# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=102

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 103

---

## [Need Help to Create Cluster with 2 Dedicated Master Node and 3 Data Node](https://discuss.elastic.co/t/need-help-to-create-cluster-with-2-dedicated-master-node-and-3-data-node/361101)

<div class="topic-metadata">

**Author:** [@waheedk](https://discuss.elastic.co/u/waheedk)\
**Replies:** 1\
**Last updated:** [June 14, 2024, 12:30pm UTC](https://discuss.elastic.co/t/need-help-to-create-cluster-with-2-dedicated-master-node-and-3-data-node/361101 "2024-06-14T12:30:59Z")

</div>

Hi, I have a total 5 Instances in Production and I am trying to create below 1: - 2 Dedicated Master Node ( Will be accessible from Http URL in browser as well to see the Stats 2: - 1 Master + Data ( to avoid Brin Spl…

---

## [Simple .NET logger does not work using NuGet 'Elastic.Extensions.Logging' v8.11.1](https://discuss.elastic.co/t/simple-net-logger-does-not-work-using-nuget-elastic-extensions-logging-v8-11-1/361489)

<div class="topic-metadata">

**Author:** [@HeikoW](https://discuss.elastic.co/u/HeikoW)\
**Replies:** 0\
**Last updated:** [June 14, 2024, 12:19pm UTC](https://discuss.elastic.co/t/simple-net-logger-does-not-work-using-nuget-elastic-extensions-logging-v8-11-1/361489 "2024-06-14T12:19:46Z")

</div>

Elastic.Extensions.Logging (NuGet v8.11.1 dotnet 8) : I'm trying to get some simple logging to Elasticsearch DataStream working with a .net8 console application using the NuGet package Elastic.Extensions.Logging. I'm no…

---

## [Timestamp in document is different from shown in kibana](https://discuss.elastic.co/t/timestamp-in-document-is-different-from-shown-in-kibana/361466)

<div class="topic-metadata">

**Author:** [@gbL2k](https://discuss.elastic.co/u/gbL2k)\
**Replies:** 6\
**Last updated:** [June 14, 2024, 11:22am UTC](https://discuss.elastic.co/t/timestamp-in-document-is-different-from-shown-in-kibana/361466 "2024-06-14T11:22:20Z")

</div>

Hello everyone! I bet its something really basic but I dont want to waste any more time by trying to find the solution myself. My issue is that in kibana the timestamp is correct and shows the correct time however in t…

---

## [Distribution of Indexing Load across specific Data Nodes for Cold Tier](https://discuss.elastic.co/t/distribution-of-indexing-load-across-specific-data-nodes-for-cold-tier/361463)

<div class="topic-metadata">

**Author:** [@mehdi-lamrani](https://discuss.elastic.co/u/mehdi-lamrani)\
**Replies:** 5\
**Last updated:** [June 14, 2024, 8:03am UTC](https://discuss.elastic.co/t/distribution-of-indexing-load-across-specific-data-nodes-for-cold-tier/361463 "2024-06-14T08:03:03Z")

</div>

Hi, I have 4 data nodes and 1 ingest Node Nodes 1,2,3 are full to 50%, with a capacity ot 10 Terabytes each I attached a fourth data node, Node 4, with an ILM pointing to its storage for cold tier. This fourth no…

---

## [Pdf documents specified in the sitemap are not being indexed by web crawler](https://discuss.elastic.co/t/pdf-documents-specified-in-the-sitemap-are-not-being-indexed-by-web-crawler/361454)

<div class="topic-metadata">

**Author:** [@vsachdeva](https://discuss.elastic.co/u/vsachdeva)\
**Replies:** 2\
**Last updated:** [June 14, 2024, 4:01am UTC](https://discuss.elastic.co/t/pdf-documents-specified-in-the-sitemap-are-not-being-indexed-by-web-crawler/361454 "2024-06-14T04:01:32Z")

</div>

Hello, I am trying to index a set of PDF documents using the web crawler. The deployment is in GCP cloud and the PDF documents are specified in the sitemap, which is documented in the robots.txt file. I am not using wo…

---

## [Problem in setting up a Watcher](https://discuss.elastic.co/t/problem-in-setting-up-a-watcher/361322)

<div class="topic-metadata">

**Author:** [@SamuelSMendes](https://discuss.elastic.co/u/SamuelSMendes)\
**Replies:** 3\
**Last updated:** [June 13, 2024, 6:55pm UTC](https://discuss.elastic.co/t/problem-in-setting-up-a-watcher/361322 "2024-06-13T18:55:37Z")

</div>

I've been trying to setup a Watcher that could print the following fields: monitor.name monitor.type url.full monitor.status So far this was my configuration: { "trigger": { "schedule": { "interval": "5m"…

---

## [\[logstash.outputs.opensearch\]\[main\]\[9182 Retrying individual bulk actions that failed or were rejected by the previous bulk request {:count=\>125}](https://discuss.elastic.co/t/logstash-outputs-opensearch-main-9182-retrying-individual-bulk-actions-that-failed-or-were-rejected-by-the-previous-bulk-request-count-125/361408)

<div class="topic-metadata">

**Author:** [@Rathiga\_Thambu](https://discuss.elastic.co/u/Rathiga_Thambu)\
**Replies:** 7\
**Last updated:** [June 13, 2024, 2:41pm UTC](https://discuss.elastic.co/t/logstash-outputs-opensearch-main-9182-retrying-individual-bulk-actions-that-failed-or-were-rejected-by-the-previous-bulk-request-count-125/361408 "2024-06-13T14:41:16Z")

</div>

bin/logstash -f /opt/logstash-8.9.0/config/conf.d/pipe.conf \[2024-06-13T12:42:19,876\]\[INFO \]\[logstash.outputs.opensearch\]\[main\]\[91823b58f6fb0958c7671051e63dcf1ae4101824338810d25e044a5a52cd36e4\] Retrying failed action {:…

---

## [Manage list of value in a watcher](https://discuss.elastic.co/t/manage-list-of-value-in-a-watcher/361427)

<div class="topic-metadata">

**Author:** [@gnzlnx](https://discuss.elastic.co/u/gnzlnx)\
**Replies:** 0\
**Last updated:** [June 13, 2024, 2:10pm UTC](https://discuss.elastic.co/t/manage-list-of-value-in-a-watcher/361427 "2024-06-13T14:10:01Z")

</div>

Hello, I want to create a watcher that checks some patterns and get IPs, but I want to exclude a list of IPs. Is there any way to manage this list of IP out of the watcher or in a parameter and that will be retrieved d…

---

## [Does elastic prune query terms automatically if the query is very long?](https://discuss.elastic.co/t/does-elastic-prune-query-terms-automatically-if-the-query-is-very-long/361422)

<div class="topic-metadata">

**Author:** [@misslorac](https://discuss.elastic.co/u/misslorac)\
**Replies:** 0\
**Last updated:** [June 13, 2024, 1:34pm UTC](https://discuss.elastic.co/t/does-elastic-prune-query-terms-automatically-if-the-query-is-very-long/361422 "2024-06-13T13:34:47Z")

</div>

Hi, I notice that elasticsearch by default provides disjunction semantics for query terms, and therefore use dynamic pruning techniques to accelerate the query execution. However, if the query is very long, say contains…

---

## [SSL "wrong version number"](https://discuss.elastic.co/t/ssl-wrong-version-number/361352)

<div class="topic-metadata">

**Author:** [@ebates](https://discuss.elastic.co/u/ebates)\
**Replies:** 4\
**Last updated:** [June 13, 2024, 12:30pm UTC](https://discuss.elastic.co/t/ssl-wrong-version-number/361352 "2024-06-13T12:30:52Z")

</div>

I had a working elasticsearch 7.x with SSL configured. I upgraded to elasticsearch 8.14 and now whenever I attempt to connect via curl I get an error message from the OpenSSL lib: # curl -vvv --cacert /etc/elasticsearc…

---

## [Backup and update the document](https://discuss.elastic.co/t/backup-and-update-the-document/361338)

<div class="topic-metadata">

**Author:** [@shrm](https://discuss.elastic.co/u/shrm)\
**Replies:** 3\
**Last updated:** [June 13, 2024, 12:22pm UTC](https://discuss.elastic.co/t/backup-and-update-the-document/361338 "2024-06-13T12:22:30Z")

</div>

How to backup the documents and restore them if I change my mind after updating them? I want to make an update from the current data with some new fields. The content of the document is huge and if I want to reverse the…

---

## [How can create index name automatically by filebeat?](https://discuss.elastic.co/t/how-can-create-index-name-automatically-by-filebeat/361344)

<div class="topic-metadata">

**Author:** [@alex\_zolat](https://discuss.elastic.co/u/alex_zolat)\
**Replies:** 12\
**Last updated:** [June 13, 2024, 12:07pm UTC](https://discuss.elastic.co/t/how-can-create-index-name-automatically-by-filebeat/361344 "2024-06-13T12:07:26Z")

</div>

My filebeat is working now want to know how can config it to create it index automatically with hostname ? my configuration is such as folllow : ###################### Filebeat Configuration Example ###################…

---

## [Elastic-agent without data-stream](https://discuss.elastic.co/t/elastic-agent-without-data-stream/361093)

<div class="topic-metadata">

**Author:** [@Viktor\_Movita](https://discuss.elastic.co/u/Viktor_Movita)\
**Replies:** 4\
**Last updated:** [June 13, 2024, 8:05am UTC](https://discuss.elastic.co/t/elastic-agent-without-data-stream/361093 "2024-06-13T08:05:36Z")

</div>

Hello everyone, I previously monitored my Linux servers using Filebeat and Metricbeat agents. The data from each of them went to a dedicated index in Elasticsearch based on the default ECS template. Now I want to switc…

---

## [Poor Performance After Migrating 8.13](https://discuss.elastic.co/t/poor-performance-after-migrating-8-13/361197)

<div class="topic-metadata">

**Author:** [@jackson\_alvarez](https://discuss.elastic.co/u/jackson_alvarez)\
**Replies:** 1\
**Last updated:** [June 13, 2024, 7:58am UTC](https://discuss.elastic.co/t/poor-performance-after-migrating-8-13/361197 "2024-06-13T07:58:15Z")

</div>

Hi everyone, We recently migrated our Elasticsearch clusters from version 7.10.2 to 8.13.0 and have noticed an increase in search latency. Our shard configuration, cluster, and index settings remain unchanged. To inve…

---

## [Random timeouts at webhook connectors to MS Teams from Elastic Watcher](https://discuss.elastic.co/t/random-timeouts-at-webhook-connectors-to-ms-teams-from-elastic-watcher/361367)

<div class="topic-metadata">

**Author:** [@momher](https://discuss.elastic.co/u/momher)\
**Replies:** 0\
**Last updated:** [June 13, 2024, 2:44am UTC](https://discuss.elastic.co/t/random-timeouts-at-webhook-connectors-to-ms-teams-from-elastic-watcher/361367 "2024-06-13T02:44:22Z")

</div>

Random timeouts at webhook connectors to MS Teams from Elastic Watcher. We are leveraging Elastic Watchers and the receive the following error message immediately upon a failure "id": "new\_alerts\_to\_teams", "type": "w…

---

## [\[2024-06-06T00:16:32,277\]\[ERROR\]\[o.e.b.Elasticsearch \] \[server.domain.co.uk\] fatal exception while booting Elasticsearch java.lang.NullPointerException: Cannot invoke "org.elasticsearch.nativeaccess.Systemd.notify\_ready()" because "this.systemd" is](https://discuss.elastic.co/t/2024-06-06t0032-277-error-o-e-b-elasticsearch-server-domain-co-uk-fatal-exception-while-booting-elasticsearch-java-lang-nullpointerexception-cannot-invoke-org-elasticsearch-nativeaccess-systemd-notify-ready-because-this-systemd-is/360895)

<div class="topic-metadata">

**Author:** [@Rezwan\_Ahmed\_Sami](https://discuss.elastic.co/u/Rezwan_Ahmed_Sami)\
**Replies:** 17\
**Last updated:** [June 12, 2024, 6:56pm UTC](https://discuss.elastic.co/t/2024-06-06t0032-277-error-o-e-b-elasticsearch-server-domain-co-uk-fatal-exception-while-booting-elasticsearch-java-lang-nullpointerexception-cannot-invoke-org-elasticsearch-nativeaccess-systemd-notify-ready-because-this-systemd-is/360895 "2024-06-12T18:56:04Z")

</div>

\[2024-06-06T00:16:32,277\]\[ERROR\]\[o.e.b.Elasticsearch \] \[server.domain.co.uk\] fatal exception while booting Elasticsearch java.lang.NullPointerException: Cannot invoke "org.elasticsearch.nativeaccess.Systemd.notify\_…

---

## [PHP Notice: Indirect modification of overloaded element](https://discuss.elastic.co/t/php-notice-indirect-modification-of-overloaded-element/361356)

<div class="topic-metadata">

**Author:** [@chongshengdz](https://discuss.elastic.co/u/chongshengdz)\
**Replies:** 0\
**Last updated:** [June 12, 2024, 6:48pm UTC](https://discuss.elastic.co/t/php-notice-indirect-modification-of-overloaded-element/361356 "2024-06-12T18:48:09Z")

</div>

end($results\['hits'\]\['hits'\]); the above line getting the below error, please help. PHP Notice: Indirect modification of overloaded element of Elastic\\Elasticsearch\\Response\\Elasticsearch has no effect i am using ela…

---

## [Elasticsearch does not remove shards on closing due to locking issues](https://discuss.elastic.co/t/elasticsearch-does-not-remove-shards-on-closing-due-to-locking-issues/361321)

<div class="topic-metadata">

**Author:** [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Replies:** 3\
**Last updated:** [June 12, 2024, 3:49pm UTC](https://discuss.elastic.co/t/elasticsearch-does-not-remove-shards-on-closing-due-to-locking-issues/361321 "2024-06-12T15:49:47Z")

</div>

Hey, we have an issue with out 7.18.18 cluster. It seems that closing a shard is throwing issues. This happens with several data nodes, so it's not a single glitch. This has never happened with out previous 7.12 version…

---

## [Ingest pipelines with cloned from filebeat ingest pipeline do not act on additinal processor](https://discuss.elastic.co/t/ingest-pipelines-with-cloned-from-filebeat-ingest-pipeline-do-not-act-on-additinal-processor/361332)

<div class="topic-metadata">

**Author:** [@Ajay\_Bhatnagar](https://discuss.elastic.co/u/Ajay_Bhatnagar)\
**Replies:** 0\
**Last updated:** [June 12, 2024, 2:08pm UTC](https://discuss.elastic.co/t/ingest-pipelines-with-cloned-from-filebeat-ingest-pipeline-do-not-act-on-additinal-processor/361332 "2024-06-12T14:08:31Z")

</div>

I tried to create a new ingest pipeline cloning from existing filebeat ingest pipeline and tried to add additional grok processor to add and modify fields. When tested the pipeline from simulation with single document o…

---

## [the maximum number of documents in an elasticsearch index and difference about stats and count](https://discuss.elastic.co/t/the-maximum-number-of-documents-in-an-elasticsearch-index-and-difference-about-stats-and-count/361328)

<div class="topic-metadata">

**Author:** [@Vincenzo\_Picarelli](https://discuss.elastic.co/u/Vincenzo_Picarelli)\
**Replies:** 1\
**Last updated:** [June 12, 2024, 2:02pm UTC](https://discuss.elastic.co/t/the-maximum-number-of-documents-in-an-elasticsearch-index-and-difference-about-stats-and-count/361328 "2024-06-12T14:02:24Z")

</div>

I have an index in elasticsearch with only 1 primary shards e 0 replica. When I do GET /index/\_count, the result is 100,815. When I do GET /index/\_stats, the result is 64,893,983. Each doc has nested fields. My questi…

---

## [Which DB is more flexible for logstash integration](https://discuss.elastic.co/t/which-db-is-more-flexible-for-logstash-integration/361326)

<div class="topic-metadata">

**Author:** [@anguri\_sudhakar](https://discuss.elastic.co/u/anguri_sudhakar)\
**Replies:** 6\
**Last updated:** [June 12, 2024, 1:40pm UTC](https://discuss.elastic.co/t/which-db-is-more-flexible-for-logstash-integration/361326 "2024-06-12T13:40:15Z")

</div>

HI , My question is which DB is more reliable for Logstash-8 version Synk. Is it Logstash ------\> MongoDB ..? is it InflexDB --------\> InflexDB..? Thanks, Sudhakar Anguri

---

## [Failed to complete action: snapshot. \<class 'KeyError'\>: 'indices'](https://discuss.elastic.co/t/failed-to-complete-action-snapshot-class-keyerror-indices/361109)

<div class="topic-metadata">

**Author:** [@Mayank\_Kumar2](https://discuss.elastic.co/u/Mayank_Kumar2)\
**Replies:** 3\
**Last updated:** [June 12, 2024, 1:17pm UTC](https://discuss.elastic.co/t/failed-to-complete-action-snapshot-class-keyerror-indices/361109 "2024-06-12T13:17:45Z")

</div>

Hello, I am stucked here, so I have configured curator to take snapshots on tha daily basis. but it fails with the error "Failed to complete action: snapshot. \<class 'KeyError'\>: 'indices'" when I manually ran the cur…

---

## [Is there any tool outside that allows me to write JavaScript code as Scripts?](https://discuss.elastic.co/t/is-there-any-tool-outside-that-allows-me-to-write-javascript-code-as-scripts/361281)

<div class="topic-metadata">

**Author:** [@Edy\_Silva](https://discuss.elastic.co/u/Edy_Silva)\
**Replies:** 0\
**Last updated:** [June 11, 2024, 4:27pm UTC](https://discuss.elastic.co/t/is-there-any-tool-outside-that-allows-me-to-write-javascript-code-as-scripts/361281 "2024-06-11T16:27:47Z")

</div>

Painless is not quite painless. My team has been struggling with painless scripts due to a couple of reasons: (as far as I know) it's not possible to execute scripts locally - it would be great to write unit tests; pai…

---

## [I cannot create a dynamic mapping](https://discuss.elastic.co/t/i-cannot-create-a-dynamic-mapping/361249)

<div class="topic-metadata">

**Author:** [@simeonch7](https://discuss.elastic.co/u/simeonch7)\
**Replies:** 2\
**Last updated:** [June 12, 2024, 9:26am UTC](https://discuss.elastic.co/t/i-cannot-create-a-dynamic-mapping/361249 "2024-06-12T09:26:45Z")

</div>

Hello everyone, I am trying to create two index templates via the UI - one of them has a dynamic mapping that would keep only text fields for all strings from an event, and one that would keep only keyword fields. I wa…

---

## [Elasticsearch Query for Exact Substring Matching with Spaces](https://discuss.elastic.co/t/elasticsearch-query-for-exact-substring-matching-with-spaces/361216)

<div class="topic-metadata">

**Author:** [@Umang\_Kamdar](https://discuss.elastic.co/u/Umang_Kamdar)\
**Replies:** 8\
**Last updated:** [June 12, 2024, 9:09am UTC](https://discuss.elastic.co/t/elasticsearch-query-for-exact-substring-matching-with-spaces/361216 "2024-06-12T09:09:07Z")

</div>

I'm trying to perform an exact substring match in Elasticsearch, including substrings that contain spaces. Here’s what I need: Search for an exact substring within a larger text field. The substring may contain spaces. …

---

## [Data ingestion to elastic in near real time from mongo db](https://discuss.elastic.co/t/data-ingestion-to-elastic-in-near-real-time-from-mongo-db/361124)

<div class="topic-metadata">

**Author:** [@Moni\_Hazarika](https://discuss.elastic.co/u/Moni_Hazarika)\
**Replies:** 5\
**Last updated:** [June 12, 2024, 5:57am UTC](https://discuss.elastic.co/t/data-ingestion-to-elastic-in-near-real-time-from-mongo-db/361124 "2024-06-12T05:57:48Z")

</div>

Our csharp dotnet application uses MongoDB for ACID compliance and primarily as the main data storage. We are in the process of moving/mirroring some of the information from our key collections to Elastic. So the transac…

---

## [Increasing number of Alerts for Detection Rules](https://discuss.elastic.co/t/increasing-number-of-alerts-for-detection-rules/357064)

<div class="topic-metadata">

**Author:** [@uhxqc](https://discuss.elastic.co/u/uhxqc)\
**Replies:** 17\
**Last updated:** [June 12, 2024, 1:14am UTC](https://discuss.elastic.co/t/increasing-number-of-alerts-for-detection-rules/357064 "2024-06-12T01:14:38Z")

</div>

Hello, I am currently using the open source version of Elastic. I have created a couple of Detection Rules. But the number of alerts I can create per rule is limited to 100. If my understanding is correct, the number o…

---

## [Which Elasticsearch versions work for the s390x architecture?](https://discuss.elastic.co/t/which-elasticsearch-versions-work-for-the-s390x-architecture/361262)

<div class="topic-metadata">

**Author:** [@musharaf](https://discuss.elastic.co/u/musharaf)\
**Replies:** 3\
**Last updated:** [June 11, 2024, 3:16pm UTC](https://discuss.elastic.co/t/which-elasticsearch-versions-work-for-the-s390x-architecture/361262 "2024-06-11T15:16:03Z")

</div>

Which Elasticsearch versions work for the s390x architecture?

---

## [In Elastic Fleet Agent, how are IDs generated for agents and machines? Is there a way to customize or standardize the ID generation to avoid showing duplicate inactive machines with the same names?](https://discuss.elastic.co/t/in-elastic-fleet-agent-how-are-ids-generated-for-agents-and-machines-is-there-a-way-to-customize-or-standardize-the-id-generation-to-avoid-showing-duplicate-inactive-machines-with-the-same-names/361036)

<div class="topic-metadata">

**Author:** [@Danyal\_Danish](https://discuss.elastic.co/u/Danyal_Danish)\
**Replies:** 7\
**Last updated:** [June 11, 2024, 12:51pm UTC](https://discuss.elastic.co/t/in-elastic-fleet-agent-how-are-ids-generated-for-agents-and-machines-is-there-a-way-to-customize-or-standardize-the-id-generation-to-avoid-showing-duplicate-inactive-machines-with-the-same-names/361036 "2024-06-11T12:51:18Z")

</div>

Every day, new agents or machines are created and deleted in our Elastic Fleet environment. As shown in the attached image, some agents are active (healthy), while others are inactive (offline). The issue we're encounter…

---

## [How to change configuration file path?](https://discuss.elastic.co/t/how-to-change-configuration-file-path/361114)

<div class="topic-metadata">

**Author:** [@apashnin.work](https://discuss.elastic.co/u/apashnin.work)\
**Replies:** 2\
**Last updated:** [June 11, 2024, 12:24pm UTC](https://discuss.elastic.co/t/how-to-change-configuration-file-path/361114 "2024-06-11T12:24:10Z")

</div>

If I want to store /etc/elasticsearch/elasticsearch.yml file somewhere else how can I specify it to Elasticsearch service?

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=101)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=103)
