# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=109

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 110

---

## [Increased write rejection count since elastic 8 upgrade](https://discuss.elastic.co/t/increased-write-rejection-count-since-elastic-8-upgrade/360055)

<div class="topic-metadata">

**Author:** [@kley](https://discuss.elastic.co/u/kley)\
**Replies:** 0\
**Last updated:** [May 23, 2024, 8:41am UTC](https://discuss.elastic.co/t/increased-write-rejection-count-since-elastic-8-upgrade/360055 "2024-05-23T08:41:28Z")

</div>

Hello! We recently upgraded one of our elasticsearch 7 environments to elasticsearch 8.9.1 and are now seeing many write rejections for whatever reason. We do not see any CPU and memory increase, we rather see a decreas…

---

## [Node: http://boardoftrustees-elk.kb.westeurope.azure.elastic-cloud.com:9243/, status: 400, \[es/indices.create\] Expecting JSON data but response content-type is: application/octet-stream](https://discuss.elastic.co/t/node-http-boardoftrustees-elk-kb-westeurope-azure-elastic-cloud-com-9243-status-400-es-indices-create-expecting-json-data-but-response-content-type-is-application-octet-stream/360024)

<div class="topic-metadata">

**Author:** [@fsk](https://discuss.elastic.co/u/fsk)\
**Replies:** 6\
**Last updated:** [May 23, 2024, 8:39am UTC](https://discuss.elastic.co/t/node-http-boardoftrustees-elk-kb-westeurope-azure-elastic-cloud-com-9243-status-400-es-indices-create-expecting-json-data-but-response-content-type-is-application-octet-stream/360024 "2024-05-23T08:39:59Z")

</div>

Hello guys. I have a project using spring boot and elastic cloud on azure. When i run command mvn clean install i have an error like below. Caused by: co.elastic.clients.transport.TransportException: node: http://trust…

---

## [Live index data transformation by using ingest pipeline](https://discuss.elastic.co/t/live-index-data-transformation-by-using-ingest-pipeline/359975)

<div class="topic-metadata">

**Author:** [@PavanSatya](https://discuss.elastic.co/u/PavanSatya)\
**Replies:** 7\
**Last updated:** [May 23, 2024, 8:32am UTC](https://discuss.elastic.co/t/live-index-data-transformation-by-using-ingest-pipeline/359975 "2024-05-23T08:32:45Z")

</div>

Dear Team, I'm new to ELK stack and need your support on this, I had an index where live date in coming form the kafka. Recently I had converted string data to date format by using the ingest pipeline. After that I h…

---

## [Create crawler index programatically](https://discuss.elastic.co/t/create-crawler-index-programatically/360048)

<div class="topic-metadata">

**Author:** [@javigsg](https://discuss.elastic.co/u/javigsg)\
**Replies:** 0\
**Last updated:** [May 23, 2024, 8:11am UTC](https://discuss.elastic.co/t/create-crawler-index-programatically/360048 "2024-05-23T08:11:07Z")

</div>

Hi Team! Do you know if it is possible to create an crawler index programatically with the API and then configure a custom ingesting pipeline? cheers

---

## [Searching words within a Sentence/paragraph](https://discuss.elastic.co/t/searching-words-within-a-sentence-paragraph/360044)

<div class="topic-metadata">

**Author:** [@Alok\_Tripathi](https://discuss.elastic.co/u/Alok_Tripathi)\
**Replies:** 2\
**Last updated:** [May 23, 2024, 7:39am UTC](https://discuss.elastic.co/t/searching-words-within-a-sentence-paragraph/360044 "2024-05-23T07:39:41Z")

</div>

I want to search for words to be in same sentence/paragraph. Example: If I search for words "Bill", "Steve" then no document2 should be returned because both words exist in the same sentence. But if I search for "Bill" …

---

## [Date stream can not be created with uppercase name?](https://discuss.elastic.co/t/date-stream-can-not-be-created-with-uppercase-name/360034)

<div class="topic-metadata">

**Author:** [@liurui](https://discuss.elastic.co/u/liurui)\
**Replies:** 1\
**Last updated:** [May 23, 2024, 7:25am UTC](https://discuss.elastic.co/t/date-stream-can-not-be-created-with-uppercase-name/360034 "2024-05-23T07:25:57Z")

</div>

Why can't date stream names contain uppercase letters? PUT \_data\_stream/Log # response { "error" : { "root\_cause" : \[ { "type" : "illegal\_argument\_exception", "reason" : "data\_stream \[Log\] m…

---

## [Upgrade ES 7.17.10 \> 8.6.2](https://discuss.elastic.co/t/upgrade-es-7-17-10-8-6-2/360014)

<div class="topic-metadata">

**Author:** [@Albert\_S](https://discuss.elastic.co/u/Albert_S)\
**Replies:** 1\
**Last updated:** [May 22, 2024, 11:02pm UTC](https://discuss.elastic.co/t/upgrade-es-7-17-10-8-6-2/360014 "2024-05-22T23:02:42Z")

</div>

Hello. I'm a complete newbie to ES. please help me, I need to update the cluster, what is the best or correct way to do this. which way to go? 9 nodes, docker, number\_of\_replics = 0.kibana and logstash are not used. …

---

## [Getting ReceiveTimeoutTransportException at Index creation, Indexing and Repo Creation](https://discuss.elastic.co/t/getting-receivetimeouttransportexception-at-index-creation-indexing-and-repo-creation/359072)

<div class="topic-metadata">

**Author:** [@dharunkumar](https://discuss.elastic.co/u/dharunkumar)\
**Replies:** 6\
**Last updated:** [May 22, 2024, 5:39pm UTC](https://discuss.elastic.co/t/getting-receivetimeouttransportexception-at-index-creation-indexing-and-repo-creation/359072 "2024-05-22T17:39:37Z")

</div>

Hi Team, while creating new Index shard acknowledgement fails, due to this mapping is not updated to the Index and status is yellow. Indexing fails due to ReceiveTimeoutTransportException. Also, Repo creation fails due …

---

## [Restore snapshot from cluster without hot-warm architecture](https://discuss.elastic.co/t/restore-snapshot-from-cluster-without-hot-warm-architecture/359886)

<div class="topic-metadata">

**Author:** [@Aliya\_Khalel](https://discuss.elastic.co/u/Aliya_Khalel)\
**Replies:** 1\
**Last updated:** [May 22, 2024, 4:06pm UTC](https://discuss.elastic.co/t/restore-snapshot-from-cluster-without-hot-warm-architecture/359886 "2024-05-22T16:06:36Z")

</div>

Hello, I have question Our customer has small 3-node cluster with 5 TB data. We planning to deploy new cluster with 3 hot, 1 warm and 3 cold nodes and 3 master. On which step I can restore snapshot with data to new c…

---

## [Kibana 8.12 transform process is too slow](https://discuss.elastic.co/t/kibana-8-12-transform-process-is-too-slow/360007)

<div class="topic-metadata">

**Author:** [@RobertC1](https://discuss.elastic.co/u/RobertC1)\
**Replies:** 0\
**Last updated:** [May 22, 2024, 3:06pm UTC](https://discuss.elastic.co/t/kibana-8-12-transform-process-is-too-slow/360007 "2024-05-22T15:06:56Z")

</div>

Every hour text files ar ingested to update the index. I have the following code of a process that transforms the data to seconds. "version": "10.0.0", "create\_time": 1714766696988, "source": { "index": \[ …

---

## [Index sorting would cause indexed data movement?](https://discuss.elastic.co/t/index-sorting-would-cause-indexed-data-movement/359978)

<div class="topic-metadata">

**Author:** [@chrwhy](https://discuss.elastic.co/u/chrwhy)\
**Replies:** 9\
**Last updated:** [May 22, 2024, 2:02pm UTC](https://discuss.elastic.co/t/index-sorting-would-cause-indexed-data-movement/359978 "2024-05-22T14:02:32Z")

</div>

Anybody know that index-sorting data is physically or logically sorted on disk? here is my question: if there are existing sorted data, when inserting a new record into the index, how will the new index-sorting data be …

---

## [Encountering NoSuchMethodError when Creating Elasticsearch Client](https://discuss.elastic.co/t/encountering-nosuchmethoderror-when-creating-elasticsearch-client/359763)

<div class="topic-metadata">

**Author:** [@Robin12](https://discuss.elastic.co/u/Robin12)\
**Replies:** 1\
**Last updated:** [May 22, 2024, 12:48pm UTC](https://discuss.elastic.co/t/encountering-nosuchmethoderror-when-creating-elasticsearch-client/359763 "2024-05-22T12:48:01Z")

</div>

I encountered a NoSuchMethodError when attempting to create an Elasticsearch client object in my Spring Boot Maven project. The error occurred specifically at the instantiation of the RestClientTransport object within th…

---

## [Alias Filter with Template Search](https://discuss.elastic.co/t/alias-filter-with-template-search/359983)

<div class="topic-metadata">

**Author:** [@bontempi](https://discuss.elastic.co/u/bontempi)\
**Replies:** 3\
**Last updated:** [May 22, 2024, 12:06pm UTC](https://discuss.elastic.co/t/alias-filter-with-template-search/359983 "2024-05-22T12:06:35Z")

</div>

I have an index pattern with documents that all have an owner field (owner\_username). This field contains the ES username of the person who owns the document. I'd like to set up a templated search alias, by which I mea…

---

## [Infinite Trial For Docker?](https://discuss.elastic.co/t/infinite-trial-for-docker/359987)

<div class="topic-metadata">

**Author:** [@Chenko](https://discuss.elastic.co/u/Chenko)\
**Replies:** 1\
**Last updated:** [May 22, 2024, 11:52am UTC](https://discuss.elastic.co/t/infinite-trial-for-docker/359987 "2024-05-22T11:52:03Z")

</div>

Hi all, I am wondering if there is a way to have an infinite trial for all my docker environments? I currently sometimes spin up a container with the trial license but if I return to that container after 30 days, which …

---

## [Java.exe consuming lot of memory and eventually Elasticsearch searches start failing](https://discuss.elastic.co/t/java-exe-consuming-lot-of-memory-and-eventually-elasticsearch-searches-start-failing/359960)

<div class="topic-metadata">

**Author:** [@Kalidastate](https://discuss.elastic.co/u/Kalidastate)\
**Replies:** 3\
**Last updated:** [May 22, 2024, 9:58am UTC](https://discuss.elastic.co/t/java-exe-consuming-lot-of-memory-and-eventually-elasticsearch-searches-start-failing/359960 "2024-05-22T09:58:30Z")

</div>

It has observed in the production environment. When a search is fired, memory consumption of Java.exe increases and it does not reduce even after the search is finished. Eventually the memory consumption reaches to above…

---

## [Getting wrong\_method\_type\_exception](https://discuss.elastic.co/t/getting-wrong-method-type-exception/359905)

<div class="topic-metadata">

**Author:** [@Aditya\_Teltia](https://discuss.elastic.co/u/Aditya_Teltia)\
**Replies:** 15\
**Last updated:** [May 22, 2024, 9:54am UTC](https://discuss.elastic.co/t/getting-wrong-method-type-exception/359905 "2024-05-22T09:54:11Z")

</div>

Query - {"timeout":"900000ms","query":{"constant\_score":{"filter":{"bool":{"must":{"bool":{"must":\[{"bool":{"should":\[{"terms":{"addI.sem.data.sentiment\_polarity":\["-1","-2","-1.0","-2.0","negative"\]}},{"terms":{"addI.s…

---

## [Convert in pipeline is not converting](https://discuss.elastic.co/t/convert-in-pipeline-is-not-converting/359964)

<div class="topic-metadata">

**Author:** [@Balu](https://discuss.elastic.co/u/Balu)\
**Replies:** 3\
**Last updated:** [May 22, 2024, 9:25am UTC](https://discuss.elastic.co/t/convert-in-pipeline-is-not-converting/359964 "2024-05-22T09:25:37Z")

</div>

Hello folks, I created an Ingest Pipeline that uses some grok patterns to split up fields. In the end I do a few converts to change the type of the fields. For example I am converting this field into an IP: { "c…

---

## [Rollover runs earlier than expected](https://discuss.elastic.co/t/rollover-runs-earlier-than-expected/359925)

<div class="topic-metadata">

**Author:** [@avnere](https://discuss.elastic.co/u/avnere)\
**Replies:** 1\
**Last updated:** [May 22, 2024, 8:09am UTC](https://discuss.elastic.co/t/rollover-runs-earlier-than-expected/359925 "2024-05-22T08:09:24Z")

</div>

I have an index with 2 shards, I configured a policy that performs rollover on max\_primary\_shard\_size=40gb. "policy": { "phases": { "hot": { "min\_age": "0ms", "actions": { "…

---

## [Sorting get Aliases](https://discuss.elastic.co/t/sorting-get-aliases/359927)

<div class="topic-metadata">

**Author:** [@avnere](https://discuss.elastic.co/u/avnere)\
**Replies:** 2\
**Last updated:** [May 22, 2024, 7:15am UTC](https://discuss.elastic.co/t/sorting-get-aliases/359927 "2024-05-22T07:15:39Z")

</div>

Hi, I am looking way to execute cat in the new Java client GET \_cat/aliases/bbb\*/?format=json&s=is\_write\_index:desc I found this way: AliasesRequest request = AliasesRequest.of(ar -\> ar.name(pattern)); var re…

---

## [Filtering by a nested common field](https://discuss.elastic.co/t/filtering-by-a-nested-common-field/359856)

<div class="topic-metadata">

**Author:** [@Fabio\_Bazurto](https://discuss.elastic.co/u/Fabio_Bazurto)\
**Replies:** 2\
**Last updated:** [May 21, 2024, 9:20pm UTC](https://discuss.elastic.co/t/filtering-by-a-nested-common-field/359856 "2024-05-21T21:20:36Z")

</div>

Given I have records with following structure: { ... , "CustomerInfo": { "GasStation": { "cardID": "abc123456" } } } { ... , "CustomerInfo": { "SuperMarket": { "cardID": "…

---

## [Transform vs update vs recreating index for historical/last values indexes](https://discuss.elastic.co/t/transform-vs-update-vs-recreating-index-for-historical-last-values-indexes/359923)

<div class="topic-metadata">

**Author:** [@PMF](https://discuss.elastic.co/u/PMF)\
**Replies:** 0\
**Last updated:** [May 21, 2024, 1:00pm UTC](https://discuss.elastic.co/t/transform-vs-update-vs-recreating-index-for-historical-last-values-indexes/359923 "2024-05-21T13:00:39Z")

</div>

On our current project we're looking for an approach where we create an index where all of our data is stored in a continuous way, creating a new document for each data change (let's call it "main index"), and another in…

---

## [Feasibility of Implementing Advanced Full Text Search Capabilities in Elasticsearch for a Big Data Warehouse](https://discuss.elastic.co/t/feasibility-of-implementing-advanced-full-text-search-capabilities-in-elasticsearch-for-a-big-data-warehouse/359936)

<div class="topic-metadata">

**Author:** [@Sarthak\_Jain](https://discuss.elastic.co/u/Sarthak_Jain)\
**Replies:** 0\
**Last updated:** [May 21, 2024, 4:27pm UTC](https://discuss.elastic.co/t/feasibility-of-implementing-advanced-full-text-search-capabilities-in-elasticsearch-for-a-big-data-warehouse/359936 "2024-05-21T16:27:56Z")

</div>

Hi Folks, I am currently working on a project to build a full text search for scientific research data. I need guidance on the feasibility of implementing the following functionality: Basic Search Operators: AND: Se…

---

## [Are snapshots taken during upgrade backward-compatible?](https://discuss.elastic.co/t/are-snapshots-taken-during-upgrade-backward-compatible/359935)

<div class="topic-metadata">

**Author:** [@shaigbdb](https://discuss.elastic.co/u/shaigbdb)\
**Replies:** 1\
**Last updated:** [May 21, 2024, 4:00pm UTC](https://discuss.elastic.co/t/are-snapshots-taken-during-upgrade-backward-compatible/359935 "2024-05-21T16:00:43Z")

</div>

I have an upgrade planned that will take several days. There is a daily snapshot scheduled in SLM. According to the documentation, "You can’t restore a snapshot to an earlier version of Elasticsearch". According to the…

---

## [\[Java SDK\] Optimistic lock occurs since switching to the 8.10 SDK](https://discuss.elastic.co/t/java-sdk-optimistic-lock-occurs-since-switching-to-the-8-10-sdk/359523)

<div class="topic-metadata">

**Author:** [@Odarik](https://discuss.elastic.co/u/Odarik)\
**Replies:** 1\
**Last updated:** [May 21, 2024, 2:35pm UTC](https://discuss.elastic.co/t/java-sdk-optimistic-lock-occurs-since-switching-to-the-8-10-sdk/359523 "2024-05-21T14:35:03Z")

</div>

Hello, We were in the process of switching from Elasticsearch 7 to Elasticsearch 8 and the first step was to update all of our Java SDK from the version 7.17.9 to 8.10.9. We have a CI that check regression on this part…

---

## [What is the best possible way to show time difference between two events in elastic search?](https://discuss.elastic.co/t/what-is-the-best-possible-way-to-show-time-difference-between-two-events-in-elastic-search/359911)

<div class="topic-metadata">

**Author:** [@gaurow.deshmukh](https://discuss.elastic.co/u/gaurow.deshmukh)\
**Replies:** 1\
**Last updated:** [May 21, 2024, 12:42pm UTC](https://discuss.elastic.co/t/what-is-the-best-possible-way-to-show-time-difference-between-two-events-in-elastic-search/359911 "2024-05-21T12:42:34Z")

</div>

What is the best possible way to show time difference between two events in Elasticsearch? Is it possible to add an additional field & show the time difference in that particular field

---

## [Elasticsearch cannot connect to the Remote Server](https://discuss.elastic.co/t/elasticsearch-cannot-connect-to-the-remote-server/359915)

<div class="topic-metadata">

**Author:** [@Akila\_P](https://discuss.elastic.co/u/Akila_P)\
**Replies:** 1\
**Last updated:** [May 21, 2024, 11:22am UTC](https://discuss.elastic.co/t/elasticsearch-cannot-connect-to-the-remote-server/359915 "2024-05-21T11:22:23Z")

</div>

When using Localhost root@ip-172-16-0-102:/etc/elasticsearch# curl localhost:9200 { "name" : "ip-172-16-0-102", "cluster\_name" : "elasticsearch", "cluster\_uuid" : "xXGFhvjvR\_qbJK\_oC0YPSg", "version" : { "num…

---

## [Why is Elasticsearch not using analyzer tokens during search?](https://discuss.elastic.co/t/why-is-elasticsearch-not-using-analyzer-tokens-during-search/359859)

<div class="topic-metadata">

**Author:** [@nikola1](https://discuss.elastic.co/u/nikola1)\
**Replies:** 1\
**Last updated:** [May 21, 2024, 11:16am UTC](https://discuss.elastic.co/t/why-is-elasticsearch-not-using-analyzer-tokens-during-search/359859 "2024-05-21T11:16:58Z")

</div>

index/\_analyze { "analyzer": "autocomplete", "field": "name", "text": "жаб" } gives me correct tokens: { "tokens": \[{ "token": "žab", "start\_offset"…

---

## [Caught exception while handling client http traffic, closing connection](https://discuss.elastic.co/t/caught-exception-while-handling-client-http-traffic-closing-connection/357567)

<div class="topic-metadata">

**Author:** [@sudharsanam132](https://discuss.elastic.co/u/sudharsanam132)\
**Replies:** 2\
**Last updated:** [May 21, 2024, 10:11am UTC](https://discuss.elastic.co/t/caught-exception-while-handling-client-http-traffic-closing-connection/357567 "2024-05-21T10:11:12Z")

</div>

While adding fleet I have this warning in elasticsearch repeatedly log: \[chamber1\] caught exception while handling client http traffic, closing connection Netty4HttpChannel{localAddress=/192.168.1.78:9200, remoteAddre…

---

## [ElasticSearch Snapshot using HDFS](https://discuss.elastic.co/t/elasticsearch-snapshot-using-hdfs/359908)

<div class="topic-metadata">

**Author:** [@saivenkatg5](https://discuss.elastic.co/u/saivenkatg5)\
**Replies:** 1\
**Last updated:** [May 21, 2024, 10:10am UTC](https://discuss.elastic.co/t/elasticsearch-snapshot-using-hdfs/359908 "2024-05-21T10:10:59Z")

</div>

Hey team, I was trying to take a snapshost of ES indices and store it in the HDFS files system, but when I give HDFS HA config, it is not able to initiate a config, whereas if we give Active NN hostname, it is working, …

---

## [Ignore API key failure from elastic cluster log](https://discuss.elastic.co/t/ignore-api-key-failure-from-elastic-cluster-log/359902)

<div class="topic-metadata">

**Author:** [@Nightingale\_John](https://discuss.elastic.co/u/Nightingale_John)\
**Replies:** 0\
**Last updated:** [May 21, 2024, 9:42am UTC](https://discuss.elastic.co/t/ignore-api-key-failure-from-elastic-cluster-log/359902 "2024-05-21T09:42:15Z")

</div>

Hi, For various reasons we have a lot of agents in the wild attempting to connect with aged API keys, e.g.: \[o.e.x.s.a.ApiKeyAuthenticator\] \[node\] Authentication using apikey failed - unable to find apikey with id Doe…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=108)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=110)
