# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=122

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 123

---

## [How can I hunt down this Java error: "a fault occurred in an unsafe memory access operation"](https://discuss.elastic.co/t/how-can-i-hunt-down-this-java-error-a-fault-occurred-in-an-unsafe-memory-access-operation/357656)

<div class="topic-metadata">

**Author:** [@artschooldropout](https://discuss.elastic.co/u/artschooldropout)\
**Replies:** 6\
**Last updated:** [April 18, 2024, 7:07pm UTC](https://discuss.elastic.co/t/how-can-i-hunt-down-this-java-error-a-fault-occurred-in-an-unsafe-memory-access-operation/357656 "2024-04-18T19:07:21Z")

</div>

I have a two-node Elasticsearch cluster with both nodes running 8.13.2. Since I added the second node to the cluster, the master node has been crashing regularly. The logs show: \[2024-04-17T15:57:09,258\]\[ERROR\]\[o.e.b.El…

---

## [Action \[indices:admin/auto\_create\] is unauthorized for user](https://discuss.elastic.co/t/action-indices-admin-auto-create-is-unauthorized-for-user/357742)

<div class="topic-metadata">

**Author:** [@Pooort](https://discuss.elastic.co/u/Pooort)\
**Replies:** 0\
**Last updated:** [April 18, 2024, 7:03pm UTC](https://discuss.elastic.co/t/action-indices-admin-auto-create-is-unauthorized-for-user/357742 "2024-04-18T19:03:47Z")

</div>

I'm trying to make \_sql request and get: action \[indices:admin/auto\_create\] is unauthorized for user \[some\_user\] with roles \[some\_role\], this action is granted by the index privileges \[auto\_configure,create\_index,manag…

---

## [Update timestamp of documents](https://discuss.elastic.co/t/update-timestamp-of-documents/357739)

<div class="topic-metadata">

**Author:** [@Abhishek\_Sen](https://discuss.elastic.co/u/Abhishek_Sen)\
**Replies:** 1\
**Last updated:** [April 18, 2024, 6:53pm UTC](https://discuss.elastic.co/t/update-timestamp-of-documents/357739 "2024-04-18T18:53:20Z")

</div>

I want to know when a particular document in an index was created, and when it was last modified. Is there a way or do we have to keep track of this manually?

---

## [How can I automate looping through an index and running a pipeline against each document?](https://discuss.elastic.co/t/how-can-i-automate-looping-through-an-index-and-running-a-pipeline-against-each-document/357719)

<div class="topic-metadata">

**Author:** [@Jingyi\_Wang](https://discuss.elastic.co/u/Jingyi_Wang)\
**Replies:** 1\
**Last updated:** [April 18, 2024, 6:38pm UTC](https://discuss.elastic.co/t/how-can-i-automate-looping-through-an-index-and-running-a-pipeline-against-each-document/357719 "2024-04-18T18:38:34Z")

</div>

I have index with documents like: \[ { "\_index" : "converted-user", "\_type" : "\_doc", "\_id" : "dTXSY0KNxU08jKDnZcc-nbkAAAAAAAAA", "\_score" : 1.0, "\_source" : { "use…

---

## [Failing to start issue](https://discuss.elastic.co/t/failing-to-start-issue/357735)

<div class="topic-metadata">

**Author:** [@Ali\_A](https://discuss.elastic.co/u/Ali_A)\
**Replies:** 1\
**Last updated:** [April 18, 2024, 6:05pm UTC](https://discuss.elastic.co/t/failing-to-start-issue/357735 "2024-04-18T18:05:07Z")

</div>

everything was working fine until I changed the IP for my virtual machine, when I tried to open the localhost it was saying kibana server is not ready yet, after that I tried some solutions but ended up facing this frus…

---

## [Searchable snapshots how it works?](https://discuss.elastic.co/t/searchable-snapshots-how-it-works/357674)

<div class="topic-metadata">

**Author:** [@Aliya\_Khalel](https://discuss.elastic.co/u/Aliya_Khalel)\
**Replies:** 4\
**Last updated:** [April 18, 2024, 3:38pm UTC](https://discuss.elastic.co/t/searchable-snapshots-how-it-works/357674 "2024-04-18T15:38:54Z")

</div>

I'm new at Elastic and I need help with understanding how searchable snapshots works. we planing a cluster with 2 hot and 2 cold nodes on prem. In hot we plan to store data 30 days and then move to cold and use searc…

---

## [Can multiple index-templates from diferent metricbeats cohexist?](https://discuss.elastic.co/t/can-multiple-index-templates-from-diferent-metricbeats-cohexist/357721)

<div class="topic-metadata">

**Author:** [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Replies:** 0\
**Last updated:** [April 18, 2024, 2:38pm UTC](https://discuss.elastic.co/t/can-multiple-index-templates-from-diferent-metricbeats-cohexist/357721 "2024-04-18T14:38:22Z")

</div>

Hello, I am reviewing a client’s cluster and I noticed that it has several index templates from different versions of Metricbeat: metricbeat-7.17.13 metricbeat-7.17.5 metricbeat-7.17.9 Some metrics come with values t…

---

## [Current Date in watcher](https://discuss.elastic.co/t/current-date-in-watcher/357681)

<div class="topic-metadata">

**Author:** [@ashish25](https://discuss.elastic.co/u/ashish25)\
**Replies:** 6\
**Last updated:** [April 18, 2024, 12:17pm UTC](https://discuss.elastic.co/t/current-date-in-watcher/357681 "2024-04-18T12:17:22Z")

</div>

Hi, I have below index which will create everyday - POST /test\_index-2024-04-17/\_doc { "field\_to\_check": "old\_value", "field\_to\_update": "old\_value" } POST /test\_index-2024-04-18/\_doc { "field\_to\_check": "old\_va…

---

## [org.janusgraph.diskstorage.es.ElasticSearchIndex.checkClusterHealth](https://discuss.elastic.co/t/org-janusgraph-diskstorage-es-elasticsearchindex-checkclusterhealth/357693)

<div class="topic-metadata">

**Author:** [@shivam\_raj](https://discuss.elastic.co/u/shivam_raj)\
**Replies:** 2\
**Last updated:** [April 18, 2024, 11:35am UTC](https://discuss.elastic.co/t/org-janusgraph-diskstorage-es-elasticsearchindex-checkclusterhealth/357693 "2024-04-18T11:35:55Z")

</div>

org.janusgraph.diskstorage.es.ElasticSearchIndex.checkClusterHealth(ElasticSearchIndex.java:412) URI \[/\_cluster/health?timeout=30s&wait\_for\_status=yellow\], status line \[HTTP/1.1 401 Unauthorized\] {"error":{"root\_cause"…

---

## [Closed indices are included in snapshot policy](https://discuss.elastic.co/t/closed-indices-are-included-in-snapshot-policy/357697)

<div class="topic-metadata">

**Author:** [@vishalk663](https://discuss.elastic.co/u/vishalk663)\
**Replies:** 1\
**Last updated:** [April 18, 2024, 11:34am UTC](https://discuss.elastic.co/t/closed-indices-are-included-in-snapshot-policy/357697 "2024-04-18T11:34:51Z")

</div>

We are using the elasticsearch 7.13.3 version using eck operator in our openshift cluster. When we are using below snapshot policy it did not include the closed indices in a snapshot. PUT \_slm/policy/elastic-snapshot {…

---

## [Dynamic mapping of dense\_vector](https://discuss.elastic.co/t/dynamic-mapping-of-dense-vector/357559)

<div class="topic-metadata">

**Author:** [@dhrchatt](https://discuss.elastic.co/u/dhrchatt)\
**Replies:** 6\
**Last updated:** [April 18, 2024, 9:42am UTC](https://discuss.elastic.co/t/dynamic-mapping-of-dense-vector/357559 "2024-04-18T09:42:19Z")

</div>

I have a float which I want to map to dense\_vector type field. I want to use dynamic mapping but it is dynamically always mapped to float type. Is there a way to map to dense\_vector type when I am using dynamic mapping f…

---

## [Elastic Client 8.x Histogram Extended Bounds](https://discuss.elastic.co/t/elastic-client-8-x-histogram-extended-bounds/357664)

<div class="topic-metadata">

**Author:** [@Kyle\_Manuel](https://discuss.elastic.co/u/Kyle_Manuel)\
**Replies:** 1\
**Last updated:** [April 18, 2024, 6:43am UTC](https://discuss.elastic.co/t/elastic-client-8-x-histogram-extended-bounds/357664 "2024-04-18T06:43:04Z")

</div>

I'm using the Elastic.Clients.Elasticsearch NuGet package to migrate away from our existing Nest implementations. I have been unable to find histogram in the new docs or source. We have searches that utilize the histog…

---

## [Entreprise Elastic License](https://discuss.elastic.co/t/entreprise-elastic-license/357585)

<div class="topic-metadata">

**Author:** [@Manal\_A](https://discuss.elastic.co/u/Manal_A)\
**Replies:** 2\
**Last updated:** [April 18, 2024, 1:46am UTC](https://discuss.elastic.co/t/entreprise-elastic-license/357585 "2024-04-18T01:46:26Z")

</div>

Hello, I received the Elastic Enterprise license with two JSON files (production environment and non-production environment). So, I installed the production license in my production environment and the other one in my l…

---

## [Where's the docs for us "mere mortals"?](https://discuss.elastic.co/t/wheres-the-docs-for-us-mere-mortals/357660)

<div class="topic-metadata">

**Author:** [@flatlander](https://discuss.elastic.co/u/flatlander)\
**Replies:** 1\
**Last updated:** [April 17, 2024, 11:36pm UTC](https://discuss.elastic.co/t/wheres-the-docs-for-us-mere-mortals/357660 "2024-04-17T23:36:11Z")

</div>

Hello, First time poster. Please don't bite my head off, or tell me to Let Me Google That For You! I've genuinely struggled finding a good source of documentation for ingest pipeline syntax that's actually helpful to …

---

## [Index in filebeat.yml doesn't match index in elasticsearch dataview](https://discuss.elastic.co/t/index-in-filebeat-yml-doesnt-match-index-in-elasticsearch-dataview/357543)

<div class="topic-metadata">

**Author:** [@Vickistan](https://discuss.elastic.co/u/Vickistan)\
**Replies:** 3\
**Last updated:** [April 17, 2024, 10:38pm UTC](https://discuss.elastic.co/t/index-in-filebeat-yml-doesnt-match-index-in-elasticsearch-dataview/357543 "2024-04-17T22:38:15Z")

</div>

I added filebeat to a Linux Mint system in an attempt to upload logs from it to my elk stack. The index is set to this in filebeat.yml: index: "vicki-desktop-filestream" When I started filebeat, I guess it created the …

---

## [Disabling Elasticsearch Index compression version 7.10+](https://discuss.elastic.co/t/disabling-elasticsearch-index-compression-version-7-10/357648)

<div class="topic-metadata">

**Author:** [@tommyd](https://discuss.elastic.co/u/tommyd)\
**Replies:** 6\
**Last updated:** [April 17, 2024, 10:03pm UTC](https://discuss.elastic.co/t/disabling-elasticsearch-index-compression-version-7-10/357648 "2024-04-17T22:03:11Z")

</div>

Hi, I am new to Elasticsearch and I have a question around Elasticsearch compression. I know it uses the codec default and best\_compression when creating an index but since my backend storage already provides LZ4 compre…

---

## [Set higher index.priority for high ingest throughput indices?](https://discuss.elastic.co/t/set-higher-index-priority-for-high-ingest-throughput-indices/357282)

<div class="topic-metadata">

**Author:** [@tronboto](https://discuss.elastic.co/u/tronboto)\
**Replies:** 2\
**Last updated:** [April 17, 2024, 9:33pm UTC](https://discuss.elastic.co/t/set-higher-index-priority-for-high-ingest-throughput-indices/357282 "2024-04-17T21:33:32Z")

</div>

Hey, Does anyone know if it makes sense to set a higher index.priority value for indices which have a high ingest throughput? My thinking is that during a rolling restart or just some node maintenance, we don't want to…

---

## [How to create SubAggregation in new JAVA API Client](https://discuss.elastic.co/t/how-to-create-subaggregation-in-new-java-api-client/357529)

<div class="topic-metadata">

**Author:** [@Ansh\_Kumar](https://discuss.elastic.co/u/Ansh_Kumar)\
**Replies:** 1\
**Last updated:** [April 17, 2024, 4:30pm UTC](https://discuss.elastic.co/t/how-to-create-subaggregation-in-new-java-api-client/357529 "2024-04-17T16:30:47Z")

</div>

Hii community , upgrading our application from JavaAPIClient version 7.x to 8.10 , aggregation is not working Neither i am able to find suitable example which i can consider in our application we are creating aggrega…

---

## [Setting Up Latest Elasticsearch Cluster](https://discuss.elastic.co/t/setting-up-latest-elasticsearch-cluster/356992)

<div class="topic-metadata">

**Author:** [@cis4life](https://discuss.elastic.co/u/cis4life)\
**Replies:** 2\
**Last updated:** [April 17, 2024, 3:31pm UTC](https://discuss.elastic.co/t/setting-up-latest-elasticsearch-cluster/356992 "2024-04-17T15:31:30Z")

</div>

Hello, I'm working on setting up a completely new ES Cluster. I will be setting up from scratch so we won't be "Upgrading" the older "Test" cluster we have (Version 6). The data is stored on SAN storage, so we will ju…

---

## [Parsing Exception on Mapped Type Object Enabled False](https://discuss.elastic.co/t/parsing-exception-on-mapped-type-object-enabled-false/357633)

<div class="topic-metadata">

**Author:** [@maxfriz](https://discuss.elastic.co/u/maxfriz)\
**Replies:** 0\
**Last updated:** [April 17, 2024, 2:15pm UTC](https://discuss.elastic.co/t/parsing-exception-on-mapped-type-object-enabled-false/357633 "2024-04-17T14:15:42Z")

</div>

One of our fields in our field mapping is mapped as type object with enabled set to false. It is our understanding this is stored in \_source, but not parsed or indexed. "payload": { "type": "object", "enabled": false },…

---

## [Accessing Security Alert Flat Field in Watcher Action Body fails](https://discuss.elastic.co/t/accessing-security-alert-flat-field-in-watcher-action-body-fails/357632)

<div class="topic-metadata">

**Author:** [@CC-89829](https://discuss.elastic.co/u/CC-89829)\
**Replies:** 0\
**Last updated:** [April 17, 2024, 2:15pm UTC](https://discuss.elastic.co/t/accessing-security-alert-flat-field-in-watcher-action-body-fails/357632 "2024-04-17T14:15:27Z")

</div>

I have a more complex issue. With a watcher checking the alert index for assigned and open alerts I want to forward the alert id, index and assignee id to an external webhook. The issue is that I can't resolve the indiv…

---

## [job for elasticsearch.service failed because of unavailable resources or another system error.](https://discuss.elastic.co/t/job-for-elasticsearch-service-failed-because-of-unavailable-resources-or-another-system-error/357625)

<div class="topic-metadata">

**Author:** [@QingHao](https://discuss.elastic.co/u/QingHao)\
**Replies:** 0\
**Last updated:** [April 17, 2024, 2:01pm UTC](https://discuss.elastic.co/t/job-for-elasticsearch-service-failed-because-of-unavailable-resources-or-another-system-error/357625 "2024-04-17T14:01:00Z")

</div>

---

## [Aggregation: Custom score for ordering via sub aggregation](https://discuss.elastic.co/t/aggregation-custom-score-for-ordering-via-sub-aggregation/356663)

<div class="topic-metadata">

**Author:** [@Martin\_Berlin](https://discuss.elastic.co/u/Martin_Berlin)\
**Replies:** 1\
**Last updated:** [April 17, 2024, 1:21pm UTC](https://discuss.elastic.co/t/aggregation-custom-score-for-ordering-via-sub-aggregation/356663 "2024-04-17T13:21:56Z")

</div>

I have an Array of Objects with keywords: "keywords":\[ { "name":"Testing Equipment", "score":0.999 }, { "name":"Film Shrinkage Tester", "score":0.666 }, { "name":"Universal T…

---

## [Cannot see the production cluster data on the monitoring cluster](https://discuss.elastic.co/t/cannot-see-the-production-cluster-data-on-the-monitoring-cluster/357422)

<div class="topic-metadata">

**Author:** [@My\_Google\_Account](https://discuss.elastic.co/u/My_Google_Account)\
**Replies:** 13\
**Last updated:** [April 17, 2024, 12:52pm UTC](https://discuss.elastic.co/t/cannot-see-the-production-cluster-data-on-the-monitoring-cluster/357422 "2024-04-17T12:52:48Z")

</div>

Hi there! I've 2 elk clusters version 7.6.1 "Basic license", 1st -production which have 3nodes (elastic, kibana, logstash and metricbeat agents on each node) and 2nd - monitoring cluster which have 1 node (elastic, kiban…

---

## [Using lookup fields in Runtime mappings with nested fields](https://discuss.elastic.co/t/using-lookup-fields-in-runtime-mappings-with-nested-fields/357612)

<div class="topic-metadata">

**Author:** [@Thijsvdp](https://discuss.elastic.co/u/Thijsvdp)\
**Replies:** 0\
**Last updated:** [April 17, 2024, 12:40pm UTC](https://discuss.elastic.co/t/using-lookup-fields-in-runtime-mappings-with-nested-fields/357612 "2024-04-17T12:40:10Z")

</div>

I saw in the documentation that there is support for lookup type in runtime\_mappings . I have tried it, and it seems to work. However, I have the following issue: I have some nested field called members , and I would …

---

## [Archiving of Index data](https://discuss.elastic.co/t/archiving-of-index-data/357571)

<div class="topic-metadata">

**Author:** [@amjad](https://discuss.elastic.co/u/amjad)\
**Replies:** 3\
**Last updated:** [April 17, 2024, 11:12am UTC](https://discuss.elastic.co/t/archiving-of-index-data/357571 "2024-04-17T11:12:05Z")

</div>

Hi All, Is there any option to archive the document level data of the Index which is created in the cloud level, Please guide me if any possibility is there to archive the data in cloud level. Thanks in advance.

---

## [Convert object type data to array in Elastic search watcher](https://discuss.elastic.co/t/convert-object-type-data-to-array-in-elastic-search-watcher/357597)

<div class="topic-metadata">

**Author:** [@JasonREC](https://discuss.elastic.co/u/JasonREC)\
**Replies:** 0\
**Last updated:** [April 17, 2024, 9:49am UTC](https://discuss.elastic.co/t/convert-object-type-data-to-array-in-elastic-search-watcher/357597 "2024-04-17T09:49:27Z")

</div>

Hi, I am trying to run a Elasticsearch watcher, but I am stuck in the chain input, I have a http fetch -\> transfrom the http response data -\> used by the index search the http response data is simply a json like this …

---

## [Send log to ELK server](https://discuss.elastic.co/t/send-log-to-elk-server/357570)

<div class="topic-metadata">

**Author:** [@m\_pahlevanzadeh](https://discuss.elastic.co/u/m_pahlevanzadeh)\
**Replies:** 3\
**Last updated:** [April 17, 2024, 9:37am UTC](https://discuss.elastic.co/t/send-log-to-elk-server/357570 "2024-04-17T09:37:06Z")

</div>

I have some firewall and want to send their log to ELK server. Can you please guide to which guide can help me to setup ELK according to Database? (pg or mysql)

---

## [How to handle dot in fields (Missing intermediate object)](https://discuss.elastic.co/t/how-to-handle-dot-in-fields-missing-intermediate-object/357584)

<div class="topic-metadata">

**Author:** [@alissan](https://discuss.elastic.co/u/alissan)\
**Replies:** 0\
**Last updated:** [April 17, 2024, 8:43am UTC](https://discuss.elastic.co/t/how-to-handle-dot-in-fields-missing-intermediate-object/357584 "2024-04-17T08:43:19Z")

</div>

Hello, Elasticsearch version: 8.8.2 I have an index template with runtime fields: "dynamic": "runtime" When i add a document to index with dotted field (bash.command.test), its added normally as a runtime field: …

---

## [Where do I disable \_source field?](https://discuss.elastic.co/t/where-do-i-disable-source-field/357573)

<div class="topic-metadata">

**Author:** [@m\_pahlevanzadeh](https://discuss.elastic.co/u/m_pahlevanzadeh)\
**Replies:** 6\
**Last updated:** [April 17, 2024, 8:51am UTC](https://discuss.elastic.co/t/where-do-i-disable-source-field/357573 "2024-04-17T08:51:19Z")

</div>

I have to disable \_source: false But I don't where file can store my \_source: false. please help me.

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=121)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=123)
