# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=133

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 134

---

## [Encountering an Issue with Newly Created Index File in Elastic Search](https://discuss.elastic.co/t/encountering-an-issue-with-newly-created-index-file-in-elastic-search/355648)

<div class="topic-metadata">

**Author:** [@Dinesh\_Raj](https://discuss.elastic.co/u/Dinesh_Raj)\
**Replies:** 13\
**Last updated:** [March 21, 2024, 6:15pm UTC](https://discuss.elastic.co/t/encountering-an-issue-with-newly-created-index-file-in-elastic-search/355648 "2024-03-21T18:15:05Z")

</div>

When reading the text data from a PDF document and saving it into the content field of an Elasticsearch document, I encountered an issue where the first saved index file did not return results when searched. However, cre…

---

## [Java Client Library - ELSER](https://discuss.elastic.co/t/java-client-library-elser/355905)

<div class="topic-metadata">

**Author:** [@sivagurlinka](https://discuss.elastic.co/u/sivagurlinka)\
**Replies:** 1\
**Last updated:** [March 21, 2024, 2:57pm UTC](https://discuss.elastic.co/t/java-client-library-elser/355905 "2024-03-21T14:57:10Z")

</div>

We are trying to leverage ELSER search functionalities within our Java application. we would like to know How to use Java client library for performing ELSER Search ? RestHighLevelClient seems to be one solution we obse…

---

## [ElasticSearch Version Upgrade and OS migration](https://discuss.elastic.co/t/elasticsearch-version-upgrade-and-os-migration/355820)

<div class="topic-metadata">

**Author:** [@mukularora89](https://discuss.elastic.co/u/mukularora89)\
**Replies:** 4\
**Last updated:** [March 21, 2024, 2:56pm UTC](https://discuss.elastic.co/t/elasticsearch-version-upgrade-and-os-migration/355820 "2024-03-21T14:56:28Z")

</div>

Hi, We have a requirement where we need to upgrade OS and for Elasticsearch to run properly on new OS we need to upgrade ES version too. Here we have two options Option 1 - Upgrade Elasticsearch version on all nodes…

---

## [Aggregate by multiple fields of object in array](https://discuss.elastic.co/t/aggregate-by-multiple-fields-of-object-in-array/355830)

<div class="topic-metadata">

**Author:** [@Kaustav\_Shouvik](https://discuss.elastic.co/u/Kaustav_Shouvik)\
**Replies:** 3\
**Last updated:** [March 21, 2024, 12:01pm UTC](https://discuss.elastic.co/t/aggregate-by-multiple-fields-of-object-in-array/355830 "2024-03-21T12:01:37Z")

</div>

My data looks like this - \[ { "orderId": "1", "items": \[ {"id": "1", "name": "Item1"}, {"id": "2", "name": "Item2"} \] }, { "orderId": "2", "items": \[ {"id": "1", "name": "Item…

---

## [ILM shrink prevent write on the shrinked index](https://discuss.elastic.co/t/ilm-shrink-prevent-write-on-the-shrinked-index/354848)

<div class="topic-metadata">

**Author:** [@voharunado](https://discuss.elastic.co/u/voharunado)\
**Replies:** 1\
**Last updated:** [March 13, 2024, 3:18pm UTC](https://discuss.elastic.co/t/ilm-shrink-prevent-write-on-the-shrinked-index/354848 "2024-03-13T15:18:01Z")

</div>

I noticed that the Shrink ILM operation makes the source & target index read only, which make sense because that's a requirement for a shrink even if done manually. The issue is that my shrinked index remains read only a…

---

## [Upgrading Kibana 7.17.6 to 8.12.2 and not logs Index](https://discuss.elastic.co/t/upgrading-kibana-7-17-6-to-8-12-2-and-not-logs-index/355593)

<div class="topic-metadata">

**Author:** [@michael8](https://discuss.elastic.co/u/michael8)\
**Replies:** 6\
**Last updated:** [March 21, 2024, 8:12am UTC](https://discuss.elastic.co/t/upgrading-kibana-7-17-6-to-8-12-2-and-not-logs-index/355593 "2024-03-21T08:12:57Z")

</div>

After upgrading Kibana 7.17.6 to 8.12.2, Kibana does not logs. Why? There were no problems before the migration. The indexes were downloading.

---

## [Fleet Server Output Setting](https://discuss.elastic.co/t/fleet-server-output-setting/355859)

<div class="topic-metadata">

**Author:** [@Nau79](https://discuss.elastic.co/u/Nau79)\
**Replies:** 0\
**Last updated:** [March 20, 2024, 11:26pm UTC](https://discuss.elastic.co/t/fleet-server-output-setting/355859 "2024-03-20T23:26:50Z")

</div>

Hi There, I am running a elsticsearch cluster with 3 Master Nodes, 3 Data Nodes and 1 Ingest Node. I am setting up the fleet server and I need to add the elasticsearch nodes in the Output section. My question is do I…

---

## [ElasticSearch Match Phrase Query Not returning expected results](https://discuss.elastic.co/t/elasticsearch-match-phrase-query-not-returning-expected-results/355664)

<div class="topic-metadata">

**Author:** [@abhijain](https://discuss.elastic.co/u/abhijain)\
**Replies:** 5\
**Last updated:** [March 20, 2024, 11:11pm UTC](https://discuss.elastic.co/t/elasticsearch-match-phrase-query-not-returning-expected-results/355664 "2024-03-20T23:11:48Z")

</div>

I have a document with field: "title1" as: "A380 Familiarization". When I run this query: the search results are empty. The document is not returned as part of the search query results. GET index/\_search { "from": …

---

## [Shard Optimization - Size vs. Count](https://discuss.elastic.co/t/shard-optimization-size-vs-count/355822)

<div class="topic-metadata">

**Author:** [@algo](https://discuss.elastic.co/u/algo)\
**Replies:** 12\
**Last updated:** [March 20, 2024, 7:22pm UTC](https://discuss.elastic.co/t/shard-optimization-size-vs-count/355822 "2024-03-20T19:22:01Z")

</div>

Hi, We are looking to optimize the search rate and snapshot rate for two of our large indices. While we are exploring hardware improvements (I know the recommendation is to use locally attached SSDs), I am hoping to dis…

---

## [Proper way to restart elasticsearch in a cluster](https://discuss.elastic.co/t/proper-way-to-restart-elasticsearch-in-a-cluster/355794)

<div class="topic-metadata">

**Author:** [@tegerei](https://discuss.elastic.co/u/tegerei)\
**Replies:** 4\
**Last updated:** [March 20, 2024, 7:17pm UTC](https://discuss.elastic.co/t/proper-way-to-restart-elasticsearch-in-a-cluster/355794 "2024-03-20T19:17:00Z")

</div>

Hello, I have a 3 node ES cluster. Sometimes I do restarts on some or all of the nodes. Despite disabling shard allocation as explained here, I still get failed shards after the restart is complete and shard re-allocati…

---

## [How to send F5 telemetray data to Elesctic Cloud](https://discuss.elastic.co/t/how-to-send-f5-telemetray-data-to-elesctic-cloud/355828)

<div class="topic-metadata">

**Author:** [@ZAN\_YOUSEF](https://discuss.elastic.co/u/ZAN_YOUSEF)\
**Replies:** 2\
**Last updated:** [March 20, 2024, 6:28pm UTC](https://discuss.elastic.co/t/how-to-send-f5-telemetray-data-to-elesctic-cloud/355828 "2024-03-20T18:28:23Z")

</div>

Hello Elastic Gurus, I am trying to send F5 telemetry data to Elsaticcloud. The documents even at Elsaticcloud only points to have a JSON file which points to a HOST via http. In my case there is no host since I am usi…

---

## [Performance impact of "named-queries"](https://discuss.elastic.co/t/performance-impact-of-named-queries/355836)

<div class="topic-metadata">

**Author:** [@alliswell](https://discuss.elastic.co/u/alliswell)\
**Replies:** 0\
**Last updated:** [March 20, 2024, 5:19pm UTC](https://discuss.elastic.co/t/performance-impact-of-named-queries/355836 "2024-03-20T17:19:04Z")

</div>

Hi Folks, I was going through the documentation of named-queries. In the document, it mentions the following: This functionality reruns each named query on every hit in a search response. Typically, this adds a small …

---

## [When indices only exist on remote cluster: datafeed \[xxxx\] cannot retrieve data because no index matches datafeed's indices](https://discuss.elastic.co/t/when-indices-only-exist-on-remote-cluster-datafeed-xxxx-cannot-retrieve-data-because-no-index-matches-datafeeds-indices/355718)

<div class="topic-metadata">

**Author:** [@sparrowt](https://discuss.elastic.co/u/sparrowt)\
**Replies:** 1\
**Last updated:** [March 20, 2024, 4:12pm UTC](https://discuss.elastic.co/t/when-indices-only-exist-on-remote-cluster-datafeed-xxxx-cannot-retrieve-data-because-no-index-matches-datafeeds-indices/355718 "2024-03-20T16:12:15Z")

</div>

I am getting the following error when trying to start the datafeed of an ML Anomaly Detection Job: mydatafeed failed to start datafeed \[mydatafeed\] cannot retrieve data because no index matches datafeed's indices \[foo.…

---

## [Need advice on building a new production ELK cluster](https://discuss.elastic.co/t/need-advice-on-building-a-new-production-elk-cluster/354344)

<div class="topic-metadata">

**Author:** [@anon85145925](https://discuss.elastic.co/u/anon85145925)\
**Replies:** 1\
**Last updated:** [February 28, 2024, 2:20pm UTC](https://discuss.elastic.co/t/need-advice-on-building-a-new-production-elk-cluster/354344 "2024-02-28T14:20:49Z")

</div>

Hello, We are in the process of building a new ELK cluster, we are looking to incorporate HA and data resiliency in a DR setup (across 2 sites). We will be using a SAN in each of our 2 sites and will be looking to be i…

---

## [Getting error "The requested resource could not be found" while trying to access /api/v1/stack/versions](https://discuss.elastic.co/t/getting-error-the-requested-resource-could-not-be-found-while-trying-to-access-api-v1-stack-versions/355415)

<div class="topic-metadata">

**Author:** [@shreyaa](https://discuss.elastic.co/u/shreyaa)\
**Replies:** 3\
**Last updated:** [March 20, 2024, 2:19pm UTC](https://discuss.elastic.co/t/getting-error-the-requested-resource-could-not-be-found-while-trying-to-access-api-v1-stack-versions/355415 "2024-03-20T14:19:39Z")

</div>

I am trying to fetch the available Elastic Stack versions through the Elasticsearch Service API using the url "https://api.elastic-cloud.com/api/v1/stack/versions" but I am getting the error as "The requested resource co…

---

## [User\_agent.version gets mapped as date](https://discuss.elastic.co/t/user-agent-version-gets-mapped-as-date/355721)

<div class="topic-metadata">

**Author:** [@apaulo](https://discuss.elastic.co/u/apaulo)\
**Replies:** 4\
**Last updated:** [March 20, 2024, 12:14pm UTC](https://discuss.elastic.co/t/user-agent-version-gets-mapped-as-date/355721 "2024-03-20T12:14:19Z")

</div>

Hi, I keep running into this error when I try to index documents and use user\_agent to parse a field that includes user agent information: { "type": "mapper\_parsing\_exception", "reason": "failed to parse field \[con…

---

## [Search query not fethcing all the results](https://discuss.elastic.co/t/search-query-not-fethcing-all-the-results/355790)

<div class="topic-metadata">

**Author:** [@Mohan\_T](https://discuss.elastic.co/u/Mohan_T)\
**Replies:** 7\
**Last updated:** [March 20, 2024, 11:25am UTC](https://discuss.elastic.co/t/search-query-not-fethcing-all-the-results/355790 "2024-03-20T11:25:34Z")

</div>

If am searching for italian marble flooring need to search for a combination of the below with the priority 1. italian marble flooring 2. italian marble 3. marble flooring 4. italian flooring 5. italian 6. marble 7…

---

## [Security Exception](https://discuss.elastic.co/t/security-exception/355581)

<div class="topic-metadata">

**Author:** [@Ganesh\_DV1](https://discuss.elastic.co/u/Ganesh_DV1)\
**Replies:** 7\
**Last updated:** [March 20, 2024, 10:43am UTC](https://discuss.elastic.co/t/security-exception/355581 "2024-03-20T10:43:55Z")

</div>

Hi team ! It will be very helpful if the following problem is resolved by any members in community!! Due to shards deletion on server wrt indices \>\> 1. fleet-servers-7, 2. .async-search The status of cluster is RED an…

---

## [Need the query to get the only matched records](https://discuss.elastic.co/t/need-the-query-to-get-the-only-matched-records/355793)

<div class="topic-metadata">

**Author:** [@IndRajesh](https://discuss.elastic.co/u/IndRajesh)\
**Replies:** 5\
**Last updated:** [March 20, 2024, 9:10am UTC](https://discuss.elastic.co/t/need-the-query-to-get-the-only-matched-records/355793 "2024-03-20T09:10:02Z")

</div>

HI , I need to get the only matched records from table:employee,users for the below mapping. put /testsqljoin { "mappings" : { "properties" : { "first\_name" : { "type" : "text", "fields" : { …

---

## [Reindex issue](https://discuss.elastic.co/t/reindex-issue/355772)

<div class="topic-metadata">

**Author:** [@Alan\_Hsiao](https://discuss.elastic.co/u/Alan_Hsiao)\
**Replies:** 5\
**Last updated:** [March 20, 2024, 6:46am UTC](https://discuss.elastic.co/t/reindex-issue/355772 "2024-03-20T06:46:07Z")

</div>

I have some issue while I am reindex this is my result of reindex when I use GET my\_index in devtool my data show this Does \_source enabled false made my reindex fall? How can I fix it?

---

## [Exception Bad certificate when connecting to ES8 from Tomcat10](https://discuss.elastic.co/t/exception-bad-certificate-when-connecting-to-es8-from-tomcat10/355688)

<div class="topic-metadata">

**Author:** [@Irgnar](https://discuss.elastic.co/u/Irgnar)\
**Replies:** 2\
**Last updated:** [March 20, 2024, 5:16am UTC](https://discuss.elastic.co/t/exception-bad-certificate-when-connecting-to-es8-from-tomcat10/355688 "2024-03-20T05:16:42Z")

</div>

Hello, i'm migratiing an app from SpringBoot2.7.5 / Tomcat9 / ES7 to SpringBoot 3 / Tomcat10 / ES8, and i have this exception on the tomcat side : Caused by: java.lang.RuntimeException: Received fatal alert: bad\_certifi…

---

## [elasticsearch cannot read certificate file](https://discuss.elastic.co/t/elasticsearch-cannot-read-certificate-file/355757)

<div class="topic-metadata">

**Author:** [@vivere-dally](https://discuss.elastic.co/u/vivere-dally)\
**Replies:** 1\
**Last updated:** [March 20, 2024, 5:10am UTC](https://discuss.elastic.co/t/elasticsearch-cannot-read-certificate-file/355757 "2024-03-20T05:10:00Z")

</div>

I generated a certificate file with certbot. It is placed in /etc/letsencrypt/.... I created a group called elk where I added the elasticsearch user, and I recursively set it as the owning group for /etc/letsencrypt and…

---

## [Configured S3 repository on multiple clusters with write-access, data corrupted](https://discuss.elastic.co/t/configured-s3-repository-on-multiple-clusters-with-write-access-data-corrupted/355602)

<div class="topic-metadata">

**Author:** [@Tariq\_Yahya](https://discuss.elastic.co/u/Tariq_Yahya)\
**Replies:** 9\
**Last updated:** [March 19, 2024, 6:34pm UTC](https://discuss.elastic.co/t/configured-s3-repository-on-multiple-clusters-with-write-access-data-corrupted/355602 "2024-03-19T18:34:05Z")

</div>

I added the same S3 repository used by one of my cluster to another cluster and I forgot to give it read-only access. It states in the documentation that this action could cause data corruption : "If you register the sa…

---

## [Elasticsearch broken pipe exception](https://discuss.elastic.co/t/elasticsearch-broken-pipe-exception/355755)

<div class="topic-metadata">

**Author:** [@Joao\_Cardoso](https://discuss.elastic.co/u/Joao_Cardoso)\
**Replies:** 0\
**Last updated:** [March 19, 2024, 6:10pm UTC](https://discuss.elastic.co/t/elasticsearch-broken-pipe-exception/355755 "2024-03-19T18:10:18Z")

</div>

Using elasticsearch v8 client for .net 8, while performing load tests (arround 5000 in one minute), having a lot of exceptions regarding the connection: Invalid Elasticsearch response built from a unsuccessful () low le…

---

## [Query cache is always empty](https://discuss.elastic.co/t/query-cache-is-always-empty/355582)

<div class="topic-metadata">

**Author:** [@Minh\_S\_D](https://discuss.elastic.co/u/Minh_S_D)\
**Replies:** 5\
**Last updated:** [March 19, 2024, 5:26pm UTC](https://discuss.elastic.co/t/query-cache-is-always-empty/355582 "2024-03-19T17:26:04Z")

</div>

In setting of index: "queries": { "cache": { "enabled": "true" } }, GET products/\_search { "query": { "bool" : { "must": \[ { "match": { "product\_flat.name":…

---

## [Any doc regarding setting up elk on ecs](https://discuss.elastic.co/t/any-doc-regarding-setting-up-elk-on-ecs/355731)

<div class="topic-metadata">

**Author:** [@Paras\_Madaan](https://discuss.elastic.co/u/Paras_Madaan)\
**Replies:** 4\
**Last updated:** [March 19, 2024, 3:30pm UTC](https://discuss.elastic.co/t/any-doc-regarding-setting-up-elk-on-ecs/355731 "2024-03-19T15:30:04Z")

</div>

Need any documentation which can help in setting up an elk cluster having 2 datanodes and 3 dedicated master nodes (ecs on ec2)

---

## [Nodes Cant Communicate to eachother](https://discuss.elastic.co/t/nodes-cant-communicate-to-eachother/355729)

<div class="topic-metadata">

**Author:** [@fatima1](https://discuss.elastic.co/u/fatima1)\
**Replies:** 0\
**Last updated:** [March 19, 2024, 2:15pm UTC](https://discuss.elastic.co/t/nodes-cant-communicate-to-eachother/355729 "2024-03-19T14:15:47Z")

</div>

Could you please review the configurations I've provided for both machines? I'm encountering an issue where I'm unable to establish communication between the two nodes in Elasticsearch. Machine 1 ======================…

---

## ['query\_string' does not return records when using wildcard since 8.9 (wilcard query does)](https://discuss.elastic.co/t/query-string-does-not-return-records-when-using-wildcard-since-8-9-wilcard-query-does/355481)

<div class="topic-metadata">

**Author:** [@pawel.kupka-trojak](https://discuss.elastic.co/u/pawel.kupka-trojak)\
**Replies:** 2\
**Last updated:** [March 19, 2024, 1:38pm UTC](https://discuss.elastic.co/t/query-string-does-not-return-records-when-using-wildcard-since-8-9-wilcard-query-does/355481 "2024-03-19T13:38:54Z")

</div>

Hi, We are testing server upgrade to 8.12.2 and we found that some of our queries stopped to works. We use 'query\_string' with wildcard to search for user requested data. I have prepared some test data to show the cha…

---

## [Assigned roles \[create\_doc\] were not found) on indices](https://discuss.elastic.co/t/assigned-roles-create-doc-were-not-found-on-indices/355470)

<div class="topic-metadata">

**Author:** [@kra28](https://discuss.elastic.co/u/kra28)\
**Replies:** 2\
**Last updated:** [March 19, 2024, 1:03pm UTC](https://discuss.elastic.co/t/assigned-roles-create-doc-were-not-found-on-indices/355470 "2024-03-19T13:03:44Z")

</div>

Hello, I have some troubles to add a document into an index. Thank you for your answer. I have created a user kra28 and index pdbs\_index and add the privileges using: { "indices": \[ { "names": \[ "p…

---

## [Resource usage / Elasticsearch on virtual machine / single node](https://discuss.elastic.co/t/resource-usage-elasticsearch-on-virtual-machine-single-node/355554)

<div class="topic-metadata">

**Author:** [@FrankyR](https://discuss.elastic.co/u/FrankyR)\
**Replies:** 2\
**Last updated:** [March 19, 2024, 10:51am UTC](https://discuss.elastic.co/t/resource-usage-elasticsearch-on-virtual-machine-single-node/355554 "2024-03-19T10:51:52Z")

</div>

Dear community, I am trying to run Elasticsearch for a very small task ( I need to only visualize dmarc data with a couple of records a day so far). I configured single node in elasticsearch.yml by: network.host: 127.…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=132)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=134)
