# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=11

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 12

---

## [The transport thread cannot be executed by CPU for a long time due to node-level scheduling/resource contention in Elasticsearch cluster](https://discuss.elastic.co/t/the-transport-thread-cannot-be-executed-by-cpu-for-a-long-time-due-to-node-level-scheduling-resource-contention-in-elasticsearch-cluster/384060)

<div class="topic-metadata">

**Author:** [@arT1](https://discuss.elastic.co/u/arT1)\
**Replies:** 3\
**Last updated:** [December 15, 2025, 2:51pm UTC](https://discuss.elastic.co/t/the-transport-thread-cannot-be-executed-by-cpu-for-a-long-time-due-to-node-level-scheduling-resource-contention-in-elasticsearch-cluster/384060 "2025-12-15T14:51:55Z")

</div>

The transport thread cannot be executed by CPU for a long time due to node-level scheduling/resource contention in Elasticsearch cluster Environment: Elasticsearch version: v8.13.3 Deploy: tar.gz Service management: …

---

## [Impossible to build Elasticsearch 9.0 anymore](https://discuss.elastic.co/t/impossible-to-build-elasticsearch-9-0-anymore/383364)

<div class="topic-metadata">

**Author:** [@benjamingdocker](https://discuss.elastic.co/u/benjamingdocker)\
**Replies:** 7\
**Last updated:** [December 15, 2025, 2:00pm UTC](https://discuss.elastic.co/t/impossible-to-build-elasticsearch-9-0-anymore/383364 "2025-12-15T14:00:30Z")

</div>

Good morning :waving\_hand: I was trying to build ES 9.0.8 from sources but I am facing some issues. I am not a Java expert so please bear with me I probably do silly things here. However, I do need to build ES from sour…

---

## [Configure High Availability setup for elastic stack](https://discuss.elastic.co/t/configure-high-availability-setup-for-elastic-stack/383819)

<div class="topic-metadata">

**Author:** [@Eshwar\_K](https://discuss.elastic.co/u/Eshwar_K)\
**Replies:** 3\
**Last updated:** [December 15, 2025, 7:35am UTC](https://discuss.elastic.co/t/configure-high-availability-setup-for-elastic-stack/383819 "2025-12-15T07:35:09Z")

</div>

Hi Elastic Experts, I would appreciate your inputs on the queries below. We have a requirement to configure high availability across two data centers (DC and DR) for Elasticsearch nodes, Logstash, and Kibana. The custo…

---

## [Master node does not allow updating](https://discuss.elastic.co/t/master-node-does-not-allow-updating/384028)

<div class="topic-metadata">

**Author:** [@juancamiloll](https://discuss.elastic.co/u/juancamiloll)\
**Replies:** 3\
**Last updated:** [December 12, 2025, 7:10pm UTC](https://discuss.elastic.co/t/master-node-does-not-allow-updating/384028 "2025-12-12T19:10:45Z")

</div>

I am currently upgrading from the highest available version, v 8.19.3, to v 8.19.8. I successfully completed the process on two of the three servers in the cluster, but now I am having problems with the one that acts as…

---

## [Facing Error while upgrading elasticsearch cluster to 8.19.8](https://discuss.elastic.co/t/facing-error-while-upgrading-elasticsearch-cluster-to-8-19-8/384017)

<div class="topic-metadata">

**Author:** [@Umang\_Pachaury](https://discuss.elastic.co/u/Umang_Pachaury)\
**Replies:** 2\
**Last updated:** [December 12, 2025, 2:49pm UTC](https://discuss.elastic.co/t/facing-error-while-upgrading-elasticsearch-cluster-to-8-19-8/384017 "2025-12-12T14:49:24Z")

</div>

Hey everyone, I am currently upgrading my elasticsearch version from 8.11.3 to 8.19.8 and I am facing an error. I am using docker containers to deploy elasticsearch nodes. I was able to upgrade my coordinator and hot no…

---

## [What is the best indexing strategy in Elasticsearch for many small shards?](https://discuss.elastic.co/t/what-is-the-best-indexing-strategy-in-elasticsearch-for-many-small-shards/384010)

<div class="topic-metadata">

**Author:** [@cilasmarques](https://discuss.elastic.co/u/cilasmarques)\
**Replies:** 3\
**Last updated:** [December 12, 2025, 2:48pm UTC](https://discuss.elastic.co/t/what-is-the-best-indexing-strategy-in-elasticsearch-for-many-small-shards/384010 "2025-12-12T14:48:27Z")

</div>

I'm new to Elasticsearch and I'm trying to understand the best practices to improve performance in my scenario. I currently have 18 indices, one for each environment and location, each index has 1 shard and is \< 1 GB in …

---

## [Elastic/kibana webserver .p12/.crt issues](https://discuss.elastic.co/t/elastic-kibana-webserver-p12-crt-issues/383903)

<div class="topic-metadata">

**Author:** [@HaydenB0101](https://discuss.elastic.co/u/HaydenB0101)\
**Replies:** 6\
**Last updated:** [December 12, 2025, 1:37am UTC](https://discuss.elastic.co/t/elastic-kibana-webserver-p12-crt-issues/383903 "2025-12-12T01:37:56Z")

</div>

My elastic setup is running into issues after I generated new certs for http encryption using elasticsearch-certutil for http and ca. I followed this documentation as well as documentation from other people Kibana is run…

---

## [Migration 5.x to 9.x](https://discuss.elastic.co/t/migration-5-x-to-9-x/383997)

<div class="topic-metadata">

**Author:** [@ppat](https://discuss.elastic.co/u/ppat)\
**Replies:** 1\
**Last updated:** [December 11, 2025, 8:36pm UTC](https://discuss.elastic.co/t/migration-5-x-to-9-x/383997 "2025-12-11T20:36:06Z")

</div>

I am migrating gtom 5.x to 9.x, match\_all returns all documents but ith query it does return no documents even though there is a match. same application code works for develop 9.x elastic but qa 9.x it doesnt. Checked th…

---

## [Are date indexes not allowed anymore?](https://discuss.elastic.co/t/are-date-indexes-not-allowed-anymore/383941)

<div class="topic-metadata">

**Author:** [@ethrbunny](https://discuss.elastic.co/u/ethrbunny)\
**Replies:** 10\
**Last updated:** [December 11, 2025, 6:31pm UTC](https://discuss.elastic.co/t/are-date-indexes-not-allowed-anymore/383941 "2025-12-11T18:31:56Z")

</div>

My indexes are created from a template as ‘name-year.month.date’. It seems that this isn’t acceptable for index-lifecycle-policies anymore. I get this error “index name \[name-2025.12.09\] does not match pattern '^.\*-\\d+$'…

---

## [Elasticsearch-reset-password on linux can't accept special characters](https://discuss.elastic.co/t/elasticsearch-reset-password-on-linux-cant-accept-special-characters/383050)

<div class="topic-metadata">

**Author:** [@Ryan\_Clark](https://discuss.elastic.co/u/Ryan_Clark)\
**Replies:** 20\
**Last updated:** [December 11, 2025, 4:50pm UTC](https://discuss.elastic.co/t/elasticsearch-reset-password-on-linux-cant-accept-special-characters/383050 "2025-12-11T16:50:32Z")

</div>

When using the elasticsearch password reset tool (elasticsearch-reset-password) in Linux, using a special character will pick up the shell interpretation and not the character itself. In particular, I’m having issues usi…

---

## [Inquiry about billing for ELK serverless](https://discuss.elastic.co/t/inquiry-about-billing-for-elk-serverless/362993)

<div class="topic-metadata">

**Author:** [@rje287573](https://discuss.elastic.co/u/rje287573)\
**Replies:** 1\
**Last updated:** [December 11, 2025, 7:50am UTC](https://discuss.elastic.co/t/inquiry-about-billing-for-elk-serverless/362993 "2025-12-11T07:50:00Z")

</div>

I assumed that using serverless for my project would incur charges based on the time I used it, so I left it without sending any INSERT or SELECT requests. However, I was charged $700 unexpectedly. I completely don't un…

---

## [ILM vs routing for growing vector database with separate clients](https://discuss.elastic.co/t/ilm-vs-routing-for-growing-vector-database-with-separate-clients/383962)

<div class="topic-metadata">

**Author:** [@Pablito77](https://discuss.elastic.co/u/Pablito77)\
**Replies:** 5\
**Last updated:** [December 10, 2025, 5:56pm UTC](https://discuss.elastic.co/t/ilm-vs-routing-for-growing-vector-database-with-separate-clients/383962 "2025-12-10T17:56:39Z")

</div>

Hello, I use elasticsearch as a vector db for 1024 dim vectors. My initial setup would be around 20 million vectors, but it may increase to 100 milion vectors over time. However i always prefilter the vector search to a…

---

## [Very strange ingest pipeline problem](https://discuss.elastic.co/t/very-strange-ingest-pipeline-problem/383942)

<div class="topic-metadata">

**Author:** [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Replies:** 5\
**Last updated:** [December 10, 2025, 5:52pm UTC](https://discuss.elastic.co/t/very-strange-ingest-pipeline-problem/383942 "2025-12-10T17:52:31Z")

</div>

I have a need to add an ingest pipeline to the elastic-cloud-logs-9 data stream in a cloud-hosted environment running 9.2. It’s not complicated logic, but it’s a little complicated extracting a field from message with 2…

---

## [Migrating from Elastic NEST v7 to .NET Elastic Client v9: Aggregation with Nested clause](https://discuss.elastic.co/t/migrating-from-elastic-nest-v7-to-net-elastic-client-v9-aggregation-with-nested-clause/383958)

<div class="topic-metadata">

**Author:** [@Vadym\_Romanenko](https://discuss.elastic.co/u/Vadym_Romanenko)\
**Replies:** 2\
**Last updated:** [December 10, 2025, 3:22pm UTC](https://discuss.elastic.co/t/migrating-from-elastic-nest-v7-to-net-elastic-client-v9-aggregation-with-nested-clause/383958 "2025-12-10T15:22:45Z")

</div>

I’m moving code from the NEST client to the Elasticsearch client v9.2. I’m trying to generate aggregation that contains a nested filter. Here is sample of the old code with NEST: AggregationContainerDescriptor\<T\> ret; …

---

## [Will the HLRC client work with Elasticsearch version 9.x](https://discuss.elastic.co/t/will-the-hlrc-client-work-with-elasticsearch-version-9-x/383952)

<div class="topic-metadata">

**Author:** [@Umang\_Pachaury](https://discuss.elastic.co/u/Umang_Pachaury)\
**Replies:** 5\
**Last updated:** [December 10, 2025, 11:23am UTC](https://discuss.elastic.co/t/will-the-hlrc-client-work-with-elasticsearch-version-9-x/383952 "2025-12-10T11:23:33Z")

</div>

Hello everyone, We have a large java application which heavily relies on HLRC code. Our current ES version is 8.x As we know that the HLRC client was deprecated with 7.17.x, it currently works with our version 8.x my …

---

## [Inconsistency count observed for term aggregation operation](https://discuss.elastic.co/t/inconsistency-count-observed-for-term-aggregation-operation/383916)

<div class="topic-metadata">

**Author:** [@harshkoshta](https://discuss.elastic.co/u/harshkoshta)\
**Replies:** 7\
**Last updated:** [December 10, 2025, 10:20am UTC](https://discuss.elastic.co/t/inconsistency-count-observed-for-term-aggregation-operation/383916 "2025-12-10T10:20:17Z")

</div>

Describe the issue: Inconsistency count observed for term aggregation operation We are applying aggregation on keyword type field (non-nested) our mapping { "mappings": { "dynamic": "strict", "prope…

---

## [Open a point in time API error after Elastic Client upgrade](https://discuss.elastic.co/t/open-a-point-in-time-api-error-after-elastic-client-upgrade/383940)

<div class="topic-metadata">

**Author:** [@tcsbears](https://discuss.elastic.co/u/tcsbears)\
**Replies:** 2\
**Last updated:** [December 10, 2025, 9:48am UTC](https://discuss.elastic.co/t/open-a-point-in-time-api-error-after-elastic-client-upgrade/383940 "2025-12-10T09:48:49Z")

</div>

We are upgrading our application from Java 11 → 17 and Spring boot 2.x.x → 3.5.6. Before the upgrade, we used RestHighLevelClient 7.17 and Elasticsearch 7.17 on the server. We replaced RestHighLevelClient with Elastics…

---

## [How can we do elasticsearch and stack migration to new hardware, retaining all old data?](https://discuss.elastic.co/t/how-can-we-do-elasticsearch-and-stack-migration-to-new-hardware-retaining-all-old-data/383950)

<div class="topic-metadata">

**Author:** [@Aditya\_M](https://discuss.elastic.co/u/Aditya_M)\
**Replies:** 1\
**Last updated:** [December 10, 2025, 9:40am UTC](https://discuss.elastic.co/t/how-can-we-do-elasticsearch-and-stack-migration-to-new-hardware-retaining-all-old-data/383950 "2025-12-10T09:40:16Z")

</div>

We actually have single node cluster for now. Server is about to expire, so we have to shift this existing stack to new server. But now we dont want to rely on single node cluster, we have 3 new nodes, which will be our …

---

## [Hypothetical - ingest nodes vs data nodes](https://discuss.elastic.co/t/hypothetical-ingest-nodes-vs-data-nodes/383932)

<div class="topic-metadata">

**Author:** [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Replies:** 3\
**Last updated:** [December 9, 2025, 5:50pm UTC](https://discuss.elastic.co/t/hypothetical-ingest-nodes-vs-data-nodes/383932 "2025-12-09T17:50:47Z")

</div>

I got into a design discussion: Is it better to use ingest nodes or direct to data (hot) nodes? One thing that I don’t think I’ve ever seen discussed is this, say we’re ingesting to data nodes, a bulk request will like…

---

## [Elasticsearch Snapshots in a Dedicated S3 Bucket (Cross-Region, Multi-Deployment)](https://discuss.elastic.co/t/elasticsearch-snapshots-in-a-dedicated-s3-bucket-cross-region-multi-deployment/383928)

<div class="topic-metadata">

**Author:** [@dr\_sce](https://discuss.elastic.co/u/dr_sce)\
**Replies:** 4\
**Last updated:** [December 9, 2025, 3:52pm UTC](https://discuss.elastic.co/t/elasticsearch-snapshots-in-a-dedicated-s3-bucket-cross-region-multi-deployment/383928 "2025-12-09T15:52:43Z")

</div>

Hello I have a question about snapshots in Elasticsearch. We use Elastic Cloud via AWS and want to use a dedicated S3 bucket in another region for snapshots instead of found-snapshots so that we can set up our deployme…

---

## [Can I sort a sematic query based on a field containing a value or not?](https://discuss.elastic.co/t/can-i-sort-a-sematic-query-based-on-a-field-containing-a-value-or-not/383906)

<div class="topic-metadata">

**Author:** [@bwagner](https://discuss.elastic.co/u/bwagner)\
**Replies:** 1\
**Last updated:** [December 6, 2025, 11:37am UTC](https://discuss.elastic.co/t/can-i-sort-a-sematic-query-based-on-a-field-containing-a-value-or-not/383906 "2025-12-06T11:37:19Z")

</div>

I am new to elastic an Elasticsearch and I guess this is a fairly simple, beginner type quesation. I have an index that contains information from websites and pdf documents. The index is used in a chat bot on an a websi…

---

## [How to add labels to sql span?](https://discuss.elastic.co/t/how-to-add-labels-to-sql-span/383901)

<div class="topic-metadata">

**Author:** [@VictoRK](https://discuss.elastic.co/u/VictoRK)\
**Replies:** 0\
**Last updated:** [December 5, 2025, 5:02pm UTC](https://discuss.elastic.co/t/how-to-add-labels-to-sql-span/383901 "2025-12-05T17:02:55Z")

</div>

I need to add labels to my autogenerated sql span details in my .NET Web Application. My agent is started in global.asax and i have the following code: Dim AgentComponents = ElasticApmModule.CreateAgentComponents() Ag…

---

## [Index pattern](https://discuss.elastic.co/t/index-pattern/383849)

<div class="topic-metadata">

**Author:** [@jgomezf](https://discuss.elastic.co/u/jgomezf)\
**Replies:** 4\
**Last updated:** [December 4, 2025, 11:11pm UTC](https://discuss.elastic.co/t/index-pattern/383849 "2025-12-04T23:11:16Z")

</div>

We have worked with the version elastic 8.4.10 and we cannot delete old index through curl delete https:localhost:9200/indices/ds.logsxxx{yesterday}\*. Do you have any idea as delete old index through scripts Thanks

---

## [Pending tasks accumulating with ES 8.17.3](https://discuss.elastic.co/t/pending-tasks-accumulating-with-es-8-17-3/383850)

<div class="topic-metadata">

**Author:** [@Phil\_Budne](https://discuss.elastic.co/u/Phil_Budne)\
**Replies:** 1\
**Last updated:** [December 4, 2025, 1:27pm UTC](https://discuss.elastic.co/t/pending-tasks-accumulating-with-es-8-17-3/383850 "2025-12-04T13:27:41Z")

</div>

We’ve seen this before, and has cleared up after the master nodes (self?) restarted ES: $ curl http://es.newsscribe.angwin:9209/ { "name" : "es02.newsscribe.angwin", "cluster\_name" : "mc\_es\_cluster", "cluster\_uuid…

---

## [Elasticsearch Integration Dashboard Data not Loading](https://discuss.elastic.co/t/elasticsearch-integration-dashboard-data-not-loading/383747)

<div class="topic-metadata">

**Author:** [@YousefNein](https://discuss.elastic.co/u/YousefNein)\
**Replies:** 4\
**Last updated:** [December 4, 2025, 12:57pm UTC](https://discuss.elastic.co/t/elasticsearch-integration-dashboard-data-not-loading/383747 "2025-12-04T12:57:42Z")

</div>

I have the Elasticsearch integration in Fleet enabled with metrics and logs; however, the dashboard isn’t loading due to several errors related to some fields not being present

---

## [Is \_refresh the same as internal periodic refresh?](https://discuss.elastic.co/t/is-refresh-the-same-as-internal-periodic-refresh/383858)

<div class="topic-metadata">

**Author:** [@Mo\_B](https://discuss.elastic.co/u/Mo_B)\
**Replies:** 2\
**Last updated:** [December 4, 2025, 9:05am UTC](https://discuss.elastic.co/t/is-refresh-the-same-as-internal-periodic-refresh/383858 "2025-12-04T09:05:17Z")

</div>

The documentation says that \_refresh is resource-intensive. But does calling \_refresh on an index have the same impact and cost as the automatic periodic refresh that is configurable via index.refresh\_interval? Is it pe…

---

## [Supporting private channels and direct messages documents from slack](https://discuss.elastic.co/t/supporting-private-channels-and-direct-messages-documents-from-slack/383830)

<div class="topic-metadata">

**Author:** [@kenseii](https://discuss.elastic.co/u/kenseii)\
**Replies:** 2\
**Last updated:** [December 4, 2025, 12:59am UTC](https://discuss.elastic.co/t/supporting-private-channels-and-direct-messages-documents-from-slack/383830 "2025-12-04T00:59:03Z")

</div>

Hello, The current slack connector does not support reading documents from private channels and direct messages when crawling the data into elastic. Elastic Slack connector reference | Reference Is there a plan to prov…

---

## [Checking if updated documents are visible to search](https://discuss.elastic.co/t/checking-if-updated-documents-are-visible-to-search/383843)

<div class="topic-metadata">

**Author:** [@Mo\_B](https://discuss.elastic.co/u/Mo_B)\
**Replies:** 6\
**Last updated:** [December 3, 2025, 10:17pm UTC](https://discuss.elastic.co/t/checking-if-updated-documents-are-visible-to-search/383843 "2025-12-03T22:17:19Z")

</div>

Given a set of recently updated documents (indexed without waiting for refresh), is there a way to check if they have been refreshed, or to wait until they have been refreshed (without calling \_refresh)? Waiting for x …

---

## [Recall Stage vs LTR: am I duplicating logic or losing good results in Elasticsearch?](https://discuss.elastic.co/t/recall-stage-vs-ltr-am-i-duplicating-logic-or-losing-good-results-in-elasticsearch/383630)

<div class="topic-metadata">

**Author:** [@Shell\_Dias](https://discuss.elastic.co/u/Shell_Dias)\
**Replies:** 1\
**Last updated:** [December 3, 2025, 8:04pm UTC](https://discuss.elastic.co/t/recall-stage-vs-ltr-am-i-duplicating-logic-or-losing-good-results-in-elasticsearch/383630 "2025-12-03T20:04:40Z")

</div>

Hey folks, I’m building a search pipeline using Elasticsearch + Vector Search + LTR, and I’ve hit a conceptual conflict. Classic pipeline: Recall (BM25 / Vector / Hybrid) LTR (rerank top-K) Pagination All g…

---

## [How can I delay HNSW index construction until a segment reaches a target size?](https://discuss.elastic.co/t/how-can-i-delay-hnsw-index-construction-until-a-segment-reaches-a-target-size/383826)

<div class="topic-metadata">

**Author:** [@sfmqrb](https://discuss.elastic.co/u/sfmqrb)\
**Replies:** 1\
**Last updated:** [December 3, 2025, 7:38pm UTC](https://discuss.elastic.co/t/how-can-i-delay-hnsw-index-construction-until-a-segment-reaches-a-target-size/383826 "2025-12-03T19:38:50Z")

</div>

I’m trying to tune vector indexing behavior. Specifically, I want the first HNSW index for a segment to be built only after the segment reaches a certain size (e.g., X MB or Y vectors), instead of building small HNSW gra…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=10)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=12)
