# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=101

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 102

---

## [Elasticsearch - start checks failing as rootless containers](https://discuss.elastic.co/t/elasticsearch-start-checks-failing-as-rootless-containers/361622)

<div class="topic-metadata">

**Author:** [@alro](https://discuss.elastic.co/u/alro)\
**Replies:** 4\
**Last updated:** [June 18, 2024, 11:53am UTC](https://discuss.elastic.co/t/elasticsearch-start-checks-failing-as-rootless-containers/361622 "2024-06-18T11:53:58Z")

</div>

Hi I'm trying to get an Elasctsearch cluster running on RHEL9.4 with Podman. My podman-compose files run and the cluster members try to start. but I get the following error message: {"@timestamp":"2024-06-18T09:25:08.…

---

## [Passing search\_after in URL as a query parameter](https://discuss.elastic.co/t/passing-search-after-in-url-as-a-query-parameter/361638)

<div class="topic-metadata">

**Author:** [@aziubin](https://discuss.elastic.co/u/aziubin)\
**Replies:** 0\
**Last updated:** [June 18, 2024, 11:22am UTC](https://discuss.elastic.co/t/passing-search-after-in-url-as-a-query-parameter/361638 "2024-06-18T11:22:52Z")

</div>

Hello! Is it possible to pass the search\_after parameter in URL of GET request somehow? Currently I am using URL like this with body below to paginate big resultset (more than 10000 entries) using search\_after paramete…

---

## [How Elasticsearch does verify JWT tokens?](https://discuss.elastic.co/t/how-elasticsearch-does-verify-jwt-tokens/361581)

<div class="topic-metadata">

**Author:** [@vnovotny98](https://discuss.elastic.co/u/vnovotny98)\
**Replies:** 13\
**Last updated:** [June 18, 2024, 11:16am UTC](https://discuss.elastic.co/t/how-elasticsearch-does-verify-jwt-tokens/361581 "2024-06-18T11:16:04Z")

</div>

Hello, I have 6 node Elasticsearch cluster in acceptance enviroment. I have 2 master, 2 hot and 2 warm nodes. I want to implement authentication via Keycloak. In elasticsearch.yml I configured. xpack.security.authc.t…

---

## [Alerting Rule with link to Discover](https://discuss.elastic.co/t/alerting-rule-with-link-to-discover/361628)

<div class="topic-metadata">

**Author:** [@\_Thomas](https://discuss.elastic.co/u/_Thomas)\
**Replies:** 6\
**Last updated:** [June 18, 2024, 11:11am UTC](https://discuss.elastic.co/t/alerting-rule-with-link-to-discover/361628 "2024-06-18T11:11:15Z")

</div>

Hi Guys, I'm trying to get my head around the following: Is it possible to have a Discover Link included in the E-Mail Alert? The Use-Case is as following: Whenever I receive an Alert over the Mail Connector, I'd lik…

---

## [Is there any way to store settings inside the server's memory, independently of individual indices?](https://discuss.elastic.co/t/is-there-any-way-to-store-settings-inside-the-servers-memory-independently-of-individual-indices/361637)

<div class="topic-metadata">

**Author:** [@mrodent](https://discuss.elastic.co/u/mrodent)\
**Replies:** 0\
**Last updated:** [June 18, 2024, 10:57am UTC](https://discuss.elastic.co/t/is-there-any-way-to-store-settings-inside-the-servers-memory-independently-of-individual-indices/361637 "2024-06-18T10:57:18Z")

</div>

The reason I ask this is because I'm working on a project to index some documents, which may be in a variety of languages. Choosing the default analysers is easy enough. But then I recently decided that I want to slight…

---

## [How can I combine in simple\_query\_string prefix search and phrase search (similar to match\_phrase\_prefix but with other features of simple\_query\_string)](https://discuss.elastic.co/t/how-can-i-combine-in-simple-query-string-prefix-search-and-phrase-search-similar-to-match-phrase-prefix-but-with-other-features-of-simple-query-string/360879)

<div class="topic-metadata">

**Author:** [@Leonid\_P](https://discuss.elastic.co/u/Leonid_P)\
**Replies:** 1\
**Last updated:** [June 18, 2024, 8:04am UTC](https://discuss.elastic.co/t/how-can-i-combine-in-simple-query-string-prefix-search-and-phrase-search-similar-to-match-phrase-prefix-but-with-other-features-of-simple-query-string/360879 "2024-06-18T08:04:31Z")

</div>

I would like to find documents containing search text with the last token (may be) uncompleted like "quick brown f\*" matching "quick brown fox" but not "quick and brave brown fox". It is similar to match\_phrase\_prefix, …

---

## [Elasticsearch .net v8 and operator](https://discuss.elastic.co/t/elasticsearch-net-v8-and-operator/361496)

<div class="topic-metadata">

**Author:** [@Odd\_Erik\_Gronberg](https://discuss.elastic.co/u/Odd_Erik_Gronberg)\
**Replies:** 4\
**Last updated:** [June 18, 2024, 7:44am UTC](https://discuss.elastic.co/t/elasticsearch-net-v8-and-operator/361496 "2024-06-18T07:44:17Z")

</div>

Hi, just started porting our ES facing code from NEST to the new V8 client. I am facing some issues that I would like to get some input on. In NEST I am able to use the AND operator to "join" multiple QueryContainers li…

---

## [After restoring the snapshot, the index is not associated with the data stream](https://discuss.elastic.co/t/after-restoring-the-snapshot-the-index-is-not-associated-with-the-data-stream/361561)

<div class="topic-metadata">

**Author:** [@dxygit1](https://discuss.elastic.co/u/dxygit1)\
**Replies:** 1\
**Last updated:** [June 18, 2024, 6:23am UTC](https://discuss.elastic.co/t/after-restoring-the-snapshot-the-index-is-not-associated-with-the-data-stream/361561 "2024-06-18T06:23:13Z")

</div>

Before deleting, the index was associated with a data stream. After restoring from the snapshot, the data stream was lost. curl -X POST "localhost:9200/\_snapshot/es-backup-log-analysis/log-analysis-2024.06.13-sflp5…

---

## [Unable to generate CSV when querying for just an IP address](https://discuss.elastic.co/t/unable-to-generate-csv-when-querying-for-just-an-ip-address/361620)

<div class="topic-metadata">

**Author:** [@hjazz6](https://discuss.elastic.co/u/hjazz6)\
**Replies:** 0\
**Last updated:** [June 18, 2024, 6:02am UTC](https://discuss.elastic.co/t/unable-to-generate-csv-when-querying-for-just-an-ip-address/361620 "2024-06-18T06:02:39Z")

</div>

Hi, I'm trying to search for an IP address in my data (ES v8.8.0). If I simply enter the IP in Kibana's Discovery's query bar, and I try to export the results into CSV, I get an empty file and the error Encountered an …

---

## [Junit for the elastic search ParsedFilter](https://discuss.elastic.co/t/junit-for-the-elastic-search-parsedfilter/361617)

<div class="topic-metadata">

**Author:** [@Bharathi\_ns](https://discuss.elastic.co/u/Bharathi_ns)\
**Replies:** 0\
**Last updated:** [June 18, 2024, 5:27am UTC](https://discuss.elastic.co/t/junit-for-the-elastic-search-parsedfilter/361617 "2024-06-18T05:27:48Z")

</div>

I am trying to cover Junit for Elasticsearch ParsedFilter. Code: private void returnDeviceColumnValues(List\<String\> uniqueColumnValues, NativeSearchQuery searchQuery) { SearchHits\<ESDashboardEntity\> searchHits = oper…

---

## [Replica allocation concurrent setting](https://discuss.elastic.co/t/replica-allocation-concurrent-setting/361313)

<div class="topic-metadata">

**Author:** [@chrwhy](https://discuss.elastic.co/u/chrwhy)\
**Replies:** 6\
**Last updated:** [June 18, 2024, 5:24am UTC](https://discuss.elastic.co/t/replica-allocation-concurrent-setting/361313 "2024-06-18T05:24:01Z")

</div>

Does anybody know what the replica concurrent setting is? I just set the number\_of\_replicas from 0 to 1 in a production environment with the below settings: cluster.routing.allocation.cluster\_concurrent\_rebalance": "10…

---

## [How to remove ldap](https://discuss.elastic.co/t/how-to-remove-ldap/361590)

<div class="topic-metadata">

**Author:** [@Himsharma](https://discuss.elastic.co/u/Himsharma)\
**Replies:** 2\
**Last updated:** [June 18, 2024, 1:15am UTC](https://discuss.elastic.co/t/how-to-remove-ldap/361590 "2024-06-18T01:15:42Z")

</div>

Hi Team, I am using the elasticsearch version 7.17.9 with three nodes there I have configured the ldap but I am facing issue with ldap password so I want to remove it as I am not able to authenticate any user. Can you …

---

## [Issue Connecting Python to Elasticsearch in Docker Environment](https://discuss.elastic.co/t/issue-connecting-python-to-elasticsearch-in-docker-environment/361507)

<div class="topic-metadata">

**Author:** [@Julia\_Campolim](https://discuss.elastic.co/u/Julia_Campolim)\
**Replies:** 2\
**Last updated:** [June 17, 2024, 11:44pm UTC](https://discuss.elastic.co/t/issue-connecting-python-to-elasticsearch-in-docker-environment/361507 "2024-06-17T23:44:58Z")

</div>

Hi, I need help. I'm working on a college project where I need to use Elasticsearch and Kibana, and access them through Docker. Here is my problem: I created the Docker setup (using docker-compose) following the steps …

---

## [Elasticsearch 7.17 spamming INFO \[monitoring\] log/log.go:184 Non-zero metrics in the last 30s](https://discuss.elastic.co/t/elasticsearch-7-17-spamming-info-monitoring-log-log-go-184-non-zero-metrics-in-the-last-30s/361600)

<div class="topic-metadata">

**Author:** [@joeelasticsearch](https://discuss.elastic.co/u/joeelasticsearch)\
**Replies:** 1\
**Last updated:** [June 17, 2024, 9:52pm UTC](https://discuss.elastic.co/t/elasticsearch-7-17-spamming-info-monitoring-log-log-go-184-non-zero-metrics-in-the-last-30s/361600 "2024-06-17T21:52:48Z")

</div>

Hello, I am supporting a few barebones installations of Elasticsearch running on Kubernetes. Is there a way I can get this log to go away? I do not need to see it every 30s. I've tried using the following but it didn't d…

---

## [elastic\_transport.ConnectionError: Connection error caused by: ConnectionError(Connection error caused by: NewConnectionError(\<urllib3.connection.HTTPConnection object at 0x7fab5b67c950\>: Failed to establish a new connection: \[Errno 111\] Connection refuse](https://discuss.elastic.co/t/elastic-transport-connectionerror-connection-error-caused-by-connectionerror-connection-error-caused-by-newconnectionerror-urllib3-connection-httpconnection-object-at-0x7fab5b67c950-failed-to-establish-a-new-connection-errno-111-connection-refuse/361545)

<div class="topic-metadata">

**Author:** [@red\_beast](https://discuss.elastic.co/u/red_beast)\
**Replies:** 2\
**Last updated:** [June 17, 2024, 10:40am UTC](https://discuss.elastic.co/t/elastic-transport-connectionerror-connection-error-caused-by-connectionerror-connection-error-caused-by-newconnectionerror-urllib3-connection-httpconnection-object-at-0x7fab5b67c950-failed-to-establish-a-new-connection-errno-111-connection-refuse/361545 "2024-06-17T10:40:25Z")

</div>

Hello , I am trying to connect to Elasticsearch using docker but I keep getting connection refused error while elasticsearch is running on localhost:9200 This is my docker-compose file version: '3.8' services: api:…

---

## [Magento How to add custom indexes](https://discuss.elastic.co/t/magento-how-to-add-custom-indexes/361569)

<div class="topic-metadata">

**Author:** [@tonysar](https://discuss.elastic.co/u/tonysar)\
**Replies:** 0\
**Last updated:** [June 17, 2024, 8:57am UTC](https://discuss.elastic.co/t/magento-how-to-add-custom-indexes/361569 "2024-06-17T08:57:32Z")

</div>

Hello. I am new to Elasticsearch . I been using Magento 2 and have installed Elasticsearch and is working . Issue is as follow. within magento 2 , I have many configurable products , each configurable product set as sim…

---

## [The Eland how to support type Keras Pre trained](https://discuss.elastic.co/t/the-eland-how-to-support-type-keras-pre-trained/361555)

<div class="topic-metadata">

**Author:** [@1057888035](https://discuss.elastic.co/u/1057888035)\
**Replies:** 0\
**Last updated:** [June 17, 2024, 3:23am UTC](https://discuss.elastic.co/t/the-eland-how-to-support-type-keras-pre-trained/361555 "2024-06-17T03:23:04Z")

</div>

I want make this pre trained : lingbionlp/AIONER-0415 at main. It contains a file : PubmedBERT-CRF-AIONER.h5, I copied to my model: cc12138/cctestAIONER at main. Run command: docker run -it --rm docker.elastic.co/eland…

---

## [Custom analyzer and phrase search](https://discuss.elastic.co/t/custom-analyzer-and-phrase-search/361486)

<div class="topic-metadata">

**Author:** [@nestor1](https://discuss.elastic.co/u/nestor1)\
**Replies:** 1\
**Last updated:** [June 17, 2024, 12:17am UTC](https://discuss.elastic.co/t/custom-analyzer-and-phrase-search/361486 "2024-06-17T00:17:27Z")

</div>

I have some encrypted text and I need to search on it. Every character in a word consists of 3 sets of 3 characters, and some random 3 characters in between. Example: Character "O" contains of \[\*A1B\*C1E\*D5X\] Character …

---

## [Occurrence of NullPointerException and role not assigned when using elasticsearch-users command in Windows](https://discuss.elastic.co/t/occurrence-of-nullpointerexception-and-role-not-assigned-when-using-elasticsearch-users-command-in-windows/361280)

<div class="topic-metadata">

**Author:** [@mousumis](https://discuss.elastic.co/u/mousumis)\
**Replies:** 2\
**Last updated:** [June 16, 2024, 8:07pm UTC](https://discuss.elastic.co/t/occurrence-of-nullpointerexception-and-role-not-assigned-when-using-elasticsearch-users-command-in-windows/361280 "2024-06-16T20:07:12Z")

</div>

I am attempting to use the elasticsearch-users.bat utility on a windows machine (Windows Server 2022) to create a user. I am running the following command: elasticsearch-users.bat useradd admin\_user -p "testpassword" -r…

---

## [Writing data to Elasticsearch 8 over NGINX reverse proxy fails when Python code running on Ubuntu](https://discuss.elastic.co/t/writing-data-to-elasticsearch-8-over-nginx-reverse-proxy-fails-when-python-code-running-on-ubuntu/360665)

<div class="topic-metadata">

**Author:** [@alrubaa](https://discuss.elastic.co/u/alrubaa)\
**Replies:** 3\
**Last updated:** [June 16, 2024, 7:42pm UTC](https://discuss.elastic.co/t/writing-data-to-elasticsearch-8-over-nginx-reverse-proxy-fails-when-python-code-running-on-ubuntu/360665 "2024-06-16T19:42:58Z")

</div>

I have an Elasticsearch 8.12 cluster on an internal network. I use self certified certificates and everything is running well, I push data into it all the time using Python, no errors and no warnings. I also have an Ngi…

---

## [How can i get the Attachment content from my search](https://discuss.elastic.co/t/how-can-i-get-the-attachment-content-from-my-search/361543)

<div class="topic-metadata">

**Author:** [@Shubham\_007](https://discuss.elastic.co/u/Shubham_007)\
**Replies:** 0\
**Last updated:** [June 16, 2024, 10:28am UTC](https://discuss.elastic.co/t/how-can-i-get-the-attachment-content-from-my-search/361543 "2024-06-16T10:28:06Z")

</div>

Hi everyone i was going through Elastic.Client.Elasticsearch 8.13 and came accross an issue of getting the attachments from my search results This is my Model public class ElasticDocument : IEntity { Analyzers Com…

---

## [I am getting an 403](https://discuss.elastic.co/t/i-am-getting-an-403/361524)

<div class="topic-metadata">

**Author:** [@Poojan\_Mehta](https://discuss.elastic.co/u/Poojan_Mehta)\
**Replies:** 2\
**Last updated:** [June 16, 2024, 8:19am UTC](https://discuss.elastic.co/t/i-am-getting-an-403/361524 "2024-06-16T08:19:11Z")

</div>

Hello, I am getting below error can someone pls guide Failed to install template {:message=\>"Got response code '403' contacting Elasticsearch at URL \<es\_host\>/\_index\_template/ecs-logstash'", :exception=\>LogStash::Outpu…

---

## [Migrate from NEST to new Elastic.Clients.Elasticsearch](https://discuss.elastic.co/t/migrate-from-nest-to-new-elastic-clients-elasticsearch/361526)

<div class="topic-metadata">

**Author:** [@krishnapss](https://discuss.elastic.co/u/krishnapss)\
**Replies:** 0\
**Last updated:** [June 14, 2024, 8:40pm UTC](https://discuss.elastic.co/t/migrate-from-nest-to-new-elastic-clients-elasticsearch/361526 "2024-06-14T20:40:47Z")

</div>

Hi, As the NEST nugget package is deprecated, we are trying to migrate new Elastic.Clients.Elasticsearch. I couldn't find much documentation on the new Elastic.Clients.Elasticsearch. NEST has very detailed examples and…

---

## [Need some help in understanding Why retrieving all snapshots is taking forever](https://discuss.elastic.co/t/need-some-help-in-understanding-why-retrieving-all-snapshots-is-taking-forever/361450)

<div class="topic-metadata">

**Author:** [@kushalOtter](https://discuss.elastic.co/u/kushalOtter)\
**Replies:** 3\
**Last updated:** [June 14, 2024, 6:02pm UTC](https://discuss.elastic.co/t/need-some-help-in-understanding-why-retrieving-all-snapshots-is-taking-forever/361450 "2024-06-14T18:02:31Z")

</div>

Hi all, We are using the elasticsearch for storing the logs of our system via the filebeat and our cluster consists of the following on 6.8 Elasticsearch Cluster "cluster\_name" : "elk", "status" : "green", "timed…

---

## [Https:9200 without user/password and certificate](https://discuss.elastic.co/t/https-9200-without-user-password-and-certificate/361514)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 6\
**Last updated:** [June 14, 2024, 5:43pm UTC](https://discuss.elastic.co/t/https-9200-without-user-password-and-certificate/361514 "2024-06-14T17:43:14Z")

</div>

Can I setup elasticsearch, so I can use curl like this curl https://server:9200 if yes what are the settings in yml

---

## [Incoherences indices](https://discuss.elastic.co/t/incoherences-indices/361268)

<div class="topic-metadata">

**Author:** [@Kirtash](https://discuss.elastic.co/u/Kirtash)\
**Replies:** 1\
**Last updated:** [June 14, 2024, 1:17pm UTC](https://discuss.elastic.co/t/incoherences-indices/361268 "2024-06-14T13:17:03Z")

</div>

Good morning, I think that I have an incoherence between the number of indices in DevTools and Cluster status: In dev Tools with this query: GET \_cat/indices?v&h=index,docs.count,store.size&s=docs.count:desc The res…

---

## [Unit testing new Java Api Client update method with Mockito](https://discuss.elastic.co/t/unit-testing-new-java-api-client-update-method-with-mockito/361497)

<div class="topic-metadata">

**Author:** [@PodarcisMuralis](https://discuss.elastic.co/u/PodarcisMuralis)\
**Replies:** 0\
**Last updated:** [June 14, 2024, 1:06pm UTC](https://discuss.elastic.co/t/unit-testing-new-java-api-client-update-method-with-mockito/361497 "2024-06-14T13:06:13Z")

</div>

Hi, I am trying to write a unit test with JUnit & Mockito for client.update() method but I am stuck. Here is my updateMyId() method to test: var searchRequest = Factory.createDocumentByIdSearchRequest(indexName, id, aP…

---

## [how to update index already created with the latest update deployed in the stack](https://discuss.elastic.co/t/how-to-update-index-already-created-with-the-latest-update-deployed-in-the-stack/361494)

<div class="topic-metadata">

**Author:** [@Ricardo\_Redrao](https://discuss.elastic.co/u/Ricardo_Redrao)\
**Replies:** 1\
**Last updated:** [June 14, 2024, 12:54pm UTC](https://discuss.elastic.co/t/how-to-update-index-already-created-with-the-latest-update-deployed-in-the-stack/361494 "2024-06-14T12:54:26Z")

</div>

Hi everyone, I deployed scripts for various stacks in Logstash to perform the respective ETL processes and filters. However, when I later incorporated new calculations into the stack called "prueba," the updates only im…

---

## [Disable Attachment Processor from ElasticSearch](https://discuss.elastic.co/t/disable-attachment-processor-from-elasticsearch/361401)

<div class="topic-metadata">

**Author:** [@akula.vamshee](https://discuss.elastic.co/u/akula.vamshee)\
**Replies:** 6\
**Last updated:** [June 14, 2024, 12:43pm UTC](https://discuss.elastic.co/t/disable-attachment-processor-from-elasticsearch/361401 "2024-06-14T12:43:06Z")

</div>

Our instance of SonarQube was flagged as having an out-of-date Elasticsearch version (8.11.0) that contains security vulnerabilities. We must upgrade the Elasticsearch version (8.11.0) to (8.11.1). Due to external factor…

---

## [Need Help to Create Cluster with 2 Dedicated Master Node and 3 Data Node](https://discuss.elastic.co/t/need-help-to-create-cluster-with-2-dedicated-master-node-and-3-data-node/361101)

<div class="topic-metadata">

**Author:** [@waheedk](https://discuss.elastic.co/u/waheedk)\
**Replies:** 1\
**Last updated:** [June 14, 2024, 12:30pm UTC](https://discuss.elastic.co/t/need-help-to-create-cluster-with-2-dedicated-master-node-and-3-data-node/361101 "2024-06-14T12:30:59Z")

</div>

Hi, I have a total 5 Instances in Production and I am trying to create below 1: - 2 Dedicated Master Node ( Will be accessible from Http URL in browser as well to see the Stats 2: - 1 Master + Data ( to avoid Brin Spl…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=100)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=102)
