# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=114

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 115

---

## [Anomaly detection algorithm](https://discuss.elastic.co/t/anomaly-detection-algorithm/359140)

<div class="topic-metadata">

**Author:** [@zi\_ninja](https://discuss.elastic.co/u/zi_ninja)\
**Replies:** 0\
**Last updated:** [May 9, 2024, 7:18am UTC](https://discuss.elastic.co/t/anomaly-detection-algorithm/359140 "2024-05-09T07:18:09Z")

</div>

I also have this question that I want answered. I looked at the links in the article, but most of them only generally explain what that value is, not detailed algorithms or calculations. Book link I can't read because …

---

## [Typical value](https://discuss.elastic.co/t/typical-value/358043)

<div class="topic-metadata">

**Author:** [@zi\_ninja](https://discuss.elastic.co/u/zi_ninja)\
**Replies:** 2\
**Last updated:** [May 9, 2024, 7:08am UTC](https://discuss.elastic.co/t/typical-value/358043 "2024-05-09T07:08:30Z")

</div>

In the single metric viewer, I see that the actual value is the value calculated from the actual data, but what about the typical value? How can I determine this typical value? Is the typical value being calculated accor…

---

## [Hardware requirements for elasticssearch](https://discuss.elastic.co/t/hardware-requirements-for-elasticssearch/359059)

<div class="topic-metadata">

**Author:** [@Muhammad\_Shahyan](https://discuss.elastic.co/u/Muhammad_Shahyan)\
**Replies:** 4\
**Last updated:** [May 9, 2024, 6:51am UTC](https://discuss.elastic.co/t/hardware-requirements-for-elasticssearch/359059 "2024-05-09T06:51:28Z")

</div>

what are the minimum hardware requirements for high availability elk cluster.

---

## [ILM enabled Logstash Pipeline Issue](https://discuss.elastic.co/t/ilm-enabled-logstash-pipeline-issue/358697)

<div class="topic-metadata">

**Author:** [@Souvik\_Das](https://discuss.elastic.co/u/Souvik_Das)\
**Replies:** 8\
**Last updated:** [May 9, 2024, 4:57am UTC](https://discuss.elastic.co/t/ilm-enabled-logstash-pipeline-issue/358697 "2024-05-09T04:57:57Z")

</div>

Hi Folks, I am facing an issue with a ILM enabled logstash pipeline. Let me describe my objective. So I have created a logstash pipeline that has upsert feature to update/insert documents in the elasticsearch index. My …

---

## [\[Elasticsearch\] How to keep cache consistent](https://discuss.elastic.co/t/elasticsearch-how-to-keep-cache-consistent/359116)

<div class="topic-metadata">

**Author:** [@david89](https://discuss.elastic.co/u/david89)\
**Replies:** 0\
**Last updated:** [May 9, 2024, 12:37am UTC](https://discuss.elastic.co/t/elasticsearch-how-to-keep-cache-consistent/359116 "2024-05-09T00:37:09Z")

</div>

Hello, I am applying rollover for my cluster, also refresh\_interval = 7d for old rollover index But sometimes the cache/or indice is refreshed, I do not know the reason Do you know the way I can keep the Elasticsearch …

---

## [Anomaly Detection API](https://discuss.elastic.co/t/anomaly-detection-api/359075)

<div class="topic-metadata">

**Author:** [@tr0lln](https://discuss.elastic.co/u/tr0lln)\
**Replies:** 0\
**Last updated:** [May 8, 2024, 2:02pm UTC](https://discuss.elastic.co/t/anomaly-detection-api/359075 "2024-05-08T14:02:41Z")

</div>

Hi, I've created an Anomaly Detection job which I'm wanting to integrate into one of our playbook orchestration tools (XSoar). In short, when triggered i want to pull the current anomaly score from the job for the speci…

---

## [Rollover to Frozen Tier](https://discuss.elastic.co/t/rollover-to-frozen-tier/359056)

<div class="topic-metadata">

**Author:** [@ksremo](https://discuss.elastic.co/u/ksremo)\
**Replies:** 1\
**Last updated:** [May 8, 2024, 1:46pm UTC](https://discuss.elastic.co/t/rollover-to-frozen-tier/359056 "2024-05-08T13:46:27Z")

</div>

Hello, As I understand it, it is necessary to have an alias defined before using ILM for migrating from the hot phase to the frozen phase. However, this is not all; the alias configuration also needs to specify which in…

---

## [Display log message in kibana alerting](https://discuss.elastic.co/t/display-log-message-in-kibana-alerting/358504)

<div class="topic-metadata">

**Author:** [@Roshan\_Joel](https://discuss.elastic.co/u/Roshan_Joel)\
**Replies:** 5\
**Last updated:** [May 8, 2024, 1:35pm UTC](https://discuss.elastic.co/t/display-log-message-in-kibana-alerting/358504 "2024-05-08T13:35:57Z")

</div>

how to display entire log message or log field in kibana alerting

---

## [Cluster rebalancing](https://discuss.elastic.co/t/cluster-rebalancing/359057)

<div class="topic-metadata">

**Author:** [@Atefeh](https://discuss.elastic.co/u/Atefeh)\
**Replies:** 2\
**Last updated:** [May 8, 2024, 1:06pm UTC](https://discuss.elastic.co/t/cluster-rebalancing/359057 "2024-05-08T13:06:34Z")

</div>

I have an issue with ES automatic rebalancing shards in my cluster: I’m using Elasticsearch 7.17.9 I have a cluster with 17 data nodes that all of them have data role Data nodes already have cluster.routing.allocation.…

---

## [Is there a way to combine scoring and highlighting from two separate (stemmer) fields?](https://discuss.elastic.co/t/is-there-a-way-to-combine-scoring-and-highlighting-from-two-separate-stemmer-fields/359044)

<div class="topic-metadata">

**Author:** [@mrodent](https://discuss.elastic.co/u/mrodent)\
**Replies:** 1\
**Last updated:** [May 8, 2024, 10:57am UTC](https://discuss.elastic.co/t/is-there-a-way-to-combine-scoring-and-highlighting-from-two-separate-stemmer-fields/359044 "2024-05-08T10:57:31Z")

</div>

I've indexed a whole load of .docx files: each file is split up into (overlapping) sequences of 10 paragraphs while parsing. So each LDoc (Lucene document) in the index consists of 10 paragraphs of text. In these docume…

---

## [Missing documents when using re-index API](https://discuss.elastic.co/t/missing-documents-when-using-re-index-api/358824)

<div class="topic-metadata">

**Author:** [@SamehSaeed](https://discuss.elastic.co/u/SamehSaeed)\
**Replies:** 10\
**Last updated:** [May 8, 2024, 10:34am UTC](https://discuss.elastic.co/t/missing-documents-when-using-re-index-api/358824 "2024-05-08T10:34:12Z")

</div>

Hello, I'm facing an issue while using re-index API. Currently we have 1 index per day of data which leaves is with just 100 days of data visible on the dashboard (cuz of the data view limitation) so I was trying to re…

---

## [Search rate and index latency is high and showing high response](https://discuss.elastic.co/t/search-rate-and-index-latency-is-high-and-showing-high-response/359046)

<div class="topic-metadata">

**Author:** [@sudhir\_singh](https://discuss.elastic.co/u/sudhir_singh)\
**Replies:** 0\
**Last updated:** [May 8, 2024, 10:15am UTC](https://discuss.elastic.co/t/search-rate-and-index-latency-is-high-and-showing-high-response/359046 "2024-05-08T10:15:08Z")

</div>

I'm using elasticsearch as database but I'm facing momentary surge in search rate and latency. Can anyone tell why there is a high search rate and latency observerd I have 10 nodes of cluster which are physical vms. It's…

---

## [Docker swarm multi-node ElasticSearch cluster error](https://discuss.elastic.co/t/docker-swarm-multi-node-elasticsearch-cluster-error/358978)

<div class="topic-metadata">

**Author:** [@taras\_volosheniuk](https://discuss.elastic.co/u/taras_volosheniuk)\
**Replies:** 0\
**Last updated:** [May 7, 2024, 5:41pm UTC](https://discuss.elastic.co/t/docker-swarm-multi-node-elasticsearch-cluster-error/358978 "2024-05-07T17:41:42Z")

</div>

I'm trying to setup docker swarm elasticsearch multi-node cluster. Here is my compose file: elasticsearch: image: elastic/elasticsearch:8.13.0 hostname: elasticsearch environment: - c…

---

## [What might be wrong with this attempt to highlight ES results?](https://discuss.elastic.co/t/what-might-be-wrong-with-this-attempt-to-highlight-es-results/356918)

<div class="topic-metadata">

**Author:** [@mrodent](https://discuss.elastic.co/u/mrodent)\
**Replies:** 5\
**Last updated:** [May 8, 2024, 9:55am UTC](https://discuss.elastic.co/t/what-might-be-wrong-with-this-attempt-to-highlight-es-results/356918 "2024-05-08T09:55:32Z")

</div>

I have a working version of an Elasticsearch 7.10.2 setup where the stemmed query results are highlighted in beautiful multiple colours. So if you have 4 words in your search query the results are delivered with the word…

---

## [Elasticsearch SAML problems](https://discuss.elastic.co/t/elasticsearch-saml-problems/358808)

<div class="topic-metadata">

**Author:** [@Juma](https://discuss.elastic.co/u/Juma)\
**Replies:** 2\
**Last updated:** [May 8, 2024, 9:36am UTC](https://discuss.elastic.co/t/elasticsearch-saml-problems/358808 "2024-05-08T09:36:53Z")

</div>

Hello, we are currently trying to integrate a SAML authentication with Azure Entra ID for one of our customers. We followed the guide from Set up SAML with Microsoft Entra ID The configuration is as follows (identifie…

---

## [Aggregate with bucket selector and sorting on data stream time series data](https://discuss.elastic.co/t/aggregate-with-bucket-selector-and-sorting-on-data-stream-time-series-data/359041)

<div class="topic-metadata">

**Author:** [@ahw](https://discuss.elastic.co/u/ahw)\
**Replies:** 0\
**Last updated:** [May 8, 2024, 9:20am UTC](https://discuss.elastic.co/t/aggregate-with-bucket-selector-and-sorting-on-data-stream-time-series-data/359041 "2024-05-08T09:20:36Z")

</div>

I have a data stream time series setup where i ingest metrics for different units. These metric was before in a postgres database, but now i try to move it into elasticsearch. One of my usecases is to answer questions li…

---

## [Elasticsearch Query Data](https://discuss.elastic.co/t/elasticsearch-query-data/358991)

<div class="topic-metadata">

**Author:** [@dp12345](https://discuss.elastic.co/u/dp12345)\
**Replies:** 1\
**Last updated:** [May 8, 2024, 8:59am UTC](https://discuss.elastic.co/t/elasticsearch-query-data/358991 "2024-05-08T08:59:37Z")

</div>

Hi Our client would like to analyze search queries that were processed by Elasticsearch. Is this data stored anywhere in Elasticsearch? If not are there any api's or plugins or extensions available that will allow us t…

---

## [Missing fields and value on Kibana runtime fields](https://discuss.elastic.co/t/missing-fields-and-value-on-kibana-runtime-fields/359034)

<div class="topic-metadata">

**Author:** [@imst](https://discuss.elastic.co/u/imst)\
**Replies:** 0\
**Last updated:** [May 8, 2024, 8:38am UTC](https://discuss.elastic.co/t/missing-fields-and-value-on-kibana-runtime-fields/359034 "2024-05-08T08:38:08Z")

</div>

Hi, I was attempting to creating field on fly in Kibana using runtime fields The following is my attempt try to temporarily label the value of the 'aws.waf.id' field as 'tmp' fields in Discover Both field and value…

---

## [No subject alternative names matching IP address 192.168.2.121 found](https://discuss.elastic.co/t/no-subject-alternative-names-matching-ip-address-192-168-2-121-found/359031)

<div class="topic-metadata">

**Author:** [@tine\_proens](https://discuss.elastic.co/u/tine_proens)\
**Replies:** 0\
**Last updated:** [May 8, 2024, 8:20am UTC](https://discuss.elastic.co/t/no-subject-alternative-names-matching-ip-address-192-168-2-121-found/359031 "2024-05-08T08:20:17Z")

</div>

I have a linux pc in my network running Elasticsearch 7.17 locally and not secured. There is already a lot of data indexed and now I want to perform searches from other pc's in the network so I decided I want to enable …

---

## [Elasticsearch unreachable from any language client](https://discuss.elastic.co/t/elasticsearch-unreachable-from-any-language-client/359017)

<div class="topic-metadata">

**Author:** [@spino17](https://discuss.elastic.co/u/spino17)\
**Replies:** 0\
**Last updated:** [May 8, 2024, 6:20am UTC](https://discuss.elastic.co/t/elasticsearch-unreachable-from-any-language-client/359017 "2024-05-08T06:20:47Z")

</div>

I suddenly started facing issue where I can hit the elasticsearch from curl but no other language client or even plain http call. I tried this in python and go, and for both es is timing out the request, whereas curl wor…

---

## [Nested Field Check fails in if condition](https://discuss.elastic.co/t/nested-field-check-fails-in-if-condition/358908)

<div class="topic-metadata">

**Author:** [@tusharnemade](https://discuss.elastic.co/u/tusharnemade)\
**Replies:** 4\
**Last updated:** [May 8, 2024, 6:17am UTC](https://discuss.elastic.co/t/nested-field-check-fails-in-if-condition/358908 "2024-05-08T06:17:43Z")

</div>

Hello Team: I am using elasticsearch mapping as below : "mappings": { "properties": { "name": { "type": "text" }, "age": { "type": "integer" }, "department": { …

---

## [Elastic Load Balancer](https://discuss.elastic.co/t/elastic-load-balancer/358553)

<div class="topic-metadata">

**Author:** [@El-k](https://discuss.elastic.co/u/El-k)\
**Replies:** 4\
**Last updated:** [May 8, 2024, 5:28am UTC](https://discuss.elastic.co/t/elastic-load-balancer/358553 "2024-05-08T05:28:53Z")

</div>

Hi, I am new to elastic, trying to set up my cluster. I have 3 master nodes, 3 data nodes and 1 client node, each one of them runs on a different machine. My question is, is there a default load balancer that gets the…

---

## [Awareness configuration](https://discuss.elastic.co/t/awareness-configuration/358994)

<div class="topic-metadata">

**Author:** [@jhonsouza](https://discuss.elastic.co/u/jhonsouza)\
**Replies:** 1\
**Last updated:** [May 8, 2024, 5:27am UTC](https://discuss.elastic.co/t/awareness-configuration/358994 "2024-05-08T05:27:36Z")

</div>

ElasticSearch Version: 7.17.15 Kibana Version: 7.17.15 Hi, I'm trying to configure the awareness to try to reduce the AWS data transfer cost, but that isn't working. I configured the node.att.zone in each data node usin…

---

## [AWS WAF Log Processing header - nested JSON array](https://discuss.elastic.co/t/aws-waf-log-processing-header-nested-json-array/359013)

<div class="topic-metadata">

**Author:** [@imst](https://discuss.elastic.co/u/imst)\
**Replies:** 0\
**Last updated:** [May 8, 2024, 4:02am UTC](https://discuss.elastic.co/t/aws-waf-log-processing-header-nested-json-array/359013 "2024-05-08T04:02:39Z")

</div>

We encounter some difficulties in mapping the following JSON array { "docs": \[ { "\_source": { .... , "httpRequest": { "clientIp": "REDACTED", …

---

## [About the Workplace Search content source synchronization](https://discuss.elastic.co/t/about-the-workplace-search-content-source-synchronization/359011)

<div class="topic-metadata">

**Author:** [@marron](https://discuss.elastic.co/u/marron)\
**Replies:** 0\
**Last updated:** [May 8, 2024, 3:32am UTC](https://discuss.elastic.co/t/about-the-workplace-search-content-source-synchronization/359011 "2024-05-08T03:32:59Z")

</div>

This site has an API to perform synchronization, but is there an API to check the synchronization status (synchronization in progress or synchronization complete etc...)? We need to know what the status of the sync is. n…

---

## [Why can't we rename indices?](https://discuss.elastic.co/t/why-cant-we-rename-indices/357011)

<div class="topic-metadata">

**Author:** [@jerrac](https://discuss.elastic.co/u/jerrac)\
**Replies:** 6\
**Last updated:** [May 7, 2024, 8:19pm UTC](https://discuss.elastic.co/t/why-cant-we-rename-indices/357011 "2024-05-07T20:19:09Z")

</div>

Ok, so, I ran into a situation where I really needed to be able to rename my index. Somehow it was created before my template was applied and as a result it was a normal index instead of an alias. Which turned into a gia…

---

## [ILM slows down node recovery/rolling upgrade process](https://discuss.elastic.co/t/ilm-slows-down-node-recovery-rolling-upgrade-process/356476)

<div class="topic-metadata">

**Author:** [@jerrac](https://discuss.elastic.co/u/jerrac)\
**Replies:** 13\
**Last updated:** [May 7, 2024, 8:04pm UTC](https://discuss.elastic.co/t/ilm-slows-down-node-recovery-rolling-upgrade-process/356476 "2024-05-07T20:04:36Z")

</div>

On my test cluster, I started a rolling upgrade. It's a 3 node cluster, so the cluster state went promptly to red. Once my upgraded node started up, I found that the index reallocation/recovery process was taking a lot l…

---

## [Analyzer for numbers with commas?](https://discuss.elastic.co/t/analyzer-for-numbers-with-commas/358985)

<div class="topic-metadata">

**Author:** [@jakehschwartz](https://discuss.elastic.co/u/jakehschwartz)\
**Replies:** 0\
**Last updated:** [May 7, 2024, 7:33pm UTC](https://discuss.elastic.co/t/analyzer-for-numbers-with-commas/358985 "2024-05-07T19:33:04Z")

</div>

Version 7.10 A bug with our analyzer was recently found dealing with commas in numbers. Imagine a string like This car has like 10,000 HP, it can go very fast We have a custom analyzer called full\_text, will attach al…

---

## [View Query in PostgreSQL agent in dashboard](https://discuss.elastic.co/t/view-query-in-postgresql-agent-in-dashboard/358854)

<div class="topic-metadata">

**Author:** [@Fernandoc4d](https://discuss.elastic.co/u/Fernandoc4d)\
**Replies:** 13\
**Last updated:** [May 7, 2024, 3:08pm UTC](https://discuss.elastic.co/t/view-query-in-postgresql-agent-in-dashboard/358854 "2024-05-07T15:08:48Z")

</div>

Hi community I need to obtain in a dashboard, two specific queries to the databases of all the agents from which I receive data (for this purpose it is this entire project among other things for which I have gotten invo…

---

## [What is my grok pattern for Time](https://discuss.elastic.co/t/what-is-my-grok-pattern-for-time/358937)

<div class="topic-metadata">

**Author:** [@baber1223](https://discuss.elastic.co/u/baber1223)\
**Replies:** 1\
**Last updated:** [May 7, 2024, 2:57pm UTC](https://discuss.elastic.co/t/what-is-my-grok-pattern-for-time/358937 "2024-05-07T14:57:37Z")

</div>

I want to use grok pattern for follow : \[07/May/2024:13:47:19 +0530\] I am using follow grok \[%{HTTPDATE:logtimestamp}\] but it does not work . Would you please say what is grok pattern for that ?

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=113)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=115)
