# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=10

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 11

---

## [failed to retrieve shard stats from node \[zxt4RAOiRZy9Lol9IdIGfg\]: \[node\_2\]\[10.202.152.18:9300\]\[indices:monitor/stats\[n\]\] request\_id \[77247 683\] timed out after \[15016ms\]](https://discuss.elastic.co/t/failed-to-retrieve-shard-stats-from-node-zxt4raoirzy9lol9idigfg-node-2-10-202-152-18-9300-indices-monitor-stats-n-request-id-77247-683-timed-out-after-15016ms/357076)

<div class="topic-metadata">

**Author:** [@zuomengjun](https://discuss.elastic.co/u/zuomengjun)\
**Replies:** 1\
**Last updated:** [January 12, 2026, 1:34pm UTC](https://discuss.elastic.co/t/failed-to-retrieve-shard-stats-from-node-zxt4raoirzy9lol9idigfg-node-2-10-202-152-18-9300-indices-monitor-stats-n-request-id-77247-683-timed-out-after-15016ms/357076 "2026-01-12T13:34:45Z")

</div>

ES total 3 nodes: 18, 10, 15 ES occasionally reports a timeout, help to see what might be the problem? And the cpu and RAM weren't high at the time This is the elasticsearch server log: \[2024-04-02T17:43:47,318\]\[WARN …

---

## [Failing to Start - License issue?](https://discuss.elastic.co/t/failing-to-start-license-issue/384468)

<div class="topic-metadata">

**Author:** [@aurora](https://discuss.elastic.co/u/aurora)\
**Replies:** 4\
**Last updated:** [January 11, 2026, 9:44pm UTC](https://discuss.elastic.co/t/failing-to-start-license-issue/384468 "2026-01-11T21:44:27Z")

</div>

I’m trying to start ES 9.0.2 as a service. Every time, the service fails with an error 143. One thing of note is that in the logs its telling me my license is not valid despite just using a basic license. I can start ela…

---

## [RHEL 10 support for Elasticsearch 8 and 9](https://discuss.elastic.co/t/rhel-10-support-for-elasticsearch-8-and-9/384461)

<div class="topic-metadata">

**Author:** [@sblack](https://discuss.elastic.co/u/sblack)\
**Replies:** 3\
**Last updated:** [January 10, 2026, 11:34pm UTC](https://discuss.elastic.co/t/rhel-10-support-for-elasticsearch-8-and-9/384461 "2026-01-10T23:34:25Z")

</div>

Does Elasticsearch 8.18.X, 8.19.X and 9.X (plus Logstash, Kibana, Fleet and Beats) support RHEL 10? I am referring to the licensed version and not just the OSS version. A quick perusal indicates that there is no issues …

---

## [Linux System User Elasticsearch](https://discuss.elastic.co/t/linux-system-user-elasticsearch/384456)

<div class="topic-metadata">

**Author:** [@aurora](https://discuss.elastic.co/u/aurora)\
**Replies:** 2\
**Last updated:** [January 10, 2026, 11:39am UTC](https://discuss.elastic.co/t/linux-system-user-elasticsearch/384456 "2026-01-10T11:39:05Z")

</div>

I’m pretty sure I installed v9.0.2 from a tarball on an ubuntu fork, so I didn’t automatically get a no-login user created to run a systemd unit. Are there any elasticsearch specific things I need to know about creating …

---

## [Elastic Agent Logs Disk Usage and Shard Count](https://discuss.elastic.co/t/elastic-agent-logs-disk-usage-and-shard-count/384417)

<div class="topic-metadata">

**Author:** [@jnpetty](https://discuss.elastic.co/u/jnpetty)\
**Replies:** 4\
**Last updated:** [January 7, 2026, 9:44pm UTC](https://discuss.elastic.co/t/elastic-agent-logs-disk-usage-and-shard-count/384417 "2026-01-07T21:44:55Z")

</div>

I’m looking for some help on how to better handle log data generated by Elastic. For example, what looks to be Elastic Agent log data is consuming almost 4.5tb on our frozen tier, double the size of any other dataset on …

---

## [Do Explicit Sort Fields Imply A Filter Context?](https://discuss.elastic.co/t/do-explicit-sort-fields-imply-a-filter-context/384377)

<div class="topic-metadata">

**Author:** [@vanschelven](https://discuss.elastic.co/u/vanschelven)\
**Replies:** 0\
**Last updated:** [January 5, 2026, 7:56pm UTC](https://discuss.elastic.co/t/do-explicit-sort-fields-imply-a-filter-context/384377 "2026-01-05T19:56:06Z")

</div>

\[A\] This page explains the differences between query and filtered context quite well: When there's no need for query context (e.g. because sorting on something else explicitly) filtered context has many advantages. \[…

---

## [Archive functionality and licensing](https://discuss.elastic.co/t/archive-functionality-and-licensing/384340)

<div class="topic-metadata">

**Author:** [@javierE](https://discuss.elastic.co/u/javierE)\
**Replies:** 2\
**Last updated:** [January 5, 2026, 12:36pm UTC](https://discuss.elastic.co/t/archive-functionality-and-licensing/384340 "2026-01-05T12:36:07Z")

</div>

Hi, I’m trying to clarify my understanding of the following paragraph from the documentation: The archive functionality provides slower read-only access to older Elasticsearch data, for compliance or regulatory reas…

---

## [Elasticsearch for TrueNAS indexing](https://discuss.elastic.co/t/elasticsearch-for-truenas-indexing/383894)

<div class="topic-metadata">

**Author:** [@chrislongros](https://discuss.elastic.co/u/chrislongros)\
**Replies:** 6\
**Last updated:** [January 5, 2026, 12:33pm UTC](https://discuss.elastic.co/t/elasticsearch-for-truenas-indexing/383894 "2026-01-05T12:33:19Z")

</div>

How can I use elasticsearch to index my TrueNAS?

---

## [java.io.IOException: Unable to parse response body for Response](https://discuss.elastic.co/t/java-io-ioexception-unable-to-parse-response-body-for-response/384353)

<div class="topic-metadata">

**Author:** [@GQ\_YAN](https://discuss.elastic.co/u/GQ_YAN)\
**Replies:** 6\
**Last updated:** [January 5, 2026, 8:54am UTC](https://discuss.elastic.co/t/java-io-ioexception-unable-to-parse-response-body-for-response/384353 "2026-01-05T08:54:44Z")

</div>

at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1128) ~\[?:?\] at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:628) ~\[?:?\] at java.lang.Thread.run(Thread.java:829)…

---

## [\_count vs track\_total\_hits](https://discuss.elastic.co/t/count-vs-track-total-hits/384346)

<div class="topic-metadata">

**Author:** [@maulik\_trapasiya](https://discuss.elastic.co/u/maulik_trapasiya)\
**Replies:** 3\
**Last updated:** [January 5, 2026, 8:33am UTC](https://discuss.elastic.co/t/count-vs-track-total-hits/384346 "2026-01-05T08:33:47Z")

</div>

in my Elasticsearch index there are around 10M document, pagination based query is happening on this, on UI need to show total count of document matching query along with some data in page-format, there are 2 approach fo…

---

## [Is java client 7.17 compatible with elastic 8.18](https://discuss.elastic.co/t/is-java-client-7-17-compatible-with-elastic-8-18/384194)

<div class="topic-metadata">

**Author:** [@Elastic04](https://discuss.elastic.co/u/Elastic04)\
**Replies:** 8\
**Last updated:** [January 2, 2026, 7:40am UTC](https://discuss.elastic.co/t/is-java-client-7-17-compatible-with-elastic-8-18/384194 "2026-01-02T07:40:07Z")

</div>

We are using Elastic stack version 8.9 currently and Java api client 7.17. we want to upgrade to 9.x. From 8.9 we are migrating to 8.18 or 8.19, then from 8.19 version to 9.x. How should we upgrade java client?

---

## [API key does or does not rely on permissions from user that created it](https://discuss.elastic.co/t/api-key-does-or-does-not-rely-on-permissions-from-user-that-created-it/383663)

<div class="topic-metadata">

**Author:** [@qd-danh](https://discuss.elastic.co/u/qd-danh)\
**Replies:** 14\
**Last updated:** [December 31, 2025, 10:08pm UTC](https://discuss.elastic.co/t/api-key-does-or-does-not-rely-on-permissions-from-user-that-created-it/383663 "2025-12-31T22:08:43Z")

</div>

We had previously been creating API keys with our SSO user accounts. Then we found that after an SSO IdP provider change our users were effectively “different” such that we could no longer edit API keys (e.g. to add or r…

---

## [Weird recall trend with HNSW int8 quantization: Smaller indices show worse recall](https://discuss.elastic.co/t/weird-recall-trend-with-hnsw-int8-quantization-smaller-indices-show-worse-recall/384322)

<div class="topic-metadata">

**Author:** [@viperv](https://discuss.elastic.co/u/viperv)\
**Replies:** 1\
**Last updated:** [December 31, 2025, 4:03pm UTC](https://discuss.elastic.co/t/weird-recall-trend-with-hnsw-int8-quantization-smaller-indices-show-worse-recall/384322 "2025-12-31T16:03:59Z")

</div>

Hi, ​I am performing recall tests on indices containing CLIP vectors of varying sizes (ranging from 500,000 to 4,500,000 vectors). I am using HNSW (with the default parameters) with int8 quantization, and each index has…

---

## [Guidance on language analyzers for non-native languages](https://discuss.elastic.co/t/guidance-on-language-analyzers-for-non-native-languages/384168)

<div class="topic-metadata">

**Author:** [@sibasish.palo](https://discuss.elastic.co/u/sibasish.palo)\
**Replies:** 1\
**Last updated:** [December 31, 2025, 6:53am UTC](https://discuss.elastic.co/t/guidance-on-language-analyzers-for-non-native-languages/384168 "2025-12-31T06:53:02Z")

</div>

i am trying to add some new locale support and looking for guidance on language analyzers to be added for the locales. i have gone through lang-analyzer page to find the appropriate analyzers for the locales which i am t…

---

## [Question about using Elasticsearch for RAG](https://discuss.elastic.co/t/question-about-using-elasticsearch-for-rag/383993)

<div class="topic-metadata">

**Author:** [@bobwiller](https://discuss.elastic.co/u/bobwiller)\
**Replies:** 1\
**Last updated:** [December 31, 2025, 6:37am UTC](https://discuss.elastic.co/t/question-about-using-elasticsearch-for-rag/383993 "2025-12-31T06:37:28Z")

</div>

Just learned about the RAG Playground in Elastic, so I am hoping this is an opportunity to simplify my project: Here is my scenario / goal: We have an old rules-based app that parses store items like bikes, bike parts,…

---

## [Explanation about DiskBBQ parameters](https://discuss.elastic.co/t/explanation-about-diskbbq-parameters/384248)

<div class="topic-metadata">

**Author:** [@viperv](https://discuss.elastic.co/u/viperv)\
**Replies:** 2\
**Last updated:** [December 30, 2025, 5:09pm UTC](https://discuss.elastic.co/t/explanation-about-diskbbq-parameters/384248 "2025-12-30T17:09:43Z")

</div>

Hi, I am looking into using DiskBBQ. I’ve read this blog post, and I noticed there are multiple parameters that can be defined, but there isn’t a thorough explanation about them: cluster size - with a default value of …

---

## [Search\_after for pagination](https://discuss.elastic.co/t/search-after-for-pagination/384309)

<div class="topic-metadata">

**Author:** [@Elastic04](https://discuss.elastic.co/u/Elastic04)\
**Replies:** 4\
**Last updated:** [December 30, 2025, 4:38pm UTC](https://discuss.elastic.co/t/search-after-for-pagination/384309 "2025-12-30T16:38:37Z")

</div>

I want to implement pagination using search\_after instead of from, size. There are different sortings in our website like sort by relevancy or a-z or z-a or lowest to highest… How will the sort values for search\_after co…

---

## [How to exclude already-swiped users when using Elasticsearch for a dating app?](https://discuss.elastic.co/t/how-to-exclude-already-swiped-users-when-using-elasticsearch-for-a-dating-app/384278)

<div class="topic-metadata">

**Author:** [@dmelendez](https://discuss.elastic.co/u/dmelendez)\
**Replies:** 3\
**Last updated:** [December 29, 2025, 2:05pm UTC](https://discuss.elastic.co/t/how-to-exclude-already-swiped-users-when-using-elasticsearch-for-a-dating-app/384278 "2025-12-29T14:05:02Z")

</div>

I’m using Elasticsearch as a matching engine for a dating app. Right now each user is indexed with: a geo\_point filters like age, gender, preferences, activity status With this I make queries like find users wi…

---

## [Understanding forcemerge with only\_expunge\_deletes](https://discuss.elastic.co/t/understanding-forcemerge-with-only-expunge-deletes/383924)

<div class="topic-metadata">

**Author:** [@ma\_br](https://discuss.elastic.co/u/ma_br)\
**Replies:** 2\
**Last updated:** [December 29, 2025, 2:28am UTC](https://discuss.elastic.co/t/understanding-forcemerge-with-only-expunge-deletes/383924 "2025-12-29T02:28:17Z")

</div>

My scenario is the following: i have a live index with a lot of updates that runs out of disk space at some time. The reason is that after some time i have a lot of max size segments (5gb) but the deleted document coun…

---

## [Indexing of large nested object failed in ES 9.1.4](https://discuss.elastic.co/t/indexing-of-large-nested-object-failed-in-es-9-1-4/384239)

<div class="topic-metadata">

**Author:** [@nchalise](https://discuss.elastic.co/u/nchalise)\
**Replies:** 4\
**Last updated:** [December 24, 2025, 9:21am UTC](https://discuss.elastic.co/t/indexing-of-large-nested-object-failed-in-es-9-1-4/384239 "2025-12-24T09:21:16Z")

</div>

Hello All, When we perform indexing in ES 9.1.4 we have encounter issue. Indexing error occurred: method \[POST\], host \[ip:9200\], URI \[/\_bulk?timeout=4m\], status line \[HTTP/1.1 413 Request Entity Too Large\] errors = or…

---

## [Seek Recommended Storage Type for Data Retention](https://discuss.elastic.co/t/seek-recommended-storage-type-for-data-retention/383945)

<div class="topic-metadata">

**Author:** [@houn\_thoeurt](https://discuss.elastic.co/u/houn_thoeurt)\
**Replies:** 3\
**Last updated:** [December 23, 2025, 7:24am UTC](https://discuss.elastic.co/t/seek-recommended-storage-type-for-data-retention/383945 "2025-12-23T07:24:14Z")

</div>

Dear Team, We would like to seek your recommendation on log data retention, as we are implementing the Elastic Stack on-premise. To align with regulatory requirements, we must store the data on NAS storage using the Hot…

---

## [Upgrade from 8 to 9 resolve issues in bulk](https://discuss.elastic.co/t/upgrade-from-8-to-9-resolve-issues-in-bulk/384146)

<div class="topic-metadata">

**Author:** [@Peterro](https://discuss.elastic.co/u/Peterro)\
**Replies:** 8\
**Last updated:** [December 18, 2025, 10:17am UTC](https://discuss.elastic.co/t/upgrade-from-8-to-9-resolve-issues-in-bulk/384146 "2025-12-18T10:17:48Z")

</div>

On the path to version 9 from version 7 I am currently on 8.19. Upgrade assistant shows a lot of deprecation issues that needs to be solved first. Mostly older indexes with compatibility version \< 8.0. It is possible to …

---

## [Hot/Warm Architecture with uniform hardware?](https://discuss.elastic.co/t/hot-warm-architecture-with-uniform-hardware/384152)

<div class="topic-metadata">

**Author:** [@algo](https://discuss.elastic.co/u/algo)\
**Replies:** 5\
**Last updated:** [December 18, 2025, 6:57am UTC](https://discuss.elastic.co/t/hot-warm-architecture-with-uniform-hardware/384152 "2025-12-18T06:57:16Z")

</div>

Is there any benefit to (or any problems with) data tiering if all nodes use the same type of storage media? In the past, I’ve seen suggestions to transition to a hot/warm/cold architecture for different storage media - …

---

## [Elastic cluster is getting down after 2 - 3 hours](https://discuss.elastic.co/t/elastic-cluster-is-getting-down-after-2-3-hours/383971)

<div class="topic-metadata">

**Author:** [@sathish12](https://discuss.elastic.co/u/sathish12)\
**Replies:** 55\
**Last updated:** [December 17, 2025, 10:50am UTC](https://discuss.elastic.co/t/elastic-cluster-is-getting-down-after-2-3-hours/383971 "2025-12-17T10:50:55Z")

</div>

Hi Everyone. I am using elastic 8.13.4 and I have 3 machines with 30 gb of RAM and 1tb of hard disk for each machine. I am creating 2 nodes per each machine through elastic portable download ealsticsearch-8.13.4.tar.gz.…

---

## [When is an error definitely a permanent failure?](https://discuss.elastic.co/t/when-is-an-error-definitely-a-permanent-failure/384083)

<div class="topic-metadata">

**Author:** [@Mo\_B](https://discuss.elastic.co/u/Mo_B)\
**Replies:** 6\
**Last updated:** [December 17, 2025, 7:58am UTC](https://discuss.elastic.co/t/when-is-an-error-definitely-a-permanent-failure/384083 "2025-12-17T07:58:47Z")

</div>

I am using the .NET Elasticsearch client v 9.1.0. I want to check when a response represents a guaranteed permanent failure, i.e. a retry would be guaranteed to fail again (e.g. if the request is malformed, the document …

---

## [Case\_insensitive terms query on \_id field - Is this behavior a bug?](https://discuss.elastic.co/t/case-insensitive-terms-query-on-id-field-is-this-behavior-a-bug/384090)

<div class="topic-metadata">

**Author:** [@khatcher](https://discuss.elastic.co/u/khatcher)\
**Replies:** 1\
**Last updated:** [December 16, 2025, 1:04pm UTC](https://discuss.elastic.co/t/case-insensitive-terms-query-on-id-field-is-this-behavior-a-bug/384090 "2025-12-16T13:04:51Z")

</div>

I have an index with IDs that I manually set to product IDs from the database, and they get prefixed with AHC or CAT, depending on which catalog the products are from. In my general search, I include a terms query that l…

---

## [Optimal JVM Heap size?](https://discuss.elastic.co/t/optimal-jvm-heap-size/384106)

<div class="topic-metadata">

**Author:** [@Aditya\_M](https://discuss.elastic.co/u/Aditya_M)\
**Replies:** 1\
**Last updated:** [December 16, 2025, 11:26am UTC](https://discuss.elastic.co/t/optimal-jvm-heap-size/384106 "2025-12-16T11:26:59Z")

</div>

Hi All, I am looking for verification on the optimal JVM Heap size configuration for our production cluster. We are running on physical nodes with 500 GB of RAM each. I have read two conflicting pieces of advice regar…

---

## [Forming an Elasticsearch cluster](https://discuss.elastic.co/t/forming-an-elasticsearch-cluster/384041)

<div class="topic-metadata">

**Author:** [@SamehSaeed](https://discuss.elastic.co/u/SamehSaeed)\
**Replies:** 3\
**Last updated:** [December 16, 2025, 7:57am UTC](https://discuss.elastic.co/t/forming-an-elasticsearch-cluster/384041 "2025-12-16T07:57:43Z")

</div>

Hello, I’m trying to add a second node to my ES cluster but I’m facing issues with SSL handshake. \[2025-12-14T15:38:54,881\]\[WARN \]\[o.e.t.TcpTransport \] \[SCPRLUWS05\] exception caught on transport layer \[Netty4TcpC…

---

## [Severe Performance Degradation After Adding High-Cardinality Text Field to Large Index](https://discuss.elastic.co/t/severe-performance-degradation-after-adding-high-cardinality-text-field-to-large-index/378571)

<div class="topic-metadata">

**Author:** [@Dimitris\_Makris](https://discuss.elastic.co/u/Dimitris_Makris)\
**Replies:** 12\
**Last updated:** [December 15, 2025, 9:23pm UTC](https://discuss.elastic.co/t/severe-performance-degradation-after-adding-high-cardinality-text-field-to-large-index/378571 "2025-12-15T21:23:59Z")

</div>

I'm experiencing a significant performance issue after adding a new multi-valued text field to a large Elasticsearch index and would appreciate insights from anyone who has faced similar challenges. Setup: Elasticsear…

---

## [ML rules How to handle timezone (UTC GMT-3) and alert duration in notifications?](https://discuss.elastic.co/t/ml-rules-how-to-handle-timezone-utc-gmt-3-and-alert-duration-in-notifications/384089)

<div class="topic-metadata">

**Author:** [@sguerrero](https://discuss.elastic.co/u/sguerrero)\
**Replies:** 0\
**Last updated:** [December 15, 2025, 5:55pm UTC](https://discuss.elastic.co/t/ml-rules-how-to-handle-timezone-utc-gmt-3-and-alert-duration-in-notifications/384089 "2025-12-15T17:55:27Z")

</div>

Hello community, We are currently using kibana machine learning anomaly detection alerts (anomaly detection jobs) with email actions triggered “for each alert \> on status change”. We have two related requirements regar…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=9)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=11)
