# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=113

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 114

---

## [Update Elastic node license without API](https://discuss.elastic.co/t/update-elastic-node-license-without-api/359278)

<div class="topic-metadata">

**Author:** [@amirnegah](https://discuss.elastic.co/u/amirnegah)\
**Replies:** 1\
**Last updated:** [May 12, 2024, 7:18am UTC](https://discuss.elastic.co/t/update-elastic-node-license-without-api/359278 "2024-05-12T07:18:08Z")

</div>

Hi Everyone. I have an ES node which is 5.6.16 and the service is failed due that license expiring. I issued a new license but since the service is down, I can't update It through curl. Do you have any suggestion or o…

---

## [ElasticSearch 1.7.3 Download Link Broken](https://discuss.elastic.co/t/elasticsearch-1-7-3-download-link-broken/358956)

<div class="topic-metadata">

**Author:** [@netshade](https://discuss.elastic.co/u/netshade)\
**Replies:** 2\
**Last updated:** [May 11, 2024, 11:21am UTC](https://discuss.elastic.co/t/elasticsearch-1-7-3-download-link-broken/358956 "2024-05-11T11:21:55Z")

</div>

For the extremely old 1.7.3 release, the download link https://download.elastic.co/elasticsearch/elasticsearch/elasticsearch-1.7.3.zip now returns a 403. This breaks any workflows that depend on testing on older ES versi…

---

## [Some questions about xpack-ml?](https://discuss.elastic.co/t/some-questions-about-xpack-ml/359232)

<div class="topic-metadata">

**Author:** [@sheli00](https://discuss.elastic.co/u/sheli00)\
**Replies:** 2\
**Last updated:** [May 11, 2024, 12:55am UTC](https://discuss.elastic.co/t/some-questions-about-xpack-ml/359232 "2024-05-11T00:55:33Z")

</div>

I am using Elasticsearch as a developer. During the compilation process, I found that the download speed of ml-cpp-8.10.0-SNAPSHOT-deps.zip is very slow, and it is not managed by maven, so I cannot use mirror to download…

---

## [Elastic Search document fields and values statistics?](https://discuss.elastic.co/t/elastic-search-document-fields-and-values-statistics/359284)

<div class="topic-metadata">

**Author:** [@dennisk](https://discuss.elastic.co/u/dennisk)\
**Replies:** 0\
**Last updated:** [May 10, 2024, 9:45pm UTC](https://discuss.elastic.co/t/elastic-search-document-fields-and-values-statistics/359284 "2024-05-10T21:45:49Z")

</div>

I am working on a Python program that gives me statistics across all documents in a given Elastic Search index. Docs in our indexes have many fields that are not specifically mapped in the ES settings. They are just trea…

---

## [Is it possible to filter aggregation return result?](https://discuss.elastic.co/t/is-it-possible-to-filter-aggregation-return-result/359238)

<div class="topic-metadata">

**Author:** [@J\_Kit](https://discuss.elastic.co/u/J_Kit)\
**Replies:** 1\
**Last updated:** [May 10, 2024, 8:42pm UTC](https://discuss.elastic.co/t/is-it-possible-to-filter-aggregation-return-result/359238 "2024-05-10T20:42:33Z")

</div>

Hi, I got example 2 documents doc: 1 { ... author: \['mike', 'adam', 'julie'\] } doc: 2 { ... author: \['mike', 'mike stephen', 'apple'\] } in keyword search scenario, user will search "mike" with query below { "q…

---

## [Enable Audit Logging IN Elasticsearch For a User](https://discuss.elastic.co/t/enable-audit-logging-in-elasticsearch-for-a-user/359227)

<div class="topic-metadata">

**Author:** [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Replies:** 7\
**Last updated:** [May 10, 2024, 1:16pm UTC](https://discuss.elastic.co/t/enable-audit-logging-in-elasticsearch-for-a-user/359227 "2024-05-10T13:16:19Z")

</div>

Hello Team, We require to enable an audit for a specific user, meaning that whenever the user logs in or performs any CRUD operations in Elasticsearch, it should be recorded. The user has reported intermittent connectiv…

---

## [Why the slow query doesn't log in slowlog file](https://discuss.elastic.co/t/why-the-slow-query-doesnt-log-in-slowlog-file/359255)

<div class="topic-metadata">

**Author:** [@DJ\_Zhu](https://discuss.elastic.co/u/DJ_Zhu)\
**Replies:** 0\
**Last updated:** [May 10, 2024, 11:30am UTC](https://discuss.elastic.co/t/why-the-slow-query-doesnt-log-in-slowlog-file/359255 "2024-05-10T11:30:35Z")

</div>

Server Version: 6.8.6 On the client side, the response indicates that the query execution time was 394ms: {"took":394,"timed\_out":false,"\_shards":{"total":5,"successful":5,"failed":0},"hits": However, despite setting …

---

## [Search api returns no documents](https://discuss.elastic.co/t/search-api-returns-no-documents/359053)

<div class="topic-metadata">

**Author:** [@jgeek](https://discuss.elastic.co/u/jgeek)\
**Replies:** 4\
**Last updated:** [May 10, 2024, 11:22am UTC](https://discuss.elastic.co/t/search-api-returns-no-documents/359053 "2024-05-10T11:22:06Z")

</div>

We're encountering a delay in real-time data retrieval from Elasticsearch despite successfully inserting data through our Java Spring Boot producer application. Our consumer application relies on Elasticsearch's /\_searc…

---

## [Basic runtime fields to pull data from message field](https://discuss.elastic.co/t/basic-runtime-fields-to-pull-data-from-message-field/355372)

<div class="topic-metadata">

**Author:** [@randomnamegenerator](https://discuss.elastic.co/u/randomnamegenerator)\
**Replies:** 1\
**Last updated:** [May 10, 2024, 9:36am UTC](https://discuss.elastic.co/t/basic-runtime-fields-to-pull-data-from-message-field/355372 "2024-05-10T09:36:48Z")

</div>

Hello all, I am trying to create a series of runtime fields to extract additional data fields from the message field. If it makes any difference this is a EFK stack running in K8s. For example I want to create level fi…

---

## [\[JAVA\] Client CreateIndexRequest is failing with dynamic templates](https://discuss.elastic.co/t/java-client-createindexrequest-is-failing-with-dynamic-templates/359217)

<div class="topic-metadata">

**Author:** [@nkachami](https://discuss.elastic.co/u/nkachami)\
**Replies:** 1\
**Last updated:** [May 10, 2024, 8:24am UTC](https://discuss.elastic.co/t/java-client-createindexrequest-is-failing-with-dynamic-templates/359217 "2024-05-10T08:24:23Z")

</div>

Using: \<dependency\> \<groupId\>co.elastic.clients\</groupId\> \<artifactId\>elasticsearch-java\</artifactId\> \<version\>8.13.4\</version\> \</dependency\> When executing something like: CreateIndexRequest c…

---

## [Snapshot specific index/aliases elasticsearch version 8.12.0](https://discuss.elastic.co/t/snapshot-specific-index-aliases-elasticsearch-version-8-12-0/359147)

<div class="topic-metadata">

**Author:** [@Shashank\_Jain](https://discuss.elastic.co/u/Shashank_Jain)\
**Replies:** 1\
**Last updated:** [May 10, 2024, 7:00am UTC](https://discuss.elastic.co/t/snapshot-specific-index-aliases-elasticsearch-version-8-12-0/359147 "2024-05-10T07:00:30Z")

</div>

Hi all, I would like to take a snapshot of specific indexes containing certain aliases.Is it possible to do so, if yes, please can you advise? Thank you

---

## [Update license API](https://discuss.elastic.co/t/update-license-api/359032)

<div class="topic-metadata">

**Author:** [@artechkey](https://discuss.elastic.co/u/artechkey)\
**Replies:** 3\
**Last updated:** [May 10, 2024, 6:23am UTC](https://discuss.elastic.co/t/update-license-api/359032 "2024-05-10T06:23:04Z")

</div>

Hi, We are trying to update the license on our cluster from "basic" to a higher one. We are planning on using the "update license" API to apply the new license. https://www.elastic.co/guide/en/elasticsearch/reference/7…

---

## [How do I renew my elasticsearch self signed certificate which will not have impact on logstash vms](https://discuss.elastic.co/t/how-do-i-renew-my-elasticsearch-self-signed-certificate-which-will-not-have-impact-on-logstash-vms/358096)

<div class="topic-metadata">

**Author:** [@sudhir\_singh](https://discuss.elastic.co/u/sudhir_singh)\
**Replies:** 10\
**Last updated:** [May 10, 2024, 6:04am UTC](https://discuss.elastic.co/t/how-do-i-renew-my-elasticsearch-self-signed-certificate-which-will-not-have-impact-on-logstash-vms/358096 "2024-05-10T06:04:47Z")

</div>

Hi Everyone. My elasticsearch self signed certificate is about to expire and I have More than thousands of logstash vms which I'm using for logstash data ingestion to elasticsearch and I'm using the elasticsearch credent…

---

## [ESET PROTECT syslog cannot be retrieved correctly](https://discuss.elastic.co/t/eset-protect-syslog-cannot-be-retrieved-correctly/359222)

<div class="topic-metadata">

**Author:** [@kagawa](https://discuss.elastic.co/u/kagawa)\
**Replies:** 0\
**Last updated:** [May 10, 2024, 2:24am UTC](https://discuss.elastic.co/t/eset-protect-syslog-cannot-be-retrieved-correctly/359222 "2024-05-10T02:24:12Z")

</div>

Hellow, I am currently trying to analyze the logs using ESET PROTECT Integrations. I can get the logs from the API, but syslog is giving me errors. "error": { "message": \[ "syslog failed to process field…

---

## [Sort buckets by count in terms aggregation using java api client](https://discuss.elastic.co/t/sort-buckets-by-count-in-terms-aggregation-using-java-api-client/359215)

<div class="topic-metadata">

**Author:** [@Rohini1](https://discuss.elastic.co/u/Rohini1)\
**Replies:** 0\
**Last updated:** [May 9, 2024, 8:15pm UTC](https://discuss.elastic.co/t/sort-buckets-by-count-in-terms-aggregation-using-java-api-client/359215 "2024-05-09T20:15:14Z")

</div>

I want to sort buckets by doc count in terms aggregation and also sort buckets by sub aggregation

---

## [Import JSON Schema for ECS Events](https://discuss.elastic.co/t/import-json-schema-for-ecs-events/358883)

<div class="topic-metadata">

**Author:** [@vances](https://discuss.elastic.co/u/vances)\
**Replies:** 5\
**Last updated:** [May 9, 2024, 5:50pm UTC](https://discuss.elastic.co/t/import-json-schema-for-ecs-events/358883 "2024-05-09T17:50:03Z")

</div>

Having written meticulous JSON Schema files, using the Elastic Common Schema (ECS) guidelines, describing our events I am surprised to find no obvious way to import and use those schemas in Elastic Stack. Am I missing s…

---

## [Unable to install multi-node cluster - Skipping security auto configuration because this node is configured to bootstrap or to join a multi-node cluster, which is not supported., with exit code 80](https://discuss.elastic.co/t/unable-to-install-multi-node-cluster-skipping-security-auto-configuration-because-this-node-is-configured-to-bootstrap-or-to-join-a-multi-node-cluster-which-is-not-supported-with-exit-code-80/358229)

<div class="topic-metadata">

**Author:** [@jimmycricket](https://discuss.elastic.co/u/jimmycricket)\
**Replies:** 15\
**Last updated:** [May 9, 2024, 5:26pm UTC](https://discuss.elastic.co/t/unable-to-install-multi-node-cluster-skipping-security-auto-configuration-because-this-node-is-configured-to-bootstrap-or-to-join-a-multi-node-cluster-which-is-not-supported-with-exit-code-80/358229 "2024-05-09T17:26:40Z")

</div>

I am trying to perform the initial installation of a two node Elasticsearch cluster. This is on Ubuntu 22.04 with Elasticsearch version 8.13 installed via RPM. This is the contents of the file /etc/elasticsearch/elastic…

---

## [Why "knn\_query" doesn’t have a separate k parameter?](https://discuss.elastic.co/t/why-knn-query-doesn-t-have-a-separate-k-parameter/358727)

<div class="topic-metadata">

**Author:** [@alliswell](https://discuss.elastic.co/u/alliswell)\
**Replies:** 13\
**Last updated:** [May 9, 2024, 5:00pm UTC](https://discuss.elastic.co/t/why-knn-query-doesn-t-have-a-separate-k-parameter/358727 "2024-05-09T17:00:08Z")

</div>

Thanks elastic team, for adding knn\_query. Now with knn\_query it is possible to use function\_score or script\_score and influence the rank of vector search result and not solely rely on the cosine similarity score. This w…

---

## [Math Calculation in Elastic Watcher not working](https://discuss.elastic.co/t/math-calculation-in-elastic-watcher-not-working/359178)

<div class="topic-metadata">

**Author:** [@Santosh\_G](https://discuss.elastic.co/u/Santosh_G)\
**Replies:** 3\
**Last updated:** [May 9, 2024, 4:57pm UTC](https://discuss.elastic.co/t/math-calculation-in-elastic-watcher-not-working/359178 "2024-05-09T16:57:02Z")

</div>

I had the below response I am receiving from Elastic dev tools and I need to calculate the % difference increase/decrease between the 2 aggregation count. { "alternative\_input": { "hits": { "total": { "value": 3390…

---

## [Elasticsearch s3 snapshots](https://discuss.elastic.co/t/elasticsearch-s3-snapshots/359115)

<div class="topic-metadata">

**Author:** [@kannan\_raj](https://discuss.elastic.co/u/kannan_raj)\
**Replies:** 3\
**Last updated:** [May 9, 2024, 4:00pm UTC](https://discuss.elastic.co/t/elasticsearch-s3-snapshots/359115 "2024-05-09T16:00:04Z")

</div>

Hello Team, Is it possible to configure or change the medata service or sts service endpoint when creating s3 snapshot with InstanceProfileCredentialsProvider authentication method. I have tried with setting the env bu…

---

## [Frequent shards failure remediation](https://discuss.elastic.co/t/frequent-shards-failure-remediation/358746)

<div class="topic-metadata">

**Author:** [@Jhankar\_jha](https://discuss.elastic.co/u/Jhankar_jha)\
**Replies:** 4\
**Last updated:** [May 9, 2024, 3:18pm UTC](https://discuss.elastic.co/t/frequent-shards-failure-remediation/358746 "2024-05-09T15:18:17Z")

</div>

Hii Folks, Does anyone can help if there exists an api command to get the number of used, unused and total shards of my elasticsearch cluster? Additionally, How can i increase the total number of shards of my multi nod…

---

## [EsRejectedExecutionException - Need suggestions to overcome](https://discuss.elastic.co/t/esrejectedexecutionexception-need-suggestions-to-overcome/359173)

<div class="topic-metadata">

**Author:** [@navaneethan](https://discuss.elastic.co/u/navaneethan)\
**Replies:** 4\
**Last updated:** [May 9, 2024, 2:53pm UTC](https://discuss.elastic.co/t/esrejectedexecutionexception-need-suggestions-to-overcome/359173 "2024-05-09T14:53:35Z")

</div>

Hi Team, In our production env cluster we are getting EsRejectedExecutionException for some requests. We have observed that there is a recurring thread running by a particular customer which are doing indexing and occu…

---

## [There's a nasty issue with filtering the aggregation results for nested documents](https://discuss.elastic.co/t/theres-a-nasty-issue-with-filtering-the-aggregation-results-for-nested-documents/359192)

<div class="topic-metadata">

**Author:** [@young\_karl](https://discuss.elastic.co/u/young_karl)\
**Replies:** 0\
**Last updated:** [May 9, 2024, 1:33pm UTC](https://discuss.elastic.co/t/theres-a-nasty-issue-with-filtering-the-aggregation-results-for-nested-documents/359192 "2024-05-09T13:33:41Z")

</div>

Regarding the following index: For each document's nested sub-document tradeRecords, internally group them and count the number of tradeRecords where tradeRecords.tradeDate falls between \[1647273600000, 1674144000000\],…

---

## [Setup Elasticsearch for In-Memory Usage: Configuration and Index Size Estimation](https://discuss.elastic.co/t/setup-elasticsearch-for-in-memory-usage-configuration-and-index-size-estimation/359054)

<div class="topic-metadata">

**Author:** [@M.S.S](https://discuss.elastic.co/u/M.S.S)\
**Replies:** 5\
**Last updated:** [May 9, 2024, 1:12pm UTC](https://discuss.elastic.co/t/setup-elasticsearch-for-in-memory-usage-configuration-and-index-size-estimation/359054 "2024-05-09T13:12:44Z")

</div>

Hey everyone, We're looking into maximizing Elasticsearch's performance by leveraging memory usage to its fullest potential. We hypothesize that reducing disk I/O by running Elasticsearch entirely in memory could lead t…

---

## [Faceted Search with multiple selections from one facet](https://discuss.elastic.co/t/faceted-search-with-multiple-selections-from-one-facet/359181)

<div class="topic-metadata">

**Author:** [@Brandon\_Brown](https://discuss.elastic.co/u/Brandon_Brown)\
**Replies:** 0\
**Last updated:** [May 9, 2024, 12:38pm UTC](https://discuss.elastic.co/t/faceted-search-with-multiple-selections-from-one-facet/359181 "2024-05-09T12:38:47Z")

</div>

I'm trying to implement a faceted search on my website that allows users to select multiple facets within a group, but it also needs to filter out irrelevant options in other facets based on selections. Here's the scenar…

---

## [Post Upgrade - To REINDEX or not to REINDEX](https://discuss.elastic.co/t/post-upgrade-to-reindex-or-not-to-reindex/359179)

<div class="topic-metadata">

**Author:** [@peledc](https://discuss.elastic.co/u/peledc)\
**Replies:** 0\
**Last updated:** [May 9, 2024, 12:26pm UTC](https://discuss.elastic.co/t/post-upgrade-to-reindex-or-not-to-reindex/359179 "2024-05-09T12:26:57Z")

</div>

This is more of general "Best Practice" question: We have a 1TB of data in our ES7 indices. We intend to upgrade it to version 8.xx Question is - Should we REINDEX existing indices (which were created in version 7.xx)…

---

## [Query\_string search not working on text field](https://discuss.elastic.co/t/query-string-search-not-working-on-text-field/359166)

<div class="topic-metadata">

**Author:** [@yanir\_goldin](https://discuss.elastic.co/u/yanir_goldin)\
**Replies:** 1\
**Last updated:** [May 9, 2024, 11:46am UTC](https://discuss.elastic.co/t/query-string-search-not-working-on-text-field/359166 "2024-05-09T11:46:25Z")

</div>

Hi, I have a field with type "name": { "type": "text", "fields": { "keyword": { "type": "keyword", "normalizer": "case\_insensitive" } } …

---

## [How to Ingest data from Microsoft SCOM DatawarehouseDB to ELK](https://discuss.elastic.co/t/how-to-ingest-data-from-microsoft-scom-datawarehousedb-to-elk/359172)

<div class="topic-metadata">

**Author:** [@rpgani](https://discuss.elastic.co/u/rpgani)\
**Replies:** 0\
**Last updated:** [May 9, 2024, 11:22am UTC](https://discuss.elastic.co/t/how-to-ingest-data-from-microsoft-scom-datawarehousedb-to-elk/359172 "2024-05-09T11:22:43Z")

</div>

We have Microsoft SCOM, which monitors the infra and it has all the alert data and performance data collected and stored in the Datawarehouse DB. May i know how to utilize those data in our ELK, so that we can utilize i…

---

## [Xuggle-xuggler🫙5.4 is not available](https://discuss.elastic.co/t/xuggle-xuggler5-4-is-not-available/359051)

<div class="topic-metadata">

**Author:** [@Radhika1](https://discuss.elastic.co/u/Radhika1)\
**Replies:** 8\
**Last updated:** [May 9, 2024, 9:37am UTC](https://discuss.elastic.co/t/xuggle-xuggler5-4-is-not-available/359051 "2024-05-09T09:37:42Z")

</div>

@carly.richmond @spinscale Downloading from elasticsearch-releases: https://artifacts.elastic.co/maven/javax/servlet/servlet-api/maven-metadata.xml Could not transfer metadata javax.servlet:servlet-api/maven-metadata.…

---

## [Actual value](https://discuss.elastic.co/t/actual-value/359159)

<div class="topic-metadata">

**Author:** [@zi\_ninja](https://discuss.elastic.co/u/zi_ninja)\
**Replies:** 0\
**Last updated:** [May 9, 2024, 9:16am UTC](https://discuss.elastic.co/t/actual-value/359159 "2024-05-09T09:16:23Z")

</div>

I created 2 jobs both using data as A, as below JOB1 "analysis\_config": { "bucket\_span": "15m", "detectors": \[ { "detector\_description": "High count of events", "function": "count", …

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=112)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=114)
