# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=117

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 118

---

## [Interested for reviewing Elastic Cloud](https://discuss.elastic.co/t/interested-for-reviewing-elastic-cloud/358663)

<div class="topic-metadata">

**Author:** [@Alta](https://discuss.elastic.co/u/Alta)\
**Replies:** 1\
**Last updated:** [May 2, 2024, 5:16pm UTC](https://discuss.elastic.co/t/interested-for-reviewing-elastic-cloud/358663 "2024-05-02T17:16:35Z")

</div>

To The Developer of the Forum, The Elastic Cloud Enterprise Greetings, It is an honor for me to be a part of the forum. I have a tech blog site and I am immensely impressed for reviewing Elastic Cloud on my site. If i…

---

## [I have dashboard i want to hide the extra fields from being accessed from anonymous user](https://discuss.elastic.co/t/i-have-dashboard-i-want-to-hide-the-extra-fields-from-being-accessed-from-anonymous-user/358224)

<div class="topic-metadata">

**Author:** [@kishorkumar](https://discuss.elastic.co/u/kishorkumar)\
**Replies:** 5\
**Last updated:** [May 2, 2024, 2:31pm UTC](https://discuss.elastic.co/t/i-have-dashboard-i-want-to-hide-the-extra-fields-from-being-accessed-from-anonymous-user/358224 "2024-05-02T14:31:53Z")

</div>

i want to hide the extra fields that are showing to anonymous user, i want him to show only the fields that are used in the dashbaoard other then that hide the fileds. i have added the fields that i wanted to show in t…

---

## [Query multiple indexes](https://discuss.elastic.co/t/query-multiple-indexes/358633)

<div class="topic-metadata">

**Author:** [@Monica\_Andhare](https://discuss.elastic.co/u/Monica_Andhare)\
**Replies:** 1\
**Last updated:** [May 2, 2024, 10:53am UTC](https://discuss.elastic.co/t/query-multiple-indexes/358633 "2024-05-02T10:53:48Z")

</div>

As a beginner in ELK . I want ask how can I query on multiple indexes. I have below 2 indexes. 1)Product index -id -DisplayName ProductAssociation index -id -SourceAssociationId -DestinationAssociationId Product…

---

## [Index design in a multitenant application](https://discuss.elastic.co/t/index-design-in-a-multitenant-application/358565)

<div class="topic-metadata">

**Author:** [@Jimmy\_nilsson](https://discuss.elastic.co/u/Jimmy_nilsson)\
**Replies:** 3\
**Last updated:** [May 2, 2024, 9:35am UTC](https://discuss.elastic.co/t/index-design-in-a-multitenant-application/358565 "2024-05-02T09:35:19Z")

</div>

I need some help validating my idea of index design. We are in the planning stages of moving from version 5.6 to 8.x. Background: We got a postgres database that is the source of truth, we've split this postgres databa…

---

## [Stack Monitoring index .monitoring-es\* kept 7 days](https://discuss.elastic.co/t/stack-monitoring-index-monitoring-es-kept-7-days/358621)

<div class="topic-metadata">

**Author:** [@Frances\_Chu](https://discuss.elastic.co/u/Frances_Chu)\
**Replies:** 0\
**Last updated:** [May 2, 2024, 9:26am UTC](https://discuss.elastic.co/t/stack-monitoring-index-monitoring-es-kept-7-days/358621 "2024-05-02T09:26:40Z")

</div>

It is found the index .monitoring-es\* only kept 7 days. How can I extend to let's say 40days

---

## [Ecommerce attribute mapping and performance](https://discuss.elastic.co/t/ecommerce-attribute-mapping-and-performance/358616)

<div class="topic-metadata">

**Author:** [@cem1835](https://discuss.elastic.co/u/cem1835)\
**Replies:** 0\
**Last updated:** [May 2, 2024, 8:54am UTC](https://discuss.elastic.co/t/ecommerce-attribute-mapping-and-performance/358616 "2024-05-02T08:54:51Z")

</div>

Hello, I have been working to map database-based products to elastic index. Our current database is based on Nopcommerce. And all other e-commerce structures, We have dynamic attributes too. That's why for mapping attri…

---

## [Getting results with duplicate sort values when searching with \_doc as the sort field](https://discuss.elastic.co/t/getting-results-with-duplicate-sort-values-when-searching-with-doc-as-the-sort-field/358606)

<div class="topic-metadata">

**Author:** [@Neeraj\_Kumar](https://discuss.elastic.co/u/Neeraj_Kumar)\
**Replies:** 0\
**Last updated:** [May 2, 2024, 7:31am UTC](https://discuss.elastic.co/t/getting-results-with-duplicate-sort-values-when-searching-with-doc-as-the-sort-field/358606 "2024-05-02T07:31:24Z")

</div>

I wish to understand what exactly happens when one uses the \_doc field for sorting while doing a search. I have an index on 4 shards and when I do search operation on it, with \_doc as the sort field then I get different …

---

## [How does the reindex api handle failure in specific documents?](https://discuss.elastic.co/t/how-does-the-reindex-api-handle-failure-in-specific-documents/358586)

<div class="topic-metadata">

**Author:** [@Emma\_Vaiserfirov](https://discuss.elastic.co/u/Emma_Vaiserfirov)\
**Replies:** 0\
**Last updated:** [May 1, 2024, 7:38pm UTC](https://discuss.elastic.co/t/how-does-the-reindex-api-handle-failure-in-specific-documents/358586 "2024-05-01T19:38:28Z")

</div>

We successfully completed a migration, but are missing a bunch of documents in a specific index. I think we know the cause, but I want to confirm. In the old index, we had some old documents with a parameter that we did…

---

## [Set up basic security for the Elastic Stack plus secured HTTPS traffic](https://discuss.elastic.co/t/set-up-basic-security-for-the-elastic-stack-plus-secured-https-traffic/358506)

<div class="topic-metadata">

**Author:** [@tneto](https://discuss.elastic.co/u/tneto)\
**Replies:** 1\
**Last updated:** [May 1, 2024, 6:17pm UTC](https://discuss.elastic.co/t/set-up-basic-security-for-the-elastic-stack-plus-secured-https-traffic/358506 "2024-05-01T18:17:49Z")

</div>

Hello all. For the past few days, I have been trying to add the correct certificates to our Elasticsearch and Kibana, but without success. Long story short, this was not setup by me. Neither I was aware of the certifi…

---

## [Unable to run Diagnostic tool](https://discuss.elastic.co/t/unable-to-run-diagnostic-tool/358561)

<div class="topic-metadata">

**Author:** [@Vivekchander](https://discuss.elastic.co/u/Vivekchander)\
**Replies:** 4\
**Last updated:** [May 1, 2024, 3:30pm UTC](https://discuss.elastic.co/t/unable-to-run-diagnostic-tool/358561 "2024-05-01T15:30:51Z")

</div>

Hi All, I'm pretty new to Elastic. I installed Elasticsearch on a cluster and I was able to port forward and access elastic cluster locally from the browser localhost:9200 just fine. Now from a different command prompt…

---

## [Repository-s3 plugin does not support IMDSv2 for EC2](https://discuss.elastic.co/t/repository-s3-plugin-does-not-support-imdsv2-for-ec2/358570)

<div class="topic-metadata">

**Author:** [@parinitha.nagaraja](https://discuss.elastic.co/u/parinitha.nagaraja)\
**Replies:** 0\
**Last updated:** [May 1, 2024, 3:16pm UTC](https://discuss.elastic.co/t/repository-s3-plugin-does-not-support-imdsv2-for-ec2/358570 "2024-05-01T15:16:07Z")

</div>

We are using repository-s3 plugin to create/restore snapshots in AWS S3. But the plugin does not support IMDSv2 metadata version. There is already an open issue to fix this. See below. Is there any update or timeline …

---

## [Likely root cause: java.nio.file.FileSystemException: /usr/share/elasticsearch/data/nodes/0: Not a directory](https://discuss.elastic.co/t/likely-root-cause-java-nio-file-filesystemexception-usr-share-elasticsearch-data-nodes-0-not-a-directory/358531)

<div class="topic-metadata">

**Author:** [@wuming1](https://discuss.elastic.co/u/wuming1)\
**Replies:** 2\
**Last updated:** [May 1, 2024, 8:16am UTC](https://discuss.elastic.co/t/likely-root-cause-java-nio-file-filesystemexception-usr-share-elasticsearch-data-nodes-0-not-a-directory/358531 "2024-05-01T08:16:29Z")

</div>

I don't know why this mistake happened. Read a lot of posts on the internet, rarely find the same mistakes as me. Because I just started learning to use this, but the simple first step can not run. This is the command…

---

## [Logstash refused connect on port 5044](https://discuss.elastic.co/t/logstash-refused-connect-on-port-5044/358544)

<div class="topic-metadata">

**Author:** [@qu\_c\_th\_nguy\_n](https://discuss.elastic.co/u/qu_c_th_nguy_n)\
**Replies:** 0\
**Last updated:** [May 1, 2024, 8:02am UTC](https://discuss.elastic.co/t/logstash-refused-connect-on-port-5044/358544 "2024-05-01T08:02:50Z")

</div>

I'm attempting to integrate Zeek into my ELK server, but I'm encountering an issue when running Filebeat setup. It's reporting a connection refusal on port 5044. Upon further investigation, attempting to connect to port …

---

## [8.13 and license](https://discuss.elastic.co/t/8-13-and-license/358540)

<div class="topic-metadata">

**Author:** [@m\_pahlevanzadeh](https://discuss.elastic.co/u/m_pahlevanzadeh)\
**Replies:** 1\
**Last updated:** [May 1, 2024, 7:54am UTC](https://discuss.elastic.co/t/8-13-and-license/358540 "2024-05-01T07:54:11Z")

</div>

Hello, I installed ELK 8.13 with basic license, is all of x-pack property? Or I can use x-pack in basic license?

---

## [Docker "Could not find or load main class org.elasticsearch.launcher.CliToolLauncher"](https://discuss.elastic.co/t/docker-could-not-find-or-load-main-class-org-elasticsearch-launcher-clitoollauncher/358466)

<div class="topic-metadata">

**Author:** [@grefon](https://discuss.elastic.co/u/grefon)\
**Replies:** 3\
**Last updated:** [April 30, 2024, 8:53pm UTC](https://discuss.elastic.co/t/docker-could-not-find-or-load-main-class-org-elasticsearch-launcher-clitoollauncher/358466 "2024-04-30T20:53:50Z")

</div>

Hello! Please help me solve the problem: I'm trying to run ElasticSearch using Docker on Centos7. docker network create elastic docker pull docker.elastic.co/elasticsearch/elasticsearch:8.13.2 When I try to start I ge…

---

## [Performance problem](https://discuss.elastic.co/t/performance-problem/358502)

<div class="topic-metadata">

**Author:** [@bbreer](https://discuss.elastic.co/u/bbreer)\
**Replies:** 10\
**Last updated:** [April 30, 2024, 6:36pm UTC](https://discuss.elastic.co/t/performance-problem/358502 "2024-04-30T18:36:06Z")

</div>

I'm trying to figure why our cluster seems to be pertually maxed out. Nnode 3 does the majority of the ingesting and is consistently around 90 - 95% CPU utilization. The other two nodes vary from 30 - 85% CPU utilizatio…

---

## [Search rate and index latency is high](https://discuss.elastic.co/t/search-rate-and-index-latency-is-high/358426)

<div class="topic-metadata">

**Author:** [@sudhir\_singh](https://discuss.elastic.co/u/sudhir_singh)\
**Replies:** 2\
**Last updated:** [April 30, 2024, 6:26pm UTC](https://discuss.elastic.co/t/search-rate-and-index-latency-is-high/358426 "2024-04-30T18:26:46Z")

</div>

I'm using elasticsearch as database but I'm facing momentary surge in search rate and latency. Can anyone tell why there is a high search rate and latency observerd I have 10 nodes of cluster which are physical vms. It's…

---

## [Error sending trace data to elasticsearch using otel collector](https://discuss.elastic.co/t/error-sending-trace-data-to-elasticsearch-using-otel-collector/358511)

<div class="topic-metadata">

**Author:** [@MSP85](https://discuss.elastic.co/u/MSP85)\
**Replies:** 0\
**Last updated:** [April 30, 2024, 6:20pm UTC](https://discuss.elastic.co/t/error-sending-trace-data-to-elasticsearch-using-otel-collector/358511 "2024-04-30T18:20:58Z")

</div>

Hi, I'm trying to send trace data to Elasticsearch using otel collector. and below is my configuration. when I send sample traces I get the below error messages: When I have httpsin the endpoint url Error: Exporting …

---

## [Random high connection latency when searching during high write activity](https://discuss.elastic.co/t/random-high-connection-latency-when-searching-during-high-write-activity/358510)

<div class="topic-metadata">

**Author:** [@dpitchford](https://discuss.elastic.co/u/dpitchford)\
**Replies:** 0\
**Last updated:** [April 30, 2024, 6:15pm UTC](https://discuss.elastic.co/t/random-high-connection-latency-when-searching-during-high-write-activity/358510 "2024-04-30T18:15:33Z")

</div>

ES version: 7.17.20 While a separate process is performing writes on an index, I'm observing wildly varying connection latency when performing a search on the index. A search (performed via cURL) on the index took 140 s…

---

## [Indexing json document using Elastic.Clients.Elasticsearch SDK](https://discuss.elastic.co/t/indexing-json-document-using-elastic-clients-elasticsearch-sdk/358498)

<div class="topic-metadata">

**Author:** [@steru](https://discuss.elastic.co/u/steru)\
**Replies:** 0\
**Last updated:** [April 30, 2024, 2:18pm UTC](https://discuss.elastic.co/t/indexing-json-document-using-elastic-clients-elasticsearch-sdk/358498 "2024-04-30T14:18:11Z")

</div>

Using Elastic.Clients.Elasticsearch dotnet SDK client. Using the IndexAsync method, but I cannot figure out how I can index an already serialized document (I can pass in an object and have it serialized by the default s…

---

## [JS client for elasticsearch times out on scroll or takes a long time](https://discuss.elastic.co/t/js-client-for-elasticsearch-times-out-on-scroll-or-takes-a-long-time/358495)

<div class="topic-metadata">

**Author:** [@BOYO](https://discuss.elastic.co/u/BOYO)\
**Replies:** 0\
**Last updated:** [April 30, 2024, 12:58pm UTC](https://discuss.elastic.co/t/js-client-for-elasticsearch-times-out-on-scroll-or-takes-a-long-time/358495 "2024-04-30T12:58:35Z")

</div>

For a particular usecase I'm trying to benchmark how long it would take to fetch all the entries for a particular search. I used the official client helper for scrolling all the entries like below, but it times out in so…

---

## [Vector Tile (SearchMvt) issues - .NET client](https://discuss.elastic.co/t/vector-tile-searchmvt-issues-net-client/358258)

<div class="topic-metadata">

**Author:** [@Jarrod](https://discuss.elastic.co/u/Jarrod)\
**Replies:** 0\
**Last updated:** [April 26, 2024, 5:22am UTC](https://discuss.elastic.co/t/vector-tile-searchmvt-issues-net-client/358258 "2024-04-26T05:22:18Z")

</div>

This is related to a previous topic I raised: Elastic.Clients.Elasticsearch .NET client - calling Vector tile search API I am attempting to update to the latest version of Elastic.Clients.Elasticsearch (v8.13.8). As th…

---

## [Kibana server is not ready yet and curl: (52) Empty reply from server](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet-and-curl-52-empty-reply-from-server/358047)

<div class="topic-metadata">

**Author:** [@riahc3](https://discuss.elastic.co/u/riahc3)\
**Replies:** 12\
**Last updated:** [April 30, 2024, 12:04pm UTC](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet-and-curl-52-empty-reply-from-server/358047 "2024-04-30T12:04:11Z")

</div>

Hello Im getting these two error messages Kibana server is not ready yet This one appears when I am going to the Kibana page. I checked that all services are up and running so that is OK. I ran a curl -XGET 'localho…

---

## [Skipping security auto configuration](https://discuss.elastic.co/t/skipping-security-auto-configuration/358409)

<div class="topic-metadata">

**Author:** [@snirw](https://discuss.elastic.co/u/snirw)\
**Replies:** 9\
**Last updated:** [April 30, 2024, 11:58am UTC](https://discuss.elastic.co/t/skipping-security-auto-configuration/358409 "2024-04-30T11:58:18Z")

</div>

Hi all I have begun my journey in elasticsearch and I have installed on my PC (Win 10) elasticsearch version 8.13. As part of my practice, I am trying to create 2 additional new nodes. I have performed the following st…

---

## [Query intermittent performance issue](https://discuss.elastic.co/t/query-intermittent-performance-issue/358473)

<div class="topic-metadata">

**Author:** [@Paul6](https://discuss.elastic.co/u/Paul6)\
**Replies:** 2\
**Last updated:** [April 30, 2024, 11:22am UTC](https://discuss.elastic.co/t/query-intermittent-performance-issue/358473 "2024-04-30T11:22:27Z")

</div>

Hello, I’m on Elastic Cloud 8.12. I’m facing an issue where the same query can take from 500ms to more than 30s. We are working with rather simple data stored in data streams but we also reproduced this behavior with …

---

## [Problem with PEM Certificate when Adding New Node in Elasticsearch Docker Cluster](https://discuss.elastic.co/t/problem-with-pem-certificate-when-adding-new-node-in-elasticsearch-docker-cluster/357657)

<div class="topic-metadata">

**Author:** [@rowish](https://discuss.elastic.co/u/rowish)\
**Replies:** 5\
**Last updated:** [April 30, 2024, 11:00am UTC](https://discuss.elastic.co/t/problem-with-pem-certificate-when-adding-new-node-in-elasticsearch-docker-cluster/357657 "2024-04-30T11:00:43Z")

</div>

Following this guide, I am trying to add a second node (es02) to my elasticsearch cluster that has been working so far. The docker-compose.yml is the following: version: "2.2" services: setup: image: docker.elast…

---

## [Enrich Policy - Match IP type](https://discuss.elastic.co/t/enrich-policy-match-ip-type/357724)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 0\
**Last updated:** [April 18, 2024, 2:52pm UTC](https://discuss.elastic.co/t/enrich-policy-match-ip-type/357724 "2024-04-18T14:52:14Z")

</div>

Hello, Can you do an enrich policy where the match field is an IP address. Essentially, I want to match an IP address to another and enrich the other index with host information related to the IP. Thanks,

---

## [Search: minimum\_should\_match: 100% not working when single term expands two more terms](https://discuss.elastic.co/t/search-minimum-should-match-100-not-working-when-single-term-expands-two-more-terms/358119)

<div class="topic-metadata">

**Author:** [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Replies:** 2\
**Last updated:** [April 30, 2024, 8:55am UTC](https://discuss.elastic.co/t/search-minimum-should-match-100-not-working-when-single-term-expands-two-more-terms/358119 "2024-04-30T08:55:41Z")

</div>

Hey, I found an interesting behaviour for an OR based query that has minimum\_should\_match: 100% set. Naively I thought that this means, it behaves the same as an AND, but it does not. Example: DELETE test PUT test {…

---

## [Mixed OS cluster - poor performance](https://discuss.elastic.co/t/mixed-os-cluster-poor-performance/358400)

<div class="topic-metadata">

**Author:** [@lubasz](https://discuss.elastic.co/u/lubasz)\
**Replies:** 2\
**Last updated:** [April 30, 2024, 7:37am UTC](https://discuss.elastic.co/t/mixed-os-cluster-poor-performance/358400 "2024-04-30T07:37:58Z")

</div>

Hello, My company has made changes and for new servers we only use RHEL OS. So for current configuration I have mixed OS cluster (Elasticsearch v 8.11.1): 1x Master Node - Debian 12.2 2x Data Nodes - Debian 12.2 2x D…

---

## [Failed to load resource: the server responded with a status of 406 (Not Acceptable)](https://discuss.elastic.co/t/failed-to-load-resource-the-server-responded-with-a-status-of-406-not-acceptable/358408)

<div class="topic-metadata">

**Author:** [@Sunil\_Jagtap](https://discuss.elastic.co/u/Sunil_Jagtap)\
**Replies:** 4\
**Last updated:** [April 30, 2024, 4:43am UTC](https://discuss.elastic.co/t/failed-to-load-resource-the-server-responded-with-a-status-of-406-not-acceptable/358408 "2024-04-30T04:43:31Z")

</div>

We have added plugin to kibana but facing as error (we can see on console tab of browser) while making API call to elasticsearch=\> Failed to load resource: the server responded with a status of 406 (Not Acceptable)

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=116)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=118)
