# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=127

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 128

---

## [Should setting op\_type = create on the \_bulk API be faster than index?](https://discuss.elastic.co/t/should-setting-op-type-create-on-the-bulk-api-be-faster-than-index/356710)

<div class="topic-metadata">

**Author:** [@pingo](https://discuss.elastic.co/u/pingo)\
**Replies:** 1\
**Last updated:** [April 6, 2024, 7:51am UTC](https://discuss.elastic.co/t/should-setting-op-type-create-on-the-bulk-api-be-faster-than-index/356710 "2024-04-06T07:51:00Z")

</div>

Hi there! We have some indices using datastreams so we have to set op\_type to create in logstash. But for other append-only non-datastream indices, is there any performance benefit to setting it there aswell?

---

## [Log is swarm with "Giving up on search" "No such index"](https://discuss.elastic.co/t/log-is-swarm-with-giving-up-on-search-no-such-index/356881)

<div class="topic-metadata">

**Author:** [@ricardocr](https://discuss.elastic.co/u/ricardocr)\
**Replies:** 1\
**Last updated:** [April 6, 2024, 7:39am UTC](https://discuss.elastic.co/t/log-is-swarm-with-giving-up-on-search-no-such-index/356881 "2024-04-06T07:39:57Z")

</div>

the log file is receiving tons of such errors after some indexes were closed and deleted a month ago, we haven't removed any after that but the error persists, what can I do about it?

---

## [How to move from 2 node cluster to single node?](https://discuss.elastic.co/t/how-to-move-from-2-node-cluster-to-single-node/356861)

<div class="topic-metadata">

**Author:** [@webfr](https://discuss.elastic.co/u/webfr)\
**Replies:** 1\
**Last updated:** [April 5, 2024, 9:23pm UTC](https://discuss.elastic.co/t/how-to-move-from-2-node-cluster-to-single-node/356861 "2024-04-05T21:23:20Z")

</div>

Hello, I've two nodes configured like this: indices replica is 1. #define node 1 as master-eligible: node.master: true #define nodes 2 and 3 as data nodes: node.data: true #ingest mode node.ingest: true #defin…

---

## [Want to show retried and failed counts separately in visulization](https://discuss.elastic.co/t/want-to-show-retried-and-failed-counts-separately-in-visulization/356535)

<div class="topic-metadata">

**Author:** [@2328943\_dc](https://discuss.elastic.co/u/2328943_dc)\
**Replies:** 1\
**Last updated:** [April 5, 2024, 9:09pm UTC](https://discuss.elastic.co/t/want-to-show-retried-and-failed-counts-separately-in-visulization/356535 "2024-04-05T21:09:50Z")

</div>

Non zero failed documents will retry on servers . doc ID is unique but Folder name is same for failed and retried docs so we want to show retry documents and failed doc separately in visulization,how can we achive this…

---

## [Is there a way to add more than a single partition field in an ML job?](https://discuss.elastic.co/t/is-there-a-way-to-add-more-than-a-single-partition-field-in-an-ml-job/356888)

<div class="topic-metadata">

**Author:** [@mir02](https://discuss.elastic.co/u/mir02)\
**Replies:** 0\
**Last updated:** [April 5, 2024, 6:56pm UTC](https://discuss.elastic.co/t/is-there-a-way-to-add-more-than-a-single-partition-field-in-an-ml-job/356888 "2024-04-05T18:56:25Z")

</div>

I have KPIs that are broken down into locations but the locations have further breakdown which I am interested in, is there a way to add more partitions to an ML model?

---

## [Integration elasticsearch in laravel app](https://discuss.elastic.co/t/integration-elasticsearch-in-laravel-app/356804)

<div class="topic-metadata">

**Author:** [@Yemboaro](https://discuss.elastic.co/u/Yemboaro)\
**Replies:** 3\
**Last updated:** [April 5, 2024, 3:57pm UTC](https://discuss.elastic.co/t/integration-elasticsearch-in-laravel-app/356804 "2024-04-05T15:57:38Z")

</div>

Hello Elastic community, I'm a beginner and I'm looking to integrate Elasticsearch into a Laravel application with a relational database. I'm seeking guidance on the process to follow in order to understand how Elastics…

---

## [Sorting nested aggregations painless](https://discuss.elastic.co/t/sorting-nested-aggregations-painless/356882)

<div class="topic-metadata">

**Author:** [@twierdzenie](https://discuss.elastic.co/u/twierdzenie)\
**Replies:** 0\
**Last updated:** [April 5, 2024, 2:50pm UTC](https://discuss.elastic.co/t/sorting-nested-aggregations-painless/356882 "2024-04-05T14:50:53Z")

</div>

Hi, let's say i have documents with fields: name, surname, score and timestamp; i'm aggregating it by combination name and surname then getting last score of the day for each pair for 1 week, BUT: i'm trying to get th…

---

## [Joining node to cluster - what am I doing wrong?](https://discuss.elastic.co/t/joining-node-to-cluster-what-am-i-doing-wrong/356817)

<div class="topic-metadata">

**Author:** [@artschooldropout](https://discuss.elastic.co/u/artschooldropout)\
**Replies:** 12\
**Last updated:** [April 5, 2024, 2:48pm UTC](https://discuss.elastic.co/t/joining-node-to-cluster-what-am-i-doing-wrong/356817 "2024-04-05T14:48:03Z")

</div>

We have an existing cluster consisting of a single node. We would like to add another node to the cluster. Both nodes are running Elasticsearch 8.13. We followed the instructions in here, and additionally here. After c…

---

## [Setting up Minimal Security with ElasticSearch Docker Image fails](https://discuss.elastic.co/t/setting-up-minimal-security-with-elasticsearch-docker-image-fails/356562)

<div class="topic-metadata">

**Author:** [@tryin2stupelk](https://discuss.elastic.co/u/tryin2stupelk)\
**Replies:** 12\
**Last updated:** [April 5, 2024, 2:46pm UTC](https://discuss.elastic.co/t/setting-up-minimal-security-with-elasticsearch-docker-image-fails/356562 "2024-04-05T14:46:04Z")

</div>

Hello everyone, I was wondering if I could get some assistance with setting up Minimal Security (Username + Password to access the console as outlined here: Set up minimal security for Elasticsearch | Elasticsearch Guid…

---

## [Elasticsearch Query function\_score ignores quotes in query string](https://discuss.elastic.co/t/elasticsearch-query-function-score-ignores-quotes-in-query-string/356877)

<div class="topic-metadata">

**Author:** [@Savo\_Pejovic](https://discuss.elastic.co/u/Savo_Pejovic)\
**Replies:** 0\
**Last updated:** [April 5, 2024, 2:22pm UTC](https://discuss.elastic.co/t/elasticsearch-query-function-score-ignores-quotes-in-query-string/356877 "2024-04-05T14:22:27Z")

</div>

The results of two same query string queries with quoted phrases return different results if one query is wrapped inside a function\_score query. In the wrapped query, the phrase isn't preserved in full but tokenized, whi…

---

## [\_search request peformance with explain option turned on](https://discuss.elastic.co/t/search-request-peformance-with-explain-option-turned-on/356717)

<div class="topic-metadata">

**Author:** [@yana2301](https://discuss.elastic.co/u/yana2301)\
**Replies:** 1\
**Last updated:** [April 5, 2024, 12:22pm UTC](https://discuss.elastic.co/t/search-request-peformance-with-explain-option-turned-on/356717 "2024-04-05T12:22:21Z")

</div>

Hello! I've got a question on explain query param: I'd like to keep track of score calculation history for each request. To do this I plan to set explain=true for each search request and log explain section from respons…

---

## [Sharepoint Connector issue - configuring api permissions](https://discuss.elastic.co/t/sharepoint-connector-issue-configuring-api-permissions/356831)

<div class="topic-metadata">

**Author:** [@Akshayd302](https://discuss.elastic.co/u/Akshayd302)\
**Replies:** 1\
**Last updated:** [April 5, 2024, 9:15am UTC](https://discuss.elastic.co/t/sharepoint-connector-issue-configuring-api-permissions/356831 "2024-04-05T09:15:00Z")

</div>

We are using elastic' sharepoint native connector but running into an issue where from organization policy perspective are only allowed to get permission to access only limited sites and not all. Elastic sharepoint conn…

---

## [Log tuning](https://discuss.elastic.co/t/log-tuning/356844)

<div class="topic-metadata">

**Author:** [@Ganesh\_DV](https://discuss.elastic.co/u/Ganesh_DV)\
**Replies:** 0\
**Last updated:** [April 5, 2024, 8:00am UTC](https://discuss.elastic.co/t/log-tuning/356844 "2024-04-05T08:00:38Z")

</div>

Hi team, Im ingesting logs from Active directory (AD) server to elastic SIEM but daily im getting 2cr logs from 1 single server. such servers we have 4. so kindly help me , how to reduce such huge log source without co…

---

## [Index LifeCycle Management](https://discuss.elastic.co/t/index-lifecycle-management/356759)

<div class="topic-metadata">

**Author:** [@spazzrabbit](https://discuss.elastic.co/u/spazzrabbit)\
**Replies:** 6\
**Last updated:** [April 5, 2024, 6:45am UTC](https://discuss.elastic.co/t/index-lifecycle-management/356759 "2024-04-05T06:45:56Z")

</div>

Hello everyone, I'm having issues with lifecycle policy. Currently I'm receiving log from one windows server, logstash outputs it to elastic succesfully. When lifecycle begins it creates new index but keeps writing to …

---

## [Store last X documents per id](https://discuss.elastic.co/t/store-last-x-documents-per-id/356737)

<div class="topic-metadata">

**Author:** [@vsadokhin](https://discuss.elastic.co/u/vsadokhin)\
**Replies:** 10\
**Last updated:** [April 5, 2024, 5:24am UTC](https://discuss.elastic.co/t/store-last-x-documents-per-id/356737 "2024-04-05T05:24:48Z")

</div>

Hello Elastic's team and community! I am looking for a way to keep only recent documents for a particular id. Ideally it happens automatically via some Elasticsearch configuration or with one hop request after a new doc…

---

## [What happens during Elasticsearch refresh?](https://discuss.elastic.co/t/what-happens-during-elasticsearch-refresh/356780)

<div class="topic-metadata">

**Author:** [@EVINDX](https://discuss.elastic.co/u/EVINDX)\
**Replies:** 2\
**Last updated:** [April 5, 2024, 4:04am UTC](https://discuss.elastic.co/t/what-happens-during-elasticsearch-refresh/356780 "2024-04-05T04:04:55Z")

</div>

Hello, I'm trying to understand the flow of data inside the Elasticsearch and based on what I could gather so far, New data is first appended to the tranlsog and an in-memory buffer. Optionally doing a refresh (explic…

---

## [Set "number\_of\_replicas" to 0 permanently](https://discuss.elastic.co/t/set-number-of-replicas-to-0-permanently/356754)

<div class="topic-metadata">

**Author:** [@DaddyYusk](https://discuss.elastic.co/u/DaddyYusk)\
**Replies:** 6\
**Last updated:** [April 4, 2024, 11:24pm UTC](https://discuss.elastic.co/t/set-number-of-replicas-to-0-permanently/356754 "2024-04-04T23:24:40Z")

</div>

Hi, Because of my current Elasticsearch cluster deployment (only one Hot node, not best practice, I know), I need to set the "number\_of\_replicas" of all my already an newly created indexes to 0. As I use a Fleet Server…

---

## [Delete index policy for every X minutes](https://discuss.elastic.co/t/delete-index-policy-for-every-x-minutes/356805)

<div class="topic-metadata">

**Author:** [@mpniel](https://discuss.elastic.co/u/mpniel)\
**Replies:** 3\
**Last updated:** [April 4, 2024, 5:39pm UTC](https://discuss.elastic.co/t/delete-index-policy-for-every-x-minutes/356805 "2024-04-04T17:39:08Z")

</div>

What is the Kibana Api command to create a delete index policy for every X minutes to a group of indexes with name starting string indA ?

---

## [Index template put versus post](https://discuss.elastic.co/t/index-template-put-versus-post/356806)

<div class="topic-metadata">

**Author:** [@mpniel](https://discuss.elastic.co/u/mpniel)\
**Replies:** 1\
**Last updated:** [April 4, 2024, 5:24pm UTC](https://discuss.elastic.co/t/index-template-put-versus-post/356806 "2024-04-04T17:24:24Z")

</div>

What is the correct Kibana Api command to create an index template ?

---

## [Is index rolling possible with parent-child modeling?](https://discuss.elastic.co/t/is-index-rolling-possible-with-parent-child-modeling/356794)

<div class="topic-metadata">

**Author:** [@getsolaris](https://discuss.elastic.co/u/getsolaris)\
**Replies:** 2\
**Last updated:** [April 4, 2024, 3:22pm UTC](https://discuss.elastic.co/t/is-index-rolling-possible-with-parent-child-modeling/356794 "2024-04-04T15:22:35Z")

</div>

Hello, I am working on parent-child modeling. We are testing whether time series-based index rolling is possible. Scenario Members are stored in index 202404 (assuming they joined in Apr 2024) Membership access inform…

---

## [High availability of ELK server](https://discuss.elastic.co/t/high-availability-of-elk-server/356783)

<div class="topic-metadata">

**Author:** [@kaushalshriyan](https://discuss.elastic.co/u/kaushalshriyan)\
**Replies:** 1\
**Last updated:** [April 4, 2024, 1:49pm UTC](https://discuss.elastic.co/t/high-availability-of-elk-server/356783 "2024-04-04T13:49:10Z")

</div>

Hi, I am running a single instance of ELK server on RHEL8.9 which is not reliable as of now if the VM instance goes down which will result in Single point of failure scenario. I have planned to setup second ELK node2 …

---

## [Is it possible to get the size of a closed index without opening it?](https://discuss.elastic.co/t/is-it-possible-to-get-the-size-of-a-closed-index-without-opening-it/356716)

<div class="topic-metadata">

**Author:** [@pingo](https://discuss.elastic.co/u/pingo)\
**Replies:** 2\
**Last updated:** [April 4, 2024, 1:20pm UTC](https://discuss.elastic.co/t/is-it-possible-to-get-the-size-of-a-closed-index-without-opening-it/356716 "2024-04-04T13:20:50Z")

</div>

The \_cat/indices API only shows the store size of open indices. Is there anyway to get the store size of closed indices?

---

## [Logstash stopped processing because of error\[system exit\]](https://discuss.elastic.co/t/logstash-stopped-processing-because-of-error-system-exit/356773)

<div class="topic-metadata">

**Author:** [@2328943\_dc](https://discuss.elastic.co/u/2328943_dc)\
**Replies:** 1\
**Last updated:** [April 4, 2024, 1:07pm UTC](https://discuss.elastic.co/t/logstash-stopped-processing-because-of-error-system-exit/356773 "2024-04-04T13:07:51Z")

</div>

We have newly installed kibana on server but when we checked logstash logs getting fatal error as highlighted below.

---

## [Ingest Custom date Format data to Elastic Index](https://discuss.elastic.co/t/ingest-custom-date-format-data-to-elastic-index/356736)

<div class="topic-metadata">

**Author:** [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Replies:** 3\
**Last updated:** [April 4, 2024, 12:26pm UTC](https://discuss.elastic.co/t/ingest-custom-date-format-data-to-elastic-index/356736 "2024-04-04T12:26:48Z")

</div>

Hi Team, We are trying to ingest a custom date format data to Elastic Index where the field mapping is as below. "edate":{ "type":"date", "format":\["yyyy-mm-dd"\] } We are using filebeat to ingest…

---

## [Access to system indices](https://discuss.elastic.co/t/access-to-system-indices/356731)

<div class="topic-metadata">

**Author:** [@Krishna\_Teja](https://discuss.elastic.co/u/Krishna_Teja)\
**Replies:** 4\
**Last updated:** [April 4, 2024, 9:48am UTC](https://discuss.elastic.co/t/access-to-system-indices/356731 "2024-04-04T09:48:03Z")

</div>

If access to system indices is removed, can we still access them by changing users permissions or via rules? Or is it totally inaccessible?

---

## [Multiple Elastic Agents on the same system](https://discuss.elastic.co/t/multiple-elastic-agents-on-the-same-system/306215)

<div class="topic-metadata">

**Author:** [@AndreiRD](https://discuss.elastic.co/u/AndreiRD)\
**Replies:** 1\
**Last updated:** [April 4, 2024, 8:38am UTC](https://discuss.elastic.co/t/multiple-elastic-agents-on-the-same-system/306215 "2024-04-04T08:38:01Z")

</div>

Is there any method by which two Elastic Agents with different Fleet&Output configurations can run simultaneously on the same server? (except for Docker Containers scenario). It looks like the installation paths cannot …

---

## [Adding Elasticsearch Node to a Cluster](https://discuss.elastic.co/t/adding-elasticsearch-node-to-a-cluster/356680)

<div class="topic-metadata">

**Author:** [@sravan\_kaheti](https://discuss.elastic.co/u/sravan_kaheti)\
**Replies:** 7\
**Last updated:** [April 4, 2024, 7:43am UTC](https://discuss.elastic.co/t/adding-elasticsearch-node-to-a-cluster/356680 "2024-04-04T07:43:27Z")

</div>

Hi Team , I have a Elasticsearch cluster of 25 nodes , which is lets say belongs subnet-a and all nodes i have configured/added to cluster using ./elasticsearch-create-enrollment-token -s node and then reconfigure comma…

---

## [\[es/search\] failed: \[x\_content\_parse\_exception\] \[2:4\] Unexpected character ('\\' (code 92)): was expecting double-quote](https://discuss.elastic.co/t/es-search-failed-x-content-parse-exception-2-4-unexpected-character-code-92-was-expecting-double-quote/356632)

<div class="topic-metadata">

**Author:** [@thatelasticguy](https://discuss.elastic.co/u/thatelasticguy)\
**Replies:** 8\
**Last updated:** [April 3, 2024, 8:20pm UTC](https://discuss.elastic.co/t/es-search-failed-x-content-parse-exception-2-4-unexpected-character-code-92-was-expecting-double-quote/356632 "2024-04-03T20:20:41Z")

</div>

I am using elastic version 8+ with spring boot elasticsearch 5.2.0 dependency. I want to query my index with Odata $filter. I have configured my parser for Odata and it's generating below query json for following query: $…

---

## [Elasticsearch 2.4.6 starts with warnings](https://discuss.elastic.co/t/elasticsearch-2-4-6-starts-with-warnings/356696)

<div class="topic-metadata">

**Author:** [@Aldahir\_Zamora](https://discuss.elastic.co/u/Aldahir_Zamora)\
**Replies:** 11\
**Last updated:** [April 3, 2024, 6:55pm UTC](https://discuss.elastic.co/t/elasticsearch-2-4-6-starts-with-warnings/356696 "2024-04-03T18:55:30Z")

</div>

Hello, I am having a problem with the elasticsearch service (2.4.6) that I am running on a centos server, currently the service goes down every so often (1-2 days) and when I start the service it gives me this warning, I…

---

## [If you have capacity, is 1 index with 5 shards better than 5 indices with 1 shard each?](https://discuss.elastic.co/t/if-you-have-capacity-is-1-index-with-5-shards-better-than-5-indices-with-1-shard-each/356636)

<div class="topic-metadata">

**Author:** [@bruce289](https://discuss.elastic.co/u/bruce289)\
**Replies:** 6\
**Last updated:** [April 3, 2024, 6:19pm UTC](https://discuss.elastic.co/t/if-you-have-capacity-is-1-index-with-5-shards-better-than-5-indices-with-1-shard-each/356636 "2024-04-03T18:19:48Z")

</div>

Let’s say the cluster is empty and we have the choice between: 1 index with 5 50 GB shards 5 indices, each with 1 50 GB shard Is there any difference between these 2 options purely from a performance standpoint? Assum…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=126)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=128)
