# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=116

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 117

---

## [Index Management](https://discuss.elastic.co/t/index-management/358828)

<div class="topic-metadata">

**Author:** [@himanshu\_2502d](https://discuss.elastic.co/u/himanshu_2502d)\
**Replies:** 0\
**Last updated:** [May 6, 2024, 12:50pm UTC](https://discuss.elastic.co/t/index-management/358828 "2024-05-06T12:50:16Z")

</div>

I have one Elastic search cluster hosted on AWS with 5 nodes , Currently we are making one index per tenant per month and we have 70 tenants registered currently and for creation of one index it requires 3 primary and 2…

---

## [How to assign weight attribute to a completion suggester field using Elasticsearch Hadoop connector (Spark/Databricks)](https://discuss.elastic.co/t/how-to-assign-weight-attribute-to-a-completion-suggester-field-using-elasticsearch-hadoop-connector-spark-databricks/358815)

<div class="topic-metadata">

**Author:** [@landlord\_matt](https://discuss.elastic.co/u/landlord_matt)\
**Replies:** 0\
**Last updated:** [May 6, 2024, 11:17am UTC](https://discuss.elastic.co/t/how-to-assign-weight-attribute-to-a-completion-suggester-field-using-elasticsearch-hadoop-connector-spark-databricks/358815 "2024-05-06T11:17:28Z")

</div>

Hi! We're successfully using the org.elasticsearch.spark.sql driver to upload our Databricks Spark tables as Elasticsearch indices. We now want to assign the weight attribute to one of our suggester fields in order to g…

---

## [Reduce number of shard](https://discuss.elastic.co/t/reduce-number-of-shard/358791)

<div class="topic-metadata">

**Author:** [@Frances\_Chu](https://discuss.elastic.co/u/Frances_Chu)\
**Replies:** 3\
**Last updated:** [May 6, 2024, 10:24am UTC](https://discuss.elastic.co/t/reduce-number-of-shard/358791 "2024-05-06T10:24:43Z")

</div>

My Elasticsearch received three logs: Log\_A Log\_B Log\_C To facilitate index lifecycle management (iLM), I updated the index names as follows: Log\_A\_YYYYMMDD Log\_B\_YYYYMMDD Log\_C\_YYYYMMDD Consequently, a new index…

---

## [Multiplication and division query](https://discuss.elastic.co/t/multiplication-and-division-query/358787)

<div class="topic-metadata">

**Author:** [@orlenkoda5](https://discuss.elastic.co/u/orlenkoda5)\
**Replies:** 1\
**Last updated:** [May 6, 2024, 8:43am UTC](https://discuss.elastic.co/t/multiplication-and-division-query/358787 "2024-05-06T08:43:11Z")

</div>

Good day evetyone. I have a question in making a query wich will count multiplication of value of two fields and then division of this multiplication on third field. Example of data in index: { "\_index" : "inst…

---

## [Struggle to connect to elasticsearch from apps](https://discuss.elastic.co/t/struggle-to-connect-to-elasticsearch-from-apps/358789)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 0\
**Last updated:** [May 6, 2024, 7:41am UTC](https://discuss.elastic.co/t/struggle-to-connect-to-elasticsearch-from-apps/358789 "2024-05-06T07:41:11Z")

</div>

Hi everyone, I'm facing an issue with my apps when I try to connect to my Elastic cluster. first of all, do you guys have ever found this error? before that, I want you to know my cluster first: Version: 8.13.2 HTTPS:…

---

## [Retention lease background sync failed - help understand this log](https://discuss.elastic.co/t/retention-lease-background-sync-failed-help-understand-this-log/358334)

<div class="topic-metadata">

**Author:** [@Vikram\_R](https://discuss.elastic.co/u/Vikram_R)\
**Replies:** 10\
**Last updated:** [May 6, 2024, 7:32am UTC](https://discuss.elastic.co/t/retention-lease-background-sync-failed-help-understand-this-log/358334 "2024-05-06T07:32:10Z")

</div>

Hi Guys, New to this technology, I've tried to use elasticsearch self-managed for our application in our organization. I'm facing this "retention lease background sync failed" issue for quite some time. I tried to get…

---

## [Question in Node Configuration](https://discuss.elastic.co/t/question-in-node-configuration/358782)

<div class="topic-metadata">

**Author:** [@hossa](https://discuss.elastic.co/u/hossa)\
**Replies:** 1\
**Last updated:** [May 6, 2024, 7:31am UTC](https://discuss.elastic.co/t/question-in-node-configuration/358782 "2024-05-06T07:31:49Z")

</div>

Hello I have a cluster consisting of 3 nodes, one of which I want to be for reading and the other for writing How can I do that?

---

## [Using Anomaly Detection in Watcher Threshold Setting](https://discuss.elastic.co/t/using-anomaly-detection-in-watcher-threshold-setting/358288)

<div class="topic-metadata">

**Author:** [@A\_Espiritu](https://discuss.elastic.co/u/A_Espiritu)\
**Replies:** 1\
**Last updated:** [May 6, 2024, 7:04am UTC](https://discuss.elastic.co/t/using-anomaly-detection-in-watcher-threshold-setting/358288 "2024-05-06T07:04:14Z")

</div>

Hi all, I am doing a POC right now - still starting out exploring Elastic so apologies if some questions are too basic. We currently have a dashboard that counts the number of incidents per day. They've also implement…

---

## [Text\_embedding configured for model but rejected for query](https://discuss.elastic.co/t/text-embedding-configured-for-model-but-rejected-for-query/357163)

<div class="topic-metadata">

**Author:** [@wnmills3](https://discuss.elastic.co/u/wnmills3)\
**Replies:** 8\
**Last updated:** [May 5, 2024, 6:45pm UTC](https://discuss.elastic.co/t/text-embedding-configured-for-model-but-rejected-for-query/357163 "2024-05-05T18:45:50Z")

</div>

I have issued a query like below: { "query": { "bool": { "should": \[ { "text\_embedding": { "path\_embedding.tokens": { …

---

## [AWS S3 logs --\> SQS --\> ELastic search](https://discuss.elastic.co/t/aws-s3-logs-sqs-elastic-search/358749)

<div class="topic-metadata">

**Author:** [@Niel.devops](https://discuss.elastic.co/u/Niel.devops)\
**Replies:** 3\
**Last updated:** [May 5, 2024, 2:58pm UTC](https://discuss.elastic.co/t/aws-s3-logs-sqs-elastic-search/358749 "2024-05-05T14:58:11Z")

</div>

Hi Guys, we can see that the performance of sending logs from S3 --\> Elastic SIEM is low compared to SQS. Elastic is doing enhancements in uploading data from S3 --\> SIEM directly. However, I created a Lambda function su…

---

## [Sharding Strategy when data is in Tb](https://discuss.elastic.co/t/sharding-strategy-when-data-is-in-tb/358741)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 6\
**Last updated:** [May 5, 2024, 8:08am UTC](https://discuss.elastic.co/t/sharding-strategy-when-data-is-in-tb/358741 "2024-05-05T08:08:51Z")

</div>

Hi Community I have a cluster of 13 nodes Six Hot nodes each with 32gb heap memory , 6tb SSD Storage, 9 CPU , RAM 125gb . Three Master nodes 32gb Heap Size , 3 CPU , 50gb Storage Three Warm nodes each with 15t…

---

## [If translog durability is set to request, then flush is required?](https://discuss.elastic.co/t/if-translog-durability-is-set-to-request-then-flush-is-required/358687)

<div class="topic-metadata">

**Author:** [@Amit\_Shukla](https://discuss.elastic.co/u/Amit_Shukla)\
**Replies:** 13\
**Last updated:** [May 5, 2024, 6:48am UTC](https://discuss.elastic.co/t/if-translog-durability-is-set-to-request-then-flush-is-required/358687 "2024-05-05T06:48:26Z")

</div>

Talking about Elasticsearch version 7.17 This is regarding how flush API and index.translog.durability settings are connected to each other. My understanding is that if this index.translog.durability is set as Request …

---

## [Data Validation for data node after rolling restart](https://discuss.elastic.co/t/data-validation-for-data-node-after-rolling-restart/358739)

<div class="topic-metadata">

**Author:** [@Amit\_Shukla](https://discuss.elastic.co/u/Amit_Shukla)\
**Replies:** 1\
**Last updated:** [May 4, 2024, 5:14pm UTC](https://discuss.elastic.co/t/data-validation-for-data-node-after-rolling-restart/358739 "2024-05-04T17:14:55Z")

</div>

Context: We are updating OS four Elasticsearch cluster and in that process we are taking out each data node one by one and then upgrading OS , bringing that data node back in cluster. Problem: We want to ensure data con…

---

## [Split brain problem with two master nodes](https://discuss.elastic.co/t/split-brain-problem-with-two-master-nodes/358710)

<div class="topic-metadata">

**Author:** [@Amit\_Shukla](https://discuss.elastic.co/u/Amit_Shukla)\
**Replies:** 6\
**Last updated:** [May 3, 2024, 8:35pm UTC](https://discuss.elastic.co/t/split-brain-problem-with-two-master-nodes/358710 "2024-05-03T20:35:21Z")

</div>

We have a requirement where we need to upgrade OS and for that Elasticsearch will be fresh installed on the nodes. I have a question related to master nodes removal. We have 3 master nodes as part of the cluster. What a…

---

## [Can't export rules using the detections api](https://discuss.elastic.co/t/cant-export-rules-using-the-detections-api/358731)

<div class="topic-metadata">

**Author:** [@Valencia](https://discuss.elastic.co/u/Valencia)\
**Replies:** 0\
**Last updated:** [May 3, 2024, 8:01pm UTC](https://discuss.elastic.co/t/cant-export-rules-using-the-detections-api/358731 "2024-05-03T20:01:39Z")

</div>

Hello, I'm trying to export the detection rules for some testing using the api. I've created two rules and I can manually export them from the gui but trying to query "api/detection\_engine/rules/\_export" doesn't really …

---

## [Update By Query fails with 400 - Bad Request - couldn't debug and no details available](https://discuss.elastic.co/t/update-by-query-fails-with-400-bad-request-couldnt-debug-and-no-details-available/358523)

<div class="topic-metadata">

**Author:** [@Janani\_Sampath\_Kumar](https://discuss.elastic.co/u/Janani_Sampath_Kumar)\
**Replies:** 5\
**Last updated:** [May 3, 2024, 6:13pm UTC](https://discuss.elastic.co/t/update-by-query-fails-with-400-bad-request-couldnt-debug-and-no-details-available/358523 "2024-05-03T18:13:19Z")

</div>

Mapping: "students": { "properties": { "\_class": { "type": "keyword", "index": false, "doc\_values": false }, "id": { …

---

## [Test Rest API through python](https://discuss.elastic.co/t/test-rest-api-through-python/357531)

<div class="topic-metadata">

**Author:** [@navya\_k](https://discuss.elastic.co/u/navya_k)\
**Replies:** 23\
**Last updated:** [May 3, 2024, 2:57pm UTC](https://discuss.elastic.co/t/test-rest-api-through-python/357531 "2024-05-03T14:57:47Z")

</div>

We have Elastic search cluster with thousands of applications. We would like to read logs through python script from elastic cluster. Use Cases : Get logs of last 1 hour or 1 day If it has error 500 or 404 We would l…

---

## [Getting "Read-only file system" error with Elasticsearch deployment on Kubernetes](https://discuss.elastic.co/t/getting-read-only-file-system-error-with-elasticsearch-deployment-on-kubernetes/358719)

<div class="topic-metadata">

**Author:** [@ascii](https://discuss.elastic.co/u/ascii)\
**Replies:** 0\
**Last updated:** [May 3, 2024, 2:17pm UTC](https://discuss.elastic.co/t/getting-read-only-file-system-error-with-elasticsearch-deployment-on-kubernetes/358719 "2024-05-03T14:17:20Z")

</div>

Hi! I'm trying to deploy Elasticsearch 7.12.0 on Kubernetes and have configured it to run as a single-node cluster. But after deployment, I encountered the following error: Exception in thread "main" org.elasticsearch…

---

## [Question Symbol filtering and machine learning error; startOffset must be non-negative, and endOffset must be \>= startOffset; got startOffset=14,endOffset=13](https://discuss.elastic.co/t/question-symbol-filtering-and-machine-learning-error-startoffset-must-be-non-negative-and-endoffset-must-be-startoffset-got-startoffset-14-endoffset-13/358716)

<div class="topic-metadata">

**Author:** [@Chenko](https://discuss.elastic.co/u/Chenko)\
**Replies:** 0\
**Last updated:** [May 3, 2024, 2:06pm UTC](https://discuss.elastic.co/t/question-symbol-filtering-and-machine-learning-error-startoffset-must-be-non-negative-and-endoffset-must-be-startoffset-got-startoffset-14-endoffset-13/358716 "2024-05-03T14:06:29Z")

</div>

Hi! I have the following error: { "error": { "root\_cause": \[ { "type": "illegal\_argument\_exception", "reason": "startOffset must be non-negative, and endOffset must be \>= startOffset; got st…

---

## [Date\_histogram returning duplicates in multi-cluster after upgrade](https://discuss.elastic.co/t/date-histogram-returning-duplicates-in-multi-cluster-after-upgrade/358569)

<div class="topic-metadata">

**Author:** [@Doc\_Kaos](https://discuss.elastic.co/u/Doc_Kaos)\
**Replies:** 2\
**Last updated:** [May 3, 2024, 1:29pm UTC](https://discuss.elastic.co/t/date-histogram-returning-duplicates-in-multi-cluster-after-upgrade/358569 "2024-05-03T13:29:28Z")

</div>

Hey all, we recently upgraded clusters from 8.10.2 to 8.13.2. Our cross-cluster search cluster is still running 7.17. We noticed we are receiving duplicate keys in buckets after the remote clusters upgraded. If we reduce…

---

## [Available performance data from ESRally Perf Tool](https://discuss.elastic.co/t/available-performance-data-from-esrally-perf-tool/358660)

<div class="topic-metadata">

**Author:** [@tommyd](https://discuss.elastic.co/u/tommyd)\
**Replies:** 8\
**Last updated:** [May 3, 2024, 1:01pm UTC](https://discuss.elastic.co/t/available-performance-data-from-esrally-perf-tool/358660 "2024-05-03T13:01:53Z")

</div>

Hello ES gurus, I am just curious if there are any performance results available for any ESRally tracks. I searched on the internet but have not come up with anything. Here is the reason why I am looking for such data…

---

## [Using 7.8X version of kibana while ssl configuration getting error as below](https://discuss.elastic.co/t/using-7-8x-version-of-kibana-while-ssl-configuration-getting-error-as-below/358707)

<div class="topic-metadata">

**Author:** [@2328943\_dc](https://discuss.elastic.co/u/2328943_dc)\
**Replies:** 0\
**Last updated:** [May 3, 2024, 11:58am UTC](https://discuss.elastic.co/t/using-7-8x-version-of-kibana-while-ssl-configuration-getting-error-as-below/358707 "2024-05-03T11:58:34Z")

</div>

Using 7.8X version of kibana we are trying for ssl configuration using below link for guidence :\[Elasticsearch Cluster Security - TLS, SSL & CERTUTIL Certificates\] But while generating CA Certificate using below command…

---

## [CRITICAL Deprecation log while Upgrading Elasticsearch from v8.4.1 to v8.11.2](https://discuss.elastic.co/t/critical-deprecation-log-while-upgrading-elasticsearch-from-v8-4-1-to-v8-11-2/356945)

<div class="topic-metadata">

**Author:** [@besanket](https://discuss.elastic.co/u/besanket)\
**Replies:** 1\
**Last updated:** [May 3, 2024, 10:35am UTC](https://discuss.elastic.co/t/critical-deprecation-log-while-upgrading-elasticsearch-from-v8-4-1-to-v8-11-2/356945 "2024-05-03T10:35:35Z")

</div>

We've observed CRITICAL Deprecation logs while Upgrading Elasticsearch from v8.4.1 to v8.11.2. Attached below logs for your reference. \[2024-01-29T15:58:04,984\]\[CRITICAL\]\[o.e.d.r.a.s.RestSearchAction\] \[dev01\] data\_str…

---

## [Custom language analyzers on Elastic cloud](https://discuss.elastic.co/t/custom-language-analyzers-on-elastic-cloud/358605)

<div class="topic-metadata">

**Author:** [@ravi\_kumar\_mvs](https://discuss.elastic.co/u/ravi_kumar_mvs)\
**Replies:** 4\
**Last updated:** [May 3, 2024, 8:41am UTC](https://discuss.elastic.co/t/custom-language-analyzers-on-elastic-cloud/358605 "2024-05-03T08:41:37Z")

</div>

Hi, I use Elasticsearch enterprise version 8.12.2 on EC cloud. I need to support search over 120 locales for our application. The problem is that I'm unable to find packages on cloud that can enable stemming and stop f…

---

## [Experiencing high latency post upgrading to elastic 8.10 and 8.12 from 8.7](https://discuss.elastic.co/t/experiencing-high-latency-post-upgrading-to-elastic-8-10-and-8-12-from-8-7/358691)

<div class="topic-metadata">

**Author:** [@gangaeswari](https://discuss.elastic.co/u/gangaeswari)\
**Replies:** 0\
**Last updated:** [May 3, 2024, 8:17am UTC](https://discuss.elastic.co/t/experiencing-high-latency-post-upgrading-to-elastic-8-10-and-8-12-from-8-7/358691 "2024-05-03T08:17:36Z")

</div>

8.7 Cluster (32 CPU 64 GB RM) 20 data nodes part of this cluster here the we see p99 latency is around 15 to 20 ms. after upgrading to 8.10 and then to 8.12, we are seeing high query cache evictions and latency started…

---

## [Porter stem applying stemmer](https://discuss.elastic.co/t/porter-stem-applying-stemmer/358177)

<div class="topic-metadata">

**Author:** [@Mohan\_T](https://discuss.elastic.co/u/Mohan_T)\
**Replies:** 9\
**Last updated:** [May 3, 2024, 7:17am UTC](https://discuss.elastic.co/t/porter-stem-applying-stemmer/358177 "2024-05-03T07:17:27Z")

</div>

Porter stem gives the result below. Keyword: 1. hospital 2. hospitality in \_analyze { "tokenizer": "standard", "filter": \[ "porter\_stem" \], "text": "hospitality" } an getting the result as b…

---

## [Fscrawler rest service has no filesize field?](https://discuss.elastic.co/t/fscrawler-rest-service-has-no-filesize-field/358630)

<div class="topic-metadata">

**Author:** [@laoyang360](https://discuss.elastic.co/u/laoyang360)\
**Replies:** 2\
**Last updated:** [May 3, 2024, 5:19am UTC](https://discuss.elastic.co/t/fscrawler-rest-service-has-no-filesize-field/358630 "2024-05-03T05:19:04Z")

</div>

https://fscrawler.readthedocs.io/en/latest/admin/fs/rest.html#uploading-a-binary-document When I upload documents using the upload interface of the rest service, there is no filesize field on the Elasticsearch side. I w…

---

## [Using Elastic Enterprise connector , Connectect to Jira DC edition system using native connector (with technical User name ) However, DLS is not getting enabled](https://discuss.elastic.co/t/using-elastic-enterprise-connector-connectect-to-jira-dc-edition-system-using-native-connector-with-technical-user-name-however-dls-is-not-getting-enabled/358676)

<div class="topic-metadata">

**Author:** [@Praveen776](https://discuss.elastic.co/u/Praveen776)\
**Replies:** 0\
**Last updated:** [May 2, 2024, 10:26pm UTC](https://discuss.elastic.co/t/using-elastic-enterprise-connector-connectect-to-jira-dc-edition-system-using-native-connector-with-technical-user-name-however-dls-is-not-getting-enabled/358676 "2024-05-02T22:26:31Z")

</div>

Using Elastic Enterprise connector , Connected to Jira DC edition system using native connector (with technical User name ) However, DLS is not getting enabled.. Using 8.13.2 version.. any suggestion to enable the Docum…

---

## [Tweak ES "documents" with non-Latin text before they are stemmed?](https://discuss.elastic.co/t/tweak-es-documents-with-non-latin-text-before-they-are-stemmed/358669)

<div class="topic-metadata">

**Author:** [@mrodent](https://discuss.elastic.co/u/mrodent)\
**Replies:** 0\
**Last updated:** [May 2, 2024, 6:35pm UTC](https://discuss.elastic.co/t/tweak-es-documents-with-non-latin-text-before-they-are-stemmed/358669 "2024-05-02T18:35:50Z")

</div>

I use the word "document" here in the sense of "Lucene Document" or LDoc, i.e. the thing which gets put into the index, analysed, etc. I'm parsing and then indexing a whole load of .docx and .docm text files in a direct…

---

## [Export parent child oracle table in elastic search](https://discuss.elastic.co/t/export-parent-child-oracle-table-in-elastic-search/358651)

<div class="topic-metadata">

**Author:** [@karthikeyanc2003](https://discuss.elastic.co/u/karthikeyanc2003)\
**Replies:** 1\
**Last updated:** [May 2, 2024, 5:35pm UTC](https://discuss.elastic.co/t/export-parent-child-oracle-table-in-elastic-search/358651 "2024-05-02T17:35:13Z")

</div>

Dear Team, I am an RDBMS guy and new to Elastic search. I require your expertise and help on the below requirements, I have the below tables in Oracle. Director & movies Director Name Year of birth Name id Birth …

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=115)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=117)
