# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=130

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 131

---

## ["File corruption occurred on recovery but checksums are ok"](https://discuss.elastic.co/t/file-corruption-occurred-on-recovery-but-checksums-are-ok/356341)

<div class="topic-metadata">

**Author:** [@CWS-Dan](https://discuss.elastic.co/u/CWS-Dan)\
**Replies:** 6\
**Last updated:** [March 28, 2024, 11:26pm UTC](https://discuss.elastic.co/t/file-corruption-occurred-on-recovery-but-checksums-are-ok/356341 "2024-03-28T23:26:51Z")

</div>

I'm running Elasticsearch 7.14.0. I have a cluster with 3 nodes: CWS-CWHELP, CWS-CWHELP2, and CWS-CWHELP3. 1 and 3 are fine, but 2 is having problems I cannot explain. When it runs, and the cluster tries to allocate shar…

---

## [How to divide sarchs to get percentage metric](https://discuss.elastic.co/t/how-to-divide-sarchs-to-get-percentage-metric/356430)

<div class="topic-metadata">

**Author:** [@MR98](https://discuss.elastic.co/u/MR98)\
**Replies:** 0\
**Last updated:** [March 28, 2024, 10:40pm UTC](https://discuss.elastic.co/t/how-to-divide-sarchs-to-get-percentage-metric/356430 "2024-03-28T22:40:12Z")

</div>

I created two searchs: Search 1 - TEXT.X\* and Search 2 - TEXT.Y\* How should I combine agregations in metric or create new search to get something like math operation (TEXT.X\* / TEXT.Y\*)\*100: I saved new search: TEX…

---

## [How to combine multiple conditional query in one query](https://discuss.elastic.co/t/how-to-combine-multiple-conditional-query-in-one-query/354033)

<div class="topic-metadata">

**Author:** [@amrswalha](https://discuss.elastic.co/u/amrswalha)\
**Replies:** 7\
**Last updated:** [March 28, 2024, 7:12pm UTC](https://discuss.elastic.co/t/how-to-combine-multiple-conditional-query-in-one-query/354033 "2024-03-28T19:12:38Z")

</div>

Hello, I'm new to using Elasticsearch. I'm using the .NET client version 8.12, I'm trying to send a query based on parameters. Only add the condition if the parameter value exists. Below is the code for the query: publi…

---

## [Elasticsearch queue issue after upgrading from 8.6.2 to 8.12.1/8.12.2](https://discuss.elastic.co/t/elasticsearch-queue-issue-after-upgrading-from-8-6-2-to-8-12-1-8-12-2/355052)

<div class="topic-metadata">

**Author:** [@elastic\_dude](https://discuss.elastic.co/u/elastic_dude)\
**Replies:** 35\
**Last updated:** [March 28, 2024, 6:51pm UTC](https://discuss.elastic.co/t/elasticsearch-queue-issue-after-upgrading-from-8-6-2-to-8-12-1-8-12-2/355052 "2024-03-28T18:51:03Z")

</div>

We have been running on Elasticsearch 8.6.2 for several months now with very few issues other than some query (un)optimizations. We have several clusters duplicated in two regions + two non-prod environments with several…

---

## [PutLifecycleRequest with new Java client](https://discuss.elastic.co/t/putlifecyclerequest-with-new-java-client/356402)

<div class="topic-metadata">

**Author:** [@avnere](https://discuss.elastic.co/u/avnere)\
**Replies:** 3\
**Last updated:** [March 28, 2024, 3:27pm UTC](https://discuss.elastic.co/t/putlifecyclerequest-with-new-java-client/356402 "2024-03-28T15:27:44Z")

</div>

Hi, What is the approach for creating Lifecycle Policy with new Java client. Policy of rollover after 10gb maxShardSize and delete after 5d. Thanks...

---

## [Query with track\_total\_hits:true faster than track\_total\_hits:false](https://discuss.elastic.co/t/query-with-track-total-hits-true-faster-than-track-total-hits-false/356291)

<div class="topic-metadata">

**Author:** [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Replies:** 6\
**Last updated:** [March 28, 2024, 3:09pm UTC](https://discuss.elastic.co/t/query-with-track-total-hits-true-faster-than-track-total-hits-false/356291 "2024-03-28T15:09:25Z")

</div>

Hey, I have a query that is actually twice as fast when tracking total hits (setting track\_total\_hits: true or adding an aggregation), than as running it with track\_total\_hits:false - which is contradictory to the idea …

---

## [Debug indexing time](https://discuss.elastic.co/t/debug-indexing-time/356334)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 2\
**Last updated:** [March 28, 2024, 11:08am UTC](https://discuss.elastic.co/t/debug-indexing-time/356334 "2024-03-28T11:08:26Z")

</div>

Hi I need to know how I can debug the case when elastic is not responding during indexing time. But index.indexing.slowlog.threshold.index. it's not enough I don't see any overload on cluster where elastic was install…

---

## [Installed elasticsearch forgot systemd!](https://discuss.elastic.co/t/installed-elasticsearch-forgot-systemd/356384)

<div class="topic-metadata">

**Author:** [@stobbe](https://discuss.elastic.co/u/stobbe)\
**Replies:** 1\
**Last updated:** [March 28, 2024, 10:46am UTC](https://discuss.elastic.co/t/installed-elasticsearch-forgot-systemd/356384 "2024-03-28T10:46:12Z")

</div>

Hello, After installing elasticsearch, I would like to be able to add systemd e.g. Wat are the steps to make elasticsearch use systemctl commands for starting and stopping? KR Henk

---

## [org.elasticsearch.common.util.concurrent.TimedRunnable@62542b52 on queueresizingESThreadPoolExecutor](https://discuss.elastic.co/t/org-elasticsearch-common-util-concurrent-timedrunnable-62542b52-on-queueresizingesthreadpoolexecutor/356387)

<div class="topic-metadata">

**Author:** [@LAKSHAY\_ARORA1](https://discuss.elastic.co/u/LAKSHAY_ARORA1)\
**Replies:** 0\
**Last updated:** [March 28, 2024, 10:42am UTC](https://discuss.elastic.co/t/org-elasticsearch-common-util-concurrent-timedrunnable-62542b52-on-queueresizingesthreadpoolexecutor/356387 "2024-03-28T10:42:23Z")

</div>

I am getting an error on my elasticsearch production cluster. I understand it is related to a thread pool which is getting out of memory or is not able to process huge amount of requests at a time. Can anyone explai…

---

## [Error: elastic agent error failed to publish events: temporary bulk send failure](https://discuss.elastic.co/t/error-elastic-agent-error-failed-to-publish-events-temporary-bulk-send-failure/356368)

<div class="topic-metadata">

**Author:** [@hasan.idriss](https://discuss.elastic.co/u/hasan.idriss)\
**Replies:** 4\
**Last updated:** [March 28, 2024, 10:05am UTC](https://discuss.elastic.co/t/error-elastic-agent-error-failed-to-publish-events-temporary-bulk-send-failure/356368 "2024-03-28T10:05:48Z")

</div>

hello I have a cluster of 3 ES nodes version 8.7.1 I am managing the agents using the fleet I had installed Elasticagent on a Windows VM to ingest the fortigate logs and it was successfully until one day logs ingesti…

---

## [Problem in match query](https://discuss.elastic.co/t/problem-in-match-query/356371)

<div class="topic-metadata">

**Author:** [@Paul\_Deveaux](https://discuss.elastic.co/u/Paul_Deveaux)\
**Replies:** 1\
**Last updated:** [March 28, 2024, 9:50am UTC](https://discuss.elastic.co/t/problem-in-match-query/356371 "2024-03-28T09:50:42Z")

</div>

Hello, I am a beginner in Elasticsearch. I'm encountering an issue with searching with specific words within a text field in my Elasticsearch index. Currently, I'm attempting to search for certain words within the fiel…

---

## [Certificate has expired](https://discuss.elastic.co/t/certificate-has-expired/356370)

<div class="topic-metadata">

**Author:** [@cyberzlo](https://discuss.elastic.co/u/cyberzlo)\
**Replies:** 0\
**Last updated:** [March 28, 2024, 8:56am UTC](https://discuss.elastic.co/t/certificate-has-expired/356370 "2024-03-28T08:56:17Z")

</div>

Hi, I hit error from logstash that was unable to connect to ES: Unable to retrieve version information from Elasticsearch nodes. certificate has expired My clusters are installed from Debian packages. Please give me mo…

---

## [Is it any Elasticsearch storage optimization applicable?](https://discuss.elastic.co/t/is-it-any-elasticsearch-storage-optimization-applicable/356362)

<div class="topic-metadata">

**Author:** [@merson](https://discuss.elastic.co/u/merson)\
**Replies:** 7\
**Last updated:** [March 28, 2024, 8:39am UTC](https://discuss.elastic.co/t/is-it-any-elasticsearch-storage-optimization-applicable/356362 "2024-03-28T08:39:24Z")

</div>

Hi Team, For my issues is per 15mins 24000hits happen in my elasticsearch so it easily filled the storage so, Is there any alternate way to optimize or compress tha data and storage in ELK?

---

## [Update by Query in the Background](https://discuss.elastic.co/t/update-by-query-in-the-background/356342)

<div class="topic-metadata">

**Author:** [@xef](https://discuss.elastic.co/u/xef)\
**Replies:** 1\
**Last updated:** [March 28, 2024, 3:26am UTC](https://discuss.elastic.co/t/update-by-query-in-the-background/356342 "2024-03-28T03:26:01Z")

</div>

Is there any possiblity/features that we can use in Elasticsearch to run an update by query on millions of records but in a background process so that it does not affect the normal search and query performance.

---

## [\[v 7.17\] Component Template Alias not working](https://discuss.elastic.co/t/v-7-17-component-template-alias-not-working/356331)

<div class="topic-metadata">

**Author:** [@parosio](https://discuss.elastic.co/u/parosio)\
**Replies:** 0\
**Last updated:** [March 27, 2024, 7:46pm UTC](https://discuss.elastic.co/t/v-7-17-component-template-alias-not-working/356331 "2024-03-27T19:46:35Z")

</div>

Hello, I needed to update a legacy template to add an alias, but the operation fails (legacy template are deprecated). I created a set of components to replicate the existing template then included them in a new in…

---

## [My watcher runs twice](https://discuss.elastic.co/t/my-watcher-runs-twice/355612)

<div class="topic-metadata">

**Author:** [@Khaled\_Saidi](https://discuss.elastic.co/u/Khaled_Saidi)\
**Replies:** 3\
**Last updated:** [March 27, 2024, 6:03pm UTC](https://discuss.elastic.co/t/my-watcher-runs-twice/355612 "2024-03-27T18:03:18Z")

</div>

Hi everyone, i'm trying to figure out what happens with my watcher. since i upgrade my elasticsearch cluster from 7.x to 8.8.2, its runs twice. First time with a success result, the second time error state with this exc…

---

## [Sorting Get Aliases with new Java client](https://discuss.elastic.co/t/sorting-get-aliases-with-new-java-client/356302)

<div class="topic-metadata">

**Author:** [@avnere](https://discuss.elastic.co/u/avnere)\
**Replies:** 0\
**Last updated:** [March 27, 2024, 3:18pm UTC](https://discuss.elastic.co/t/sorting-get-aliases-with-new-java-client/356302 "2024-03-27T15:18:05Z")

</div>

Hi, I am looking way to execute cat in the new Java client GET \_cat/aliases/bbb\*/?format=json&s=is\_write\_index:desc I found this way: AliasesRequest request = AliasesRequest.of(ar -\> ar.name(pattern)); var re…

---

## [Add componentTemplate with mapping with new Java client](https://discuss.elastic.co/t/add-componenttemplate-with-mapping-with-new-java-client/356252)

<div class="topic-metadata">

**Author:** [@avnere](https://discuss.elastic.co/u/avnere)\
**Replies:** 7\
**Last updated:** [March 27, 2024, 4:25pm UTC](https://discuss.elastic.co/t/add-componenttemplate-with-mapping-with-new-java-client/356252 "2024-03-27T16:25:37Z")

</div>

Hi, I have started using new Java client. I want to add new componentTemplate with mapping. What is the approach with the new client? This was the approach on 7.17: java-rest-high-put-index-template-v2.html

---

## [ElasticClient unable to connect to Elasticsearch server running on k8s](https://discuss.elastic.co/t/elasticclient-unable-to-connect-to-elasticsearch-server-running-on-k8s/356283)

<div class="topic-metadata">

**Author:** [@roamik](https://discuss.elastic.co/u/roamik)\
**Replies:** 1\
**Last updated:** [March 27, 2024, 4:21pm UTC](https://discuss.elastic.co/t/elasticclient-unable-to-connect-to-elasticsearch-server-running-on-k8s/356283 "2024-03-27T16:21:54Z")

</div>

Hi I have deployed Elasticsearch locally to Docker Desktop Kubernetes as following: install operator: kubectl create -f {linktoEck}/eck/2.11.1/crds.yaml kubectl apply -f {linktoEck}/eck/2.11.1/operator.yaml then I d…

---

## [Best Way to Ensure Elasticsearch Optimal Performance](https://discuss.elastic.co/t/best-way-to-ensure-elasticsearch-optimal-performance/356290)

<div class="topic-metadata">

**Author:** [@mibeyki](https://discuss.elastic.co/u/mibeyki)\
**Replies:** 3\
**Last updated:** [March 27, 2024, 2:56pm UTC](https://discuss.elastic.co/t/best-way-to-ensure-elasticsearch-optimal-performance/356290 "2024-03-27T14:56:34Z")

</div>

Hello, I am writing to seek guidance on how to ensure optimal performance of Elasticsearch cluster. I am running a three node ES cluster with huge resources (16vCPUs, 128GB RAM, 10 TB Disk) on each node. However, i am…

---

## [Issues with elastic 8.x yum repository](https://discuss.elastic.co/t/issues-with-elastic-8-x-yum-repository/356184)

<div class="topic-metadata">

**Author:** [@kunalyadav](https://discuss.elastic.co/u/kunalyadav)\
**Replies:** 6\
**Last updated:** [March 27, 2024, 2:39pm UTC](https://discuss.elastic.co/t/issues-with-elastic-8-x-yum-repository/356184 "2024-03-27T14:39:56Z")

</div>

Hi, we've been experiencing issues with the elastic 8.x yum repository since this morning (UTC). The yum update command is failing with the following error $ sudo yum -y update-minimal --security --skip-broken Loaded p…

---

## [Fuzzy query using Levenshtein distance in Simple\_query\_string doesn't work on Chinese/Japanese words](https://discuss.elastic.co/t/fuzzy-query-using-levenshtein-distance-in-simple-query-string-doesnt-work-on-chinese-japanese-words/356296)

<div class="topic-metadata">

**Author:** [@sudo](https://discuss.elastic.co/u/sudo)\
**Replies:** 0\
**Last updated:** [March 27, 2024, 2:32pm UTC](https://discuss.elastic.co/t/fuzzy-query-using-levenshtein-distance-in-simple-query-string-doesnt-work-on-chinese-japanese-words/356296 "2024-03-27T14:32:43Z")

</div>

I have been using simple\_query\_string and it works well with english words/chars: { "simple\_query\_string": { "default\_operator": "OR", "analyze\_wildcard": true, "fields": \[ "d.c.a…

---

## [SSL issues with the Docker setup](https://discuss.elastic.co/t/ssl-issues-with-the-docker-setup/356156)

<div class="topic-metadata">

**Author:** [@Sensanaty](https://discuss.elastic.co/u/Sensanaty)\
**Replies:** 6\
**Last updated:** [March 27, 2024, 1:41pm UTC](https://discuss.elastic.co/t/ssl-issues-with-the-docker-setup/356156 "2024-03-27T13:41:03Z")

</div>

I'm on: MacOS 14.2.1 (Sonoma on an M1 Macbook Pro) OpenSSL 3.2.1 Docker Desktop has 8GB of RAM allocated to it I'm following this guide to setup Elasticsearch + Kibana locally for development purposes, but am encounte…

---

## [Query Assistance Needed](https://discuss.elastic.co/t/query-assistance-needed/356198)

<div class="topic-metadata">

**Author:** [@dawiro](https://discuss.elastic.co/u/dawiro)\
**Replies:** 3\
**Last updated:** [March 27, 2024, 1:32pm UTC](https://discuss.elastic.co/t/query-assistance-needed/356198 "2024-03-27T13:32:49Z")

</div>

Hi, I have a need to search our log indices to: find documents containing fields with names prefixed with a specific string return those fields return the field "application.name", which is a standard field How might…

---

## [Best way to remove docs from index](https://discuss.elastic.co/t/best-way-to-remove-docs-from-index/356271)

<div class="topic-metadata">

**Author:** [@Khaled\_Saidi](https://discuss.elastic.co/u/Khaled_Saidi)\
**Replies:** 1\
**Last updated:** [March 27, 2024, 12:59pm UTC](https://discuss.elastic.co/t/best-way-to-remove-docs-from-index/356271 "2024-03-27T12:59:50Z")

</div>

Hi everyone, I want to clean an index and remove some docs related to a specific filter. Notice that this index is used by several logstash pipelines... I have about 5639694 docs to remove, and a total docs count abou…

---

## [DATA\_FROZEN](https://discuss.elastic.co/t/data-frozen/356280)

<div class="topic-metadata">

**Author:** [@bouzeghoub](https://discuss.elastic.co/u/bouzeghoub)\
**Replies:** 0\
**Last updated:** [March 27, 2024, 12:18pm UTC](https://discuss.elastic.co/t/data-frozen/356280 "2024-03-27T12:18:36Z")

</div>

Hello, When I put node.roles: \[ data\_frozen \] on /etc/elasticsearch/elasticsearch.yml file I can't start service elasticsearch Elasticsearch v 8 Thank you

---

## [Failed to process cluster event (put-lifecycle-fb\_test) within 30s](https://discuss.elastic.co/t/failed-to-process-cluster-event-put-lifecycle-fb-test-within-30s/356180)

<div class="topic-metadata">

**Author:** [@tegerei](https://discuss.elastic.co/u/tegerei)\
**Replies:** 5\
**Last updated:** [March 27, 2024, 12:11pm UTC](https://discuss.elastic.co/t/failed-to-process-cluster-event-put-lifecycle-fb-test-within-30s/356180 "2024-03-27T12:11:14Z")

</div>

I am running a 3 node cluster for Elasticsearch. I get the error below when I try to create an ILM policy org.elasticsearch.transport.RemoteTransportException: \[es3\]\[192.168.10.52:9300\]\[cluster:admin/ilm/put\] Caused by:…

---

## [Unable to establish the connection between two clusters](https://discuss.elastic.co/t/unable-to-establish-the-connection-between-two-clusters/354499)

<div class="topic-metadata">

**Author:** [@Subrahmanyam\_Veerank](https://discuss.elastic.co/u/Subrahmanyam_Veerank)\
**Replies:** 14\
**Last updated:** [March 27, 2024, 12:06pm UTC](https://discuss.elastic.co/t/unable-to-establish-the-connection-between-two-clusters/354499 "2024-03-27T12:06:51Z")

</div>

Hi sir, im trying to establish the connection between the two clusters (local and remote) and i have used the same CA of local cluster to generate the certificates of the remote cluster node. In kibana remote clusters, …

---

## [Slow queries - is ES waiting for resources?](https://discuss.elastic.co/t/slow-queries-is-es-waiting-for-resources/356273)

<div class="topic-metadata">

**Author:** [@pgala](https://discuss.elastic.co/u/pgala)\
**Replies:** 3\
**Last updated:** [March 27, 2024, 11:56am UTC](https://discuss.elastic.co/t/slow-queries-is-es-waiting-for-resources/356273 "2024-03-27T11:56:28Z")

</div>

Hello, I run the simple query with one term filter. During the heavy indexing into ES, the search took: for 40 shards - 0.2s for 80 shards - \>10s My elastic setup: Elastic 8.5 Node: 5 x 16vCPU, 64GB 5 data nodes …

---

## [Elastic SQL - exclude documents based on nested objects](https://discuss.elastic.co/t/elastic-sql-exclude-documents-based-on-nested-objects/356272)

<div class="topic-metadata">

**Author:** [@elichai](https://discuss.elastic.co/u/elichai)\
**Replies:** 0\
**Last updated:** [March 27, 2024, 11:19am UTC](https://discuss.elastic.co/t/elastic-sql-exclude-documents-based-on-nested-objects/356272 "2024-03-27T11:19:42Z")

</div>

Hi, I need to filter out documents that meet a condition in one of its nested objects. For example, if there is at least one nested object that has a code of 708 the document should not match. However, when I specify "A…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=129)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=131)
