# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=110

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 111

---

## [Help Needed: Interpreting MemoryAnalyzer Results for Memory Leak in ElasticSearch](https://discuss.elastic.co/t/help-needed-interpreting-memoryanalyzer-results-for-memory-leak-in-elasticsearch/359894)

<div class="topic-metadata">

**Author:** [@524186aa](https://discuss.elastic.co/u/524186aa)\
**Replies:** 0\
**Last updated:** [May 21, 2024, 8:41am UTC](https://discuss.elastic.co/t/help-needed-interpreting-memoryanalyzer-results-for-memory-leak-in-elasticsearch/359894 "2024-05-21T08:41:42Z")

</div>

Hi everyone, I'm encountering an issue with Elasticsearch and would greatly appreciate some assistance. Background Information: Elasticsearch Version: 7.15.2 Problem Description: I've been experiencing memory manage…

---

## [Lower case all fields](https://discuss.elastic.co/t/lower-case-all-fields/359791)

<div class="topic-metadata">

**Author:** [@han\_fatzot](https://discuss.elastic.co/u/han_fatzot)\
**Replies:** 8\
**Last updated:** [May 21, 2024, 7:44am UTC](https://discuss.elastic.co/t/lower-case-all-fields/359791 "2024-05-21T07:44:20Z")

</div>

hello :blush: I want to create visualizations on lowercase fields. Text type can not work because it can be aggerated. example: I want to create a visualization that shows the top ten process.executable but i want to…

---

## [Elastic Search Cluster node set up and best practices](https://discuss.elastic.co/t/elastic-search-cluster-node-set-up-and-best-practices/359781)

<div class="topic-metadata">

**Author:** [@Bibhutibhusan\_Sahoo](https://discuss.elastic.co/u/Bibhutibhusan_Sahoo)\
**Replies:** 2\
**Last updated:** [May 21, 2024, 5:03am UTC](https://discuss.elastic.co/t/elastic-search-cluster-node-set-up-and-best-practices/359781 "2024-05-21T05:03:36Z")

</div>

Hi team, We have two data center and hosted three Elasticsearch (master + data) node in each of these two data centers (2 node + 1 node). The intension is to achieve high availability during diester recovery. All these …

---

## [Filebeat with Kafka Does Not Insert Message Missing a Colon into Kibana](https://discuss.elastic.co/t/filebeat-with-kafka-does-not-insert-message-missing-a-colon-into-kibana/359737)

<div class="topic-metadata">

**Author:** [@jquisenberry](https://discuss.elastic.co/u/jquisenberry)\
**Replies:** 4\
**Last updated:** [May 20, 2024, 11:51pm UTC](https://discuss.elastic.co/t/filebeat-with-kafka-does-not-insert-message-missing-a-colon-into-kibana/359737 "2024-05-20T23:51:10Z")

</div>

I am working with an application that writes to a log file. Filebeat uses the Kafka module to send the log data to a central logging server. I am testing the process by appending to the log file with echo. This command …

---

## [Access number of tokens of a query from a filter](https://discuss.elastic.co/t/access-number-of-tokens-of-a-query-from-a-filter/359869)

<div class="topic-metadata">

**Author:** [@antoinelefloch](https://discuss.elastic.co/u/antoinelefloch)\
**Replies:** 0\
**Last updated:** [May 20, 2024, 9:12pm UTC](https://discuss.elastic.co/t/access-number-of-tokens-of-a-query-from-a-filter/359869 "2024-05-20T21:12:03Z")

</div>

Hello, I would like to filter only if there is more than one token in the query. I don't want to filter if there is a single stop word in the query. I was thinking of using something like here below in my settings, but…

---

## [Error encountered in metric beat installation](https://discuss.elastic.co/t/error-encountered-in-metric-beat-installation/359783)

<div class="topic-metadata">

**Author:** [@viera120](https://discuss.elastic.co/u/viera120)\
**Replies:** 1\
**Last updated:** [May 20, 2024, 7:49pm UTC](https://discuss.elastic.co/t/error-encountered-in-metric-beat-installation/359783 "2024-05-20T19:49:57Z")

</div>

Hi, We are running a 3 Node Elastic Cluster with Basic security features enabled and HTTPS communication with browser and Kibana enabled. We have followed the \[https://www.elastic.co/guide/en/elasticsearch/reference/cu…

---

## [Scaling cluster waits on shard initialization](https://discuss.elastic.co/t/scaling-cluster-waits-on-shard-initialization/359863)

<div class="topic-metadata">

**Author:** [@cvarano](https://discuss.elastic.co/u/cvarano)\
**Replies:** 0\
**Last updated:** [May 20, 2024, 7:22pm UTC](https://discuss.elastic.co/t/scaling-cluster-waits-on-shard-initialization/359863 "2024-05-20T19:22:45Z")

</div>

Hi team! When scaling up our Elastic-managed cluster, the new nodes do not begin serving search requests until all shards on all indices are initialized. I've increased our primary search index's priority so it's initia…

---

## [How come RefreshResponse is missing in 8.13.0. Needed for RHLC compatibility with v8](https://discuss.elastic.co/t/how-come-refreshresponse-is-missing-in-8-13-0-needed-for-rhlc-compatibility-with-v8/359678)

<div class="topic-metadata">

**Author:** [@buitcj](https://discuss.elastic.co/u/buitcj)\
**Replies:** 8\
**Last updated:** [May 20, 2024, 2:41pm UTC](https://discuss.elastic.co/t/how-come-refreshresponse-is-missing-in-8-13-0-needed-for-rhlc-compatibility-with-v8/359678 "2024-05-20T14:41:31Z")

</div>

This file/class exists in 8.12.2 (elasticsearch/server/src/main/java/org/elasticsearch/action/admin/indices/refresh/RefreshResponse.java at v8.12.2 · elastic/elasticsearch · GitHub) but is gone starting in 8.13.0. I didn…

---

## [Cache and disk rack filling](https://discuss.elastic.co/t/cache-and-disk-rack-filling/359837)

<div class="topic-metadata">

**Author:** [@ruslan12\_10](https://discuss.elastic.co/u/ruslan12_10)\
**Replies:** 0\
**Last updated:** [May 20, 2024, 1:50pm UTC](https://discuss.elastic.co/t/cache-and-disk-rack-filling/359837 "2024-05-20T13:50:08Z")

</div>

Hello everyone, I was updating the operating system and faced the problem that all the requests went not to the cache, but to the disk rack, which is why it loaded 100%. Could this have happened because of the update. Be…

---

## [Is there a way to speed up the average inference time?](https://discuss.elastic.co/t/is-there-a-way-to-speed-up-the-average-inference-time/359418)

<div class="topic-metadata">

**Author:** [@shwanlee](https://discuss.elastic.co/u/shwanlee)\
**Replies:** 12\
**Last updated:** [May 20, 2024, 11:27am UTC](https://discuss.elastic.co/t/is-there-a-way-to-speed-up-the-average-inference-time/359418 "2024-05-20T11:27:54Z")

</div>

Is there a way to speed up the average inference time in ML, as it is currently slow? I’m currently running version 8.13.2. The ML node currently has 32 vCPUs, and I've allocated 32 threads to the model. My goal is to ac…

---

## [NPE Initializing PluginsService in ES8](https://discuss.elastic.co/t/npe-initializing-pluginsservice-in-es8/359667)

<div class="topic-metadata">

**Author:** [@buitcj](https://discuss.elastic.co/u/buitcj)\
**Replies:** 4\
**Last updated:** [May 20, 2024, 9:54am UTC](https://discuss.elastic.co/t/npe-initializing-pluginsservice-in-es8/359667 "2024-05-20T09:54:16Z")

</div>

I am trying to create a Node, which was working in ES7 and now am trying to do the same thing in ES v8.11.3. The simple code is final Settings settings = Settings.builder() .put(ACTION\_AUTO\_CREATE\_INDEX, false) …

---

## [What query string can I supply to ensure no results?](https://discuss.elastic.co/t/what-query-string-can-i-supply-to-ensure-no-results/359774)

<div class="topic-metadata">

**Author:** [@catmanjan](https://discuss.elastic.co/u/catmanjan)\
**Replies:** 3\
**Last updated:** [May 20, 2024, 9:03am UTC](https://discuss.elastic.co/t/what-query-string-can-i-supply-to-ensure-no-results/359774 "2024-05-20T09:03:13Z")

</div>

Hello our application pipes things directly to elasticsearch query strings like so: "title:test and word:filter" But in some cases we want to pipe the filter in such a way that it never returns a hit, e.g. something li…

---

## [Elasticsearch and Kibana Quires](https://discuss.elastic.co/t/elasticsearch-and-kibana-quires/359806)

<div class="topic-metadata">

**Author:** [@Minz00](https://discuss.elastic.co/u/Minz00)\
**Replies:** 1\
**Last updated:** [May 20, 2024, 8:53am UTC](https://discuss.elastic.co/t/elasticsearch-and-kibana-quires/359806 "2024-05-20T08:53:18Z")

</div>

Hi, I would like to enquire some technical questions on security. Context: Elasticsearch and Kibana are running locally on host. Not connected to any cloud environments. The intent is to injest dataset into kibana dash…

---

## [Tracking the execution of Scroll API in Elasticsearch](https://discuss.elastic.co/t/tracking-the-execution-of-scroll-api-in-elasticsearch/359630)

<div class="topic-metadata">

**Author:** [@yago82](https://discuss.elastic.co/u/yago82)\
**Replies:** 3\
**Last updated:** [May 20, 2024, 8:17am UTC](https://discuss.elastic.co/t/tracking-the-execution-of-scroll-api-in-elasticsearch/359630 "2024-05-20T08:17:34Z")

</div>

Hi everyone, I'm currently working with Elasticsearch and I'm interested in tracking the execution of the Scroll API. Specifically, I want to audit the use of the Scroll API to keep track of when it is executed and by w…

---

## [\>10K fields: is it a problem? Why exactly?](https://discuss.elastic.co/t/10k-fields-is-it-a-problem-why-exactly/359285)

<div class="topic-metadata">

**Author:** [@Mikhail\_Khludnev](https://discuss.elastic.co/u/Mikhail_Khludnev)\
**Replies:** 1\
**Last updated:** [May 20, 2024, 7:40am UTC](https://discuss.elastic.co/t/10k-fields-is-it-a-problem-why-exactly/359285 "2024-05-20T07:40:37Z")

</div>

Hello. I have shards about 20G size with 600K docs each. Response time is acceptable. After a shard receives about 200K updates, it ends up 20 segments, response time exceeds the reasonable value. In profile, I spott…

---

## [Paging issues when developing search capabilities using Elasticsearch and MySQL](https://discuss.elastic.co/t/paging-issues-when-developing-search-capabilities-using-elasticsearch-and-mysql/359777)

<div class="topic-metadata">

**Author:** [@jaden](https://discuss.elastic.co/u/jaden)\
**Replies:** 4\
**Last updated:** [May 20, 2024, 6:34am UTC](https://discuss.elastic.co/t/paging-issues-when-developing-search-capabilities-using-elasticsearch-and-mysql/359777 "2024-05-20T06:34:58Z")

</div>

We are developing a search function for space rental products using Elasticsearch and MySQL. \[Search form\] From DateTime To DateTime Min Price Max Price The search form is the same as above, and there is no problem w…

---

## [3 nodes(7.17) on a single server](https://discuss.elastic.co/t/3-nodes-7-17-on-a-single-server/359410)

<div class="topic-metadata">

**Author:** [@bfarr11](https://discuss.elastic.co/u/bfarr11)\
**Replies:** 8\
**Last updated:** [May 20, 2024, 1:47am UTC](https://discuss.elastic.co/t/3-nodes-7-17-on-a-single-server/359410 "2024-05-20T01:47:31Z")

</div>

I need help with the configuration to run 3 nodes on a single server. It has 32 core, 128GB RAM, 10T disk - so plenty of space. Please do not post with negative - you should not do this posts. I simply need help with th…

---

## [Setup rollover in index template](https://discuss.elastic.co/t/setup-rollover-in-index-template/359610)

<div class="topic-metadata">

**Author:** [@Frances\_Chu](https://discuss.elastic.co/u/Frances_Chu)\
**Replies:** 3\
**Last updated:** [May 19, 2024, 5:13pm UTC](https://discuss.elastic.co/t/setup-rollover-in-index-template/359610 "2024-05-19T17:13:28Z")

</div>

in order to setup rollover I have to setup ilm policy and enable rollover create index template and use the policy I created in step 1 I need to config the logstash pipeline output { elasticsearch { ilm\_rollover…

---

## [Why a custom pipeline doesn't run automatically on a Crawler index?](https://discuss.elastic.co/t/why-a-custom-pipeline-doesnt-run-automatically-on-a-crawler-index/358235)

<div class="topic-metadata">

**Author:** [@freddyrb](https://discuss.elastic.co/u/freddyrb)\
**Replies:** 3\
**Last updated:** [May 19, 2024, 4:09pm UTC](https://discuss.elastic.co/t/why-a-custom-pipeline-doesnt-run-automatically-on-a-crawler-index/358235 "2024-05-19T16:09:40Z")

</div>

The situation: I created a Crawler index using a domain. After is created I added via script the field "indexedContentType": PUT /search-testindex1/\_mapping { "properties": { "indexedContentType": { "type":…

---

## [How to rollover data stream during reindex](https://discuss.elastic.co/t/how-to-rollover-data-stream-during-reindex/359765)

<div class="topic-metadata">

**Author:** [@jacob.k](https://discuss.elastic.co/u/jacob.k)\
**Replies:** 1\
**Last updated:** [May 19, 2024, 3:42pm UTC](https://discuss.elastic.co/t/how-to-rollover-data-stream-during-reindex/359765 "2024-05-19T15:42:15Z")

</div>

I have an index with size 5gb. I would like to reindex it to a data stream with rollover policy of max size 1gb and 7 days. This is my policy PUT \_ilm/policy/jacob\_policy { "policy": { "phases": { "hot": {…

---

## [Regarding clarification in ca](https://discuss.elastic.co/t/regarding-clarification-in-ca/359743)

<div class="topic-metadata">

**Author:** [@Yogesh\_AS](https://discuss.elastic.co/u/Yogesh_AS)\
**Replies:** 3\
**Last updated:** [May 18, 2024, 5:22pm UTC](https://discuss.elastic.co/t/regarding-clarification-in-ca/359743 "2024-05-18T17:22:49Z")

</div>

Hi Team, We are in the process of adding a self-signed certificate to our Elasticsearch or Kibana setup. I have a couple of questions: Without a CA, can I use only the elastic.crt and elastic.key files? If I have a ce…

---

## [Issue on my query](https://discuss.elastic.co/t/issue-on-my-query/359748)

<div class="topic-metadata">

**Author:** [@Claudio\_Clemente](https://discuss.elastic.co/u/Claudio_Clemente)\
**Replies:** 6\
**Last updated:** [May 18, 2024, 4:09pm UTC](https://discuss.elastic.co/t/issue-on-my-query/359748 "2024-05-18T16:09:57Z")

</div>

I would like to aggregate the result of the rows that have the error field with the same jobid { "query": { "match\_phrase": { "level": "ERROR" }, "exists": { "field": "metadata.CSBJobId" },…

---

## [Error - Invalid or missing build flavor \[oss\] for ES server upgrade to 7.10](https://discuss.elastic.co/t/error-invalid-or-missing-build-flavor-oss-for-es-server-upgrade-to-7-10/359601)

<div class="topic-metadata">

**Author:** [@jdinla](https://discuss.elastic.co/u/jdinla)\
**Replies:** 5\
**Last updated:** [May 18, 2024, 7:28am UTC](https://discuss.elastic.co/t/error-invalid-or-missing-build-flavor-oss-for-es-server-upgrade-to-7-10/359601 "2024-05-18T07:28:02Z")

</div>

Hi, I upgraded ES server on AWS from 6.8 to 7.10 (this is the latest offered for now). Until now I have been using Restclient 7.17.x. After upgrading the server I started getting - Note: This works fine on docker local…

---

## [TermQuery upgrade](https://discuss.elastic.co/t/termquery-upgrade/358110)

<div class="topic-metadata">

**Author:** [@ajt001](https://discuss.elastic.co/u/ajt001)\
**Replies:** 4\
**Last updated:** [May 18, 2024, 5:04am UTC](https://discuss.elastic.co/t/termquery-upgrade/358110 "2024-05-18T05:04:03Z")

</div>

Hi, I'm working through an upgrade and have an existing function using List for values in a TermQueryBuilder. I've found online a method to convert the values into a FieldValue, but I'm not sure how to handle the case w…

---

## [High Amount of Document Deletes on Elastic Search Version Upgrade](https://discuss.elastic.co/t/high-amount-of-document-deletes-on-elastic-search-version-upgrade/359738)

<div class="topic-metadata">

**Author:** [@luv](https://discuss.elastic.co/u/luv)\
**Replies:** 0\
**Last updated:** [May 17, 2024, 9:59pm UTC](https://discuss.elastic.co/t/high-amount-of-document-deletes-on-elastic-search-version-upgrade/359738 "2024-05-17T21:59:37Z")

</div>

I have a small Elasticsearch cluster having 3 master nodes(2core,2gb t3.small ec2) and 2 data nodes data-0 and data-1 (2core 8GB m6a.large ec2 4gb max heap for data nodes). Cluster runs in an EKS cluster. Cluster has on…

---

## [Can an elasticsearch cluster create indices in two different data directories](https://discuss.elastic.co/t/can-an-elasticsearch-cluster-create-indices-in-two-different-data-directories/359731)

<div class="topic-metadata">

**Author:** [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Replies:** 2\
**Last updated:** [May 17, 2024, 7:45pm UTC](https://discuss.elastic.co/t/can-an-elasticsearch-cluster-create-indices-in-two-different-data-directories/359731 "2024-05-17T19:45:53Z")

</div>

Hi All, We are running Elasticsearch (ES) v8.7.0 There are various feeds coming into ES from various sources via Logstash. I want to configure ES to create indices for one particular feed into a data directory which i…

---

## [Getting "Failed to index document for reason failed to parse field rank\_feature .elser\_model\_1](https://discuss.elastic.co/t/getting-failed-to-index-document-for-reason-failed-to-parse-field-rank-feature-elser-model-1/359662)

<div class="topic-metadata">

**Author:** [@wnmills3](https://discuss.elastic.co/u/wnmills3)\
**Replies:** 2\
**Last updated:** [May 17, 2024, 7:11pm UTC](https://discuss.elastic.co/t/getting-failed-to-index-document-for-reason-failed-to-parse-field-rank-feature-elser-model-1/359662 "2024-05-17T19:11:48Z")

</div>

I have mappings and processors in line with other examples here. However, during the index generation, I get an error like: {"date":"2024-05-16 14:53:43,147", "type":"ERROR", "class":"com.ibm.dp.datastore.utilities.ESUt…

---

## [How to prevent must clause not being added into bool query if it has null value in Java API Client](https://discuss.elastic.co/t/how-to-prevent-must-clause-not-being-added-into-bool-query-if-it-has-null-value-in-java-api-client/359729)

<div class="topic-metadata">

**Author:** [@PodarcisMuralis](https://discuss.elastic.co/u/PodarcisMuralis)\
**Replies:** 0\
**Last updated:** [May 17, 2024, 5:42pm UTC](https://discuss.elastic.co/t/how-to-prevent-must-clause-not-being-added-into-bool-query-if-it-has-null-value-in-java-api-client/359729 "2024-05-17T17:42:15Z")

</div>

I have a simple SearchRequest using the new elasticsearch Java API Client Library. return SearchRequest.of(sr -\> sr .index("myIndex") .query(q -\> q .bool(b -\> b …

---

## [Issues with Elasticsearch clustering](https://discuss.elastic.co/t/issues-with-elasticsearch-clustering/359724)

<div class="topic-metadata">

**Author:** [@cisco-oops](https://discuss.elastic.co/u/cisco-oops)\
**Replies:** 0\
**Last updated:** [May 17, 2024, 3:04pm UTC](https://discuss.elastic.co/t/issues-with-elasticsearch-clustering/359724 "2024-05-17T15:04:11Z")

</div>

Hello, We're attempting to build a 3-node Elastic cluster and were looking to get some assistance. We have a master node that we're trying to join two other Elastic nodes to. We were able to generate an enrollment toke…

---

## [Cross-cluster security](https://discuss.elastic.co/t/cross-cluster-security/359712)

<div class="topic-metadata">

**Author:** [@gbL2k](https://discuss.elastic.co/u/gbL2k)\
**Replies:** 2\
**Last updated:** [May 17, 2024, 1:18pm UTC](https://discuss.elastic.co/t/cross-cluster-security/359712 "2024-05-17T13:18:33Z")

</div>

Hello everyone! I am setting up cross-cluster search between a local cluster and two remote clusters. Each cluster has three Elasticsearch nodes and a Fleet server, and the local cluster also includes a Kibana instance.…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=109)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=111)
