# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=131

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 132

---

## [Unable to send logs to elasticsearch from .Net 8 using serilog when security is enabled](https://discuss.elastic.co/t/unable-to-send-logs-to-elasticsearch-from-net-8-using-serilog-when-security-is-enabled/356263)

<div class="topic-metadata">

**Author:** [@Shahid\_Hussain](https://discuss.elastic.co/u/Shahid_Hussain)\
**Replies:** 2\
**Last updated:** [March 27, 2024, 11:01am UTC](https://discuss.elastic.co/t/unable-to-send-logs-to-elasticsearch-from-net-8-using-serilog-when-security-is-enabled/356263 "2024-03-27T11:01:48Z")

</div>

Hello, I am unable to send logs to elasticsearch 8.12.2 when security is enabled on elasticsearch server. However, when I disable the security I can see the logs on elasticsearch server. Below are the settings from ela…

---

## [Only one document is indexed](https://discuss.elastic.co/t/only-one-document-is-indexed/356254)

<div class="topic-metadata">

**Author:** [@Khaled\_Saidi](https://discuss.elastic.co/u/Khaled_Saidi)\
**Replies:** 0\
**Last updated:** [March 27, 2024, 9:47am UTC](https://discuss.elastic.co/t/only-one-document-is-indexed/356254 "2024-03-27T09:47:56Z")

</div>

My filebeat agent has the monitoring section configured to send logs every 5s, directly to an elasticsearch cluster dedicated only for logs monitoring. However, only one document is indexed at midnight during the rollov…

---

## [Randomly out of memory exception when bulk importing data](https://discuss.elastic.co/t/randomly-out-of-memory-exception-when-bulk-importing-data/355555)

<div class="topic-metadata">

**Author:** [@docwarems](https://discuss.elastic.co/u/docwarems)\
**Replies:** 3\
**Last updated:** [March 27, 2024, 9:47am UTC](https://discuss.elastic.co/t/randomly-out-of-memory-exception-when-bulk-importing-data/355555 "2024-03-27T09:47:11Z")

</div>

Hi, we use the Javascript bulk helper API to bulk import data to ES. Randomly the import process crashes with out of memory exception (OOME). Of course we check for errors from the bulk import but there aren't any. I'm…

---

## [Logstash8.12.2 restart many times may encounter plugin load errors 'cabin/metrics','cabin/log/logger', "logstash::codecs::multiline::grok"](https://discuss.elastic.co/t/logstash8-12-2-restart-many-times-may-encounter-plugin-load-errors-cabin-metrics-cabin-log-logger-logstash-grok/355206)

<div class="topic-metadata">

**Author:** [@LiYuzhuo2020](https://discuss.elastic.co/u/LiYuzhuo2020)\
**Replies:** 15\
**Last updated:** [March 27, 2024, 9:31am UTC](https://discuss.elastic.co/t/logstash8-12-2-restart-many-times-may-encounter-plugin-load-errors-cabin-metrics-cabin-log-logger-logstash-grok/355206 "2024-03-27T09:31:40Z")

</div>

I upgrade the logstash from 7.16.3 to 8.12.2 and it can start up successfully after the configuration file adjustment, but if I restart the logstash service time from times it may encounter above plugin load errors. Can …

---

## [CURL query, search in a bunch of indexes](https://discuss.elastic.co/t/curl-query-search-in-a-bunch-of-indexes/356248)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 0\
**Last updated:** [March 27, 2024, 9:26am UTC](https://discuss.elastic.co/t/curl-query-search-in-a-bunch-of-indexes/356248 "2024-03-27T09:26:55Z")

</div>

Hi Just I'm looking a method for use curl as a search in a bunch of index. If it's possible for search over created data view?

---

## [Elastic doesn't meet my requirements](https://discuss.elastic.co/t/elastic-doesnt-meet-my-requirements/356212)

<div class="topic-metadata">

**Author:** [@deathofangel](https://discuss.elastic.co/u/deathofangel)\
**Replies:** 4\
**Last updated:** [March 27, 2024, 8:22am UTC](https://discuss.elastic.co/t/elastic-doesnt-meet-my-requirements/356212 "2024-03-27T08:22:42Z")

</div>

Hello. I am continuously listening to data from a receiver. It continuously sends the data to a port in json format. I need to parse and save the data I receive from the receiver very quickly. When I write a server for …

---

## [ELSER ingest pipeline with ingest processor](https://discuss.elastic.co/t/elser-ingest-pipeline-with-ingest-processor/356219)

<div class="topic-metadata">

**Author:** [@Abhilash\_B](https://discuss.elastic.co/u/Abhilash_B)\
**Replies:** 0\
**Last updated:** [March 27, 2024, 3:57am UTC](https://discuss.elastic.co/t/elser-ingest-pipeline-with-ingest-processor/356219 "2024-03-27T03:57:33Z")

</div>

I have peculiar situation where I need to create embeddings for each text value of a field within an array of objects. Sample Document: { "areas\_of\_expertise":\[{ "id": 14, "is\_active": true,…

---

## [Query assistance for conditional querying](https://discuss.elastic.co/t/query-assistance-for-conditional-querying/356218)

<div class="topic-metadata">

**Author:** [@Spandana](https://discuss.elastic.co/u/Spandana)\
**Replies:** 1\
**Last updated:** [March 27, 2024, 3:52am UTC](https://discuss.elastic.co/t/query-assistance-for-conditional-querying/356218 "2024-03-27T03:52:22Z")

</div>

I have elastic index with fields styleId, sellingStyleId, styleName, inventoryEnabled, inventoryCount need help with query to pull all the records but if inventoryEnabled is true then check if inventoryCount is greater …

---

## [Java api client example for rollover](https://discuss.elastic.co/t/java-api-client-example-for-rollover/356131)

<div class="topic-metadata">

**Author:** [@linkerc](https://discuss.elastic.co/u/linkerc)\
**Replies:** 3\
**Last updated:** [March 26, 2024, 11:06pm UTC](https://discuss.elastic.co/t/java-api-client-example-for-rollover/356131 "2024-03-26T23:06:34Z")

</div>

Is there a centralized place with examples of how java API clients are being invoked? It seems to be very lacking even after several years deprecating the old REST client. I am trying to figure out how to issue rollove…

---

## [Information about licensing](https://discuss.elastic.co/t/information-about-licensing/356147)

<div class="topic-metadata">

**Author:** [@Yerbolat\_Talasbekov](https://discuss.elastic.co/u/Yerbolat_Talasbekov)\
**Replies:** 5\
**Last updated:** [March 26, 2024, 7:26pm UTC](https://discuss.elastic.co/t/information-about-licensing/356147 "2024-03-26T19:26:03Z")

</div>

Hello everyone! Can someone help me with understanding elasticsearch license, how it works, differencies between licences.

---

## [NEST 7.17 RequestBodyInBytes invalid JSON?](https://discuss.elastic.co/t/nest-7-17-requestbodyinbytes-invalid-json/356181)

<div class="topic-metadata">

**Author:** [@TomRom27](https://discuss.elastic.co/u/TomRom27)\
**Replies:** 0\
**Last updated:** [March 26, 2024, 1:16pm UTC](https://discuss.elastic.co/t/nest-7-17-requestbodyinbytes-invalid-json/356181 "2024-03-26T13:16:37Z")

</div>

Hi, Recently played a bit with diagnostics of queries sent to ES via NEST and noticed that RequestBodyInBytes (when Utf8 decoded) returns invalid JSON - see attachment: last closing bracket (red) should match 2nd openin…

---

## [Kuromoji\_tokenizer: sort clause does not seem to work for some specific character combinations](https://discuss.elastic.co/t/kuromoji-tokenizer-sort-clause-does-not-seem-to-work-for-some-specific-character-combinations/356173)

<div class="topic-metadata">

**Author:** [@Ajay\_Purohit](https://discuss.elastic.co/u/Ajay_Purohit)\
**Replies:** 0\
**Last updated:** [March 26, 2024, 11:40am UTC](https://discuss.elastic.co/t/kuromoji-tokenizer-sort-clause-does-not-seem-to-work-for-some-specific-character-combinations/356173 "2024-03-26T11:40:35Z")

</div>

Query: { "query": { "bool": { } }, "sort": \[ { "attribute.sortable": { "order": "asc" } } \] } Results: "hits": \[ { "\_index": "example\_1", "\_type": "example\_1", …

---

## [Querying elasticsearch during a rolling update](https://discuss.elastic.co/t/querying-elasticsearch-during-a-rolling-update/356152)

<div class="topic-metadata">

**Author:** [@Lucy\_Johnson](https://discuss.elastic.co/u/Lucy_Johnson)\
**Replies:** 0\
**Last updated:** [March 26, 2024, 8:26am UTC](https://discuss.elastic.co/t/querying-elasticsearch-during-a-rolling-update/356152 "2024-03-26T08:26:14Z")

</div>

Hello everyone. I'm not super sure if that's the best place to ask but I'm hoping to get further information from here. My goal is to query my elasticsearch-cluster (v 7.17) with either the deprecated elastic client or …

---

## [Basic license, users, and https](https://discuss.elastic.co/t/basic-license-users-and-https/356163)

<div class="topic-metadata">

**Author:** [@RainTown](https://discuss.elastic.co/u/RainTown)\
**Replies:** 3\
**Last updated:** [March 26, 2024, 10:45am UTC](https://discuss.elastic.co/t/basic-license-users-and-https/356163 "2024-03-26T10:45:25Z")

</div>

hi i have a local (my personal use only) elasticsearch/kibana instance insalled and setup in Jan 2024 on my Mac. All worked fine, until it didn't. My basic license has expired. This was expected. I did not anticpate …

---

## [Enrich Fleet Integration](https://discuss.elastic.co/t/enrich-fleet-integration/355895)

<div class="topic-metadata">

**Author:** [@Eran\_Hadad](https://discuss.elastic.co/u/Eran_Hadad)\
**Replies:** 3\
**Last updated:** [March 26, 2024, 9:46am UTC](https://discuss.elastic.co/t/enrich-fleet-integration/355895 "2024-03-26T09:46:06Z")

</div>

Hi, I'm using Elastic Fleet to integrate with Azure Event Hub and import logs. One of the log fields is a URL. I want to create a new short URL filed that extracts the URL until the first question mark. URL: www.webs…

---

## [Display top 500 based on ltr and remaining top 500 based on initial scores](https://discuss.elastic.co/t/display-top-500-based-on-ltr-and-remaining-top-500-based-on-initial-scores/356141)

<div class="topic-metadata">

**Author:** [@Sri\_Devi\_Gollapudi](https://discuss.elastic.co/u/Sri_Devi_Gollapudi)\
**Replies:** 0\
**Last updated:** [March 26, 2024, 4:33am UTC](https://discuss.elastic.co/t/display-top-500-based-on-ltr-and-remaining-top-500-based-on-initial-scores/356141 "2024-03-26T04:33:12Z")

</div>

I want to use one model to retrieve top 1000 documents and for top 500 documents I want to rescore using ltr model while displaying results I want to display top 500 sorted based on ltr scores and remaining 500 using ini…

---

## [Drop Events while using elastic kubernetes integration to collect logs](https://discuss.elastic.co/t/drop-events-while-using-elastic-kubernetes-integration-to-collect-logs/356083)

<div class="topic-metadata">

**Author:** [@Jobin\_James](https://discuss.elastic.co/u/Jobin_James)\
**Replies:** 3\
**Last updated:** [March 25, 2024, 5:19pm UTC](https://discuss.elastic.co/t/drop-events-while-using-elastic-kubernetes-integration-to-collect-logs/356083 "2024-03-25T17:19:04Z")

</div>

Hello, Elastic search Version: 8.12.2 ECK Operator Version: 2.11.0 I am using elastic Kubernetes integration for pushing logs from the k8s cluster using an elastic agent. I would like to know how can i drop the unwant…

---

## [Master not discovered yet, this node has not previously joined a bootstrapped (v7+) cluster](https://discuss.elastic.co/t/master-not-discovered-yet-this-node-has-not-previously-joined-a-bootstrapped-v7-cluster/356116)

<div class="topic-metadata">

**Author:** [@horra\_hayfa](https://discuss.elastic.co/u/horra_hayfa)\
**Replies:** 0\
**Last updated:** [March 25, 2024, 4:53pm UTC](https://discuss.elastic.co/t/master-not-discovered-yet-this-node-has-not-previously-joined-a-bootstrapped-v7-cluster/356116 "2024-03-25T16:53:22Z")

</div>

hello i'm trying to install elasticsearch7.17.13 in my vmware workstation along with wazuh 4.5 follwing wazuh documentation ""/deployment-options/elastic-stack/distributed-deployment/elasticsearch-cluster/elasticsearch…

---

## [Updating nested in Elasticsearch DSL within DRF?](https://discuss.elastic.co/t/updating-nested-in-elasticsearch-dsl-within-drf/356014)

<div class="topic-metadata">

**Author:** [@Manikandan\_FMJ](https://discuss.elastic.co/u/Manikandan_FMJ)\
**Replies:** 2\
**Last updated:** [March 25, 2024, 4:14pm UTC](https://discuss.elastic.co/t/updating-nested-in-elasticsearch-dsl-within-drf/356014 "2024-03-25T16:14:24Z")

</div>

When updating nested objects in Django Rest Framework (DRF), they might be stored as objects instead of Nested, causing issues during search queries. How can I resolve this issue? View file profile = DetailsDocument.ge…

---

## [Geoip2 ASN resolution in Ingest Pipeline](https://discuss.elastic.co/t/geoip2-asn-resolution-in-ingest-pipeline/356093)

<div class="topic-metadata">

**Author:** [@Patryk\_Ostrowski](https://discuss.elastic.co/u/Patryk_Ostrowski)\
**Replies:** 5\
**Last updated:** [March 25, 2024, 2:41pm UTC](https://discuss.elastic.co/t/geoip2-asn-resolution-in-ingest-pipeline/356093 "2024-03-25T14:41:48Z")

</div>

Hello, I tried to use GeoIP2 plugin to resolve iP to ASN. Unfortunately during log processing I have information in tag: \[netflow, forwarded, \_geoip\_database\_unavailable\_GeoLite2-City.mmdb, \_geoip\_database\_unavailable…

---

## [Query cache is getting evicted though we have enough memory available (8.10 and 8.12 version)](https://discuss.elastic.co/t/query-cache-is-getting-evicted-though-we-have-enough-memory-available-8-10-and-8-12-version/356104)

<div class="topic-metadata">

**Author:** [@Balaji5007](https://discuss.elastic.co/u/Balaji5007)\
**Replies:** 0\
**Last updated:** [March 25, 2024, 2:45pm UTC](https://discuss.elastic.co/t/query-cache-is-getting-evicted-though-we-have-enough-memory-available-8-10-and-8-12-version/356104 "2024-03-25T14:45:37Z")

</div>

Query cache is getting evicted though we have enough memory available. We are seeing this behavior only from version 8.10, we tried upgrading the cluster to 8.12 as well but still the last workable stable version on this…

---

## [GeoIP challenges - Custom-City.mmdb](https://discuss.elastic.co/t/geoip-challenges-custom-city-mmdb/355173)

<div class="topic-metadata">

**Author:** [@SteveB1963](https://discuss.elastic.co/u/SteveB1963)\
**Replies:** 16\
**Last updated:** [March 25, 2024, 2:08pm UTC](https://discuss.elastic.co/t/geoip-challenges-custom-city-mmdb/355173 "2024-03-25T14:08:57Z")

</div>

I am new to the forum, but not new to Elastic Stack. I have been using it for about 7 years. Started with Version 5 and upgraded to 8 over time. Sorry for the long post but felt that some foundation was necessary. Curr…

---

## [Elastic and Fleet without xpack.security](https://discuss.elastic.co/t/elastic-and-fleet-without-xpack-security/355903)

<div class="topic-metadata">

**Author:** [@michal\_XD](https://discuss.elastic.co/u/michal_XD)\
**Replies:** 1\
**Last updated:** [March 25, 2024, 1:49pm UTC](https://discuss.elastic.co/t/elastic-and-fleet-without-xpack-security/355903 "2024-03-25T13:49:29Z")

</div>

Hello !! I need confgiure APM and Fleet on my ELK stakc instance. But I want to d thaht witout this "xpack.security.enabled: true xpack.security.authc.api\_key.enabled: true" We didnt need it on our organization. We …

---

## [Snapshot in local drive](https://discuss.elastic.co/t/snapshot-in-local-drive/356092)

<div class="topic-metadata">

**Author:** [@manikandanid](https://discuss.elastic.co/u/manikandanid)\
**Replies:** 5\
**Last updated:** [March 25, 2024, 12:52pm UTC](https://discuss.elastic.co/t/snapshot-in-local-drive/356092 "2024-03-25T12:52:00Z")

</div>

Can we take snapshot of index on the local drive. All the docs are pointing towards snapshot in cloud providers and no doc for how to snapshot to a local network drive.

---

## [Ignore fields when indexing using JsonData.of](https://discuss.elastic.co/t/ignore-fields-when-indexing-using-jsondata-of/356084)

<div class="topic-metadata">

**Author:** [@ndtreviv](https://discuss.elastic.co/u/ndtreviv)\
**Replies:** 5\
**Last updated:** [March 25, 2024, 12:41pm UTC](https://discuss.elastic.co/t/ignore-fields-when-indexing-using-jsondata-of/356084 "2024-03-25T12:41:57Z")

</div>

I'm using the Java SDK to update a document, like so: UpdateResponse\<Void\> response = elasticsearchService.getClient().update(u -\> u.index(INDEX) .id(id) .doc(JsonData.of(myObject)).refresh(Refresh.True), Void.c…

---

## [Avoid hiting unecessary shards with wildcard dated index](https://discuss.elastic.co/t/avoid-hiting-unecessary-shards-with-wildcard-dated-index/354526)

<div class="topic-metadata">

**Author:** [@voharunado](https://discuss.elastic.co/u/voharunado)\
**Replies:** 2\
**Last updated:** [March 25, 2024, 10:00am UTC](https://discuss.elastic.co/t/avoid-hiting-unecessary-shards-with-wildcard-dated-index/354526 "2024-03-25T10:00:19Z")

</div>

I have multiple indices with a date in the name that stores data for specific days for each months, so I have day-2024.01.01, day-2024.02.01 and so on. The indices are managed by ILM and I always have 2 years of future d…

---

## [Elasticsearch: search relevent query using washbasin and fetch the result for wash basin related result](https://discuss.elastic.co/t/elasticsearch-search-relevent-query-using-washbasin-and-fetch-the-result-for-wash-basin-related-result/356068)

<div class="topic-metadata">

**Author:** [@Mohan\_T](https://discuss.elastic.co/u/Mohan_T)\
**Replies:** 1\
**Last updated:** [March 25, 2024, 8:32am UTC](https://discuss.elastic.co/t/elasticsearch-search-relevent-query-using-washbasin-and-fetch-the-result-for-wash-basin-related-result/356068 "2024-03-25T08:32:33Z")

</div>

search documents have the value of Doc 1 { "s\_title": "washbasin" } Doc 2 { "s\_title": "wash basin" } Doc 3 { "s\_title": "wash and basin" } Doc 4 { "s\_title": "wash basin tap" } Doc 5 { "s\_t…

---

## [ELK PROD Cluster - Running multiple data docker containers on same machine. Docker Swarm](https://discuss.elastic.co/t/elk-prod-cluster-running-multiple-data-docker-containers-on-same-machine-docker-swarm/356074)

<div class="topic-metadata">

**Author:** [@vdcharter](https://discuss.elastic.co/u/vdcharter)\
**Replies:** 0\
**Last updated:** [March 25, 2024, 5:55am UTC](https://discuss.elastic.co/t/elk-prod-cluster-running-multiple-data-docker-containers-on-same-machine-docker-swarm/356074 "2024-03-25T05:55:19Z")

</div>

Hi, I have a 16 server PROD cluster with 3 VM's and 13 Baremetal servers. These are very high performance servers with below configurations 3 VM's with each having -- 8x vCPU, 48GB RAM, ~900GB Storage (ES Masters) 13 …

---

## [Elasticsearch Indexing Performance Degradation](https://discuss.elastic.co/t/elasticsearch-indexing-performance-degradation/356035)

<div class="topic-metadata">

**Author:** [@joeroot](https://discuss.elastic.co/u/joeroot)\
**Replies:** 5\
**Last updated:** [March 25, 2024, 5:42am UTC](https://discuss.elastic.co/t/elasticsearch-indexing-performance-degradation/356035 "2024-03-25T05:42:16Z")

</div>

I've been encountering some performance degradation issues with indexing in my Elasticsearch cluster and I'm seeking advice on how to troubleshoot and resolve this issue. Scenario: I have a moderately sized Elasticsear…

---

## [How to make our deployment URLs private only for our organization?](https://discuss.elastic.co/t/how-to-make-our-deployment-urls-private-only-for-our-organization/355220)

<div class="topic-metadata">

**Author:** [@surya\_dadi\_dhamarake](https://discuss.elastic.co/u/surya_dadi_dhamarake)\
**Replies:** 4\
**Last updated:** [March 25, 2024, 3:34am UTC](https://discuss.elastic.co/t/how-to-make-our-deployment-urls-private-only-for-our-organization/355220 "2024-03-25T03:34:49Z")

</div>

Hi Team, Currently our deployments are publicly accessible but I want to make it private only for our organization. Can you please tell me the procedure to do this activity? Thanks, Surya

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=130)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=132)
