# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=105

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 106

---

## [Elastalert Not sending Alerts](https://discuss.elastic.co/t/elastalert-not-sending-alerts/360777)

<div class="topic-metadata">

**Author:** [@Amritpal](https://discuss.elastic.co/u/Amritpal)\
**Replies:** 1\
**Last updated:** [June 4, 2024, 11:46am UTC](https://discuss.elastic.co/t/elastalert-not-sending-alerts/360777 "2024-06-04T11:46:23Z")

</div>

I have Setup Elastalert but it is not sending any alerts in elastalert logs I am keep getting : INFO:elastalert:Ran ELK Rules from 2024-06-04 10:59 UTC to 2024-06-04 11:14 UTC: 0 query hits (0 already seen), 0 matches, 0…

---

## [System indices closed, not able to do anything](https://discuss.elastic.co/t/system-indices-closed-not-able-to-do-anything/360725)

<div class="topic-metadata">

**Author:** [@albertino87](https://discuss.elastic.co/u/albertino87)\
**Replies:** 6\
**Last updated:** [June 4, 2024, 11:04am UTC](https://discuss.elastic.co/t/system-indices-closed-not-able-to-do-anything/360725 "2024-06-04T11:04:34Z")

</div>

Hi, by mistake I closed all the indices (even the system indices) of my cluster and now i cannot do anything, not even log into kibana or open them with curl, the credentials (even if correct) are not recognized. how ca…

---

## [Ingestion Failure with ML inference for E5 model](https://discuss.elastic.co/t/ingestion-failure-with-ml-inference-for-e5-model/359188)

<div class="topic-metadata">

**Author:** [@Sanjay\_Samanaboina](https://discuss.elastic.co/u/Sanjay_Samanaboina)\
**Replies:** 3\
**Last updated:** [June 4, 2024, 10:51am UTC](https://discuss.elastic.co/t/ingestion-failure-with-ml-inference-for-e5-model/359188 "2024-06-04T10:51:11Z")

</div>

I have a use case where I need to reindex my documents to use Machine Learning capabilities for my data. Hence, I have been E5 Text Embedding model with body\_content field chunked using Ingest pipeline and also using Inf…

---

## [Receiving nested exception "java.lang.NoClassDefFoundError: jakarta/json/JsonException" when trying to use ElasticsearchClient with SpringBoot in Java](https://discuss.elastic.co/t/receiving-nested-exception-java-lang-noclassdeffounderror-jakarta-json-jsonexception-when-trying-to-use-elasticsearchclient-with-springboot-in-java/360742)

<div class="topic-metadata">

**Author:** [@Priyansh\_Maheshwari](https://discuss.elastic.co/u/Priyansh_Maheshwari)\
**Replies:** 1\
**Last updated:** [June 4, 2024, 8:28am UTC](https://discuss.elastic.co/t/receiving-nested-exception-java-lang-noclassdeffounderror-jakarta-json-jsonexception-when-trying-to-use-elasticsearchclient-with-springboot-in-java/360742 "2024-06-04T08:28:17Z")

</div>

Hi, I am new to Elasticsearch and trying to implement ElasticsearchClient in an already existing SpringBoot application. However, I am receiving the error "java.lang.NoClassDefFoundError: jakarta/json/JsonException" when…

---

## [How to suggest words instead of exact data match in suggestions?](https://discuss.elastic.co/t/how-to-suggest-words-instead-of-exact-data-match-in-suggestions/360763)

<div class="topic-metadata">

**Author:** [@furkangulec](https://discuss.elastic.co/u/furkangulec)\
**Replies:** 0\
**Last updated:** [June 4, 2024, 7:27am UTC](https://discuss.elastic.co/t/how-to-suggest-words-instead-of-exact-data-match-in-suggestions/360763 "2024-06-04T07:27:36Z")

</div>

For example, I have 5 products Samsung Galaxy S24 Phone Samsung Galaxy Phone S23 Samsung Smart TV HD 4K Smart TV Samsung Full HD 4K Samsung Smart Phone S20FE 64GB etc. etc. When I type something using edge ngram o…

---

## [Is it possible to use terraform to create cluster privileges and roles?](https://discuss.elastic.co/t/is-it-possible-to-use-terraform-to-create-cluster-privileges-and-roles/360752)

<div class="topic-metadata">

**Author:** [@wshao12](https://discuss.elastic.co/u/wshao12)\
**Replies:** 0\
**Last updated:** [June 4, 2024, 1:34am UTC](https://discuss.elastic.co/t/is-it-possible-to-use-terraform-to-create-cluster-privileges-and-roles/360752 "2024-06-04T01:34:16Z")

</div>

Hi Support, I want to do cross cluster replication. The prerequisites of this process need manager privilege and master node role, as documented here: ccr prerequisites Is it possible to use terraform to manage it? I d…

---

## [Seeing performance issues and time outs in elasticsearch but not finding much useful in the logs](https://discuss.elastic.co/t/seeing-performance-issues-and-time-outs-in-elasticsearch-but-not-finding-much-useful-in-the-logs/360743)

<div class="topic-metadata">

**Author:** [@dfinn](https://discuss.elastic.co/u/dfinn)\
**Replies:** 0\
**Last updated:** [June 3, 2024, 6:50pm UTC](https://discuss.elastic.co/t/seeing-performance-issues-and-time-outs-in-elasticsearch-but-not-finding-much-useful-in-the-logs/360743 "2024-06-03T18:50:21Z")

</div>

We have been having issues lately with our production cluster. All of our grafana alerts will trigger with an error like so: Error = \[sse.dataQueryError\] failed to execute query \[A\]: Post "https://elastic.prod2-obsv-ea…

---

## [Query String query with multiple terms](https://discuss.elastic.co/t/query-string-query-with-multiple-terms/360723)

<div class="topic-metadata">

**Author:** [@darrylds](https://discuss.elastic.co/u/darrylds)\
**Replies:** 2\
**Last updated:** [June 3, 2024, 4:13pm UTC](https://discuss.elastic.co/t/query-string-query-with-multiple-terms/360723 "2024-06-03T16:13:16Z")

</div>

I have a quite large index, well at least to me, 3 million records and adds between 500 to 2000 more a day. There are 150 categories, I want to be able to search for query strings within those categories. There are al…

---

## [Accented and non-accented characters in Elasticsearch](https://discuss.elastic.co/t/accented-and-non-accented-characters-in-elasticsearch/360703)

<div class="topic-metadata">

**Author:** [@navaneethan](https://discuss.elastic.co/u/navaneethan)\
**Replies:** 3\
**Last updated:** [June 3, 2024, 3:52pm UTC](https://discuss.elastic.co/t/accented-and-non-accented-characters-in-elasticsearch/360703 "2024-06-03T15:52:21Z")

</div>

Hi Team, We need to produce both accented & non-accented characters for the non-accented searches in elasticsearch EX: for Amelie, the search should show Amelie as well as Amélie, Amèlie, Amélié, Ámelié, Àmelie To r…

---

## [Need Help Searching for Similarities in my Logs](https://discuss.elastic.co/t/need-help-searching-for-similarities-in-my-logs/357322)

<div class="topic-metadata">

**Author:** [@vpolius](https://discuss.elastic.co/u/vpolius)\
**Replies:** 1\
**Last updated:** [June 3, 2024, 3:34pm UTC](https://discuss.elastic.co/t/need-help-searching-for-similarities-in-my-logs/357322 "2024-06-03T15:34:01Z")

</div>

I am trying to find a query or filter to help me solve an issue. I have MFA logs coming into Elastic and I am trying to create an alert to let me know when an account authenticates using a phone number that is already us…

---

## [There are many defunct process while esrally race success](https://discuss.elastic.co/t/there-are-many-defunct-process-while-esrally-race-success/360719)

<div class="topic-metadata">

**Author:** [@Andy\_Cong](https://discuss.elastic.co/u/Andy_Cong)\
**Replies:** 1\
**Last updated:** [June 3, 2024, 3:08pm UTC](https://discuss.elastic.co/t/there-are-many-defunct-process-while-esrally-race-success/360719 "2024-06-03T15:08:51Z")

</div>

There are many defunct process while esrally race success. I have commit a complete issue on GitHub, but there is no response. Has anyone encountered this problem before? Can you provide some suggestions? add: run es…

---

## [import new third party models into elastic](https://discuss.elastic.co/t/import-new-third-party-models-into-elastic/360721)

<div class="topic-metadata">

**Author:** [@Imen\_Bakir](https://discuss.elastic.co/u/Imen_Bakir)\
**Replies:** 1\
**Last updated:** [June 3, 2024, 2:42pm UTC](https://discuss.elastic.co/t/import-new-third-party-models-into-elastic/360721 "2024-06-03T14:42:16Z")

</div>

Hello, is there a solution for this problem? I wanted to load a model into Elastic, (it's a clustering model: hdbscan), but I've encountered an error: NotImplementedError: Importing ML models of type \<class 'hdbscan.hd…

---

## [Ordering terms in term aggregation in the new Java API Client](https://discuss.elastic.co/t/ordering-terms-in-term-aggregation-in-the-new-java-api-client/360716)

<div class="topic-metadata">

**Author:** [@PodarcisMuralis](https://discuss.elastic.co/u/PodarcisMuralis)\
**Replies:** 4\
**Last updated:** [June 3, 2024, 2:08pm UTC](https://discuss.elastic.co/t/ordering-terms-in-term-aggregation-in-the-new-java-api-client/360716 "2024-06-03T14:08:57Z")

</div>

I have such an aggregation query in the old High Rest Client and want to convert it into the same query in the new Java API Client but there is not sort function in the terms query. How can we convert it? Or is it by def…

---

## [Boost field in the new Java API Client](https://discuss.elastic.co/t/boost-field-in-the-new-java-api-client/360715)

<div class="topic-metadata">

**Author:** [@PodarcisMuralis](https://discuss.elastic.co/u/PodarcisMuralis)\
**Replies:** 1\
**Last updated:** [June 3, 2024, 1:33pm UTC](https://discuss.elastic.co/t/boost-field-in-the-new-java-api-client/360715 "2024-06-03T13:33:41Z")

</div>

I am migrating old High Rest Java Api Client into Java Api Client but there are everywhere in queries of the old code, this "boost" field. I could not find out if these both fields are used in the new client by default…

---

## [Index template not getting applied to my index](https://discuss.elastic.co/t/index-template-not-getting-applied-to-my-index/360697)

<div class="topic-metadata">

**Author:** [@vijay117](https://discuss.elastic.co/u/vijay117)\
**Replies:** 7\
**Last updated:** [June 3, 2024, 1:33pm UTC](https://discuss.elastic.co/t/index-template-not-getting-applied-to-my-index/360697 "2024-06-03T13:33:05Z")

</div>

Hi Community, I have created a new index template( for total\_field\_limit) using Kibana console, but it is not getting applied with my index. I have deleted my index and then ran the code so that the index will pick the …

---

## [How query index data and indexed data](https://discuss.elastic.co/t/how-query-index-data-and-indexed-data/360537)

<div class="topic-metadata">

**Author:** [@Andy\_Cong](https://discuss.elastic.co/u/Andy_Cong)\
**Replies:** 2\
**Last updated:** [June 3, 2024, 11:49am UTC](https://discuss.elastic.co/t/how-query-index-data-and-indexed-data/360537 "2024-06-03T11:49:03Z")

</div>

Hi，andybody. I want to query an index table data and for other data related to this table, such as indexed data. I want to estimate how much disk storage capacity is needed based on the growth of index data. How can I…

---

## [Insert float data into Integer type success](https://discuss.elastic.co/t/insert-float-data-into-integer-type-success/360691)

<div class="topic-metadata">

**Author:** [@lht](https://discuss.elastic.co/u/lht)\
**Replies:** 2\
**Last updated:** [June 3, 2024, 8:57am UTC](https://discuss.elastic.co/t/insert-float-data-into-integer-type-success/360691 "2024-06-03T08:57:33Z")

</div>

I attempted to create a field of type integer in Elasticsearch, expecting to only be able to insert integers. However, I found that I was able to insert integers, floating-point numbers, and even strings (using co.elasti…

---

## [Insert a new json-record into an indexed document](https://discuss.elastic.co/t/insert-a-new-json-record-into-an-indexed-document/360683)

<div class="topic-metadata">

**Author:** [@Noureddine\_Ettalhi](https://discuss.elastic.co/u/Noureddine_Ettalhi)\
**Replies:** 1\
**Last updated:** [June 3, 2024, 5:04am UTC](https://discuss.elastic.co/t/insert-a-new-json-record-into-an-indexed-document/360683 "2024-06-03T05:04:41Z")

</div>

I am new to Elasticsearch, and I am trying to find a way to have an analogy with Oracle / SQL culture : Create table. insert records. update a record. select a record ...etc my current example is so simple: PUT /ett…

---

## [ELK Enterprise License](https://discuss.elastic.co/t/elk-enterprise-license/360685)

<div class="topic-metadata">

**Author:** [@Rutuja\_More](https://discuss.elastic.co/u/Rutuja_More)\
**Replies:** 1\
**Last updated:** [June 3, 2024, 4:31am UTC](https://discuss.elastic.co/t/elk-enterprise-license/360685 "2024-06-03T04:31:29Z")

</div>

In the ELK stack enterprise license, there is a drill-down option for selecting visuals on the dashboard, and we can also access the cloud platform. What are the features we can get more

---

## [Kubernetes log to elasticsearch](https://discuss.elastic.co/t/kubernetes-log-to-elasticsearch/360684)

<div class="topic-metadata">

**Author:** [@Frances\_Chu](https://discuss.elastic.co/u/Frances_Chu)\
**Replies:** 0\
**Last updated:** [June 3, 2024, 4:03am UTC](https://discuss.elastic.co/t/kubernetes-log-to-elasticsearch/360684 "2024-06-03T04:03:10Z")

</div>

I would like to send the Kubernetes log to my ES. I found some solutions like fluentd. I also found some information about install the Kubernetes integration assets Is there any updated method to do that. Any idea?

---

## [Failing to serialize 2D arrays \[Elasticsearch.NET\]](https://discuss.elastic.co/t/failing-to-serialize-2d-arrays-elasticsearch-net/360094)

<div class="topic-metadata">

**Author:** [@Motsols](https://discuss.elastic.co/u/Motsols)\
**Replies:** 1\
**Last updated:** [June 2, 2024, 4:55pm UTC](https://discuss.elastic.co/t/failing-to-serialize-2d-arrays-elasticsearch-net/360094 "2024-06-02T16:55:52Z")

</div>

A simple 2D array (aka multi-dimensional array) for a linestring such as this fails to serialize into json: new\[,\] { { 10.0, 10.0 }, {15.0, 15.0 } } With the exception message Elastic.Transport.UnexpectedTran…

---

## [Lower performance after migrating from Ceph to OpenEbs](https://discuss.elastic.co/t/lower-performance-after-migrating-from-ceph-to-openebs/360652)

<div class="topic-metadata">

**Author:** [@Sajad\_Soltanian](https://discuss.elastic.co/u/Sajad_Soltanian)\
**Replies:** 1\
**Last updated:** [June 1, 2024, 9:05am UTC](https://discuss.elastic.co/t/lower-performance-after-migrating-from-ceph-to-openebs/360652 "2024-06-01T09:05:02Z")

</div>

We have previously gotten 16 warm-data-nodes (running on Kuber) all having the same resource (32Gb heap, 64Gb Ram, 3 Tb hdd). Since it is not much recommended to use a distributed storage system for Elasticsearch, we ha…

---

## [Exiting: error unpacking config data: more than one namespace configured accessing 'output' (source:'/etc/filebeat/filebeat.yml')](https://discuss.elastic.co/t/exiting-error-unpacking-config-data-more-than-one-namespace-configured-accessing-output-source-etc-filebeat-filebeat-yml/360650)

<div class="topic-metadata">

**Author:** [@Kamalesh\_Seervi](https://discuss.elastic.co/u/Kamalesh_Seervi)\
**Replies:** 0\
**Last updated:** [June 1, 2024, 3:40am UTC](https://discuss.elastic.co/t/exiting-error-unpacking-config-data-more-than-one-namespace-configured-accessing-output-source-etc-filebeat-filebeat-yml/360650 "2024-06-01T03:40:14Z")

</div>

This is my filebeat.yml file I have commented the Logstash Now when I run this below command I get this error. sudo filebeat setup --index-management -E output.logstash.enable=false -E 'output.elasticsearch.hosts=\[…

---

## [Retrieve the configured max\_clause\_count setting 8.x](https://discuss.elastic.co/t/retrieve-the-configured-max-clause-count-setting-8-x/359873)

<div class="topic-metadata">

**Author:** [@mengjiann](https://discuss.elastic.co/u/mengjiann)\
**Replies:** 5\
**Last updated:** [June 1, 2024, 3:16am UTC](https://discuss.elastic.co/t/retrieve-the-configured-max-clause-count-setting-8-x/359873 "2024-06-01T03:16:25Z")

</div>

Hi, I understand that indices.query.bool.max\_clause\_count is deprecated in 8.x. The calculation is performed dynamically depending on the heap size and also the thread pool. But is there is a way to retrieve it durin…

---

## [Deprecated Nest library](https://discuss.elastic.co/t/deprecated-nest-library/360635)

<div class="topic-metadata">

**Author:** [@tchaudhry](https://discuss.elastic.co/u/tchaudhry)\
**Replies:** 0\
**Last updated:** [May 31, 2024, 4:23pm UTC](https://discuss.elastic.co/t/deprecated-nest-library/360635 "2024-05-31T16:23:17Z")

</div>

Has anyone tried replacing Nest v7 library with Elastic.Clients.Elasticsearch?

---

## [Two instance of es is failing unexpectedly error code 137](https://discuss.elastic.co/t/two-instance-of-es-is-failing-unexpectedly-error-code-137/360631)

<div class="topic-metadata">

**Author:** [@nagkumar](https://discuss.elastic.co/u/nagkumar)\
**Replies:** 4\
**Last updated:** [May 31, 2024, 3:12pm UTC](https://discuss.elastic.co/t/two-instance-of-es-is-failing-unexpectedly-error-code-137/360631 "2024-05-31T15:12:11Z")

</div>

two instance of Elasticsearch are failing to start any clues why it says unexpected exit..

---

## [Go-elasticsearch Term Aggregations using Typed Client](https://discuss.elastic.co/t/go-elasticsearch-term-aggregations-using-typed-client/360628)

<div class="topic-metadata">

**Author:** [@btcarlson](https://discuss.elastic.co/u/btcarlson)\
**Replies:** 0\
**Last updated:** [May 31, 2024, 1:37pm UTC](https://discuss.elastic.co/t/go-elasticsearch-term-aggregations-using-typed-client/360628 "2024-05-31T13:37:25Z")

</div>

I've been struggling to create term aggregations using the typed client v8.13.1, and am wondering whether I've uncovered a bug. To start, I've created three simple test documents like the following: { "type": "A" }…

---

## [Trying to deploy statefulSet of Elasticsearch, persisting config and keystore not work](https://discuss.elastic.co/t/trying-to-deploy-statefulset-of-elasticsearch-persisting-config-and-keystore-not-work/360595)

<div class="topic-metadata">

**Author:** [@dan\_kim](https://discuss.elastic.co/u/dan_kim)\
**Replies:** 0\
**Last updated:** [May 31, 2024, 6:19am UTC](https://discuss.elastic.co/t/trying-to-deploy-statefulset-of-elasticsearch-persisting-config-and-keystore-not-work/360595 "2024-05-31T06:19:52Z")

</div>

Hello , i need help to persist config file and keystore in k8s stateful set . this version is 8.13, and somehow it is really okay to persist data directory but, it not works when trying to persist config directory. …

---

## [Whitelisting URL || ElasticAgent || APM Agent || JAVA](https://discuss.elastic.co/t/whitelisting-url-elasticagent-apm-agent-java/360594)

<div class="topic-metadata">

**Author:** [@Yogesh\_AS](https://discuss.elastic.co/u/Yogesh_AS)\
**Replies:** 0\
**Last updated:** [May 31, 2024, 6:05am UTC](https://discuss.elastic.co/t/whitelisting-url-elasticagent-apm-agent-java/360594 "2024-05-31T06:05:34Z")

</div>

Hi Team , We are in airgap environment without any internent connectvitiy we need to install the elk , elk agent and elk APM agent what are the URL need to be whitelisted please let us know Thanks in advance!!!

---

## [Create index in which one field as an Object of not same structure](https://discuss.elastic.co/t/create-index-in-which-one-field-as-an-object-of-not-same-structure/360593)

<div class="topic-metadata">

**Author:** [@Parameshwar\_Wankhede](https://discuss.elastic.co/u/Parameshwar_Wankhede)\
**Replies:** 0\
**Last updated:** [May 31, 2024, 5:37am UTC](https://discuss.elastic.co/t/create-index-in-which-one-field-as-an-object-of-not-same-structure/360593 "2024-05-31T05:37:53Z")

</div>

So i need some suggestion , in my project there is existing sql table .in which i have some fields and one nested object. that nested object i am storing as json string and i am querying on that. and main thing is that o…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=104)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=106)
