# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=108

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 109

---

## [Data Modifications Following ElasticSearch Upgrade](https://discuss.elastic.co/t/data-modifications-following-elasticsearch-upgrade/360259)

<div class="topic-metadata">

**Author:** [@paaraj](https://discuss.elastic.co/u/paaraj)\
**Replies:** 0\
**Last updated:** [May 27, 2024, 7:15am UTC](https://discuss.elastic.co/t/data-modifications-following-elasticsearch-upgrade/360259 "2024-05-27T07:15:10Z")

</div>

Hello All, I have Elasticsearch Enterprise version 8.10 and I am considering upgrading to version 8.13.x. However, during our previous upgrade, we faced a significant issue where all our rules were automatically disable…

---

## [\[Elasticsearch\]\[ILM\] Set readonly for warn phase is not working](https://discuss.elastic.co/t/elasticsearch-ilm-set-readonly-for-warn-phase-is-not-working/360230)

<div class="topic-metadata">

**Author:** [@david89](https://discuss.elastic.co/u/david89)\
**Replies:** 1\
**Last updated:** [May 26, 2024, 8:13pm UTC](https://discuss.elastic.co/t/elasticsearch-ilm-set-readonly-for-warn-phase-is-not-working/360230 "2024-05-26T20:13:59Z")

</div>

Dear Bro, I am trying to set readonly for index in warn phase, using ILM but it is not readonly This is my setting "warm": { "min\_age": "2d", "actions": { "readonly": {} } }, P…

---

## [Create a mapping for an unmapped field in a data](https://discuss.elastic.co/t/create-a-mapping-for-an-unmapped-field-in-a-data/360237)

<div class="topic-metadata">

**Author:** [@PavanSatya](https://discuss.elastic.co/u/PavanSatya)\
**Replies:** 0\
**Last updated:** [May 26, 2024, 1:04pm UTC](https://discuss.elastic.co/t/create-a-mapping-for-an-unmapped-field-in-a-data/360237 "2024-05-26T13:04:59Z")

</div>

Dear Team, We are having a APM integration in our Elasticsearch instance, where we are having some of the unmapped fields as highlighted in the above Screenshot (please consider the field names which are highlighted)…

---

## [Elastic sink data for new index with ingest pipeline](https://discuss.elastic.co/t/elastic-sink-data-for-new-index-with-ingest-pipeline/360236)

<div class="topic-metadata">

**Author:** [@PavanSatya](https://discuss.elastic.co/u/PavanSatya)\
**Replies:** 0\
**Last updated:** [May 26, 2024, 12:23pm UTC](https://discuss.elastic.co/t/elastic-sink-data-for-new-index-with-ingest-pipeline/360236 "2024-05-26T12:23:33Z")

</div>

Dear Team, We are having data coming from the elastic sink kafka topics \>\>elastic Sink \>\> Elastic Search When we get data to Elasticsearch, there are some fields in which we want to transform data. Example : LastMod…

---

## [Converting Query DSL into human readable format](https://discuss.elastic.co/t/converting-query-dsl-into-human-readable-format/360234)

<div class="topic-metadata">

**Author:** [@Venkateshan\_Niladri](https://discuss.elastic.co/u/Venkateshan_Niladri)\
**Replies:** 0\
**Last updated:** [May 26, 2024, 11:45am UTC](https://discuss.elastic.co/t/converting-query-dsl-into-human-readable-format/360234 "2024-05-26T11:45:00Z")

</div>

Is there a way / predefined API to convert the Query DSL into human readable format (URL encoded query string) ? For example, this Query DSL - { "bool": { "should": \[ { "term": { "status":…

---

## [Having difficulty changing field type](https://discuss.elastic.co/t/having-difficulty-changing-field-type/360203)

<div class="topic-metadata">

**Author:** [@roman-tasi](https://discuss.elastic.co/u/roman-tasi)\
**Replies:** 1\
**Last updated:** [May 25, 2024, 7:57pm UTC](https://discuss.elastic.co/t/having-difficulty-changing-field-type/360203 "2024-05-25T19:57:13Z")

</div>

In Index Template I am trying to change my file field from type Text to type Keyword, however when I do this and save the settings I get this error: Unable to create template Failed to parse mapping \[\_doc\]: Unknown valu…

---

## [Elastic timestamp ingest via logstash](https://discuss.elastic.co/t/elastic-timestamp-ingest-via-logstash/359924)

<div class="topic-metadata">

**Author:** [@dfir](https://discuss.elastic.co/u/dfir)\
**Replies:** 24\
**Last updated:** [May 25, 2024, 4:29pm UTC](https://discuss.elastic.co/t/elastic-timestamp-ingest-via-logstash/359924 "2024-05-25T16:29:53Z")

</div>

I have a CSV file I am ingesting. The 'timestamp' field shows the time like this: 2024-03-14 09:30:58.000. In Logstash my Date Filter is show below. When the ingest runs the elastic index shows the timestamp field as …

---

## [Getting \`Query contains too many nested clauses; maxClauseCount is set to 252061\` in ES8](https://discuss.elastic.co/t/getting-query-contains-too-many-nested-clauses-maxclausecount-is-set-to-252061-in-es8/358798)

<div class="topic-metadata">

**Author:** [@Aditya\_Teltia](https://discuss.elastic.co/u/Aditya_Teltia)\
**Replies:** 2\
**Last updated:** [May 25, 2024, 1:58pm UTC](https://discuss.elastic.co/t/getting-query-contains-too-many-nested-clauses-maxclausecount-is-set-to-252061-in-es8/358798 "2024-05-25T13:58:41Z")

</div>

Hi, We are migrating from ES7 to ES8 and while running a query on ES7 and ES8 respectively, I am getting Query contains too many nested clauses; maxClauseCount is set to 252061 error in ES8 while it is working in ES7. …

---

## [Self host cluster no geoip data](https://discuss.elastic.co/t/self-host-cluster-no-geoip-data/360193)

<div class="topic-metadata">

**Author:** [@Honestabe](https://discuss.elastic.co/u/Honestabe)\
**Replies:** 5\
**Last updated:** [May 24, 2024, 11:25pm UTC](https://discuss.elastic.co/t/self-host-cluster-no-geoip-data/360193 "2024-05-24T23:25:08Z")

</div>

I haven been trying to get geoip data but logs show attempt to download database \[GeoLite2-Country.mmdb\] failed I suspect it is a authentication issue and that I need to add them to the domain list. How Is this acc…

---

## [Logs cannot be written and doesn't work basic auth after setting OIDC](https://discuss.elastic.co/t/logs-cannot-be-written-and-doesnt-work-basic-auth-after-setting-oidc/360190)

<div class="topic-metadata">

**Author:** [@cass1ope1a](https://discuss.elastic.co/u/cass1ope1a)\
**Replies:** 1\
**Last updated:** [May 24, 2024, 6:26pm UTC](https://discuss.elastic.co/t/logs-cannot-be-written-and-doesnt-work-basic-auth-after-setting-oidc/360190 "2024-05-24T18:26:40Z")

</div>

I need to switch Kibana to OIDC auth through keycloak I have default user dev with basic auth and logs writing by vector (with username logstash) to elasticsearch When i switch on OIDC, i cannot auth with that dev user…

---

## [Regex for a large text (book paragraphs)](https://discuss.elastic.co/t/regex-for-a-large-text-book-paragraphs/360192)

<div class="topic-metadata">

**Author:** [@Hugh\_Dancy](https://discuss.elastic.co/u/Hugh_Dancy)\
**Replies:** 1\
**Last updated:** [May 24, 2024, 5:05pm UTC](https://discuss.elastic.co/t/regex-for-a-large-text-book-paragraphs/360192 "2024-05-24T17:05:20Z")

</div>

I am taking singular paragraphs from a book and inserting them as text fields. I want to be able to run regexp expressions across multiple words, like "night.\*sky" to find sentences like The midnight sky cracked opened…

---

## [what this？](https://discuss.elastic.co/t/what-this/360184)

<div class="topic-metadata">

**Author:** [@rjs520](https://discuss.elastic.co/u/rjs520)\
**Replies:** 3\
**Last updated:** [May 24, 2024, 3:13pm UTC](https://discuss.elastic.co/t/what-this/360184 "2024-05-24T15:13:33Z")

</div>

\[2024-05-24T22:37:28,865\]\[INFO \]\[o.e.n.NativeAccess \] \[RJS\] Using \[jdk\] native provider and native methods for \[Windows\] \[2024-05-24T22:37:28,943\]\[ERROR\]\[o.e.b.Elasticsearch \] \[RJS\] fatal exception while boot…

---

## [Restrict access to my Azure blob container from Elastic Cloud static IPs](https://discuss.elastic.co/t/restrict-access-to-my-azure-blob-container-from-elastic-cloud-static-ips/360188)

<div class="topic-metadata">

**Author:** [@Hrusha](https://discuss.elastic.co/u/Hrusha)\
**Replies:** 0\
**Last updated:** [May 24, 2024, 3:09pm UTC](https://discuss.elastic.co/t/restrict-access-to-my-azure-blob-container-from-elastic-cloud-static-ips/360188 "2024-05-24T15:09:02Z")

</div>

I have a working Elastic Cloud deployment (as an ISV) on my Azure subscription. I am using the platforms' Azure blob connector to sync documents from a Blob container to Elasticsearch. Since the ES deployment is not on …

---

## [Term query with empty string and case\_insensitive setting become invalid](https://discuss.elastic.co/t/term-query-with-empty-string-and-case-insensitive-setting-become-invalid/359961)

<div class="topic-metadata">

**Author:** [@DannyDuo](https://discuss.elastic.co/u/DannyDuo)\
**Replies:** 5\
**Last updated:** [May 24, 2024, 1:51pm UTC](https://discuss.elastic.co/t/term-query-with-empty-string-and-case-insensitive-setting-become-invalid/359961 "2024-05-24T13:51:50Z")

</div>

Hello, everyone Here is my search request and response, I filter oceanchannelid to empty value, but I still get oceanchannelid with empty value. { "bool" : { "must\_not" : \[ { "term" : { "o…

---

## [Best practice about reindex](https://discuss.elastic.co/t/best-practice-about-reindex/360113)

<div class="topic-metadata">

**Author:** [@Frances\_Chu](https://discuss.elastic.co/u/Frances_Chu)\
**Replies:** 3\
**Last updated:** [May 24, 2024, 1:39pm UTC](https://discuss.elastic.co/t/best-practice-about-reindex/360113 "2024-05-24T13:39:35Z")

</div>

I got index\_A --\> hold the data 2022 index\_B\_Jan --\> hold the data of jan 2023 index\_B\_Feb --\> hold the data of Feb 2023 index\_B\_Mar --\> hold the data of Mar 2023 ..... index\_B\_Dec --\> hold the data of De…

---

## [Security Detection Rules ( SIEM )](https://discuss.elastic.co/t/security-detection-rules-siem/360163)

<div class="topic-metadata">

**Author:** [@Elk\_huh](https://discuss.elastic.co/u/Elk_huh)\
**Replies:** 0\
**Last updated:** [May 24, 2024, 1:34pm UTC](https://discuss.elastic.co/t/security-detection-rules-siem/360163 "2024-05-24T13:34:01Z")

</div>

For the Alerts , Detection rules Under Action when i am trying to output to an email Why doesn't the variable {{context.rule.investigation\_fields}} give me the values of the investigation fields, in the emails i just…

---

## [How to replace NEST class Attachment?](https://discuss.elastic.co/t/how-to-replace-nest-class-attachment/360074)

<div class="topic-metadata">

**Author:** [@frankmehlhop.com](https://discuss.elastic.co/u/frankmehlhop.com)\
**Replies:** 1\
**Last updated:** [May 24, 2024, 12:47pm UTC](https://discuss.elastic.co/t/how-to-replace-nest-class-attachment/360074 "2024-05-24T12:47:52Z")

</div>

I used to use the NEST library. This is now deprecated. I have implemented the recommended Elastic.Client.Elasticsearch. However, this library does not recognise the Attachment or ElasticClient class. How do I deal with…

---

## [Template migration from parent-child to nested give java heap memory issue](https://discuss.elastic.co/t/template-migration-from-parent-child-to-nested-give-java-heap-memory-issue/360147)

<div class="topic-metadata">

**Author:** [@swappy](https://discuss.elastic.co/u/swappy)\
**Replies:** 0\
**Last updated:** [May 24, 2024, 10:45am UTC](https://discuss.elastic.co/t/template-migration-from-parent-child-to-nested-give-java-heap-memory-issue/360147 "2024-05-24T10:45:25Z")

</div>

Hello, We are in a process of upgrading our elasticsearch version and for that we decided to convert existing parent-child template\_mapping to nested. During this process one of the scenario where more 10000 nested obje…

---

## [Wildcard is not working as expected](https://discuss.elastic.co/t/wildcard-is-not-working-as-expected/360117)

<div class="topic-metadata">

**Author:** [@venkatesh\_aamanchi](https://discuss.elastic.co/u/venkatesh_aamanchi)\
**Replies:** 7\
**Last updated:** [May 24, 2024, 8:51am UTC](https://discuss.elastic.co/t/wildcard-is-not-working-as-expected/360117 "2024-05-24T08:51:33Z")

</div>

Hello, I am using "wildcard" for matching fields of type text with a specific pattern. "query": { "wildcard": { "description": { "value": "objective\*", "case\_inse…

---

## [Setting up ES multi-node on multiple hosts](https://discuss.elastic.co/t/setting-up-es-multi-node-on-multiple-hosts/360063)

<div class="topic-metadata">

**Author:** [@Hugo\_Perez\_Fernandez](https://discuss.elastic.co/u/Hugo_Perez_Fernandez)\
**Replies:** 2\
**Last updated:** [May 24, 2024, 6:58am UTC](https://discuss.elastic.co/t/setting-up-es-multi-node-on-multiple-hosts/360063 "2024-05-24T06:58:56Z")

</div>

Hi all, When creating an Elasticsearch cluster using Docker with multiple nodes, where each one runs on its own host, a problem arises when forming the cluster when the containers are raised, because it cannot be formed…

---

## [Elasticsearch missing authentication credentials for REST request and won't let me setup elasticsearch passwords](https://discuss.elastic.co/t/elasticsearch-missing-authentication-credentials-for-rest-request-and-wont-let-me-setup-elasticsearch-passwords/359887)

<div class="topic-metadata">

**Author:** [@daniela09](https://discuss.elastic.co/u/daniela09)\
**Replies:** 3\
**Last updated:** [May 24, 2024, 5:52am UTC](https://discuss.elastic.co/t/elasticsearch-missing-authentication-credentials-for-rest-request-and-wont-let-me-setup-elasticsearch-passwords/359887 "2024-05-24T05:52:40Z")

</div>

I deployed Elasticsearch on Kubernetes and its running but I get these errors in my logs: "message":"monitoring execution failed", "ecs.version": "1.2.0","service.name":"ES\_ECS","event.dataset":"elasticsearch.server","p…

---

## [EsIntegTestCase in es8 cannot be used to test with RHLC?](https://discuss.elastic.co/t/esintegtestcase-in-es8-cannot-be-used-to-test-with-rhlc/360030)

<div class="topic-metadata">

**Author:** [@buitcj](https://discuss.elastic.co/u/buitcj)\
**Replies:** 5\
**Last updated:** [May 24, 2024, 5:50am UTC](https://discuss.elastic.co/t/esintegtestcase-in-es8-cannot-be-used-to-test-with-rhlc/360030 "2024-05-24T05:50:48Z")

</div>

I have automated tests that make use of the Rest High Level Client (RHLC) to communicate with an HA Elasticsearch cluster created using EsIntegTestCase to run the cluster in the JVM/process. I was previously testing agai…

---

## [Elasticsearch 7.16.2 Snapshot Status Error: 'duration cannot be negative'](https://discuss.elastic.co/t/elasticsearch-7-16-2-snapshot-status-error-duration-cannot-be-negative/359721)

<div class="topic-metadata">

**Author:** [@Anastasia\_Kornienko](https://discuss.elastic.co/u/Anastasia_Kornienko)\
**Replies:** 2\
**Last updated:** [May 23, 2024, 9:30pm UTC](https://discuss.elastic.co/t/elasticsearch-7-16-2-snapshot-status-error-duration-cannot-be-negative/359721 "2024-05-23T21:30:26Z")

</div>

Hello, I'm encountering an error when trying to check the status of a snapshot. The situation is as follows: I have an Elasticsearch 7.16.2 cluster consisting of 5 nodes. One node is currently unavailable while a snaps…

---

## [Elastic is failing to start with error Failed to parse mappings for index](https://discuss.elastic.co/t/elastic-is-failing-to-start-with-error-failed-to-parse-mappings-for-index/360012)

<div class="topic-metadata">

**Author:** [@ermisma](https://discuss.elastic.co/u/ermisma)\
**Replies:** 1\
**Last updated:** [May 23, 2024, 5:31pm UTC](https://discuss.elastic.co/t/elastic-is-failing-to-start-with-error-failed-to-parse-mappings-for-index/360012 "2024-05-23T17:31:53Z")

</div>

Elasticsearch fail to start with following error Error1 : Failed to parse mappings for index \[\[atlaslog\_latest/CwYSy1IAT9upXlq7inaeJg\]\] Error2: unexpected exception while waiting for http server to close I see root d…

---

## [Index documents with out type](https://discuss.elastic.co/t/index-documents-with-out-type/360087)

<div class="topic-metadata">

**Author:** [@gjahagir](https://discuss.elastic.co/u/gjahagir)\
**Replies:** 0\
**Last updated:** [May 23, 2024, 3:23pm UTC](https://discuss.elastic.co/t/index-documents-with-out-type/360087 "2024-05-23T15:23:13Z")

</div>

Hi, We have legacy code that utilizes NEST to index documents that are not backed by POCO. It builds JSON and calls lowlevel bulk index api to index the documents. The reason for this is that we do not know the propert…

---

## [\[Error\] Unable to run esrally benchmark in local](https://discuss.elastic.co/t/error-unable-to-run-esrally-benchmark-in-local/360053)

<div class="topic-metadata">

**Author:** [@gmittal22](https://discuss.elastic.co/u/gmittal22)\
**Replies:** 2\
**Last updated:** [May 23, 2024, 9:45am UTC](https://discuss.elastic.co/t/error-unable-to-run-esrally-benchmark-in-local/360053 "2024-05-23T09:45:36Z")

</div>

Command used: esrally race --distribution-version=7.10.0 --track=geonames --challenge=append-no-conflicts --target-hosts=127.0.0.1:9200 --kill-running-processes --pipeline=benchmark-only Logs: 2024-05-23 04:51:49,486 …

---

## [Improving Elasticsearach ingest capacity](https://discuss.elastic.co/t/improving-elasticsearach-ingest-capacity/360050)

<div class="topic-metadata">

**Author:** [@grazingelk](https://discuss.elastic.co/u/grazingelk)\
**Replies:** 6\
**Last updated:** [May 23, 2024, 9:33am UTC](https://discuss.elastic.co/t/improving-elasticsearach-ingest-capacity/360050 "2024-05-23T09:33:08Z")

</div>

Hi all, I have a self-hosted Kafka -\> Logstash -\> Elasticsearch setup. Logstash doesn't seem to be the bottleneck. By sending the LS output to /dev/null, I was able to achieve an average rate of 97,000 documents per s…

---

## [Reindex find different storage size](https://discuss.elastic.co/t/reindex-find-different-storage-size/360045)

<div class="topic-metadata">

**Author:** [@Frances\_Chu](https://discuss.elastic.co/u/Frances_Chu)\
**Replies:** 5\
**Last updated:** [May 23, 2024, 9:33am UTC](https://discuss.elastic.co/t/reindex-find-different-storage-size/360045 "2024-05-23T09:33:07Z")

</div>

i got 2 index: index\_A with 10 docs indexB with 4 docs I try to reindex index\_A and index\_B to index\_C reindex index\_A and index\_B to index\_D with no error message I found both index\_C and index\_D got 14 docs, expec…

---

## [Compare query performance between two index](https://discuss.elastic.co/t/compare-query-performance-between-two-index/360060)

<div class="topic-metadata">

**Author:** [@Frances\_Chu](https://discuss.elastic.co/u/Frances_Chu)\
**Replies:** 0\
**Last updated:** [May 23, 2024, 9:12am UTC](https://discuss.elastic.co/t/compare-query-performance-between-two-index/360060 "2024-05-23T09:12:31Z")

</div>

Would like to know is there any method to compare the performance of two index

---

## [Data field type changed from date to text](https://discuss.elastic.co/t/data-field-type-changed-from-date-to-text/360046)

<div class="topic-metadata">

**Author:** [@Frances\_Chu](https://discuss.elastic.co/u/Frances_Chu)\
**Replies:** 1\
**Last updated:** [May 23, 2024, 8:51am UTC](https://discuss.elastic.co/t/data-field-type-changed-from-date-to-text/360046 "2024-05-23T08:51:37Z")

</div>

My logstash configuration file like this After reading the csv file I change the log\_datetime field from "dd-MM HH:mm:ss" to "2024-05-23T01:18:07.000Z" by the following configuration in test.conf date { match =\> …

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=107)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=109)
