# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=103

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 104

---

## [Intermittent Connection Timeouts and "No Living Connections" Issues with AWS OpenSearch](https://discuss.elastic.co/t/intermittent-connection-timeouts-and-no-living-connections-issues-with-aws-opensearch/361211)

<div class="topic-metadata">

**Author:** [@Ganapathi\_Subramania](https://discuss.elastic.co/u/Ganapathi_Subramania)\
**Replies:** 3\
**Last updated:** [June 11, 2024, 12:10pm UTC](https://discuss.elastic.co/t/intermittent-connection-timeouts-and-no-living-connections-issues-with-aws-opensearch/361211 "2024-06-11T12:10:25Z")

</div>

Hi everyone, We have hosted our Elasticsearch using AWS OpenSearch service with the following configuration: Instance type: m5.large.search EBS volume size: 150 GiB Provisioned IOPS: 3000 IOPS Provisioned Throughput: …

---

## [In-place Upgradation](https://discuss.elastic.co/t/in-place-upgradation/361182)

<div class="topic-metadata">

**Author:** [@Aditya\_Teltia](https://discuss.elastic.co/u/Aditya_Teltia)\
**Replies:** 3\
**Last updated:** [June 11, 2024, 11:52am UTC](https://discuss.elastic.co/t/in-place-upgradation/361182 "2024-06-11T11:52:33Z")

</div>

We are trying to in-place upgradation of our elasticsearch cluster. We operate on timesharded index so what we were thinking is currently the cluster is on ES-7.17.6 version. We will upgrade the cluster to ES-8.11.1 an…

---

## [Pre migration step "Migrate system indices" failed](https://discuss.elastic.co/t/pre-migration-step-migrate-system-indices-failed/360822)

<div class="topic-metadata">

**Author:** [@mansoorpn](https://discuss.elastic.co/u/mansoorpn)\
**Replies:** 3\
**Last updated:** [June 11, 2024, 11:32am UTC](https://discuss.elastic.co/t/pre-migration-step-migrate-system-indices-failed/360822 "2024-06-11T11:32:41Z")

</div>

Hello, We checked the pre-migration step before upgrading the cloud instance from 7.17.5 to 8. The "Migrate system indices" step failed with the error " System indices migration failed, An error occurred while migratin…

---

## [Is circuit breaker config help to control Memory usage](https://discuss.elastic.co/t/is-circuit-breaker-config-help-to-control-memory-usage/361125)

<div class="topic-metadata">

**Author:** [@nchalise](https://discuss.elastic.co/u/nchalise)\
**Replies:** 3\
**Last updated:** [June 10, 2024, 9:45pm UTC](https://discuss.elastic.co/t/is-circuit-breaker-config-help-to-control-memory-usage/361125 "2024-06-10T21:45:04Z")

</div>

Is circuit breaker configuration help to control the Memory usage? By default it is 95% but I noticed that the memory reach to 99% in some of the nodes. Is there any other way to control the memory usage via configurati…

---

## [ERROR: Elasticsearch exited unexpectedly, with exit code 137](https://discuss.elastic.co/t/error-elasticsearch-exited-unexpectedly-with-exit-code-137/361047)

<div class="topic-metadata">

**Author:** [@optimuspur3](https://discuss.elastic.co/u/optimuspur3)\
**Replies:** 2\
**Last updated:** [June 10, 2024, 9:27pm UTC](https://discuss.elastic.co/t/error-elasticsearch-exited-unexpectedly-with-exit-code-137/361047 "2024-06-10T21:27:25Z")

</div>

I have been using this guide to setup an ELK. Current version of Ubuntu: 20.04 Elasticsearch version: 8.1 Hiding my IP address but when I start up Logstash after finishing configuring Logstash configuration, Elastics…

---

## [Delay assigning new replica shards](https://discuss.elastic.co/t/delay-assigning-new-replica-shards/361199)

<div class="topic-metadata">

**Author:** [@linkerc](https://discuss.elastic.co/u/linkerc)\
**Replies:** 0\
**Last updated:** [June 10, 2024, 8:59pm UTC](https://discuss.elastic.co/t/delay-assigning-new-replica-shards/361199 "2024-06-10T20:59:52Z")

</div>

Whenever I tweak the following settings. PUT \_cluster/settings { "persistent": { "cluster.routing.allocation.balance.threshold": null, "cluster.routing.allocation.cluster\_concurrent\_rebalance": null, "clus…

---

## [Why match\_bool\_prefix with a query with trailing space will generate different results](https://discuss.elastic.co/t/why-match-bool-prefix-with-a-query-with-trailing-space-will-generate-different-results/360673)

<div class="topic-metadata">

**Author:** [@bigpotato](https://discuss.elastic.co/u/bigpotato)\
**Replies:** 1\
**Last updated:** [June 10, 2024, 5:59pm UTC](https://discuss.elastic.co/t/why-match-bool-prefix-with-a-query-with-trailing-space-will-generate-different-results/360673 "2024-06-10T17:59:57Z")

</div>

The index mapping: "orgName": { "type": "text", "fields": { "keyword": { "type": "keyword", "ignore…

---

## [Bulk index documents only if they don't already exist without using an id](https://discuss.elastic.co/t/bulk-index-documents-only-if-they-dont-already-exist-without-using-an-id/361166)

<div class="topic-metadata">

**Author:** [@catalin8](https://discuss.elastic.co/u/catalin8)\
**Replies:** 2\
**Last updated:** [June 10, 2024, 3:14pm UTC](https://discuss.elastic.co/t/bulk-index-documents-only-if-they-dont-already-exist-without-using-an-id/361166 "2024-06-10T15:14:38Z")

</div>

I'm looking to index a list of documents using the bulk API. I want to add only the ones that are not already indexed, and I don't use IDs. Is this possible?

---

## [Improve Search Performance](https://discuss.elastic.co/t/improve-search-performance/359306)

<div class="topic-metadata">

**Author:** [@sravan\_kaheti](https://discuss.elastic.co/u/sravan_kaheti)\
**Replies:** 19\
**Last updated:** [June 10, 2024, 2:17pm UTC](https://discuss.elastic.co/t/improve-search-performance/359306 "2024-06-10T14:17:26Z")

</div>

Hi Team , I ingested huge amount of data (3-4 B records)with bellow index configuration Index - Data Stream Primaries - 5 replicas - 0 Master and Master eligible node - 3 Voting only node - 1 coordinator node - 1 …

---

## [Elasticsearch Search Query Load Testing using Jmeter](https://discuss.elastic.co/t/elasticsearch-search-query-load-testing-using-jmeter/361156)

<div class="topic-metadata">

**Author:** [@kishorkumar](https://discuss.elastic.co/u/kishorkumar)\
**Replies:** 0\
**Last updated:** [June 10, 2024, 2:05pm UTC](https://discuss.elastic.co/t/elasticsearch-search-query-load-testing-using-jmeter/361156 "2024-06-10T14:05:11Z")

</div>

Hello i have been trying to test the load of my clustor of 1 node using JMeter. i have data of millions records, i have created csv which contians the 6000 ids. i have following configs: Thread Group: Thread Group …

---

## [How to boost source engine insid ethe meta engine](https://discuss.elastic.co/t/how-to-boost-source-engine-insid-ethe-meta-engine/360921)

<div class="topic-metadata">

**Author:** [@Ashok\_Vadya](https://discuss.elastic.co/u/Ashok_Vadya)\
**Replies:** 3\
**Last updated:** [June 10, 2024, 11:06am UTC](https://discuss.elastic.co/t/how-to-boost-source-engine-insid-ethe-meta-engine/360921 "2024-06-10T11:06:56Z")

</div>

Conside a meta engine having m and having two source engine a and engine b. and order of these engines are based on created date. when search for a document always document from engine a get highest score and always co…

---

## [NEST to ElasticSearch.net migration issue with DeleteMany](https://discuss.elastic.co/t/nest-to-elasticsearch-net-migration-issue-with-deletemany/361096)

<div class="topic-metadata">

**Author:** [@AMElastic](https://discuss.elastic.co/u/AMElastic)\
**Replies:** 0\
**Last updated:** [June 9, 2024, 10:18am UTC](https://discuss.elastic.co/t/nest-to-elasticsearch-net-migration-issue-with-deletemany/361096 "2024-06-09T10:18:56Z")

</div>

I have an issue while migrating the code from NEST to ES client 8.14. I have a list of ids, that I would want to delete. I tried the following, but it doesn't work as it doesn't accept ids as a parameter for the Delete…

---

## [Use result of an aggregation query to enrich doc](https://discuss.elastic.co/t/use-result-of-an-aggregation-query-to-enrich-doc/361130)

<div class="topic-metadata">

**Author:** [@StefanC](https://discuss.elastic.co/u/StefanC)\
**Replies:** 1\
**Last updated:** [June 10, 2024, 9:26am UTC](https://discuss.elastic.co/t/use-result-of-an-aggregation-query-to-enrich-doc/361130 "2024-06-10T09:26:11Z")

</div>

Is its possible to execute an aggregation query on an index and use the results in one action to enrich the same index/documents with it. Assume i have serveral document with field region, sensor type sensor. I want to…

---

## [Error Benchmarking AWS Managed Elasticsearch Cluster (version 7.10) using esrally](https://discuss.elastic.co/t/error-benchmarking-aws-managed-elasticsearch-cluster-version-7-10-using-esrally/361031)

<div class="topic-metadata">

**Author:** [@Peter\_Eskandar](https://discuss.elastic.co/u/Peter_Eskandar)\
**Replies:** 11\
**Last updated:** [June 9, 2024, 6:13pm UTC](https://discuss.elastic.co/t/error-benchmarking-aws-managed-elasticsearch-cluster-version-7-10-using-esrally/361031 "2024-06-09T18:13:17Z")

</div>

I'm attempting to benchmark an AWS Managed Elasticsearch Cluster (version: 7.10) using esrally, but I'm encountering the following error: \_\_\_\_ \_\_\_\_ / \_\_ \\\_\_\_\_ \_/ / /\_ \_\_ / /\_/ / \_\_ \`/ / / / / / / \_, \_/…

---

## [Elasticsearch Change Logging Level](https://discuss.elastic.co/t/elasticsearch-change-logging-level/361102)

<div class="topic-metadata">

**Author:** [@Ahmed\_Essam](https://discuss.elastic.co/u/Ahmed_Essam)\
**Replies:** 1\
**Last updated:** [June 9, 2024, 4:01pm UTC](https://discuss.elastic.co/t/elasticsearch-change-logging-level/361102 "2024-06-09T16:01:50Z")

</div>

I want to be able to change various logs level for different elasticsearch module such as the following PUT /\_cluster/settings { "persistent": { "logger.org.elasticsearch.discovery": "OFF" } } But I cannot find…

---

## [The num\_candidates parameter leads to some confusing query results](https://discuss.elastic.co/t/the-num-candidates-parameter-leads-to-some-confusing-query-results/359355)

<div class="topic-metadata">

**Author:** [@EricTowns](https://discuss.elastic.co/u/EricTowns)\
**Replies:** 7\
**Last updated:** [June 9, 2024, 12:17pm UTC](https://discuss.elastic.co/t/the-num-candidates-parameter-leads-to-some-confusing-query-results/359355 "2024-06-09T12:17:04Z")

</div>

Hi team! I have an index, only 1 primary shard, I insert documents and then knn searching. When I do a knn query with k=10 and num\_candidates=20, I get a batch of results. When k=10 and num\_candidates=25, I got some doc…

---

## [Spring data Elasticsearch](https://discuss.elastic.co/t/spring-data-elasticsearch/361089)

<div class="topic-metadata">

**Author:** [@mmahmood](https://discuss.elastic.co/u/mmahmood)\
**Replies:** 1\
**Last updated:** [June 9, 2024, 5:35am UTC](https://discuss.elastic.co/t/spring-data-elasticsearch/361089 "2024-06-09T05:35:00Z")

</div>

Hi all I have added aggregation to elasticsearch query by using QueryBuilder class provided in spring boot elasticsearch library but it is not working as expected. I may be missing something. following is code snippet …

---

## [SocketTimeout Exception issue reported for Elasticsearch Node with moderate resource usage](https://discuss.elastic.co/t/sockettimeout-exception-issue-reported-for-elasticsearch-node-with-moderate-resource-usage/360984)

<div class="topic-metadata">

**Author:** [@lzz118](https://discuss.elastic.co/u/lzz118)\
**Replies:** 9\
**Last updated:** [June 9, 2024, 5:32am UTC](https://discuss.elastic.co/t/sockettimeout-exception-issue-reported-for-elasticsearch-node-with-moderate-resource-usage/360984 "2024-06-09T05:32:24Z")

</div>

The Elasticsearch Cluster with the reported issue includes 86 data nodes and 3 dedicated master nodes, each with 32 GB heap 64 to 128GB OS memory, and between 16 ~ 32 CPU cores per node. We have two ES clusters with sim…

---

## [Shard Allocation Awareness and .security-7 index](https://discuss.elastic.co/t/shard-allocation-awareness-and-security-7-index/361072)

<div class="topic-metadata">

**Author:** [@Sajad\_Soltanian](https://discuss.elastic.co/u/Sajad_Soltanian)\
**Replies:** 0\
**Last updated:** [June 8, 2024, 11:57am UTC](https://discuss.elastic.co/t/shard-allocation-awareness-and-security-7-index/361072 "2024-06-08T11:57:52Z")

</div>

We have recently added node attributes and update the cluster setting to allocate the shards based on this attribute. below is my cluster settings. "cluster" : { "routing" : { "allocation" : { …

---

## [Custom sorting](https://discuss.elastic.co/t/custom-sorting/360530)

<div class="topic-metadata">

**Author:** [@alexander.korkhov](https://discuss.elastic.co/u/alexander.korkhov)\
**Replies:** 1\
**Last updated:** [June 7, 2024, 10:56pm UTC](https://discuss.elastic.co/t/custom-sorting/360530 "2024-06-07T22:56:39Z")

</div>

Good afternoon! We need to do custom sorting in elastic. You need to give elastic a list of document IDs as input, according to which you need to sort the output. That is, we first sort by this list (to the top of the o…

---

## [Determine count of fields in a document](https://discuss.elastic.co/t/determine-count-of-fields-in-a-document/360946)

<div class="topic-metadata">

**Author:** [@lolabam](https://discuss.elastic.co/u/lolabam)\
**Replies:** 1\
**Last updated:** [June 7, 2024, 10:39pm UTC](https://discuss.elastic.co/t/determine-count-of-fields-in-a-document/360946 "2024-06-07T22:39:56Z")

</div>

I'm new to painless scripts. I'd like to create a runtime field that returns the count of fields in a document. Can anyone help with the right script to use?

---

## [Incomplete jdk.app in the installation package｜Unable to start Elasticsearch｜macOS x86\_64 | elasticsearch-8.13.2](https://discuss.elastic.co/t/incomplete-jdk-app-in-the-installation-package-unable-to-start-elasticsearch-macos-x86-64-elasticsearch-8-13-2/357275)

<div class="topic-metadata">

**Author:** [@Joanna\_Chang](https://discuss.elastic.co/u/Joanna_Chang)\
**Replies:** 4\
**Last updated:** [June 7, 2024, 10:19pm UTC](https://discuss.elastic.co/t/incomplete-jdk-app-in-the-installation-package-unable-to-start-elasticsearch-macos-x86-64-elasticsearch-8-13-2/357275 "2024-06-07T22:19:10Z")

</div>

Downloaded the installation package, elasticsearch-8.13.2, several times, but the system indicates that jdk.app is incomplete. Privacy and security settings are configured to allow open. Unable to start Elasticse…

---

## [Write to TSDS index via python](https://discuss.elastic.co/t/write-to-tsds-index-via-python/361001)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 9\
**Last updated:** [June 7, 2024, 7:53pm UTC](https://discuss.elastic.co/t/write-to-tsds-index-via-python/361001 "2024-06-07T19:53:42Z")

</div>

I create ILM/Template and Index when I try to write via python it errors but same record works via dev tool POST sachin\_test/\_doc { "@timestamp": "2024-06-06T19:21:15.000Z", --\> this part I did manually "system\_ty…

---

## [Connect remote cluster between a cluster disabled TLS/SSL and a cluster enabled TLS/SSL](https://discuss.elastic.co/t/connect-remote-cluster-between-a-cluster-disabled-tls-ssl-and-a-cluster-enabled-tls-ssl/361005)

<div class="topic-metadata">

**Author:** [@Huy\_Nguyen](https://discuss.elastic.co/u/Huy_Nguyen)\
**Replies:** 5\
**Last updated:** [June 7, 2024, 12:18pm UTC](https://discuss.elastic.co/t/connect-remote-cluster-between-a-cluster-disabled-tls-ssl-and-a-cluster-enabled-tls-ssl/361005 "2024-06-07T12:18:00Z")

</div>

I have a task migrate Elasticsearch from v7 to v8. I'd like new cluster add old cluster as a remote cluster. A cluster Elasticsearch v8 require enable https ssl/tls, however a cluster Elasticsearch v7 in prod environment…

---

## [Connection Timeout for AWS-S3 Repository](https://discuss.elastic.co/t/connection-timeout-for-aws-s3-repository/360952)

<div class="topic-metadata">

**Author:** [@Sasan\_Askari](https://discuss.elastic.co/u/Sasan_Askari)\
**Replies:** 1\
**Last updated:** [June 7, 2024, 8:28am UTC](https://discuss.elastic.co/t/connection-timeout-for-aws-s3-repository/360952 "2024-06-07T08:28:16Z")

</div>

Hi,I want to save my backups in AWS,below is my elastic for my docker compose that is run and up and work well and i add to enviornment into this configuration: version: '3' services: elasticsearch: image: focker.…

---

## [Is correct way register a snapshot repository for security?](https://discuss.elastic.co/t/is-correct-way-register-a-snapshot-repository-for-security/361013)

<div class="topic-metadata">

**Author:** [@zmaxutbekov](https://discuss.elastic.co/u/zmaxutbekov)\
**Replies:** 2\
**Last updated:** [June 7, 2024, 6:39am UTC](https://discuss.elastic.co/t/is-correct-way-register-a-snapshot-repository-for-security/361013 "2024-06-07T06:39:32Z")

</div>

Hello everyone. I have an elastic cluster with version 7.16.2. A crontab script is run on one node, which makes a snapshot. Now, the situation is like this, it was decided to add a repository snapshot registration and de…

---

## [Reindex SentinelOne Agent log through a new ingest pipeline to rename network\_interfaces field](https://discuss.elastic.co/t/reindex-sentinelone-agent-log-through-a-new-ingest-pipeline-to-rename-network-interfaces-field/361014)

<div class="topic-metadata">

**Author:** [@Chaviru](https://discuss.elastic.co/u/Chaviru)\
**Replies:** 0\
**Last updated:** [June 7, 2024, 6:31am UTC](https://discuss.elastic.co/t/reindex-sentinelone-agent-log-through-a-new-ingest-pipeline-to-rename-network-interfaces-field/361014 "2024-06-07T06:31:33Z")

</div>

I am currently working with SentinelOne agent logs in my Elasticsearch Stack. And I need to reindex my managed SentinelOne agent index to a new index through a pipeline where I need to rename some fields from the log and…

---

## [Elastic agent for aws custom integration](https://discuss.elastic.co/t/elastic-agent-for-aws-custom-integration/360644)

<div class="topic-metadata">

**Author:** [@mealbert23](https://discuss.elastic.co/u/mealbert23)\
**Replies:** 1\
**Last updated:** [June 7, 2024, 5:50am UTC](https://discuss.elastic.co/t/elastic-agent-for-aws-custom-integration/360644 "2024-06-07T05:50:27Z")

</div>

Hi, A little background: I have setup elastic and kibana on an aws eks system. I am now trying to setup the aws custom integration piece. I have created the s3 bucket, sqs and a role with all the necessary permission…

---

## [Can't connect graylog client to ElasticSearch cluster](https://discuss.elastic.co/t/cant-connect-graylog-client-to-elasticsearch-cluster/360992)

<div class="topic-metadata">

**Author:** [@stecino](https://discuss.elastic.co/u/stecino)\
**Replies:** 1\
**Last updated:** [June 7, 2024, 5:45am UTC](https://discuss.elastic.co/t/cant-connect-graylog-client-to-elasticsearch-cluster/360992 "2024-06-07T05:45:29Z")

</div>

Hello, I have reconfigured graylog client to connect from one Elasticsearch cluster to another. Both clusters are version 2.3.5. But when I try to restart the client, I am getting error On master side \[WARN \]\[discover…

---

## [Create a cluster between elasticsearch nodes](https://discuss.elastic.co/t/create-a-cluster-between-elasticsearch-nodes/361002)

<div class="topic-metadata">

**Author:** [@mario\_kazela](https://discuss.elastic.co/u/mario_kazela)\
**Replies:** 1\
**Last updated:** [June 7, 2024, 5:26am UTC](https://discuss.elastic.co/t/create-a-cluster-between-elasticsearch-nodes/361002 "2024-06-07T05:26:47Z")

</div>

Hi, Need your help!!. I got some issue when creating the elasticsearch 7.x cluster. Right now I already created and have 3 elasticsearch nodes. But the issue when I verify my cluster state, it is show the number of no…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=102)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=104)
