# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=104

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 105

---

## [How to effectively kill defunct child processes generated by esrally tool?](https://discuss.elastic.co/t/how-to-effectively-kill-defunct-child-processes-generated-by-esrally-tool/361006)

<div class="topic-metadata">

**Author:** [@Andy\_Cong](https://discuss.elastic.co/u/Andy_Cong)\
**Replies:** 0\
**Last updated:** [June 7, 2024, 3:06am UTC](https://discuss.elastic.co/t/how-to-effectively-kill-defunct-child-processes-generated-by-esrally-tool/361006 "2024-06-07T03:06:05Z")

</div>

I am using the esrally tool, which generates a large number of child processes. I've noticed that some of these child processes become defunct. I am looking for an effective way to kill these defunct processes. Any sugge…

---

## [ILM policy not applied](https://discuss.elastic.co/t/ilm-policy-not-applied/359780)

<div class="topic-metadata">

**Author:** [@parthmaniar](https://discuss.elastic.co/u/parthmaniar)\
**Replies:** 5\
**Last updated:** [June 6, 2024, 8:21pm UTC](https://discuss.elastic.co/t/ilm-policy-not-applied/359780 "2024-06-06T20:21:41Z")

</div>

Hello, I have an indice that does not follow the applied lifecycle policy. Other indexes for the indice are rotating correctly. The current size of the index is over 230 GB for the primary shard. Here is the ILM co…

---

## [Hybrid Search Java Api not returning Rank](https://discuss.elastic.co/t/hybrid-search-java-api-not-returning-rank/360700)

<div class="topic-metadata">

**Author:** [@Tommaso\_FAVARON](https://discuss.elastic.co/u/Tommaso_FAVARON)\
**Replies:** 5\
**Last updated:** [June 6, 2024, 5:31pm UTC](https://discuss.elastic.co/t/hybrid-search-java-api-not-returning-rank/360700 "2024-06-06T17:31:54Z")

</div>

Hello. I want to perform hybrid search using java client. With elasticsarch-java 8.11 environment, this is my query: SearchResponse\<Map\> response = esClient.search(s -\> s .index(index) …

---

## [Filebeat configuration for handling high file creation rate and small file sizes version 7.17](https://discuss.elastic.co/t/filebeat-configuration-for-handling-high-file-creation-rate-and-small-file-sizes-version-7-17/360955)

<div class="topic-metadata">

**Author:** [@Danyal\_Danish](https://discuss.elastic.co/u/Danyal_Danish)\
**Replies:** 2\
**Last updated:** [June 6, 2024, 1:54pm UTC](https://discuss.elastic.co/t/filebeat-configuration-for-handling-high-file-creation-rate-and-small-file-sizes-version-7-17/360955 "2024-06-06T13:54:04Z")

</div>

Can Filebeat be configured for handling high file creation rate (10 - 15 files per second) and for small file sizes of (500kb per file) version 7.17. My actual question is that what specific input type is preferable for …

---

## [Multiplexer with synonyms doesn't work as expected](https://discuss.elastic.co/t/multiplexer-with-synonyms-doesnt-work-as-expected/360959)

<div class="topic-metadata">

**Author:** [@NikKozh](https://discuss.elastic.co/u/NikKozh)\
**Replies:** 0\
**Last updated:** [June 6, 2024, 12:25pm UTC](https://discuss.elastic.co/t/multiplexer-with-synonyms-doesnt-work-as-expected/360959 "2024-06-06T12:25:07Z")

</div>

Hello, I'm using almost latest Elastic 8.13 and currently trying to make analyzer with multiplexer, that uses synonym filter. However, I found out that results from simple filter-chaining (without multiplexer) differ fro…

---

## [Can't start any pivot transform - getting allocation explanation error without reason](https://discuss.elastic.co/t/cant-start-any-pivot-transform-getting-allocation-explanation-error-without-reason/360849)

<div class="topic-metadata">

**Author:** [@Django](https://discuss.elastic.co/u/Django)\
**Replies:** 4\
**Last updated:** [June 6, 2024, 9:21am UTC](https://discuss.elastic.co/t/cant-start-any-pivot-transform-getting-allocation-explanation-error-without-reason/360849 "2024-06-06T09:21:09Z")

</div>

Hi! Something strange happened with our Elasticsearch v7.17 cluster - I can't start pivot transforms due to an error {"root\_cause":\[{"type":"status\_exception","reason":"Could not start transform, allocation explanation…

---

## [Date range query returns different results in ES7 vs. ES8 - does not respect include\_lower](https://discuss.elastic.co/t/date-range-query-returns-different-results-in-es7-vs-es8-does-not-respect-include-lower/360844)

<div class="topic-metadata">

**Author:** [@buitcj](https://discuss.elastic.co/u/buitcj)\
**Replies:** 4\
**Last updated:** [June 6, 2024, 9:08am UTC](https://discuss.elastic.co/t/date-range-query-returns-different-results-in-es7-vs-es8-does-not-respect-include-lower/360844 "2024-06-06T09:08:26Z")

</div>

Using a date range query with include\_lower set to false is not working as expected in ES8. In ES7 a doc with a date of 1969-12-31 with date range query set to 1969-12-31 as the lower bound and include\_lower=false would …

---

## [Elastic stuck while starting](https://discuss.elastic.co/t/elastic-stuck-while-starting/360931)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 1\
**Last updated:** [June 6, 2024, 8:23am UTC](https://discuss.elastic.co/t/elastic-stuck-while-starting/360931 "2024-06-06T08:23:44Z")

</div>

Hi there, Have you guys ever experienced this while running Elastic? the log is stuck at this point. currently, my elastic node is using LUN storage and I'm using the 7.17.0 version

---

## [ElasticSearch 7.x index mapping update performance](https://discuss.elastic.co/t/elasticsearch-7-x-index-mapping-update-performance/360934)

<div class="topic-metadata">

**Author:** [@Jakentop](https://discuss.elastic.co/u/Jakentop)\
**Replies:** 1\
**Last updated:** [June 6, 2024, 8:22am UTC](https://discuss.elastic.co/t/elasticsearch-7-x-index-mapping-update-performance/360934 "2024-06-06T08:22:49Z")

</div>

We have about 2000w of data in a single index in a production environment, we are not currently deploying a cluster and only have a single slice. How long does it take to add a non-existing field using update mapping in …

---

## [Boosting source engine inside meta engine](https://discuss.elastic.co/t/boosting-source-engine-inside-meta-engine/360925)

<div class="topic-metadata">

**Author:** [@Ashok\_Vadya](https://discuss.elastic.co/u/Ashok_Vadya)\
**Replies:** 1\
**Last updated:** [June 6, 2024, 7:25am UTC](https://discuss.elastic.co/t/boosting-source-engine-inside-meta-engine/360925 "2024-06-06T07:25:25Z")

</div>

Do we have any api to boost source engine insid the meta engine? if so then please share some details.

---

## [Elasticsearch: update existing document by inserting elements to its array fields](https://discuss.elastic.co/t/elasticsearch-update-existing-document-by-inserting-elements-to-its-array-fields/360905)

<div class="topic-metadata">

**Author:** [@Satyam\_Kaushik](https://discuss.elastic.co/u/Satyam_Kaushik)\
**Replies:** 0\
**Last updated:** [June 6, 2024, 4:20am UTC](https://discuss.elastic.co/t/elasticsearch-update-existing-document-by-inserting-elements-to-its-array-fields/360905 "2024-06-06T04:20:56Z")

</div>

Consider the following document { "title": "My first blog entry", "text": "Starting to get the hang of this...", "tags": \[ "testing" \], "views": 0 } I need to run kind of an upsert operation. If I encount…

---

## [Set\_upgrade\_mode?enabled=false failed on 7.17](https://discuss.elastic.co/t/set-upgrade-mode-enabled-false-failed-on-7-17/360897)

<div class="topic-metadata">

**Author:** [@dove-young](https://discuss.elastic.co/u/dove-young)\
**Replies:** 1\
**Last updated:** [June 6, 2024, 4:11am UTC](https://discuss.elastic.co/t/set-upgrade-mode-enabled-false-failed-on-7-17/360897 "2024-06-06T04:11:14Z")

</div>

I am doing an entire cluster restore. After index restore, I am resetting \_ml/set\_upgrade\_mode, but it did not work sh-5.1$ curl -X POST 'http://instana-es-http:9200/\_ml/set\_upgrade\_mode?enabled=false' -u elastic:$ELAS…

---

## [How to install Elasticsearch in Kubernetes by Helm?](https://discuss.elastic.co/t/how-to-install-elasticsearch-in-kubernetes-by-helm/360136)

<div class="topic-metadata">

**Author:** [@seikyo-cho-lvgs](https://discuss.elastic.co/u/seikyo-cho-lvgs)\
**Replies:** 1\
**Last updated:** [June 6, 2024, 4:03am UTC](https://discuss.elastic.co/t/how-to-install-elasticsearch-in-kubernetes-by-helm/360136 "2024-06-06T04:03:33Z")

</div>

I installed Elasticsearch on Kubernetes in Rancher Desktop by this guide: https://artifacthub.io/packages/helm/elastic/elasticsearch#installing helm repo add elastic https://helm.elastic.co helm install elasticsearch e…

---

## [Filter query is quite slow in 8.11 compared to 7.13](https://discuss.elastic.co/t/filter-query-is-quite-slow-in-8-11-compared-to-7-13/360524)

<div class="topic-metadata">

**Author:** [@vjgorla](https://discuss.elastic.co/u/vjgorla)\
**Replies:** 3\
**Last updated:** [June 5, 2024, 11:55pm UTC](https://discuss.elastic.co/t/filter-query-is-quite-slow-in-8-11-compared-to-7-13/360524 "2024-06-05T23:55:04Z")

</div>

There seems to be a big performance difference for a bool query between 7.13 and 8.11 when there are no matches. The query in question has two terms filters, one of them very selective and the other is very broad. In 7…

---

## [ElasticSearch Terms Query not working correctly on text with mixed case](https://discuss.elastic.co/t/elasticsearch-terms-query-not-working-correctly-on-text-with-mixed-case/358825)

<div class="topic-metadata">

**Author:** [@jash\_edcast](https://discuss.elastic.co/u/jash_edcast)\
**Replies:** 1\
**Last updated:** [June 5, 2024, 6:50pm UTC](https://discuss.elastic.co/t/elasticsearch-terms-query-not-working-correctly-on-text-with-mixed-case/358825 "2024-06-05T18:50:04Z")

</div>

Running a query on text field with Below is my index mapping { "users\_index": { "settings": { "index": { "provided\_name": "users\_index", "number\_of\_replicas": "1", "uuid": "IpNHWSiDSb…

---

## [Elastic Map Server with PKI Auth](https://discuss.elastic.co/t/elastic-map-server-with-pki-auth/360873)

<div class="topic-metadata">

**Author:** [@m.hanna](https://discuss.elastic.co/u/m.hanna)\
**Replies:** 0\
**Last updated:** [June 5, 2024, 4:13pm UTC](https://discuss.elastic.co/t/elastic-map-server-with-pki-auth/360873 "2024-06-05T16:13:52Z")

</div>

We are running an Elastic Maps Server (EMS) in a docker swarm. I am wondering if it possible to configure EMS to use PKI authentication to Elasticsearch instead of username/password. I have configured PKI certificates a…

---

## [Use Epoch Format with Nanoseconds (19 digits)](https://discuss.elastic.co/t/use-epoch-format-with-nanoseconds-19-digits/360632)

<div class="topic-metadata">

**Author:** [@andre\_bx](https://discuss.elastic.co/u/andre_bx)\
**Replies:** 2\
**Last updated:** [June 5, 2024, 2:22pm UTC](https://discuss.elastic.co/t/use-epoch-format-with-nanoseconds-19-digits/360632 "2024-06-05T14:22:52Z")

</div>

Hi, i am beginner with elastic, but i would use elastic for our Bluecat DNS Server. The Server send the time as Unix epoche format with 19 digits, so i checked it and it is in nanoseconds like google search told me. I…

---

## [How to remove hits after aggregation](https://discuss.elastic.co/t/how-to-remove-hits-after-aggregation/360735)

<div class="topic-metadata">

**Author:** [@p4charu](https://discuss.elastic.co/u/p4charu)\
**Replies:** 5\
**Last updated:** [June 5, 2024, 2:00pm UTC](https://discuss.elastic.co/t/how-to-remove-hits-after-aggregation/360735 "2024-06-05T14:00:41Z")

</div>

Hello, I'm trying to do an aggregate query to get issues at their highest state but if the highest state is 'closed' then I want to completely ignore the issue. For example, docId action issue Doc1 raised issue1…

---

## [Elastic search master issue](https://discuss.elastic.co/t/elastic-search-master-issue/360861)

<div class="topic-metadata">

**Author:** [@gedrasaknagufum.com](https://discuss.elastic.co/u/gedrasaknagufum.com)\
**Replies:** 1\
**Last updated:** [June 5, 2024, 1:35pm UTC](https://discuss.elastic.co/t/elastic-search-master-issue/360861 "2024-06-05T13:35:29Z")

</div>

Jun 05 13:00:53 ip-172-31-43-63 elasticsearch\[505\]: \[2024-06-05T13:00:53,419\]\[INFO \]\[o.e.x.s.a.AuthenticationService\] \[es\_euwest\_prd\_ec2\_2\] Authentication of \[elastic\] was terminated by realm \[rese rved\] - failed to aut…

---

## [The ECK data storage location](https://discuss.elastic.co/t/the-eck-data-storage-location/360853)

<div class="topic-metadata">

**Author:** [@dxygit1](https://discuss.elastic.co/u/dxygit1)\
**Replies:** 0\
**Last updated:** [June 5, 2024, 1:04pm UTC](https://discuss.elastic.co/t/the-eck-data-storage-location/360853 "2024-06-05T13:04:40Z")

</div>

Can ECK data be directly stored in an Azure bucket in a Kubernetes environment with Helm installation?

---

## [Elastic search smart chinese plugin returns invalid tokens](https://discuss.elastic.co/t/elastic-search-smart-chinese-plugin-returns-invalid-tokens/360843)

<div class="topic-metadata">

**Author:** [@HARI\_RAM](https://discuss.elastic.co/u/HARI_RAM)\
**Replies:** 0\
**Last updated:** [June 5, 2024, 10:46am UTC](https://discuss.elastic.co/t/elastic-search-smart-chinese-plugin-returns-invalid-tokens/360843 "2024-06-05T10:46:33Z")

</div>

ES version: 7.17.15 I was recently checking the smartcn plugin and the tokens that it returned does not look relevant. I used the config from here - Reimplementing and extending the analyzers | Elasticsearch Plugins an…

---

## [Garbage collection causing long queries](https://discuss.elastic.co/t/garbage-collection-causing-long-queries/360841)

<div class="topic-metadata">

**Author:** [@wwn\_or](https://discuss.elastic.co/u/wwn_or)\
**Replies:** 0\
**Last updated:** [June 5, 2024, 10:15am UTC](https://discuss.elastic.co/t/garbage-collection-causing-long-queries/360841 "2024-06-05T10:15:11Z")

</div>

We have a tiny two-node Elasticsearch 6 cluster that during node garbage collection can result in query timeouts (the timeouts are at client end for UX reasons, not at Elasticsearch end). I'm not much of an ES expert - i…

---

## [GCS repository creation times out on one node (starts working after restart)](https://discuss.elastic.co/t/gcs-repository-creation-times-out-on-one-node-starts-working-after-restart/360292)

<div class="topic-metadata">

**Author:** [@sumant-pangotra](https://discuss.elastic.co/u/sumant-pangotra)\
**Replies:** 11\
**Last updated:** [June 5, 2024, 9:44am UTC](https://discuss.elastic.co/t/gcs-repository-creation-times-out-on-one-node-starts-working-after-restart/360292 "2024-06-05T09:44:31Z")

</div>

GCS repository creation times out on one node (starts working after restart) { "name" : "elasticsearch-client-6fdc44747f-2h2md", "cluster\_name" : "es-123", "cluster\_uuid" : "dfQbgOeVTXieyW3JUWcEQw", "version" : …

---

## [Index template create automatically](https://discuss.elastic.co/t/index-template-create-automatically/360815)

<div class="topic-metadata">

**Author:** [@Frances\_Chu](https://discuss.elastic.co/u/Frances_Chu)\
**Replies:** 0\
**Last updated:** [June 5, 2024, 2:49am UTC](https://discuss.elastic.co/t/index-template-create-automatically/360815 "2024-06-05T02:49:06Z")

</div>

I would like to setup the index lifecycle by using index template to create a new index (test\_index-yyyy.MM.dd) every 30 days My log will send form filebeat --\> logstash --\> Elasticsearch. configuration a policy (tes…

---

## [Elastic API returns 401 from browser client (CORS)](https://discuss.elastic.co/t/elastic-api-returns-401-from-browser-client-cors/360686)

<div class="topic-metadata">

**Author:** [@qd-danh](https://discuss.elastic.co/u/qd-danh)\
**Replies:** 1\
**Last updated:** [June 4, 2024, 3:41pm UTC](https://discuss.elastic.co/t/elastic-api-returns-401-from-browser-client-cors/360686 "2024-06-04T15:41:16Z")

</div>

I have followed the documentation and enabled CORS on Elastic cluster (hosted in Azure), so edited the elastic YAML via the cloud portal. Shown below. Calling Elastic APIs from ObservableHQ as the client and getting COR…

---

## [Parameter timestamp is not working](https://discuss.elastic.co/t/parameter-timestamp-is-not-working/360805)

<div class="topic-metadata">

**Author:** [@noe.gonza](https://discuss.elastic.co/u/noe.gonza)\
**Replies:** 1\
**Last updated:** [June 4, 2024, 4:30pm UTC](https://discuss.elastic.co/t/parameter-timestamp-is-not-working/360805 "2024-06-04T16:30:31Z")

</div>

Hello everyone, I have problems with the timestamp parameter because when an alert is triggered in the email I get a time that doesn't correspond (they are 4 hours apart) but in the log itself it shows the correct inform…

---

## [Elastic 7 : unable to do simple Min/Max agg with date\_range type](https://discuss.elastic.co/t/elastic-7-unable-to-do-simple-min-max-agg-with-date-range-type/360731)

<div class="topic-metadata">

**Author:** [@jeanpl](https://discuss.elastic.co/u/jeanpl)\
**Replies:** 3\
**Last updated:** [June 4, 2024, 3:53pm UTC](https://discuss.elastic.co/t/elastic-7-unable-to-do-simple-min-max-agg-with-date-range-type/360731 "2024-06-04T15:53:11Z")

</div>

My index document is as simple as (end\_date and start\_date are long) : { "\_index" : "myindex\_1639524591", "\_type" : "\_doc", "\_id" : "UwtsvH0BFRn\_76fpoFuN", "\_score" : 1.0, "fields" : { "end\_date" : \[ …

---

## [Used split API, resulting index is much, much larger than the source index](https://discuss.elastic.co/t/used-split-api-resulting-index-is-much-much-larger-than-the-source-index/360792)

<div class="topic-metadata">

**Author:** [@daviddawson](https://discuss.elastic.co/u/daviddawson)\
**Replies:** 1\
**Last updated:** [June 4, 2024, 3:00pm UTC](https://discuss.elastic.co/t/used-split-api-resulting-index-is-much-much-larger-than-the-source-index/360792 "2024-06-04T15:00:24Z")

</div>

An index in our cluster was created by accident with a single shard. We looked at various ways to expand the shards, as performance is suffering. It's currently about 280gb. We tried the split API to generate a new ind…

---

## [Issue with forced shard allocation awareness](https://discuss.elastic.co/t/issue-with-forced-shard-allocation-awareness/360770)

<div class="topic-metadata">

**Author:** [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Replies:** 3\
**Last updated:** [June 4, 2024, 1:46pm UTC](https://discuss.elastic.co/t/issue-with-forced-shard-allocation-awareness/360770 "2024-06-04T13:46:53Z")

</div>

I recently set up a small test cluster on docker in order to show how forced shard allocation awareness works and was surprised to find that my configuration is not working as expected. As this is old and trusted functio…

---

## [java.security.AccessControlException: access denied (\\”java.net.SocketPermission\\” \\”localhost:0\\” \\”listen,resolve\\”)](https://discuss.elastic.co/t/java-security-accesscontrolexception-access-denied-java-net-socketpermission-localhost-0-listen-resolve/360476)

<div class="topic-metadata">

**Author:** [@logicr](https://discuss.elastic.co/u/logicr)\
**Replies:** 7\
**Last updated:** [June 4, 2024, 12:14pm UTC](https://discuss.elastic.co/t/java-security-accesscontrolexception-access-denied-java-net-socketpermission-localhost-0-listen-resolve/360476 "2024-06-04T12:14:19Z")

</div>

hi all, I have configured SocketPermission ("localhost: 0", "listen, resolve"), but this error will still be reported. Please help me solve it. Thanks!

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=103)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=105)
