# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=128

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 129

---

## [Why do we have so many bulk indexing tasks?](https://discuss.elastic.co/t/why-do-we-have-so-many-bulk-indexing-tasks/354331)

<div class="topic-metadata">

**Author:** [@tronboto](https://discuss.elastic.co/u/tronboto)\
**Replies:** 3\
**Last updated:** [April 3, 2024, 5:58pm UTC](https://discuss.elastic.co/t/why-do-we-have-so-many-bulk-indexing-tasks/354331 "2024-04-03T17:58:59Z")

</div>

We ingest data into our elasticsearch cluster solely using 16 logstash nodes each configured with the following settings: pipeline.workers: 48 pipeline.batch.size: 4000 pipeline.batch.delay: 1000 These hosts only have …

---

## [Mapping issue in adding a new filed to existing index](https://discuss.elastic.co/t/mapping-issue-in-adding-a-new-filed-to-existing-index/356681)

<div class="topic-metadata">

**Author:** [@Kesavan](https://discuss.elastic.co/u/Kesavan)\
**Replies:** 1\
**Last updated:** [April 3, 2024, 5:40pm UTC](https://discuss.elastic.co/t/mapping-issue-in-adding-a-new-filed-to-existing-index/356681 "2024-04-03T17:40:12Z")

</div>

WE are using Spring-boot-Elasticsearch to create a index into elastic from java. We are facing a issue describe below: Entity: @Document(indexName = "user") @Setting(settingPath = "/settings/lower-case-normalizer.json…

---

## [How can I get the (randomly generated) watcher ID?](https://discuss.elastic.co/t/how-can-i-get-the-randomly-generated-watcher-id/356708)

<div class="topic-metadata">

**Author:** [@fun-with-ES](https://discuss.elastic.co/u/fun-with-ES)\
**Replies:** 0\
**Last updated:** [April 3, 2024, 5:20pm UTC](https://discuss.elastic.co/t/how-can-i-get-the-randomly-generated-watcher-id/356708 "2024-04-03T17:20:09Z")

</div>

I'm creating a watch in Kibana, and Elastic creates its ID as a random hash. That's fine as I don't necessarily want to override it. Now in the watcher JSON definition, I'm trying to get the randomly generated watcher I…

---

## [java.net.SocketTimeoutException: Read timed out when nodes leave the cluster](https://discuss.elastic.co/t/java-net-sockettimeoutexception-read-timed-out-when-nodes-leave-the-cluster/356701)

<div class="topic-metadata">

**Author:** [@Chuck\_Reynolds](https://discuss.elastic.co/u/Chuck_Reynolds)\
**Replies:** 0\
**Last updated:** [April 3, 2024, 3:13pm UTC](https://discuss.elastic.co/t/java-net-sockettimeoutexception-read-timed-out-when-nodes-leave-the-cluster/356701 "2024-04-03T15:13:31Z")

</div>

I'm seeing a lot of SocketTimeout read errors when nodes leave the cluster. The nodes return with in a few minutes of leaving. The cluster has a primary and 1 replica. We are using Elasticsearch 7.16.3 in Kubernetes a…

---

## [Error":"handle volume expansion: volume claim templates can only have their storage requests increased, if the storage class allows volume expansion. Any other change is forbidden"](https://discuss.elastic.co/t/error-handle-volume-expansion-volume-claim-templates-can-only-have-their-storage-requests-increased-if-the-storage-class-allows-volume-expansion-any-other-change-is-forbidden/356679)

<div class="topic-metadata">

**Author:** [@sagarbud](https://discuss.elastic.co/u/sagarbud)\
**Replies:** 0\
**Last updated:** [April 3, 2024, 12:34pm UTC](https://discuss.elastic.co/t/error-handle-volume-expansion-volume-claim-templates-can-only-have-their-storage-requests-increased-if-the-storage-class-allows-volume-expansion-any-other-change-is-forbidden/356679 "2024-04-03T12:34:10Z")

</div>

Hello All, I have 12 node elastic cluster(7.4.2) on GKE K8s cluster. Also, I have installed elastic operator. But when I upgrade elastic operator from 1.0.0-beta to 2.4.0, it gives below error. To upgrade elastic operat…

---

## [Query for documents with datetime field where time is outside office hours](https://discuss.elastic.co/t/query-for-documents-with-datetime-field-where-time-is-outside-office-hours/356297)

<div class="topic-metadata">

**Author:** [@Peter\_K](https://discuss.elastic.co/u/Peter_K)\
**Replies:** 5\
**Last updated:** [April 3, 2024, 11:25am UTC](https://discuss.elastic.co/t/query-for-documents-with-datetime-field-where-time-is-outside-office-hours/356297 "2024-04-03T11:25:08Z")

</div>

query for documents with datetime field where time is outside office hours. There's a field vraag\_datumtijd (same format as @timestamp) that's filled with a date time stamp of the moment of doing an user action and a fi…

---

## [Problem with unique count and cardinality](https://discuss.elastic.co/t/problem-with-unique-count-and-cardinality/356298)

<div class="topic-metadata">

**Author:** [@Peter\_K](https://discuss.elastic.co/u/Peter_K)\
**Replies:** 3\
**Last updated:** [April 3, 2024, 10:14am UTC](https://discuss.elastic.co/t/problem-with-unique-count-and-cardinality/356298 "2024-04-03T10:14:55Z")

</div>

There are the following fields: documentnumber user (user identifier) @timestamp field I want to create the following monitoring (as EQL or other query, as alert and if possible in dashboard form) in Kibana: Show the …

---

## [Logstash synced with MySQL taking to long to execute the queries](https://discuss.elastic.co/t/logstash-synced-with-mysql-taking-to-long-to-execute-the-queries/356646)

<div class="topic-metadata">

**Author:** [@abhinavtyagi](https://discuss.elastic.co/u/abhinavtyagi)\
**Replies:** 17\
**Last updated:** [April 3, 2024, 10:07am UTC](https://discuss.elastic.co/t/logstash-synced-with-mysql-taking-to-long-to-execute-the-queries/356646 "2024-04-03T10:07:17Z")

</div>

Look at the below screenshot, you can see that while querying a table with just 146 records it's taking 6.2 seconds to execute. Now, take a look at my configuration files for logstash: base.conf: input { jdbc { …

---

## [How can i modify the index name when using ILM?](https://discuss.elastic.co/t/how-can-i-modify-the-index-name-when-using-ilm/355659)

<div class="topic-metadata">

**Author:** [@e-ferrari](https://discuss.elastic.co/u/e-ferrari)\
**Replies:** 5\
**Last updated:** [April 3, 2024, 8:22am UTC](https://discuss.elastic.co/t/how-can-i-modify-the-index-name-when-using-ilm/355659 "2024-04-03T08:22:20Z")

</div>

Hi, i'm using ILM. I'd like to have index names which reflect the source of the data, e.g. index-mysql-hostname. I read that i can configure the index name in filebeat, but only without ILM. Is there a way to create an…

---

## [In facet i want to show all result?](https://discuss.elastic.co/t/in-facet-i-want-to-show-all-result/356648)

<div class="topic-metadata">

**Author:** [@Deshant\_Pandit](https://discuss.elastic.co/u/Deshant_Pandit)\
**Replies:** 1\
**Last updated:** [April 3, 2024, 7:03am UTC](https://discuss.elastic.co/t/in-facet-i-want-to-show-all-result/356648 "2024-04-03T07:03:25Z")

</div>

In facet i want all the result. I found show prop which only take number and i don't know exact result. How to show all results in facet? I do not want to use more button instead i will use scroller. So, I want all the…

---

## [Data is duplicating without restart of any services of kibana](https://discuss.elastic.co/t/data-is-duplicating-without-restart-of-any-services-of-kibana/356616)

<div class="topic-metadata">

**Author:** [@2328943\_dc](https://discuss.elastic.co/u/2328943_dc)\
**Replies:** 3\
**Last updated:** [April 3, 2024, 6:15am UTC](https://discuss.elastic.co/t/data-is-duplicating-without-restart-of-any-services-of-kibana/356616 "2024-04-03T06:15:37Z")

</div>

for payment URL index hits are coming after every one min for 2 different urls. i.e for each url we are getting 60 hits per min. we have created sincedb path for index and observed data but we found that data is duplic…

---

## [How to properly prepare and cleanse a search term before sending to Elastic?](https://discuss.elastic.co/t/how-to-properly-prepare-and-cleanse-a-search-term-before-sending-to-elastic/356635)

<div class="topic-metadata">

**Author:** [@vitor-awork](https://discuss.elastic.co/u/vitor-awork)\
**Replies:** 0\
**Last updated:** [April 2, 2024, 7:22pm UTC](https://discuss.elastic.co/t/how-to-properly-prepare-and-cleanse-a-search-term-before-sending-to-elastic/356635 "2024-04-02T19:22:02Z")

</div>

I am using Elasticsearch with C# NEST and my application does some cleansing and preparation when getting a search term in the API. A few scenarios: Removal of special characters, such as " \\ ' ( ) \[ \] { } Escaping ce…

---

## [ES for logs -- field conflict hell 🔥](https://discuss.elastic.co/t/es-for-logs-field-conflict-hell/355849)

<div class="topic-metadata">

**Author:** [@rsk0](https://discuss.elastic.co/u/rsk0)\
**Replies:** 18\
**Last updated:** [April 2, 2024, 5:17pm UTC](https://discuss.elastic.co/t/es-for-logs-field-conflict-hell/355849 "2024-04-02T17:17:23Z")

</div>

In a large enterprise with diverse log sources, if you want to provide the benefits of structured logging you could turn on dynamic mapping. But those diverse sources may not be able to coordinate and share schema, and …

---

## [Faceting after Collapse](https://discuss.elastic.co/t/faceting-after-collapse/356453)

<div class="topic-metadata">

**Author:** [@fvsadem](https://discuss.elastic.co/u/fvsadem)\
**Replies:** 3\
**Last updated:** [April 2, 2024, 4:26pm UTC](https://discuss.elastic.co/t/faceting-after-collapse/356453 "2024-04-02T16:26:13Z")

</div>

Hi, I struggle to migrated from Algolia to Elasticsearch. My problem is facet after distinct option equivalent in Elasticsaerch. I successfuly collapse my index to distinct by an attribute but there is a problem with t…

---

## [How can i increase text field limit on aggregations?](https://discuss.elastic.co/t/how-can-i-increase-text-field-limit-on-aggregations/356552)

<div class="topic-metadata">

**Author:** [@barisbeytur](https://discuss.elastic.co/u/barisbeytur)\
**Replies:** 6\
**Last updated:** [April 2, 2024, 3:13pm UTC](https://discuss.elastic.co/t/how-can-i-increase-text-field-limit-on-aggregations/356552 "2024-04-02T15:13:21Z")

</div>

Hello, I have a SearchGroupedErrorByCriteria method for take data on Elasticsearch and view it on a admin panel table. I'm using Elasticsearch .NET Client. I have a search descriptor: var searchDescriptor = new Search…

---

## [Is there a processor that can group my data correctly?](https://discuss.elastic.co/t/is-there-a-processor-that-can-group-my-data-correctly/356200)

<div class="topic-metadata">

**Author:** [@Nama\_Chintamani\_Illo](https://discuss.elastic.co/u/Nama_Chintamani_Illo)\
**Replies:** 4\
**Last updated:** [April 2, 2024, 2:53pm UTC](https://discuss.elastic.co/t/is-there-a-processor-that-can-group-my-data-correctly/356200 "2024-04-02T14:53:31Z")

</div>

I have tried multiple methods and they all seem to keep the data in an array of the same field instead of the grouping to match. I am attempting to turn this type of grouping: "service": { "name": \[ "value…

---

## [Search by sum of nested objects](https://discuss.elastic.co/t/search-by-sum-of-nested-objects/356621)

<div class="topic-metadata">

**Author:** [@pikorro](https://discuss.elastic.co/u/pikorro)\
**Replies:** 0\
**Last updated:** [April 2, 2024, 2:46pm UTC](https://discuss.elastic.co/t/search-by-sum-of-nested-objects/356621 "2024-04-02T14:46:17Z")

</div>

I have list of docs with following struct: { "name": "John Doe", "work\_experiences": \[ { "company": "Accenture", "duration": 24 }, { "company": "IBM", "duration": 36 } \] } c…

---

## [ECS RFC process questions](https://discuss.elastic.co/t/ecs-rfc-process-questions/356576)

<div class="topic-metadata">

**Author:** [@rsk0](https://discuss.elastic.co/u/rsk0)\
**Replies:** 4\
**Last updated:** [April 2, 2024, 2:11pm UTC](https://discuss.elastic.co/t/ecs-rfc-process-questions/356576 "2024-04-02T14:11:53Z")

</div>

The RFC process includes at least one step that I'm not sure how to participate in, highlighted here: Create a new RFC document from the RFC template (described below) Fill in the details for your strawperson Open a P…

---

## [How to upgrade elasticsearch cluster from 7.9 to 8.13 without data loss](https://discuss.elastic.co/t/how-to-upgrade-elasticsearch-cluster-from-7-9-to-8-13-without-data-loss/356606)

<div class="topic-metadata">

**Author:** [@Krishna\_Sailesh](https://discuss.elastic.co/u/Krishna_Sailesh)\
**Replies:** 3\
**Last updated:** [April 2, 2024, 12:24pm UTC](https://discuss.elastic.co/t/how-to-upgrade-elasticsearch-cluster-from-7-9-to-8-13-without-data-loss/356606 "2024-04-02T12:24:51Z")

</div>

Hi I am running Elasticsearch with a 3-node cluster with 7.9.2 version which contains some huge data. I need to upgrade it to 8.10.3 without the data loss. can someone help me with how to do it? Thanks Krishna

---

## [Elasticsearch Multi-Tier Architecture – Master/Hot/Frozen](https://discuss.elastic.co/t/elasticsearch-multi-tier-architecture-master-hot-frozen/356383)

<div class="topic-metadata">

**Author:** [@bouzeghoub](https://discuss.elastic.co/u/bouzeghoub)\
**Replies:** 18\
**Last updated:** [April 2, 2024, 12:00pm UTC](https://discuss.elastic.co/t/elasticsearch-multi-tier-architecture-master-hot-frozen/356383 "2024-04-02T12:00:58Z")

</div>

Hello, I want deploy Elasticsearch Multi-Tier Architecture – Master/Hot/Frozen on prime. Please could you help me with documents or blog. Best regards.

---

## [Timestamp is no longer transferred correctly](https://discuss.elastic.co/t/timestamp-is-no-longer-transferred-correctly/356608)

<div class="topic-metadata">

**Author:** [@benhartwich](https://discuss.elastic.co/u/benhartwich)\
**Replies:** 3\
**Last updated:** [April 2, 2024, 11:31am UTC](https://discuss.elastic.co/t/timestamp-is-no-longer-transferred-correctly/356608 "2024-04-02T11:31:33Z")

</div>

Hello everyone, I import values from a CSV via Logstash to Elasticsearch, whereby the timestamp is correctly determined from the name of the CSV and then the correct format is also written to Elasticsearch - e.g.: 2024-…

---

## [Merging buckets after top\_hits](https://discuss.elastic.co/t/merging-buckets-after-top-hits/356609)

<div class="topic-metadata">

**Author:** [@Vivek\_Burman](https://discuss.elastic.co/u/Vivek_Burman)\
**Replies:** 0\
**Last updated:** [April 2, 2024, 11:29am UTC](https://discuss.elastic.co/t/merging-buckets-after-top-hits/356609 "2024-04-02T11:29:49Z")

</div>

Hi, I've a use case which I need help with. The mapping is as shown below of an elastic index: { "test\_case":{ "type":"nested", "properties":{ "end\_timestamp":{ "type":"date" …

---

## [I am getting elastic\_transport.node\_pool WARNING when doing elastic search benchmarking using rally](https://discuss.elastic.co/t/i-am-getting-elastic-transport-node-pool-warning-when-doing-elastic-search-benchmarking-using-rally/356607)

<div class="topic-metadata">

**Author:** [@Mukul](https://discuss.elastic.co/u/Mukul)\
**Replies:** 0\
**Last updated:** [April 2, 2024, 11:01am UTC](https://discuss.elastic.co/t/i-am-getting-elastic-transport-node-pool-warning-when-doing-elastic-search-benchmarking-using-rally/356607 "2024-04-02T11:01:39Z")

</div>

I am doing benchmarking on our cluster using rally but data is not getting ingested in index and getting below warnings. 024-03-26 07:31:51,713 -not-actor-/PID:141 elastic\_transport.node\_pool WARNING Node \<RallyAiohttpH…

---

## [Prefix type Search which datatype should choose](https://discuss.elastic.co/t/prefix-type-search-which-datatype-should-choose/356592)

<div class="topic-metadata">

**Author:** [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Replies:** 1\
**Last updated:** [April 2, 2024, 7:34am UTC](https://discuss.elastic.co/t/prefix-type-search-which-datatype-should-choose/356592 "2024-04-02T07:34:32Z")

</div>

Hi Team, For prefix type query search in Elasticsearch which datatype we should choose. It is known that the prefix type search has the capability to support both text and keyword. We need your help in determining the…

---

## [Need help on azure container apps](https://discuss.elastic.co/t/need-help-on-azure-container-apps/356590)

<div class="topic-metadata">

**Author:** [@Clynt\_Neiko\_Rupinta](https://discuss.elastic.co/u/Clynt_Neiko_Rupinta)\
**Replies:** 0\
**Last updated:** [April 2, 2024, 5:59am UTC](https://discuss.elastic.co/t/need-help-on-azure-container-apps/356590 "2024-04-02T05:59:00Z")

</div>

I am a complete beginner in es. Im having trouble deploying it on azure container apps. I have deployed 2 container apps for master and data nodes, i have problem connecting my data nodes to my master node. Master confi…

---

## [Is license required to implement SSO in ELK](https://discuss.elastic.co/t/is-license-required-to-implement-sso-in-elk/356588)

<div class="topic-metadata">

**Author:** [@Manjiri](https://discuss.elastic.co/u/Manjiri)\
**Replies:** 1\
**Last updated:** [April 2, 2024, 5:46am UTC](https://discuss.elastic.co/t/is-license-required-to-implement-sso-in-elk/356588 "2024-04-02T05:46:27Z")

</div>

Hi All, We are implementing the ELK 8.11.1 and we wanted to check with you, wheather license is required to implement SSO?

---

## [Issue with container creation](https://discuss.elastic.co/t/issue-with-container-creation/356587)

<div class="topic-metadata">

**Author:** [@LoganJFisher](https://discuss.elastic.co/u/LoganJFisher)\
**Replies:** 0\
**Last updated:** [April 2, 2024, 5:27am UTC](https://discuss.elastic.co/t/issue-with-container-creation/356587 "2024-04-02T05:27:53Z")

</div>

Synology ARM64 using Container Manager When I try to create a container using the Elasticsearch image on Docker hub, the resulting container crashes and produces the following log message: exec /docker-entrypoint.sh: e…

---

## [Index stuck in yellow unable to assign replica due to translog corruption](https://discuss.elastic.co/t/index-stuck-in-yellow-unable-to-assign-replica-due-to-translog-corruption/356556)

<div class="topic-metadata">

**Author:** [@Dheeraj\_Gupta](https://discuss.elastic.co/u/Dheeraj_Gupta)\
**Replies:** 5\
**Last updated:** [April 2, 2024, 5:15am UTC](https://discuss.elastic.co/t/index-stuck-in-yellow-unable-to-assign-replica-due-to-translog-corruption/356556 "2024-04-02T05:15:42Z")

</div>

Hi, We had some server issues in one node of our elasticsearch cluster (8.12.0). While resolving the issue, another node went down and consequently some indexes went into red. After the original failure was recovered, w…

---

## [How to get traces for service which onboarded through dev tools](https://discuss.elastic.co/t/how-to-get-traces-for-service-which-onboarded-through-dev-tools/356577)

<div class="topic-metadata">

**Author:** [@navya\_k](https://discuss.elastic.co/u/navya_k)\
**Replies:** 0\
**Last updated:** [April 2, 2024, 1:00am UTC](https://discuss.elastic.co/t/how-to-get-traces-for-service-which-onboarded-through-dev-tools/356577 "2024-04-02T01:00:14Z")

</div>

Hello, I have tried below lines to get traces for last 1hr. GET \_search { "filter":{ "query":{ "range":{ "@timestamp":{ "get: " now -1h" } …

---

## [Missing required property 'Hit.index'](https://discuss.elastic.co/t/missing-required-property-hit-index/356564)

<div class="topic-metadata">

**Author:** [@Shai\_Bentin](https://discuss.elastic.co/u/Shai_Bentin)\
**Replies:** 0\
**Last updated:** [April 1, 2024, 3:27pm UTC](https://discuss.elastic.co/t/missing-required-property-hit-index/356564 "2024-04-01T15:27:13Z")

</div>

I've recently upgraded an on-premise Elastic 7.17.19 server to 8.13.0. Since I had problems with the java client I had (especially with digesting) I've decided to also upgrade by java client to 8.13 with jackson 2.17.0. …

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=127)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=129)
