# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=1

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 2

---

## [Snapshot repository](https://discuss.elastic.co/t/snapshot-repository/389276)

<div class="topic-metadata">

**Author:** [@Shahar\_Argov](https://discuss.elastic.co/u/Shahar_Argov)\
**Replies:** 6\
**Last updated:** [August 9, 2026, 8:03am UTC](https://discuss.elastic.co/t/snapshot-repository/389276 "2026-08-09T08:03:24Z")

</div>

hi again, i have a problem with my snapshot repository I'm using the data tiers in the elastic (the data from my winbeats is going from my winlogbeats to the logstash and from there to the elastic hot node, warm node a…

---

## [How to handle ILM for managed system data streams (logs, metrics)](https://discuss.elastic.co/t/how-to-handle-ilm-for-managed-system-data-streams-logs-metrics/389330)

<div class="topic-metadata">

**Author:** [@rex656](https://discuss.elastic.co/u/rex656)\
**Replies:** 1\
**Last updated:** [August 8, 2026, 8:07pm UTC](https://discuss.elastic.co/t/how-to-handle-ilm-for-managed-system-data-streams-logs-metrics/389330 "2026-08-08T20:07:41Z")

</div>

I recently migrated from beats to fleet managed agents (about 500 servers total, mostly windows) and am wondering what best practice is for managing the system managed data streams for logs and metrics (logs-system\*, met…

---

## [Logstash ILM rollover alias unexpectedly treated as Data Stream after backing index deletion](https://discuss.elastic.co/t/logstash-ilm-rollover-alias-unexpectedly-treated-as-data-stream-after-backing-index-deletion/389295)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 2\
**Last updated:** [August 8, 2026, 7:21pm UTC](https://discuss.elastic.co/t/logstash-ilm-rollover-alias-unexpectedly-treated-as-data-stream-after-backing-index-deletion/389295 "2026-08-08T19:21:42Z")

</div>

Hello Folks, I am using Elastic Cloud v8.16. I am sending some data to Elasticsearch using Logstash.Below is the logstash configuration (output to elastic) elasticsearch { hosts =\> '${ELASTIC\_URL}' user =\> "${ELASTIC…

---

## [Does doing a POST query via the devtools update index-pattern?](https://discuss.elastic.co/t/does-doing-a-post-query-via-the-devtools-update-index-pattern/389264)

<div class="topic-metadata">

**Author:** [@Whoami1980](https://discuss.elastic.co/u/Whoami1980)\
**Replies:** 1\
**Last updated:** [August 5, 2026, 4:03pm UTC](https://discuss.elastic.co/t/does-doing-a-post-query-via-the-devtools-update-index-pattern/389264 "2026-08-05T16:03:54Z")

</div>

Does doing a POST query likes these via the devtools update index-pattern? If the answer is yes. Does it impact the data in Elasticsearch? Or its purely visualization? POST /\_query?format=txt { "query": """ FROM …

---

## [Ubuntu 26.04 LTS Support Timeline — Open Source Elasticsearch 8.19.19](https://discuss.elastic.co/t/ubuntu-26-04-lts-support-timeline-open-source-elasticsearch-8-19-19/388964)

<div class="topic-metadata">

**Author:** [@Rex\_Rajat](https://discuss.elastic.co/u/Rex_Rajat)\
**Replies:** 2\
**Last updated:** [August 5, 2026, 7:25am UTC](https://discuss.elastic.co/t/ubuntu-26-04-lts-support-timeline-open-source-elasticsearch-8-19-19/388964 "2026-08-05T07:25:25Z")

</div>

Hi Elastic team, We run open-source Elasticsearch (self-managed) on Ubuntu 24.04 LTS and are evaluating a move to Ubuntu 26.04 LTS. The official Support Matrix doesn't yet list 26.04. Could you share: Expected timelin…

---

## [Inquiry About Quarantined Kibana Task Manager Index File](https://discuss.elastic.co/t/inquiry-about-quarantined-kibana-task-manager-index-file/388947)

<div class="topic-metadata">

**Author:** [@Frances\_Chu](https://discuss.elastic.co/u/Frances_Chu)\
**Replies:** 1\
**Last updated:** [August 3, 2026, 9:04am UTC](https://discuss.elastic.co/t/inquiry-about-quarantined-kibana-task-manager-index-file/388947 "2026-08-03T09:04:25Z")

</div>

We would like to raise a case regarding a quarantined file related to one of our Elasticsearch/Kibana indices. While checking the index UUID, we found that it appears to be related to the following Kibana index ".kiban…

---

## [Merging Deployments](https://discuss.elastic.co/t/merging-deployments/388830)

<div class="topic-metadata">

**Author:** [@Tortoise](https://discuss.elastic.co/u/Tortoise)\
**Replies:** 4\
**Last updated:** [August 1, 2026, 12:42pm UTC](https://discuss.elastic.co/t/merging-deployments/388830 "2026-08-01T12:42:28Z")

</div>

Hello Folks , Say on Cloud i have a deployment ABC & XYZ. I now want to merge these 2 deployments say XYZ to ABC instead of managing both the deployments separately . Could someone share pointers or high level steps , …

---

## [ES Java Client 9.2.4 -\> 9.4.4 performance regression. HttpComponents 5.4.4 -\> 5.6 to blame?](https://discuss.elastic.co/t/es-java-client-9-2-4-9-4-4-performance-regression-httpcomponents-5-4-4-5-6-to-blame/388868)

<div class="topic-metadata">

**Author:** [@peedeeboy](https://discuss.elastic.co/u/peedeeboy)\
**Replies:** 2\
**Last updated:** [July 31, 2026, 4:22pm UTC](https://discuss.elastic.co/t/es-java-client-9-2-4-9-4-4-performance-regression-httpcomponents-5-4-4-5-6-to-blame/388868 "2026-07-31T16:22:33Z")

</div>

Hey friends :waving\_hand: We just upgraded all our ES clusters from 9.2.4 -\> 9.4.4. Server upgrade was buttery smooth, as always! :flexed\_biceps: However, upgrading the ES Java client from 9.2.4 to 9.4.4 we noticed a …

---

## [Removing empty indices](https://discuss.elastic.co/t/removing-empty-indices/388901)

<div class="topic-metadata">

**Author:** [@bbreer](https://discuss.elastic.co/u/bbreer)\
**Replies:** 3\
**Last updated:** [July 31, 2026, 12:43pm UTC](https://discuss.elastic.co/t/removing-empty-indices/388901 "2026-07-31T12:43:19Z")

</div>

I would like to remove these empty indices because I need to free up the shards. I know this is a restricted data stream which may be why no matter what privileges i add to the role, I still can't delete them. Any on…

---

## [Should Master nodes only receive the traffic in an ES cluster?](https://discuss.elastic.co/t/should-master-nodes-only-receive-the-traffic-in-an-es-cluster/388916)

<div class="topic-metadata">

**Author:** [@Aditya\_Sugandhi](https://discuss.elastic.co/u/Aditya_Sugandhi)\
**Replies:** 3\
**Last updated:** [July 30, 2026, 9:19pm UTC](https://discuss.elastic.co/t/should-master-nodes-only-receive-the-traffic-in-an-es-cluster/388916 "2026-07-30T21:19:01Z")

</div>

Currently, I have 16 nodes (5 master + 11 data nodes) in my cluster and via Haproxy I am sending the requests to only the master nodes. Recently, due to some issue one of the master node was flapping and latency spiked …

---

## [Discover fails with "content length bigger than max allowed string" on index with large text field](https://discuss.elastic.co/t/discover-fails-with-content-length-bigger-than-max-allowed-string-on-index-with-large-text-field/388911)

<div class="topic-metadata">

**Author:** [@Mouly\_Infy](https://discuss.elastic.co/u/Mouly_Infy)\
**Replies:** 1\
**Last updated:** [July 30, 2026, 5:23pm UTC](https://discuss.elastic.co/t/discover-fails-with-content-length-bigger-than-max-allowed-string-on-index-with-large-text-field/388911 "2026-07-30T17:23:27Z")

</div>

Hello Connections, We're facing an issue when trying to retrieve documents in Discover, and wanted to get community input on the best long-term fix. Environment: Elastic Stack version: \[8.19.3\] Deployment: self-manag…

---

## [Elastic Serverless Forwarder - Millions of API calls causing excess costs](https://discuss.elastic.co/t/elastic-serverless-forwarder-millions-of-api-calls-causing-excess-costs/388327)

<div class="topic-metadata">

**Author:** [@Watsong](https://discuss.elastic.co/u/Watsong)\
**Replies:** 2\
**Last updated:** [July 30, 2026, 10:17am UTC](https://discuss.elastic.co/t/elastic-serverless-forwarder-millions-of-api-calls-causing-excess-costs/388327 "2026-07-30T10:17:37Z")

</div>

The Elastic Serverless Forwarder AWS Lambda function accesses two credential values: ESF-CLOUD-ID, ESF-API-KEY The Lambda function does not cache the credentials. It retrieves them on every invocation of the Lambda func…

---

## [Readiness check for Elasticsearch coordinator nodes behind a load balancer?](https://discuss.elastic.co/t/readiness-check-for-elasticsearch-coordinator-nodes-behind-a-load-balancer/386690)

<div class="topic-metadata">

**Author:** [@sagar\_cenation](https://discuss.elastic.co/u/sagar_cenation)\
**Replies:** 33\
**Last updated:** [July 29, 2026, 10:54am UTC](https://discuss.elastic.co/t/readiness-check-for-elasticsearch-coordinator-nodes-behind-a-load-balancer/386690 "2026-07-29T10:54:03Z")

</div>

Hello, I am trying to choose the right readiness check for Elasticsearch coordinator nodes behind a load balancer / proxy. We are on Elasticsearch 8.8.2. The coorinator nodes serve search traffic behind a load balancer…

---

## [Search highlights a non-matched field if query contains a nested query](https://discuss.elastic.co/t/search-highlights-a-non-matched-field-if-query-contains-a-nested-query/388844)

<div class="topic-metadata">

**Author:** [@Mehis](https://discuss.elastic.co/u/Mehis)\
**Replies:** 1\
**Last updated:** [July 28, 2026, 1:35pm UTC](https://discuss.elastic.co/t/search-highlights-a-non-matched-field-if-query-contains-a-nested-query/388844 "2026-07-28T13:35:54Z")

</div>

Hello, I am having trouble with the highlight-feature highlighting fields that should not be. This problem only occurs if the search contains a nested query. I have set require\_field\_match to true in my search and my ES…

---

## ["AlreadyClosedException" with "Too Many Open Files" - breaking indexing](https://discuss.elastic.co/t/alreadyclosedexception-with-too-many-open-files-breaking-indexing/388808)

<div class="topic-metadata">

**Author:** [@astrodi](https://discuss.elastic.co/u/astrodi)\
**Replies:** 6\
**Last updated:** [July 27, 2026, 5:17pm UTC](https://discuss.elastic.co/t/alreadyclosedexception-with-too-many-open-files-breaking-indexing/388808 "2026-07-27T17:17:09Z")

</div>

Hello there :waving\_hand: I'm experiencing allocation issues on cluster with 22 data nodes (K8S cluster, each node holds 29-41 shards). In total, there is 122M documents, 13TB of storage consumed and 456 pri. shards + …

---

## [Optimizing wildcard and regex query performance on large indices in Elasticsearch](https://discuss.elastic.co/t/optimizing-wildcard-and-regex-query-performance-on-large-indices-in-elasticsearch/388642)

<div class="topic-metadata">

**Author:** [@Maaz](https://discuss.elastic.co/u/Maaz)\
**Replies:** 4\
**Last updated:** [July 24, 2026, 7:56am UTC](https://discuss.elastic.co/t/optimizing-wildcard-and-regex-query-performance-on-large-indices-in-elasticsearch/388642 "2026-07-24T07:56:06Z")

</div>

Hi everyone, I am working on tuning a search query pipeline in Elasticsearch and running into a performance bottleneck when executing high-frequency wildcard and regular expression searches against a rapidly growing ind…

---

## [.geoip\_database index created in es7 prevents es9 upgrade](https://discuss.elastic.co/t/geoip-database-index-created-in-es7-prevents-es9-upgrade/388618)

<div class="topic-metadata">

**Author:** [@manick02](https://discuss.elastic.co/u/manick02)\
**Replies:** 14\
**Last updated:** [July 24, 2026, 6:22am UTC](https://discuss.elastic.co/t/geoip-database-index-created-in-es7-prevents-es9-upgrade/388618 "2026-07-24T06:22:49Z")

</div>

We follow an es upgrade approach where we reindex the index on every major version upgrade. We noticed during our es9 upgrade from es8, there is a system index .geoip\_database which was created in es7 is not allowing es…

---

## [Where is Elasticsearch storing unmapped field](https://discuss.elastic.co/t/where-is-elasticsearch-storing-unmapped-field/388701)

<div class="topic-metadata">

**Author:** [@ddoroshenko](https://discuss.elastic.co/u/ddoroshenko)\
**Replies:** 7\
**Last updated:** [July 24, 2026, 5:51am UTC](https://discuss.elastic.co/t/where-is-elasticsearch-storing-unmapped-field/388701 "2026-07-24T05:51:26Z")

</div>

I have an index created with index.mode=logsdb and index.mapping.source.mode=synthetic. The mapping also has dynamic: false. If I index a document containing an unmapped field, for example: { "@timestamp": "2026-07-2…

---

## [Elasticsearch S3 Snapshot Repository - Is s3:DeleteObject Mandatory for S3 Repository and SLM?](https://discuss.elastic.co/t/elasticsearch-s3-snapshot-repository-is-s3-deleteobject-mandatory-for-s3-repository-and-slm/388588)

<div class="topic-metadata">

**Author:** [@Shubham\_Khodpe](https://discuss.elastic.co/u/Shubham_Khodpe)\
**Replies:** 5\
**Last updated:** [July 22, 2026, 3:18pm UTC](https://discuss.elastic.co/t/elasticsearch-s3-snapshot-repository-is-s3-deleteobject-mandatory-for-s3-repository-and-slm/388588 "2026-07-22T15:18:44Z")

</div>

Hi Team, We are configuring Elasticsearch 9.1.3 snapshots to an AWS S3 bucket using the repository-s3 plugin and would like to clarify whether s3:DeleteObject permission is mandatory. Environment Elasticsearch Version…

---

## [Problems matching synonyms after stemming](https://discuss.elastic.co/t/problems-matching-synonyms-after-stemming/388548)

<div class="topic-metadata">

**Author:** [@hmpalmeida](https://discuss.elastic.co/u/hmpalmeida)\
**Replies:** 0\
**Last updated:** [July 21, 2026, 5:09pm UTC](https://discuss.elastic.co/t/problems-matching-synonyms-after-stemming/388548 "2026-07-21T17:09:09Z")

</div>

Hello! I'm currently having some problems trying to use a synonym\_graph filter after applying a stemmer. My problem can be replicated with the following "\_analyze" request: \`\`\` { "tokenizer": "whitespace", "filter"…

---

## [Urgent Help Needed Elastic Shutting down ingestion & All the write load is being transferred to one of the hot nodes](https://discuss.elastic.co/t/urgent-help-needed-elastic-shutting-down-ingestion-all-the-write-load-is-being-transferred-to-one-of-the-hot-nodes/388083)

<div class="topic-metadata">

**Author:** [@kkumar123](https://discuss.elastic.co/u/kkumar123)\
**Replies:** 30\
**Last updated:** [July 21, 2026, 2:48pm UTC](https://discuss.elastic.co/t/urgent-help-needed-elastic-shutting-down-ingestion-all-the-write-load-is-being-transferred-to-one-of-the-hot-nodes/388083 "2026-07-21T14:48:33Z")

</div>

I have issue with cluster all the time i can see is queue on one of the hot nodes at a time. node\_name name active queue rejected elastic-frozen2 write 0 0 0 elastic-hot…

---

## [Elasticsearch Migration from Windows to Linux – Swap Enabled and SELinux Enforcing](https://discuss.elastic.co/t/elasticsearch-migration-from-windows-to-linux-swap-enabled-and-selinux-enforcing/388113)

<div class="topic-metadata">

**Author:** [@Shubham\_Khodpe](https://discuss.elastic.co/u/Shubham_Khodpe)\
**Replies:** 5\
**Last updated:** [July 15, 2026, 9:58am UTC](https://discuss.elastic.co/t/elasticsearch-migration-from-windows-to-linux-swap-enabled-and-selinux-enforcing/388113 "2026-07-15T09:58:57Z")

</div>

Hi Team, We are migrating our Elasticsearch 9.1.3 cluster from Windows Server to RHEL Linux (9.8). The environment consists of 2 dedicated master nodes, 4 data nodes, nodes, and 2 Logstash nodes. As part of the Linux p…

---

## [Elasticsearch data encryption](https://discuss.elastic.co/t/elasticsearch-data-encryption/388100)

<div class="topic-metadata">

**Author:** [@Kesavan](https://discuss.elastic.co/u/Kesavan)\
**Replies:** 10\
**Last updated:** [July 13, 2026, 10:17am UTC](https://discuss.elastic.co/t/elasticsearch-data-encryption/388100 "2026-07-13T10:17:42Z")

</div>

HI Everyone, Currently i am using elastic 7.17.5 along with spring boot. Index creation and data save and retrieval is happening via Java only. Below is my requirement, I need to have a data saved in the Elasticsearch…

---

## [Use master/data or cordinating node for search?](https://discuss.elastic.co/t/use-master-data-or-cordinating-node-for-search/388127)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 7\
**Last updated:** [July 11, 2026, 11:00pm UTC](https://discuss.elastic.co/t/use-master-data-or-cordinating-node-for-search/388127 "2026-07-11T23:00:52Z")

</div>

I have six data node, three master and two coordinating (which is also kibana) I am setting up proxy in front. for elk:5601 is easy as it is just kibana. for elk:9200 should I use coordinating nodes or master node or …

---

## [Cost of E5 model usage](https://discuss.elastic.co/t/cost-of-e5-model-usage/388115)

<div class="topic-metadata">

**Author:** [@MR\_INTENSE\_GAMING](https://discuss.elastic.co/u/MR_INTENSE_GAMING)\
**Replies:** 0\
**Last updated:** [July 10, 2026, 10:51am UTC](https://discuss.elastic.co/t/cost-of-e5-model-usage/388115 "2026-07-10T10:51:27Z")

</div>

I reviewed the documentation for the E5 embedding model and found that it is available with the Enterprise subscription. However, upon further reading, I noticed that deploying the model requires an ML node, which incurs…

---

## [Migrate unmanaged index to data stream](https://discuss.elastic.co/t/migrate-unmanaged-index-to-data-stream/387725)

<div class="topic-metadata">

**Author:** [@Ts\_P](https://discuss.elastic.co/u/Ts_P)\
**Replies:** 2\
**Last updated:** [July 10, 2026, 8:24am UTC](https://discuss.elastic.co/t/migrate-unmanaged-index-to-data-stream/387725 "2026-07-10T08:24:58Z")

</div>

Hi, I have an index that receives a large amount of data. It is currently 250 GB in size (Elasticsearch 9.4.2), and data is continuously being ingested into it. I want to migrate it to a data stream. I also want to ap…

---

## [Cannot renew free Basic license on 5.2.2 — register.elastic.co reCAPTCHA shows "Invalid site key"](https://discuss.elastic.co/t/cannot-renew-free-basic-license-on-5-2-2-register-elastic-co-recaptcha-shows-invalid-site-key/387409)

<div class="topic-metadata">

**Author:** [@gbl0915](https://discuss.elastic.co/u/gbl0915)\
**Replies:** 12\
**Last updated:** [July 10, 2026, 12:07am UTC](https://discuss.elastic.co/t/cannot-renew-free-basic-license-on-5-2-2-register-elastic-co-recaptcha-shows-invalid-site-key/387409 "2026-07-10T00:07:11Z")

</div>

Hi, I'm trying to renew the free Basic license for a self-managed Elasticsearch/Kibana 5.2.2 cluster (X-Pack), which uses the one-year Basic license that has to be re-registered. The official self-service page no longe…

---

## [Elastic Mapping For Search and Updates](https://discuss.elastic.co/t/elastic-mapping-for-search-and-updates/387907)

<div class="topic-metadata">

**Author:** [@Harinder\_Singh](https://discuss.elastic.co/u/Harinder_Singh)\
**Replies:** 5\
**Last updated:** [July 9, 2026, 5:57pm UTC](https://discuss.elastic.co/t/elastic-mapping-for-search-and-updates/387907 "2026-07-09T17:57:05Z")

</div>

Hi, I am building an Enterprise level search for a Digital Asset Management where I can have below Entities Asset id, name, source, owner, expirationdate , tags Each of these assets can be tagged to i items , campaig…

---

## [Elasticsearch 7.17.28 Critical Bugs](https://discuss.elastic.co/t/elasticsearch-7-17-28-critical-bugs/387493)

<div class="topic-metadata">

**Author:** [@Abdullah\_Shah](https://discuss.elastic.co/u/Abdullah_Shah)\
**Replies:** 4\
**Last updated:** [July 9, 2026, 8:40am UTC](https://discuss.elastic.co/t/elasticsearch-7-17-28-critical-bugs/387493 "2026-07-09T08:40:31Z")

</div>

Anyone still using Elasticsearch 7.17.28 I'm facing some issues and would like to see if it's a elasticsearch issue or something else Issues like Snapshot repo permission issue Desc: Elasticsearch loses repo access…

---

## [LLM token usage in Elasticsearch Service Billing integration](https://discuss.elastic.co/t/llm-token-usage-in-elasticsearch-service-billing-integration/387893)

<div class="topic-metadata">

**Author:** [@nnikushkin](https://discuss.elastic.co/u/nnikushkin)\
**Replies:** 2\
**Last updated:** [July 9, 2026, 6:59am UTC](https://discuss.elastic.co/t/llm-token-usage-in-elasticsearch-service-billing-integration/387893 "2026-07-09T06:59:29Z")

</div>

Hey guys! I installed Elasticsearch Service Billing integration but cannot find my LLM token usage. I may see it in Elastic Cloud: However, I want to see this info in Elastic integration If it is not possible, how …

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=2)
