have deployed ES7 to an Oracle PCA environment. This consists of several Oracle VMs connected to an Oracle NAS filer. Initially, the ES data partitions were mounted as NFS, but we are hitting the filer IOPS limits. Ou…

---

## [Watcher: comparing two fields in same Doc?](https://discuss.elastic.co/t/watcher-comparing-two-fields-in-same-doc/309267)

<div class="topic-metadata">

**Author:** [@gabrielfsousa](https://discuss.elastic.co/u/gabrielfsousa)\
**Replies:** 0\
**Last updated:** [July 10, 2022, 2:57pm UTC](https://discuss.elastic.co/t/watcher-comparing-two-fields-in-same-doc/309267 "2022-07-10T14:57:05Z")

</div>

how i compare two fields in same doc ?

---

## [How to use the value in buckets\_path to filter the whole document？](https://discuss.elastic.co/t/how-to-use-the-value-in-buckets-path-to-filter-the-whole-document/309265)

<div class="topic-metadata">

**Author:** [@josephLiu](https://discuss.elastic.co/u/josephLiu)\
**Replies:** 0\
**Last updated:** [July 10, 2022, 2:07pm UTC](https://discuss.elastic.co/t/how-to-use-the-value-in-buckets-path-to-filter-the-whole-document/309265 "2022-07-10T14:07:39Z")

</div>

I have a DSL，i want to use the value return from buckets\_path to filter the whole index. can ES supports this kind of operation？In SQL SERVER like select \* from table where max(datatime) \< (select max(datatime) from …

---

## [Randomise hits results every iterations](https://discuss.elastic.co/t/randomise-hits-results-every-iterations/309260)

<div class="topic-metadata">

**Author:** [@Eddie\_Vuong](https://discuss.elastic.co/u/Eddie_Vuong)\
**Replies:** 5\
**Last updated:** [July 10, 2022, 10:42am UTC](https://discuss.elastic.co/t/randomise-hits-results-every-iterations/309260 "2022-07-10T10:42:34Z")

</div>

Is there any way to randomise the search hits every I rerun a query? Due to the large number of hits, I just want to sample my results and do some statistical test on it. However, I have yet to find a way to randomise t…

---

## [Connecting logstash to Elasticsearch via SSL](https://discuss.elastic.co/t/connecting-logstash-to-elasticsearch-via-ssl/308828)

<div class="topic-metadata">

**Author:** [@dsilvera](https://discuss.elastic.co/u/dsilvera)\
**Replies:** 5\
**Last updated:** [July 10, 2022, 2:01am UTC](https://discuss.elastic.co/t/connecting-logstash-to-elasticsearch-via-ssl/308828 "2022-07-10T02:01:32Z")

</div>

So I have read that since v8.0 Elasticsearch has encryption turned on by default for connections from Logstash, Kabana, Beats. But I'm not finding a guide on how to setup the certificate and connect to Elasticsearch fro…

---

## [Looking for way to search for wildcard with space characters. Does KQL have character escaping?](https://discuss.elastic.co/t/looking-for-way-to-search-for-wildcard-with-space-characters-does-kql-have-character-escaping/309250)

<div class="topic-metadata">

**Author:** [@megaksa](https://discuss.elastic.co/u/megaksa)\
**Replies:** 0\
**Last updated:** [July 9, 2022, 1:57pm UTC](https://discuss.elastic.co/t/looking-for-way-to-search-for-wildcard-with-space-characters-does-kql-have-character-escaping/309250 "2022-07-09T13:57:50Z")

</div>

Basically, I have log strings that I wanted to keep as a wildcard type to be able to search for exact substrings with either wildcard query \*abc\* or with regex /.\*abc.\*/. The problem is that Observability → Logs doesn't…

---

## [The CPU useage of elasticsearch three nodes is not balance](https://discuss.elastic.co/t/the-cpu-useage-of-elasticsearch-three-nodes-is-not-balance/309243)

<div class="topic-metadata">

**Author:** [@zekaifeng](https://discuss.elastic.co/u/zekaifeng)\
**Replies:** 3\
**Last updated:** [July 9, 2022, 11:27am UTC](https://discuss.elastic.co/t/the-cpu-useage-of-elasticsearch-three-nodes-is-not-balance/309243 "2022-07-09T11:27:59Z")

</div>

elasticsearch version：7.10.2 nodes：3 indice config：3 primary shard & 1 Replica I use {"query": {"match\_all": {}} to query 10 pieces of data, and the CPU useage of the three nodes is not balance. node-0: node-1: …

---

## [Not equal condtions in elasticsearch aggregation](https://discuss.elastic.co/t/not-equal-condtions-in-elasticsearch-aggregation/308976)

<div class="topic-metadata">

**Author:** [@hadii](https://discuss.elastic.co/u/hadii)\
**Replies:** 5\
**Last updated:** [July 9, 2022, 5:21am UTC](https://discuss.elastic.co/t/not-equal-condtions-in-elasticsearch-aggregation/308976 "2022-07-09T05:21:23Z")

</div>

I have a rails app that connects to Elasticsearch and the user could define some conditions like (at least),(at most), and ... to compare and find his specific result. everything is fine but now I have to add not equal t…

---

## [Logstash filter if internal networks](https://discuss.elastic.co/t/logstash-filter-if-internal-networks/309238)

<div class="topic-metadata">

**Author:** [@VamPikmin](https://discuss.elastic.co/u/VamPikmin)\
**Replies:** 2\
**Last updated:** [July 9, 2022, 5:07am UTC](https://discuss.elastic.co/t/logstash-filter-if-internal-networks/309238 "2022-07-09T05:07:01Z")

</div>

This is a continuation of my previous thread which Badger kindly solved. I have sflow data coming in with the src\_ip and dst\_ip fields My internal networks are in this range and I'd like them not to be scanned for geoi…

---

## [ECS expect \`target\` value](https://discuss.elastic.co/t/ecs-expect-target-value/308652)

<div class="topic-metadata">

**Author:** [@VamPikmin](https://discuss.elastic.co/u/VamPikmin)\
**Replies:** 8\
**Last updated:** [July 2, 2022, 12:40am UTC](https://discuss.elastic.co/t/ecs-expect-target-value/308652 "2022-07-02T00:40:54Z")

</div>

Hello boys and girls, I'm playing with logstash and sflow codec input Trying to enrich the data with geoip and get this error: \[WARN \]\[logstash.filters.geoip \]\[3\_sflow\] ECS expect \`target\` value \`destination.geo.ip\`…

---

## [If statement not work](https://discuss.elastic.co/t/if-statement-not-work/309183)

<div class="topic-metadata">

**Author:** [@david-a76](https://discuss.elastic.co/u/david-a76)\
**Replies:** 6\
**Last updated:** [July 8, 2022, 6:13pm UTC](https://discuss.elastic.co/t/if-statement-not-work/309183 "2022-07-08T18:13:32Z")

</div>

Hi all, I'm trying to import a sample json file: ... { "id": 2, "timestamp": "2019-08-11T17:55:56Z", "paymentType": "Visa", "name": "Darby Dacks", "gender": "Female", "ip\_address": "77.72.239.47", "purpos…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=587)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=589)
