# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=118

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 119

---

## [Hierarchical user management setup](https://discuss.elastic.co/t/hierarchical-user-management-setup/356886)

<div class="topic-metadata">

**Author:** [@cshacks](https://discuss.elastic.co/u/cshacks)\
**Replies:** 1\
**Last updated:** [April 30, 2024, 4:40am UTC](https://discuss.elastic.co/t/hierarchical-user-management-setup/356886 "2024-04-30T04:40:08Z")

</div>

Hello, So, I am curious if there is a way to setup a hierarchical user management system where I would have one account in Kibana that has the "superuser" role, then I would have other accounts with a custom role called…

---

## [Same space usage when disabling storing the source document](https://discuss.elastic.co/t/same-space-usage-when-disabling-storing-the-source-document/358451)

<div class="topic-metadata">

**Author:** [@ahmedasadi](https://discuss.elastic.co/u/ahmedasadi)\
**Replies:** 2\
**Last updated:** [April 30, 2024, 3:20am UTC](https://discuss.elastic.co/t/same-space-usage-when-disabling-storing-the-source-document/358451 "2024-04-30T03:20:33Z")

</div>

Hi, I've ingested 120GB of data into an elasticsearch index, and ~115GB of that data is used for storing the source document. Considering I don't need the source document and I only need the IDs of the documents that ma…

---

## [Security\_exception: unable to authenticate user \[me\] for REST request \[/\_nodes?filter\_path=nodes.\*.version%2Cnodes.\*.http.publish\_address%2Cnodes.\*.ip\]](https://discuss.elastic.co/t/security-exception-unable-to-authenticate-user-me-for-rest-request-nodes-filter-path-nodes-version-2cnodes-http-publish-address-2cnodes-ip/358442)

<div class="topic-metadata">

**Author:** [@clarac1996](https://discuss.elastic.co/u/clarac1996)\
**Replies:** 5\
**Last updated:** [April 30, 2024, 2:43am UTC](https://discuss.elastic.co/t/security-exception-unable-to-authenticate-user-me-for-rest-request-nodes-filter-path-nodes-version-2cnodes-http-publish-address-2cnodes-ip/358442 "2024-04-30T02:43:21Z")

</div>

Hello! I really need some help, been struggling with this. I am trying to set up Kibana and Elasticsearch using docker-compose, and I have already generated a service account user (left it as my name clara), but the kib…

---

## [Filebeat installation](https://discuss.elastic.co/t/filebeat-installation/358447)

<div class="topic-metadata">

**Author:** [@Ali\_A](https://discuss.elastic.co/u/Ali_A)\
**Replies:** 0\
**Last updated:** [April 29, 2024, 7:47pm UTC](https://discuss.elastic.co/t/filebeat-installation/358447 "2024-04-29T19:47:13Z")

</div>

hello guys, I am trying to install filebeat on my firewall through kalipurple terminal, but as you can see I am not able to proceed because the make install command is not working, I tried some tricks but it's not workin…

---

## [Kibana and elasticsearch failing to start](https://discuss.elastic.co/t/kibana-and-elasticsearch-failing-to-start/357732)

<div class="topic-metadata">

**Author:** [@Ali\_A](https://discuss.elastic.co/u/Ali_A)\
**Replies:** 3\
**Last updated:** [April 29, 2024, 7:43pm UTC](https://discuss.elastic.co/t/kibana-and-elasticsearch-failing-to-start/357732 "2024-04-29T19:43:23Z")

</div>

everything was working fine until I changed the IP for my virtual machine, when I tried to open the localhost it was saying kibana server is not ready yet, after that I tried some solutions but ended up facing this frus…

---

## [Elasticsearch cluster across multiple docker hosts](https://discuss.elastic.co/t/elasticsearch-cluster-across-multiple-docker-hosts/358314)

<div class="topic-metadata">

**Author:** [@Janusz\_Mikluszka](https://discuss.elastic.co/u/Janusz_Mikluszka)\
**Replies:** 4\
**Last updated:** [April 29, 2024, 5:59pm UTC](https://discuss.elastic.co/t/elasticsearch-cluster-across-multiple-docker-hosts/358314 "2024-04-29T17:59:13Z")

</div>

Hello, I'm trying to create multi node cluster across multiple VMs running docker. For now I tried setting up master node on my local docker engine. When second node is in the same docker network then there is no issue…

---

## [Elastic Search Aggregation Based On Case Insensitive](https://discuss.elastic.co/t/elastic-search-aggregation-based-on-case-insensitive/358435)

<div class="topic-metadata">

**Author:** [@ranjithkumar.rottela](https://discuss.elastic.co/u/ranjithkumar.rottela)\
**Replies:** 1\
**Last updated:** [April 29, 2024, 2:28pm UTC](https://discuss.elastic.co/t/elastic-search-aggregation-based-on-case-insensitive/358435 "2024-04-29T14:28:30Z")

</div>

Hi Team, I have requirement I need to fetch data in Elasticsearch case insensitivity, but need on both key and value field. Sample code below POST test-index999/\_doc { "key": "testKey:testValue", "count": 200, "…

---

## [Optimizing Elasticsearch Performance with ILM: Seeking Guidance](https://discuss.elastic.co/t/optimizing-elasticsearch-performance-with-ilm-seeking-guidance/358431)

<div class="topic-metadata">

**Author:** [@Souvik\_Das](https://discuss.elastic.co/u/Souvik_Das)\
**Replies:** 0\
**Last updated:** [April 29, 2024, 1:50pm UTC](https://discuss.elastic.co/t/optimizing-elasticsearch-performance-with-ilm-seeking-guidance/358431 "2024-04-29T13:50:33Z")

</div>

Hey Folks, I'm reaching out for some guidance on grasping the ins and outs of ILM (Index Lifecycle Management). Currently, my ELK setup for production consists of a three-node Elasticsearch cluster, with dedicated serv…

---

## [Elastic Search Case Insensitive for key](https://discuss.elastic.co/t/elastic-search-case-insensitive-for-key/358402)

<div class="topic-metadata">

**Author:** [@Harinder\_Singh](https://discuss.elastic.co/u/Harinder_Singh)\
**Replies:** 3\
**Last updated:** [April 29, 2024, 12:09pm UTC](https://discuss.elastic.co/t/elastic-search-case-insensitive-for-key/358402 "2024-04-29T12:09:30Z")

</div>

Hi, I have a requirement where I need to do the Elasticsearch search case insensitivity, but need on both key and value field. Sample Documents POST test-index21/\_doc { "Name": "something" } POST test-index21/\_doc …

---

## [Collect Windows DNS Server Querries with Elastic Agent?](https://discuss.elastic.co/t/collect-windows-dns-server-querries-with-elastic-agent/358421)

<div class="topic-metadata">

**Author:** [@ben-sec](https://discuss.elastic.co/u/ben-sec)\
**Replies:** 0\
**Last updated:** [April 29, 2024, 11:33am UTC](https://discuss.elastic.co/t/collect-windows-dns-server-querries-with-elastic-agent/358421 "2024-04-29T11:33:44Z")

</div>

Hi! Can I use Elastic Agent to collect all Windows DNS server activity to store them in my Elastic Search server? If yes, do I have to setup the parsing on my own? Thanks in advance! Cheers, Ben

---

## [Facing some challenges with elastic storage in the cloud](https://discuss.elastic.co/t/facing-some-challenges-with-elastic-storage-in-the-cloud/357909)

<div class="topic-metadata">

**Author:** [@Fayis\_Vadakkan](https://discuss.elastic.co/u/Fayis_Vadakkan)\
**Replies:** 7\
**Last updated:** [April 29, 2024, 9:16am UTC](https://discuss.elastic.co/t/facing-some-challenges-with-elastic-storage-in-the-cloud/357909 "2024-04-29T09:16:22Z")

</div>

I am facing some challenges with elastic storage in the cloud. Is there any way to transfer unwanted logs directly to frozen storage to reduce hot storage consumption?

---

## [Using BoolQuery.Builder with NativeQuery](https://discuss.elastic.co/t/using-boolquery-builder-with-nativequery/358363)

<div class="topic-metadata">

**Author:** [@ajt001](https://discuss.elastic.co/u/ajt001)\
**Replies:** 1\
**Last updated:** [April 29, 2024, 8:54am UTC](https://discuss.elastic.co/t/using-boolquery-builder-with-nativequery/358363 "2024-04-29T08:54:25Z")

</div>

Hi. Maybe this is basic, but I can't find the answer. I used to have this code: ... BoolQueryBuilder boolQueryBuilder = processElasticRequest() NativeSearchQuery query = new NativeSearchQueryBuilder() .withQ…

---

## [Compare a field between two Index](https://discuss.elastic.co/t/compare-a-field-between-two-index/358401)

<div class="topic-metadata">

**Author:** [@ajaya\_panda](https://discuss.elastic.co/u/ajaya_panda)\
**Replies:** 1\
**Last updated:** [April 29, 2024, 8:07am UTC](https://discuss.elastic.co/t/compare-a-field-between-two-index/358401 "2024-04-29T08:07:40Z")

</div>

Hi Team, I want to compare a field between two index are have same value or not. How can we perform that? please provide the suggestions. Example: Let's say I have two indexes one is onlineSale and another is offlineS…

---

## [Search template with compare equal](https://discuss.elastic.co/t/search-template-with-compare-equal/358390)

<div class="topic-metadata">

**Author:** [@h\_ng\_d\_ng](https://discuss.elastic.co/u/h_ng_d_ng)\
**Replies:** 3\
**Last updated:** [April 29, 2024, 7:24am UTC](https://discuss.elastic.co/t/search-template-with-compare-equal/358390 "2024-04-29T07:24:11Z")

</div>

Hi i am trying using search template to compare equal string to return specific records, it looks like this {{#equals false isJobInProgress}} ,{"bool":{"should":\[{"term":{"is\_job\_in\_progress":false}},{"bool":{"must\_no…

---

## [I have data in Azure Table storage and i want to publish that data in Elasticsearch for better filtration](https://discuss.elastic.co/t/i-have-data-in-azure-table-storage-and-i-want-to-publish-that-data-in-elasticsearch-for-better-filtration/358372)

<div class="topic-metadata">

**Author:** [@S\_DevOps](https://discuss.elastic.co/u/S_DevOps)\
**Replies:** 0\
**Last updated:** [April 28, 2024, 1:38pm UTC](https://discuss.elastic.co/t/i-have-data-in-azure-table-storage-and-i-want-to-publish-that-data-in-elasticsearch-for-better-filtration/358372 "2024-04-28T13:38:56Z")

</div>

Hi All, I have data stored in Azure Table storage(attached image for reference). I want that data in to our elastic cloud for better filtration and bifurcation based on requirement. Need your Support to achieve it. I;m …

---

## [Docker elasticsearch FileSystemException - Not a directory](https://discuss.elastic.co/t/docker-elasticsearch-filesystemexception-not-a-directory/358362)

<div class="topic-metadata">

**Author:** [@bharat\_soni1](https://discuss.elastic.co/u/bharat_soni1)\
**Replies:** 3\
**Last updated:** [April 28, 2024, 11:53am UTC](https://discuss.elastic.co/t/docker-elasticsearch-filesystemexception-not-a-directory/358362 "2024-04-28T11:53:40Z")

</div>

Hi, I'm very new to Docker as well as Elasticsearch. I was following a tutorial and used this docker compose file to install Elasticsearch: version: "4.6" services: es01: image: "docker.elastic.co/elasticsearch/el…

---

## [ES + ES Enterprise Search via Docker Compose ignores password](https://discuss.elastic.co/t/es-es-enterprise-search-via-docker-compose-ignores-password/358358)

<div class="topic-metadata">

**Author:** [@fherder](https://discuss.elastic.co/u/fherder)\
**Replies:** 0\
**Last updated:** [April 28, 2024, 12:05am UTC](https://discuss.elastic.co/t/es-es-enterprise-search-via-docker-compose-ignores-password/358358 "2024-04-28T00:05:22Z")

</div>

Hey all, I'm trying to get Elasticsearch configured with Enterprise Search. I'm using docker compose to do so. I'm using the following files: # Password for the 'elastic' user (at least 6 characters) ELASTIC\_PASSWORD=su…

---

## [Error in Creating Elastic Config file - JAVA - Springboot](https://discuss.elastic.co/t/error-in-creating-elastic-config-file-java-springboot/356542)

<div class="topic-metadata">

**Author:** [@Priyam\_Omer](https://discuss.elastic.co/u/Priyam_Omer)\
**Replies:** 10\
**Last updated:** [April 27, 2024, 10:05pm UTC](https://discuss.elastic.co/t/error-in-creating-elastic-config-file-java-springboot/356542 "2024-04-27T22:05:31Z")

</div>

package com.example.springbootelasticseach; import org.springframework.context.annotation.Configuration; import org.springframework.data.elasticsearch.client.ClientConfiguration; import org.springframework.data.elastics…

---

## [Can I deploy open source ELK stack for multi cloud scenario like GCP and AWS for capturing logs, metrics and Kibana dashboard centrally on GCP of the cloud? Or does multi cloud scenario require a licensed version only?](https://discuss.elastic.co/t/can-i-deploy-open-source-elk-stack-for-multi-cloud-scenario-like-gcp-and-aws-for-capturing-logs-metrics-and-kibana-dashboard-centrally-on-gcp-of-the-cloud-or-does-multi-cloud-scenario-require-a-licensed-version-only/358352)

<div class="topic-metadata">

**Author:** [@hsinha09](https://discuss.elastic.co/u/hsinha09)\
**Replies:** 3\
**Last updated:** [April 27, 2024, 6:32pm UTC](https://discuss.elastic.co/t/can-i-deploy-open-source-elk-stack-for-multi-cloud-scenario-like-gcp-and-aws-for-capturing-logs-metrics-and-kibana-dashboard-centrally-on-gcp-of-the-cloud-or-does-multi-cloud-scenario-require-a-licensed-version-only/358352 "2024-04-27T18:32:43Z")

</div>

Can someone help me with details around how to install opensource ELK tools on multi cloud environment GKE and EKS to achive end to end central observability for logs and metrics. What are the limitations of open sourc…

---

## [I am getting the dynamic method error](https://discuss.elastic.co/t/i-am-getting-the-dynamic-method-error/358337)

<div class="topic-metadata">

**Author:** [@Anil\_Alapati](https://discuss.elastic.co/u/Anil_Alapati)\
**Replies:** 1\
**Last updated:** [April 27, 2024, 2:46pm UTC](https://discuss.elastic.co/t/i-am-getting-the-dynamic-method-error/358337 "2024-04-27T14:46:26Z")

</div>

Hi, I am getting the dynamic method error . dynamic method \[java.time.ZonedDateTime, toString/1\] not found. the issue sis related to datetime field. epoch = (doc\['field'\].value).tostring("MM.dd.yyyy HH:mm:ss"); Could…

---

## [Query to list all \_ignored field values](https://discuss.elastic.co/t/query-to-list-all-ignored-field-values/358312)

<div class="topic-metadata">

**Author:** [@Alex\_Raguero](https://discuss.elastic.co/u/Alex_Raguero)\
**Replies:** 4\
**Last updated:** [April 26, 2024, 11:05pm UTC](https://discuss.elastic.co/t/query-to-list-all-ignored-field-values/358312 "2024-04-26T23:05:23Z")

</div>

I am running ES version 7.10. What is the query to get all docs where \_ignored field exists and lists the value?

---

## [Using elastic search with langchain](https://discuss.elastic.co/t/using-elastic-search-with-langchain/357748)

<div class="topic-metadata">

**Author:** [@David\_Alzate](https://discuss.elastic.co/u/David_Alzate)\
**Replies:** 6\
**Last updated:** [April 26, 2024, 8:01pm UTC](https://discuss.elastic.co/t/using-elastic-search-with-langchain/357748 "2024-04-26T20:01:32Z")

</div>

This category relates to the Enterprise Search set of products - App Search, Site Search and Workplace Search. If your question relates to core Elasticsearch functionality, please head over to the Elasticsearch category…

---

## [Is it possible to create rolling index using template?](https://discuss.elastic.co/t/is-it-possible-to-create-rolling-index-using-template/358241)

<div class="topic-metadata">

**Author:** [@linkerc](https://discuss.elastic.co/u/linkerc)\
**Replies:** 4\
**Last updated:** [April 26, 2024, 7:42pm UTC](https://discuss.elastic.co/t/is-it-possible-to-create-rolling-index-using-template/358241 "2024-04-26T19:42:12Z")

</div>

Like the title suggests. The process of creating a rolling index is to create "indexName-000001" with alias "indexName". The way to use rolling index is to have the applications write data to "indexName" (the alias), …

---

## [Search and partial search using or not special characters](https://discuss.elastic.co/t/search-and-partial-search-using-or-not-special-characters/358172)

<div class="topic-metadata">

**Author:** [@DarshanOS](https://discuss.elastic.co/u/DarshanOS)\
**Replies:** 1\
**Last updated:** [April 26, 2024, 4:37pm UTC](https://discuss.elastic.co/t/search-and-partial-search-using-or-not-special-characters/358172 "2024-04-26T16:37:49Z")

</div>

The biggest issue reported by the test group was the inability to search for a partial designation with or without spaces or punction. actual indexed field: AATCC EP12-2010e(2017)e2 Searchable fields : EP 12, EP-12 si…

---

## [Elastic search array value](https://discuss.elastic.co/t/elastic-search-array-value/358260)

<div class="topic-metadata">

**Author:** [@J\_Kit](https://discuss.elastic.co/u/J_Kit)\
**Replies:** 1\
**Last updated:** [April 26, 2024, 4:32pm UTC](https://discuss.elastic.co/t/elastic-search-array-value/358260 "2024-04-26T16:32:28Z")

</div>

Hi Woud like to ask for advice on array type value Example, I got my index mapping for this field author: { type: integer } and when we store the value we would like to store as array as might contain 1 or more Ex…

---

## [Inquiry on Elastic Search Terms for Prepositions](https://discuss.elastic.co/t/inquiry-on-elastic-search-terms-for-prepositions/358255)

<div class="topic-metadata">

**Author:** [@aisyaharifin](https://discuss.elastic.co/u/aisyaharifin)\
**Replies:** 9\
**Last updated:** [April 26, 2024, 4:22pm UTC](https://discuss.elastic.co/t/inquiry-on-elastic-search-terms-for-prepositions/358255 "2024-04-26T16:22:21Z")

</div>

Hello Elastic, My dev team did a testing on the search terms for Elasticsearch on our apps site and the findings is that Elastic didn't highlight I would group it as preposition terms, such as 'the', 'with', are and etc…

---

## [Can´t use the ilm explain in elasticsearch-java](https://discuss.elastic.co/t/can-t-use-the-ilm-explain-in-elasticsearch-java/358297)

<div class="topic-metadata">

**Author:** [@heldergr](https://discuss.elastic.co/u/heldergr)\
**Replies:** 1\
**Last updated:** [April 26, 2024, 4:18pm UTC](https://discuss.elastic.co/t/can-t-use-the-ilm-explain-in-elasticsearch-java/358297 "2024-04-26T16:18:03Z")

</div>

Dear all, I'm trying to use the ilm explain api in the elasticsearch-java client. When I run the following code, I got an error, which is described below. Could someone please help me on this? My dependencies: \<depe…

---

## [Can I automate this task in elastic without leveraging external programming?](https://discuss.elastic.co/t/can-i-automate-this-task-in-elastic-without-leveraging-external-programming/358237)

<div class="topic-metadata">

**Author:** [@Jingyi\_Wang](https://discuss.elastic.co/u/Jingyi_Wang)\
**Replies:** 4\
**Last updated:** [April 26, 2024, 1:42pm UTC](https://discuss.elastic.co/t/can-i-automate-this-task-in-elastic-without-leveraging-external-programming/358237 "2024-04-26T13:42:42Z")

</div>

One elastic index1 have documents like: {username: u1, analysisId: 1} {username: u1, analysisId: 2} {username: u2, analysisId: 3} {username: u3, analysisId: 4} {username: u3, analysisId: 5} In this index, analysis Id i…

---

## [Cannot increase total shards](https://discuss.elastic.co/t/cannot-increase-total-shards/358257)

<div class="topic-metadata">

**Author:** [@My\_Google\_Account](https://discuss.elastic.co/u/My_Google_Account)\
**Replies:** 7\
**Last updated:** [April 26, 2024, 1:39pm UTC](https://discuss.elastic.co/t/cannot-increase-total-shards/358257 "2024-04-26T13:39:53Z")

</div>

Hello there, we have 3 data nodes with 7.6.1 elk version and before we add the new nodes in our cluster we want to increase the amount of shards for each node and we did it with the following directives: { "persisten…

---

## [org.elasticsearch.xpack.monitoring.exporter.ExportException: failed to flush export bulks](https://discuss.elastic.co/t/org-elasticsearch-xpack-monitoring-exporter-exportexception-failed-to-flush-export-bulks/358294)

<div class="topic-metadata">

**Author:** [@Anish\_Suvarna](https://discuss.elastic.co/u/Anish_Suvarna)\
**Replies:** 1\
**Last updated:** [April 26, 2024, 1:34pm UTC](https://discuss.elastic.co/t/org-elasticsearch-xpack-monitoring-exporter-exportexception-failed-to-flush-export-bulks/358294 "2024-04-26T13:34:09Z")

</div>

monitoring execution failed org.elasticsearch.xpack.monitoring.exporter.ExportException: failed to flush export bulks at org.elasticsearch.xpack.monitoring.exporter.ExportBulk$Compound.lambda$doFlush$0(ExportBulk.java:…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=117)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=119)
