# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=120

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 121

---

## [Do I have too many shards?](https://discuss.elastic.co/t/do-i-have-too-many-shards/358027)

<div class="topic-metadata">

**Author:** [@Yoann\_Buzenet](https://discuss.elastic.co/u/Yoann_Buzenet)\
**Replies:** 1\
**Last updated:** [April 24, 2024, 2:15pm UTC](https://discuss.elastic.co/t/do-i-have-too-many-shards/358027 "2024-04-24T14:15:03Z")

</div>

My ELK stack passed in red status this morning because of missing memory on disk. After cleaning it a bit, it could reassign an unassigned shard and it came back to yellow again and it works. I checked the health endpoi…

---

## [Need to increase the return count from 10K for some benchmark testing](https://discuss.elastic.co/t/need-to-increase-the-return-count-from-10k-for-some-benchmark-testing/358127)

<div class="topic-metadata">

**Author:** [@BOYO](https://discuss.elastic.co/u/BOYO)\
**Replies:** 1\
**Last updated:** [April 24, 2024, 1:48pm UTC](https://discuss.elastic.co/t/need-to-increase-the-return-count-from-10k-for-some-benchmark-testing/358127 "2024-04-24T13:48:18Z")

</div>

As part of an internal POC we're trying to benchmark various queries from the JS client. We need to increase the return count for an individual query over 10k for one test. Tried scroll api since as per the docs it can …

---

## [Query throws error just by one term other working great](https://discuss.elastic.co/t/query-throws-error-just-by-one-term-other-working-great/358115)

<div class="topic-metadata">

**Author:** [@libertey](https://discuss.elastic.co/u/libertey)\
**Replies:** 0\
**Last updated:** [April 24, 2024, 11:12am UTC](https://discuss.elastic.co/t/query-throws-error-just-by-one-term-other-working-great/358115 "2024-04-24T11:12:20Z")

</div>

Im having a Problem with one query which throws that error: {"error":{"root\_cause":\[{"type":"illegal\_argument\_exception","reason":"\[from\] parameter cannot be negative"}\],"type":"illegal\_argument\_exception","reason":"\[f…

---

## [Delete logs from past year](https://discuss.elastic.co/t/delete-logs-from-past-year/358101)

<div class="topic-metadata">

**Author:** [@frh](https://discuss.elastic.co/u/frh)\
**Replies:** 0\
**Last updated:** [April 24, 2024, 8:59am UTC](https://discuss.elastic.co/t/delete-logs-from-past-year/358101 "2024-04-24T08:59:36Z")

</div>

Hi, I'm in attempt of deleting logs from past year 2022 in shrink-logstash-2021.11.28-000010. This index also contains logs from current year 2023-2024. I have millions of logs from past year 2022 and it's taking up to…

---

## [Java API Client - Geo Bounding Box Query from Geohash](https://discuss.elastic.co/t/java-api-client-geo-bounding-box-query-from-geohash/358082)

<div class="topic-metadata">

**Author:** [@tschmidt01](https://discuss.elastic.co/u/tschmidt01)\
**Replies:** 2\
**Last updated:** [April 24, 2024, 8:18am UTC](https://discuss.elastic.co/t/java-api-client-geo-bounding-box-query-from-geohash/358082 "2024-04-24T08:18:35Z")

</div>

Using the old java client you could create a geo bounding box query by just supplying a geohash like so: QueryBuilders.geoBoundingBoxQuery("some-field") .setCorners("some-geo-hash") Was this feature rem…

---

## [Location of logs](https://discuss.elastic.co/t/location-of-logs/358088)

<div class="topic-metadata">

**Author:** [@m\_pahlevanzadeh](https://discuss.elastic.co/u/m_pahlevanzadeh)\
**Replies:** 1\
**Last updated:** [April 24, 2024, 7:30am UTC](https://discuss.elastic.co/t/location-of-logs/358088 "2024-04-24T07:30:55Z")

</div>

I installed ELK and it strores log and yesterday my / was 9.3G and today / is 33G. So I decided to change path of logs to new disk. But i don't know which directory should be mounted.

---

## [TLS configuration](https://discuss.elastic.co/t/tls-configuration/357802)

<div class="topic-metadata">

**Author:** [@boosterino](https://discuss.elastic.co/u/boosterino)\
**Replies:** 6\
**Last updated:** [April 24, 2024, 7:27am UTC](https://discuss.elastic.co/t/tls-configuration/357802 "2024-04-24T07:27:55Z")

</div>

Hi I ran out of ideas. I have kibana (my wildcard cert, \*.hostname.net). Kibana is ok. kibana.yml server.publicBaseUrl: "https://kibanaprod.hostname.net" elasticsearch.hosts: \["https://elkprod1.hostname.net:9200", "…

---

## [Can Rollover API / ILM be used to keep only last x days of data in the current index](https://discuss.elastic.co/t/can-rollover-api-ilm-be-used-to-keep-only-last-x-days-of-data-in-the-current-index/358093)

<div class="topic-metadata">

**Author:** [@touseef\_rafique](https://discuss.elastic.co/u/touseef_rafique)\
**Replies:** 0\
**Last updated:** [April 24, 2024, 6:43am UTC](https://discuss.elastic.co/t/can-rollover-api-ilm-be-used-to-keep-only-last-x-days-of-data-in-the-current-index/358093 "2024-04-24T06:43:38Z")

</div>

I went thru some threads regarding this question and most of them suggest using DeleteByQuery as Rollover API seems to delete/move to other phase the indices and create the new ones based on given condition. but DeleteB…

---

## [How to provide input from keyboard to script. Input can be service name or application](https://discuss.elastic.co/t/how-to-provide-input-from-keyboard-to-script-input-can-be-service-name-or-application/358046)

<div class="topic-metadata">

**Author:** [@navya\_k](https://discuss.elastic.co/u/navya_k)\
**Replies:** 3\
**Last updated:** [April 24, 2024, 5:47am UTC](https://discuss.elastic.co/t/how-to-provide-input-from-keyboard-to-script-input-can-be-service-name-or-application/358046 "2024-04-24T05:47:38Z")

</div>

Hello, I have written below code to accept input from keyboard and retrieve data from elasticsearch cluster from elasticsearch import Elasticsearch from datetime import datetime es = Elasticsearch ("https://localhost…

---

## [Version of org.elasticsearch.common.inject library used in Elasticsearch 7.10.2](https://discuss.elastic.co/t/version-of-org-elasticsearch-common-inject-library-used-in-elasticsearch-7-10-2/357993)

<div class="topic-metadata">

**Author:** [@Prashant\_Singh](https://discuss.elastic.co/u/Prashant_Singh)\
**Replies:** 5\
**Last updated:** [April 24, 2024, 5:36am UTC](https://discuss.elastic.co/t/version-of-org-elasticsearch-common-inject-library-used-in-elasticsearch-7-10-2/357993 "2024-04-24T05:36:22Z")

</div>

How to know which version of org.elasticsearch.common.inject library used in Elasticsearch 7.10.2 ?

---

## [Project does not support PATCH request](https://discuss.elastic.co/t/project-does-not-support-patch-request/358075)

<div class="topic-metadata">

**Author:** [@minhdai998](https://discuss.elastic.co/u/minhdai998)\
**Replies:** 1\
**Last updated:** [April 24, 2024, 5:25am UTC](https://discuss.elastic.co/t/project-does-not-support-patch-request/358075 "2024-04-24T05:25:28Z")

</div>

I need to update certain fields for documents in Elastic Search Cloud, but my project does not support PATCH request. I found a solution where I can override POST request by adding the following parameter in header "X-HT…

---

## [Overcoming search.max\_buckets Limitation in AWS Elasticsearch for Shard-Level Aggregations](https://discuss.elastic.co/t/overcoming-search-max-buckets-limitation-in-aws-elasticsearch-for-shard-level-aggregations/358079)

<div class="topic-metadata">

**Author:** [@Yuki\_Hara](https://discuss.elastic.co/u/Yuki_Hara)\
**Replies:** 3\
**Last updated:** [April 24, 2024, 5:23am UTC](https://discuss.elastic.co/t/overcoming-search-max-buckets-limitation-in-aws-elasticsearch-for-shard-level-aggregations/358079 "2024-04-24T05:23:50Z")

</div>

Objective: Perform aggregation (terms aggregation) on all documents within each shard. Actions Taken & Issues: Set size: 100 (assuming size should remain unchanged) Set shard\_size to 2147483519 Set shard\_size to 1000…

---

## [Enrich source index compression](https://discuss.elastic.co/t/enrich-source-index-compression/358058)

<div class="topic-metadata">

**Author:** [@cvarano](https://discuss.elastic.co/u/cvarano)\
**Replies:** 0\
**Last updated:** [April 23, 2024, 8:29pm UTC](https://discuss.elastic.co/t/enrich-source-index-compression/358058 "2024-04-23T20:29:59Z")

</div>

I have a very large source index for an enrich policy that stores two sparse\_vector fields, which is almost 500gb on disk (no replicas). Here's the source index mappings: { "mappings": { "dynamic\_templates": \[\], …

---

## [Cómo saber, en base a la cantidad de consultas que recibe una tienda en línea, los requisitos para instalar elastic](https://discuss.elastic.co/t/como-saber-en-base-a-la-cantidad-de-consultas-que-recibe-una-tienda-en-linea-los-requisitos-para-instalar-elastic/358054)

<div class="topic-metadata">

**Author:** [@omarod](https://discuss.elastic.co/u/omarod)\
**Replies:** 0\
**Last updated:** [April 23, 2024, 7:20pm UTC](https://discuss.elastic.co/t/como-saber-en-base-a-la-cantidad-de-consultas-que-recibe-una-tienda-en-linea-los-requisitos-para-instalar-elastic/358054 "2024-04-23T19:20:09Z")

</div>

Quiero usar Elastic pero no se cuánto de memoria y disco asignarle. El dato que tengo, es que tengo 120 mil búsquedas en promedio al mes en mi sitio web

---

## [Annotations section](https://discuss.elastic.co/t/annotations-section/358041)

<div class="topic-metadata">

**Author:** [@zi\_ninja](https://discuss.elastic.co/u/zi_ninja)\
**Replies:** 2\
**Last updated:** [April 23, 2024, 4:29pm UTC](https://discuss.elastic.co/t/annotations-section/358041 "2024-04-23T16:29:33Z")

</div>

In the single metric viewer, I see a lot of annotations, marked 1,2,3,... (1 as the red arrow points to). What this means. I see that the birth of 1,2,3,... does not follow a rule, am I misunderstanding the problem here? …

---

## [Does using phonetic analyzer using .json file kills the effect of Fuzzy Search](https://discuss.elastic.co/t/does-using-phonetic-analyzer-using-json-file-kills-the-effect-of-fuzzy-search/357916)

<div class="topic-metadata">

**Author:** [@satadru\_biswas](https://discuss.elastic.co/u/satadru_biswas)\
**Replies:** 10\
**Last updated:** [April 23, 2024, 2:44pm UTC](https://discuss.elastic.co/t/does-using-phonetic-analyzer-using-json-file-kills-the-effect-of-fuzzy-search/357916 "2024-04-23T14:44:51Z")

</div>

So created an entity class. @Data @Document(indexName = "ABC") @Setting(settingPath = "analyzer/search-analyzer.json") @JsonIgnoreProperties(ignoreUnknown = true) @Slf4j @EqualsAndHashCode public class XYZ { @Field(ty…

---

## [Azure Blob Storage - Using Blobfuse2](https://discuss.elastic.co/t/azure-blob-storage-using-blobfuse2/357932)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 3\
**Last updated:** [April 23, 2024, 2:37pm UTC](https://discuss.elastic.co/t/azure-blob-storage-using-blobfuse2/357932 "2024-04-23T14:37:22Z")

</div>

Hello, We are currently running self-managed Elastic using Azure VMs. Due to vast amount of data ingested, 100TB+ we are leveraging Azure's premium disks for our cold and hot data nodes. We are trying to move away fro…

---

## [Efficient Metadata Indexing for Large Filesystem in Elasticsearch](https://discuss.elastic.co/t/efficient-metadata-indexing-for-large-filesystem-in-elasticsearch/357981)

<div class="topic-metadata">

**Author:** [@geekahmed](https://discuss.elastic.co/u/geekahmed)\
**Replies:** 2\
**Last updated:** [April 23, 2024, 2:05pm UTC](https://discuss.elastic.co/t/efficient-metadata-indexing-for-large-filesystem-in-elasticsearch/357981 "2024-04-23T14:05:57Z")

</div>

Hello everyone, I'm working with a mounted network filesystem on Linux that contains a massive collection of files (text, images, videos, etc.). My goal is to index specific metadata from these files into Elasticsearch. …

---

## [Search query with aggregation and sorting](https://discuss.elastic.co/t/search-query-with-aggregation-and-sorting/358021)

<div class="topic-metadata">

**Author:** [@mananchhajer](https://discuss.elastic.co/u/mananchhajer)\
**Replies:** 0\
**Last updated:** [April 23, 2024, 12:37pm UTC](https://discuss.elastic.co/t/search-query-with-aggregation-and-sorting/358021 "2024-04-23T12:37:45Z")

</div>

in the below mentioned elasticsearch search query, I want to fetch the documents in a way that all have different variant ids and the product which is fetched from the variant group has the least sort order. { "from…

---

## [Replica Use In Elasticsearch](https://discuss.elastic.co/t/replica-use-in-elasticsearch/357684)

<div class="topic-metadata">

**Author:** [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Replies:** 10\
**Last updated:** [April 23, 2024, 8:23am UTC](https://discuss.elastic.co/t/replica-use-in-elasticsearch/357684 "2024-04-23T08:23:28Z")

</div>

Hi Team, I had generic question on Elasticsearch replica. Is the replica main purpose is to provide HA to the docs which are stored in Elastic or any other benefits. My questions is suppose we are querying a index with…

---

## [Runtime field script error](https://discuss.elastic.co/t/runtime-field-script-error/357901)

<div class="topic-metadata">

**Author:** [@Khaled\_Saidi](https://discuss.elastic.co/u/Khaled_Saidi)\
**Replies:** 2\
**Last updated:** [April 23, 2024, 8:55am UTC](https://discuss.elastic.co/t/runtime-field-script-error/357901 "2024-04-23T08:55:29Z")

</div>

Hi, On a cross cluster, using kibana, I'm trying to add a runtime field in a dataview pointing to a remote index. In the preview section, a "script error" message is displayed. My script code: emit('TEST'); Did I forg…

---

## [While searching how are shards picked for cluster with index.routing\_partition\_size](https://discuss.elastic.co/t/while-searching-how-are-shards-picked-for-cluster-with-index-routing-partition-size/357957)

<div class="topic-metadata">

**Author:** [@ktech007](https://discuss.elastic.co/u/ktech007)\
**Replies:** 1\
**Last updated:** [April 23, 2024, 6:26am UTC](https://discuss.elastic.co/t/while-searching-how-are-shards-picked-for-cluster-with-index-routing-partition-size/357957 "2024-04-23T06:26:26Z")

</div>

Let's say my cluster is set up with index.routing\_partition\_size of 20. For a routing key abc, it can then route documents to max 20 shards. Here is a scenario: Suppose a document comes with routing key abc and it is r…

---

## [Delete API without without any write](https://discuss.elastic.co/t/delete-api-without-without-any-write/357973)

<div class="topic-metadata">

**Author:** [@Sajad\_Soltanian](https://discuss.elastic.co/u/Sajad_Soltanian)\
**Replies:** 1\
**Last updated:** [April 23, 2024, 6:02am UTC](https://discuss.elastic.co/t/delete-api-without-without-any-write/357973 "2024-04-23T06:02:57Z")

</div>

We have an index which has been rolloverd many time using an ILM, which also force merge the rollovered indices. We will never update or write any new document to those rollovers, though we want to delete some documents…

---

## [What is the different between parameters, primaries and new\_primaries of index setting index.routing.allocation.enable](https://discuss.elastic.co/t/what-is-the-different-between-parameters-primaries-and-new-primaries-of-index-setting-index-routing-allocation-enable/357975)

<div class="topic-metadata">

**Author:** [@niuchaoyang0520](https://discuss.elastic.co/u/niuchaoyang0520)\
**Replies:** 0\
**Last updated:** [April 23, 2024, 5:59am UTC](https://discuss.elastic.co/t/what-is-the-different-between-parameters-primaries-and-new-primaries-of-index-setting-index-routing-allocation-enable/357975 "2024-04-23T05:59:01Z")

</div>

what is the different between parameters, primaries and new\_primaries of index setting index.routing.allocation.enable

---

## [Elasticsearch 7.10.2 End of Support Date and End of Life Date](https://discuss.elastic.co/t/elasticsearch-7-10-2-end-of-support-date-and-end-of-life-date/357941)

<div class="topic-metadata">

**Author:** [@zhangyifei](https://discuss.elastic.co/u/zhangyifei)\
**Replies:** 1\
**Last updated:** [April 22, 2024, 8:05pm UTC](https://discuss.elastic.co/t/elasticsearch-7-10-2-end-of-support-date-and-end-of-life-date/357941 "2024-04-22T20:05:45Z")

</div>

Hi Team, Are there any documents specifying the End of Support Date and End of Life Date for Elasticsearch 7.10.2? The website currently only provides this information for version 7.17.x. Thanks.

---

## [Elastic Search, Docker and max virtual memory areas error](https://discuss.elastic.co/t/elastic-search-docker-and-max-virtual-memory-areas-error/357907)

<div class="topic-metadata">

**Author:** [@hack3rcon](https://discuss.elastic.co/u/hack3rcon)\
**Replies:** 1\
**Last updated:** [April 22, 2024, 1:36pm UTC](https://discuss.elastic.co/t/elastic-search-docker-and-max-virtual-memory-areas-error/357907 "2024-04-22T13:36:25Z")

</div>

Hello, My YAML file is as follows: services: es01: image: elasticsearch:8.13.0 container\_name: Elasticsearch01 environment: - node.name=es01 - cluster.name=es-docker-cluster - discovery.…

---

## [Restart node after 15 mins](https://discuss.elastic.co/t/restart-node-after-15-mins/357911)

<div class="topic-metadata">

**Author:** [@mukularora89](https://discuss.elastic.co/u/mukularora89)\
**Replies:** 1\
**Last updated:** [April 22, 2024, 1:54pm UTC](https://discuss.elastic.co/t/restart-node-after-15-mins/357911 "2024-04-22T13:54:41Z")

</div>

Hi, We want to put the node offline for 15 mins and then bring back into the cluster. So the approach we are following is mentioned below disable shard allocation except for primaries Perform flush Shutdown Elasticsea…

---

## [How we can do monitorying for elasticsearch install as pod in k8s](https://discuss.elastic.co/t/how-we-can-do-monitorying-for-elasticsearch-install-as-pod-in-k8s/357912)

<div class="topic-metadata">

**Author:** [@pratik\_jain163](https://discuss.elastic.co/u/pratik_jain163)\
**Replies:** 0\
**Last updated:** [April 22, 2024, 1:46pm UTC](https://discuss.elastic.co/t/how-we-can-do-monitorying-for-elasticsearch-install-as-pod-in-k8s/357912 "2024-04-22T13:46:57Z")

</div>

i am looking for some tool or anything that we use to monitor ES cluster which is install in k8s. and also how we can read hot\_threads

---

## [Watcher: How to execute “condition” after “transform”?](https://discuss.elastic.co/t/watcher-how-to-execute-condition-after-transform/357906)

<div class="topic-metadata">

**Author:** [@ashish25](https://discuss.elastic.co/u/ashish25)\
**Replies:** 0\
**Last updated:** [April 22, 2024, 11:07am UTC](https://discuss.elastic.co/t/watcher-how-to-execute-condition-after-transform/357906 "2024-04-22T11:07:12Z")

</div>

I saw this thread in past but not seeing any reply on that. I want to achieve the same thing, want to perform transformation before condition. Is it possible?

---

## [Elastic.Clients.Elasticsearch Support for Update without index name](https://discuss.elastic.co/t/elastic-clients-elasticsearch-support-for-update-without-index-name/357794)

<div class="topic-metadata">

**Author:** [@DdeM](https://discuss.elastic.co/u/DdeM)\
**Replies:** 3\
**Last updated:** [April 22, 2024, 11:05am UTC](https://discuss.elastic.co/t/elastic-clients-elasticsearch-support-for-update-without-index-name/357794 "2024-04-22T11:05:48Z")

</div>

Using the .Net client for elasticsearch I can do all actions using a generic contstraint, eg. return \_client.DeleteAsync\<T\>(id, cancellationToken); However, when I want to edit a document this doesn't work. Is there a …

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=119)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=121)
