# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

---

## [About the Elasticsearch category](https://discuss.elastic.co/t/about-the-elasticsearch-category/21)

<div class="topic-metadata">

**Author:** [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Replies:** 0\
**Last updated:** [April 22, 2015, 3:34pm UTC](https://discuss.elastic.co/t/about-the-elasticsearch-category/21 "2015-04-22T15:34:27Z")

</div>

The heart of the free and open Elastic Stack Elasticsearch is a distributed, RESTful search and analytics engine capable of addressing a growing number of use cases. As the heart of the Elastic Stack, it centrally stores…

---

## [Capture Elasticsearch diagnostics](https://discuss.elastic.co/t/capture-elasticsearch-diagnostics/390628)

<div class="topic-metadata">

**Author:** [@smm](https://discuss.elastic.co/u/smm)\
**Replies:** 1\
**Last updated:** [September 26, 2026, 3:50am UTC](https://discuss.elastic.co/t/capture-elasticsearch-diagnostics/390628 "2026-09-26T03:50:04Z")

</div>

Hi there, very soon I am going to purchase elastic licence. In a prior company I had also elastic licences and was used to use the Elasticsearch diagnostics script by the support to collect cluster health parameters. M…

---

## [Logstash at Tenant end or server end?](https://discuss.elastic.co/t/logstash-at-tenant-end-or-server-end/390608)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 1\
**Last updated:** [September 25, 2026, 10:59pm UTC](https://discuss.elastic.co/t/logstash-at-tenant-end-or-server-end/390608 "2026-09-25T22:59:52Z")

</div>

I’m trying to design an architecture where multiple tenants ingest their logs into Elastic. My understanding is that if the requirement is primarily log collection, I can use Elastic Agent, and if additional enrichment,…

---

## [ILM unable to delete old index since upgrade to 8.19.20](https://discuss.elastic.co/t/ilm-unable-to-delete-old-index-since-upgrade-to-8-19-20/390601)

<div class="topic-metadata">

**Author:** [@numpty-boy](https://discuss.elastic.co/u/numpty-boy)\
**Replies:** 0\
**Last updated:** [September 23, 2026, 8:58am UTC](https://discuss.elastic.co/t/ilm-unable-to-delete-old-index-since-upgrade-to-8-19-20/390601 "2026-09-23T08:58:47Z")

</div>

Morning Team, Since upgrading to 8.19.20, I've started getting these errors: policy \[.fleet-actions-results-ilm-policy\] for index \[.ds-.fleet-actions-results-2026.05.02-000014\] on an error step due to a transient error…

---

## [SAN required in cert?](https://discuss.elastic.co/t/san-required-in-cert/390541)

<div class="topic-metadata">

**Author:** [@rik](https://discuss.elastic.co/u/rik)\
**Replies:** 2\
**Last updated:** [September 20, 2026, 7:06pm UTC](https://discuss.elastic.co/t/san-required-in-cert/390541 "2026-09-20T19:06:49Z")

</div>

I am trying to use an ES service from a remote machine, using the cert copied from the container: podman cp app:/usr/share/elasticsearch/config/certs But simply doing a client.info() I am getting a elastic\_transport.Co…

---

## [java.nio.file.NoSuchFileException: /usr/share/elasticsearch/data/\_state/\_pu2t.cfs](https://discuss.elastic.co/t/java-nio-file-nosuchfileexception-usr-share-elasticsearch-data-state-pu2t-cfs/390250)

<div class="topic-metadata">

**Author:** [@TheJ](https://discuss.elastic.co/u/TheJ)\
**Replies:** 15\
**Last updated:** [September 19, 2026, 6:07pm UTC](https://discuss.elastic.co/t/java-nio-file-nosuchfileexception-usr-share-elasticsearch-data-state-pu2t-cfs/390250 "2026-09-19T18:07:12Z")

</div>

Hi, I have a problem with one of my elasticsearch node. For some reason node was shutdown due to some error. When I look into the log, I get the error java.nio.file.NoSuchFileException: /usr/share/elasticsearch/data/\_st…

---

## [Upgrade from 7.17.9 to 8.19.18 to 9.4.3](https://discuss.elastic.co/t/upgrade-from-7-17-9-to-8-19-18-to-9-4-3/390473)

<div class="topic-metadata">

**Author:** [@sundar.s](https://discuss.elastic.co/u/sundar.s)\
**Replies:** 4\
**Last updated:** [September 17, 2026, 10:17am UTC](https://discuss.elastic.co/t/upgrade-from-7-17-9-to-8-19-18-to-9-4-3/390473 "2026-09-17T10:17:24Z")

</div>

Hi Team, I am trying to run upgrades on a dockerized ES environment. With indices created in 7.17.9, I am able to successfuly migrate to 8.19.18, by just bringing up a new container of ES 8.19.18 pointing to the same v…

---

## [Hot/Warm/Cold phases being ignored. Data goes directly to Cold](https://discuss.elastic.co/t/hot-warm-cold-phases-being-ignored-data-goes-directly-to-cold/389910)

<div class="topic-metadata">

**Author:** [@Alberto\_Martinez](https://discuss.elastic.co/u/Alberto_Martinez)\
**Replies:** 7\
**Last updated:** [September 15, 2026, 12:41pm UTC](https://discuss.elastic.co/t/hot-warm-cold-phases-being-ignored-data-goes-directly-to-cold/389910 "2026-09-15T12:41:27Z")

</div>

Hello, As the title says, all my streams share a common ILM policy but somehow it is ignored. All nodes are capable of hot/warm/cold. It is a recent setup and we don't have separate roles yet. Any pointer to wha…

---

## [Processing Heterogeneous IoT Logs with Fluent Bit and Elasticsearch Ingest Pipelines](https://discuss.elastic.co/t/processing-heterogeneous-iot-logs-with-fluent-bit-and-elasticsearch-ingest-pipelines/390311)

<div class="topic-metadata">

**Author:** [@cchaussat](https://discuss.elastic.co/u/cchaussat)\
**Replies:** 0\
**Last updated:** [September 10, 2026, 4:26pm UTC](https://discuss.elastic.co/t/processing-heterogeneous-iot-logs-with-fluent-bit-and-elasticsearch-ingest-pipelines/390311 "2026-09-10T16:26:18Z")

</div>

I would like to report on the experience of developing a simple home automation data collection and processing pipeline able to work with data and metrics from Domoticz and from many other various IoT devices and scripts…

---

## [HA-Cluster: Simple design on prem, self managed](https://discuss.elastic.co/t/ha-cluster-simple-design-on-prem-self-managed/390177)

<div class="topic-metadata">

**Author:** [@smm](https://discuss.elastic.co/u/smm)\
**Replies:** 12\
**Last updated:** [September 9, 2026, 5:33pm UTC](https://discuss.elastic.co/t/ha-cluster-simple-design-on-prem-self-managed/390177 "2026-09-09T17:33:34Z")

</div>

Hi there, I am looking for a simple HA-design for a logging use case, on prem & self managed. Would this be a good design? NODE-1 master, data, ingest, kibana, logstash, redis NODE-2 master, data, ingest, kibana, log…

---

## [Elasticsearch Engineer Learning (Changing Data) Module not loading environment](https://discuss.elastic.co/t/elasticsearch-engineer-learning-changing-data-module-not-loading-environment/389925)

<div class="topic-metadata">

**Author:** [@Etiosa](https://discuss.elastic.co/u/Etiosa)\
**Replies:** 3\
**Last updated:** [September 2, 2026, 4:21pm UTC](https://discuss.elastic.co/t/elasticsearch-engineer-learning-changing-data-module-not-loading-environment/389925 "2026-09-02T16:21:16Z")

</div>

Hi, i have an issue, when i try to to load changing data module in the elastic course it will not load the environment for days now, i have tried different browsers and same thing and other modules open except this on…

---

## [Release Version Dates](https://discuss.elastic.co/t/release-version-dates/390130)

<div class="topic-metadata">

**Author:** [@jameswiggins](https://discuss.elastic.co/u/jameswiggins)\
**Replies:** 3\
**Last updated:** [September 2, 2026, 2:54pm UTC](https://discuss.elastic.co/t/release-version-dates/390130 "2026-09-02T14:54:37Z")

</div>

The documentation states You can upgrade to a higher version if the target version was released after your current version. Upgrades to versions released before your current version are not supported, even if the versi…

---

## [Jakarta.mail dependency downgraded](https://discuss.elastic.co/t/jakarta-mail-dependency-downgraded/390039)

<div class="topic-metadata">

**Author:** [@manick02](https://discuss.elastic.co/u/manick02)\
**Replies:** 2\
**Last updated:** [September 1, 2026, 8:11pm UTC](https://discuss.elastic.co/t/jakarta-mail-dependency-downgraded/390039 "2026-09-01T20:11:07Z")

</div>

I noticed jakarta.mail dependency downgraded from 1.6.8( in 8.18.6 )to 1.6.3 (in 8.19.20) We were tracking the CVE CVE-2025-7962 internally and was wondering if this downgrade made it open it again

---

## [Netapp & elasticsearch?](https://discuss.elastic.co/t/netapp-elasticsearch/390020)

<div class="topic-metadata">

**Author:** [@smm](https://discuss.elastic.co/u/smm)\
**Replies:** 2\
**Last updated:** [September 1, 2026, 4:47am UTC](https://discuss.elastic.co/t/netapp-elasticsearch/390020 "2026-09-01T04:47:01Z")

</div>

I would like to run an Elastic stack on VMware VMs. These VMs should run on NetApp via iSCSI/FC with XFS. It is a good or a bad idea? Does it work as good as local storage? Any input, shared story / experience about thi…

---

## [How to reliably verify a snapshot restore succeeded? Failed shards disappear from \_recovery](https://discuss.elastic.co/t/how-to-reliably-verify-a-snapshot-restore-succeeded-failed-shards-disappear-from-recovery/389912)

<div class="topic-metadata">

**Author:** [@ciprianamza](https://discuss.elastic.co/u/ciprianamza)\
**Replies:** 10\
**Last updated:** [August 30, 2026, 4:03pm UTC](https://discuss.elastic.co/t/how-to-reliably-verify-a-snapshot-restore-succeeded-failed-shards-disappear-from-recovery/389912 "2026-08-30T16:03:41Z")

</div>

Hello, I'd like to raise a possible problem I recently ran into in an internal application, and which I see the current Curator implementation mirrors as well (curator/curator/utils.py at v5.8.4 · elastic/curator · GitH…

---

## [Potential impact of Apache Log4j issue #4255 on Elastic products](https://discuss.elastic.co/t/potential-impact-of-apache-log4j-issue-4255-on-elastic-products/389937)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 2\
**Last updated:** [August 26, 2026, 6:33pm UTC](https://discuss.elastic.co/t/potential-impact-of-apache-log4j-issue-4255-on-elastic-products/389937 "2026-08-26T18:33:20Z")

</div>

Hello, A new Apache Log4j security issue was reported on August 24, 2026: There is also a public PoC/reproduction here: According to the report, the issue affects Log4j's handling of serialized LogEvent objects an…

---

## [Elastic Defend Endpoint Protection Complete message](https://discuss.elastic.co/t/elastic-defend-endpoint-protection-complete-message/389934)

<div class="topic-metadata">

**Author:** [@jpedersm](https://discuss.elastic.co/u/jpedersm)\
**Replies:** 0\
**Last updated:** [August 26, 2026, 2:48pm UTC](https://discuss.elastic.co/t/elastic-defend-endpoint-protection-complete-message/389934 "2026-08-26T14:48:20Z")

</div>

In a lab, I am trying to make a switch on the settings in Elastic Defend. The default is set to protect and notify on items from Malware to ransomware. When changing the settings from Protect to Detect and disabling no…

---

## [Elasticsearch-hadoop Spark 4 compatible release timelines](https://discuss.elastic.co/t/elasticsearch-hadoop-spark-4-compatible-release-timelines/389906)

<div class="topic-metadata">

**Author:** [@Nathan\_Grand](https://discuss.elastic.co/u/Nathan_Grand)\
**Replies:** 7\
**Last updated:** [August 26, 2026, 1:27pm UTC](https://discuss.elastic.co/t/elasticsearch-hadoop-spark-4-compatible-release-timelines/389906 "2026-08-26T13:27:20Z")

</div>

Hi, I'd like to know when a Spark 4 compatible release of GitHub - elastic/elasticsearch-hadoop: Elasticsearch real-time search and analytics natively integrated with Hadoop · GitHub is expected? I believe this might be…

---

## [Indexing a small multi-field text dataset with the Elasticsearch Python client](https://discuss.elastic.co/t/indexing-a-small-multi-field-text-dataset-with-the-elasticsearch-python-client/389858)

<div class="topic-metadata">

**Author:** [@Cagatay\_Aydin](https://discuss.elastic.co/u/Cagatay_Aydin)\
**Replies:** 1\
**Last updated:** [August 24, 2026, 1:17pm UTC](https://discuss.elastic.co/t/indexing-a-small-multi-field-text-dataset-with-the-elasticsearch-python-client/389858 "2026-08-24T13:17:45Z")

</div>

Hi everyone, I have been testing Elasticsearch with a small dataset where each document contains several related text fields rather than one large body field. The dataset has 78 tarot card records. Each record includes…

---

## [ES, kibana both having ca.crt issues?](https://discuss.elastic.co/t/es-kibana-both-having-ca-crt-issues/389738)

<div class="topic-metadata">

**Author:** [@rik](https://discuss.elastic.co/u/rik)\
**Replies:** 12\
**Last updated:** [August 21, 2026, 10:13am UTC](https://discuss.elastic.co/t/es-kibana-both-having-ca-crt-issues/389738 "2026-08-21T10:13:56Z")

</div>

I'm not able to start up either the ES or kibana containers and I suspect the root cause has to do with ca-cert issues. i'm attaching my compose file below for reference with ES, the log shows this error: "@timestamp"…

---

## [Set Custom Agent as Default in Agent Selection](https://discuss.elastic.co/t/set-custom-agent-as-default-in-agent-selection/389809)

<div class="topic-metadata">

**Author:** [@venkatkumar229](https://discuss.elastic.co/u/venkatkumar229)\
**Replies:** 1\
**Last updated:** [August 20, 2026, 8:42pm UTC](https://discuss.elastic.co/t/set-custom-agent-as-default-in-agent-selection/389809 "2026-08-20T20:42:10Z")

</div>

Hi Elastic Team, We have created a custom agent using Elastic Agent Builder. Currently, when a user opens the Agent Builder chat, the Agent Selection is automatically set to “Elastic AI Agent”. Our requirement is to m…

---

## [Recommended Resources](https://discuss.elastic.co/t/recommended-resources/389231)

<div class="topic-metadata">

**Author:** [@Rahul\_Kumar8](https://discuss.elastic.co/u/Rahul_Kumar8)\
**Replies:** 1\
**Last updated:** [August 18, 2026, 7:45am UTC](https://discuss.elastic.co/t/recommended-resources/389231 "2026-08-18T07:45:29Z")

</div>

I could not find any public documentation stating recommended resources for my kibana, elastic and logstash. What would the resource guide be if i had 100GB/day logs ?

---

## [Es9.4.x and jvm supportability matrix](https://discuss.elastic.co/t/es9-4-x-and-jvm-supportability-matrix/389716)

<div class="topic-metadata">

**Author:** [@manick02](https://discuss.elastic.co/u/manick02)\
**Replies:** 5\
**Last updated:** [August 17, 2026, 11:45am UTC](https://discuss.elastic.co/t/es9-4-x-and-jvm-supportability-matrix/389716 "2026-08-17T11:45:31Z")

</div>

I am trying to bring up es9.4.x in openjdk 25, where i would be bringing in the jdk. I dont see a :white\_check\_mark:in the row es9.4.x against openjdk25 in the supportability matrix link. Am i interpreting this matrix wr…

---

## [How to get details about es CVE fixes](https://discuss.elastic.co/t/how-to-get-details-about-es-cve-fixes/389615)

<div class="topic-metadata">

**Author:** [@manick02](https://discuss.elastic.co/u/manick02)\
**Replies:** 7\
**Last updated:** [August 17, 2026, 11:27am UTC](https://discuss.elastic.co/t/how-to-get-details-about-es-cve-fixes/389615 "2026-08-17T11:27:41Z")

</div>

I read somewhere in the forum that Elastic does not discuss about CVE fixes in the forum. What is the right method to reach-out to elastic? There are two things we need to document for every CVE identified in ES - 1 whet…

---

## [Installing es-kb-stack via helm overriding nodeSelector](https://discuss.elastic.co/t/installing-es-kb-stack-via-helm-overriding-nodeselector/389620)

<div class="topic-metadata">

**Author:** [@lesio999](https://discuss.elastic.co/u/lesio999)\
**Replies:** 0\
**Last updated:** [August 14, 2026, 12:26pm UTC](https://discuss.elastic.co/t/installing-es-kb-stack-via-helm-overriding-nodeselector/389620 "2026-08-14T12:26:01Z")

</div>

Hi, I'm fighting installation es-kb-stack installation via helm in cluster when I have Windows and Linux node. I can fix post installation by adding nodeSelector on running statefulset and deployment but could not get i…

---

## [Alert rule using an ES QL query with fork branches and email action on conditional fork1 result](https://discuss.elastic.co/t/alert-rule-using-an-es-ql-query-with-fork-branches-and-email-action-on-conditional-fork1-result/389616)

<div class="topic-metadata">

**Author:** [@mape](https://discuss.elastic.co/u/mape)\
**Replies:** 0\
**Last updated:** [August 14, 2026, 11:11am UTC](https://discuss.elastic.co/t/alert-rule-using-an-es-ql-query-with-fork-branches-and-email-action-on-conditional-fork1-result/389616 "2026-08-14T11:11:46Z")

</div>

Hi. I want to create an Alert Rule using the elasticsearch query which contains an ES QL query with 4 fork branches, each fork running a different query and collecting STATS on different fields. This works all well. N…

---

## [AI chat history retention](https://discuss.elastic.co/t/ai-chat-history-retention/389614)

<div class="topic-metadata">

**Author:** [@venkatkumar229](https://discuss.elastic.co/u/venkatkumar229)\
**Replies:** 2\
**Last updated:** [August 14, 2026, 11:03am UTC](https://discuss.elastic.co/t/ai-chat-history-retention/389614 "2026-08-14T11:03:30Z")

</div>

Hi Team, Could you please confirm how long the Elastic AI Assistant / Agent Builder chat history is retained by default? Is there any default retention period (e.g., 30/60/90 days), and can this retention period be con…

---

## [Error occurred during the signature verification](https://discuss.elastic.co/t/error-occurred-during-the-signature-verification/389364)

<div class="topic-metadata">

**Author:** [@yoitsdope](https://discuss.elastic.co/u/yoitsdope)\
**Replies:** 2\
**Last updated:** [August 12, 2026, 1:25pm UTC](https://discuss.elastic.co/t/error-occurred-during-the-signature-verification/389364 "2026-08-12T13:25:50Z")

</div>

on my kali linux system every time i run apt upgrade i get this error Warning: An error occurred during the signature verification. The repository is not updated and the previous index files will be used. OpenPGP sign…

---

## [Elastic Agent/Fleet - Winlog input missing security events](https://discuss.elastic.co/t/elastic-agent-fleet-winlog-input-missing-security-events/389452)

<div class="topic-metadata">

**Author:** [@Stephen\_P](https://discuss.elastic.co/u/Stephen_P)\
**Replies:** 1\
**Last updated:** [August 12, 2026, 12:47pm UTC](https://discuss.elastic.co/t/elastic-agent-fleet-winlog-input-missing-security-events/389452 "2026-08-12T12:47:07Z")

</div>

Hey all I'm working on deploying a Elastic stac POC but have hit a strange issue with collecting windows security event logs Environment Elasticsearch/Kibana/Fleet Server: 9.5.1 Tested Elastic Agent: 9.5.1 and 9.…

---

## [Elasticsearch Search Results on My Website Become Increasingly Slow After the Index Runs for Several Days](https://discuss.elastic.co/t/elasticsearch-search-results-on-my-website-become-increasingly-slow-after-the-index-runs-for-several-days/389392)

<div class="topic-metadata">

**Author:** [@joeroot](https://discuss.elastic.co/u/joeroot)\
**Replies:** 1\
**Last updated:** [August 11, 2026, 7:53am UTC](https://discuss.elastic.co/t/elasticsearch-search-results-on-my-website-become-increasingly-slow-after-the-index-runs-for-several-days/389392 "2026-08-11T07:53:21Z")

</div>

Hello Elastic Community, I am currently facing one persistent performance issue with the search functionality on my website, which uses Elasticsearch to index and retrieve website content. The core problem is that searc…

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=1)
