# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=134

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 135

---

## [Docs count on migration - difference between \`\_count\` and \`\_stats\`](https://discuss.elastic.co/t/docs-count-on-migration-difference-between-count-and-stats/355620)

<div class="topic-metadata">

**Author:** [@maxxer](https://discuss.elastic.co/u/maxxer)\
**Replies:** 5\
**Last updated:** [March 19, 2024, 10:24am UTC](https://discuss.elastic.co/t/docs-count-on-migration-difference-between-count-and-stats/355620 "2024-03-19T10:24:33Z")

</div>

Hi. We're migrating from an on-premise Elasticsearch 7.17.10 to an Elastic-cloud 7.17.14 one. We are migrating using esm. Everything seems fine, but we noticed some high-volume indexes have a \_count very different from…

---

## [ELK Migration](https://discuss.elastic.co/t/elk-migration/355698)

<div class="topic-metadata">

**Author:** [@Aniket\_Dubey](https://discuss.elastic.co/u/Aniket_Dubey)\
**Replies:** 1\
**Last updated:** [March 19, 2024, 9:39am UTC](https://discuss.elastic.co/t/elk-migration/355698 "2024-03-19T09:39:40Z")

</div>

I have an Elasticsearch cluster on Elastic Cloud. I have another Elastic cluster on kubernetes (ECK). How do I take a snapshot from Elasticsearch cluster on Elastic Cloud and store it in S3 bucket and restore this on Ela…

---

## [Classification of long text](https://discuss.elastic.co/t/classification-of-long-text/355324)

<div class="topic-metadata">

**Author:** [@tartiflette](https://discuss.elastic.co/u/tartiflette)\
**Replies:** 6\
**Last updated:** [March 19, 2024, 9:14am UTC](https://discuss.elastic.co/t/classification-of-long-text/355324 "2024-03-19T09:14:59Z")

</div>

Hey, I am using the ES machine learning classification feature trying to predict a category of a certain text. I have orientated myself on this blog post, but I believe I'm doing something wrong in preparing the data. I…

---

## [RedHat elastic search image in openshift](https://discuss.elastic.co/t/redhat-elastic-search-image-in-openshift/353769)

<div class="topic-metadata">

**Author:** [@Sohaib\_El\_Mediouni](https://discuss.elastic.co/u/Sohaib_El_Mediouni)\
**Replies:** 1\
**Last updated:** [March 19, 2024, 3:36am UTC](https://discuss.elastic.co/t/redhat-elastic-search-image-in-openshift/353769 "2024-03-19T03:36:56Z")

</div>

Hello i'm trying to setup an Elasticsearch and a kibana on openshift and i used a redhat image but when i go to the pod and i see what's inside elasticsearch.yml i find this : \*\*cat elasticsearch.yml\*\* \*\*cluster.name: …

---

## [Basic Semantic Search or Semantic Search with ELSER](https://discuss.elastic.co/t/basic-semantic-search-or-semantic-search-with-elser/353845)

<div class="topic-metadata">

**Author:** [@9d224d4833094bd482cf](https://discuss.elastic.co/u/9d224d4833094bd482cf)\
**Replies:** 1\
**Last updated:** [March 18, 2024, 11:29pm UTC](https://discuss.elastic.co/t/basic-semantic-search-or-semantic-search-with-elser/353845 "2024-03-18T23:29:47Z")

</div>

I want to understand difference between Creating simple vector search by importing model (may be from hugging face) versus Using ELSER Any guidelines or recommendations on choosing approach? What are the use cases fo…

---

## [Search after| Same request return different results](https://discuss.elastic.co/t/search-after-same-request-return-different-results/355665)

<div class="topic-metadata">

**Author:** [@amladenovic](https://discuss.elastic.co/u/amladenovic)\
**Replies:** 0\
**Last updated:** [March 18, 2024, 10:56pm UTC](https://discuss.elastic.co/t/search-after-same-request-return-different-results/355665 "2024-03-18T22:56:08Z")

</div>

Hello. I have 2 instances and index with 3 shards. For my deep search im using search after. Search after uses doc id of document as sort parameter, with the following options "\_source":false , stored\_fields":\["none"\] . …

---

## [Unexpected behavior with date fields in Elasticsearch](https://discuss.elastic.co/t/unexpected-behavior-with-date-fields-in-elasticsearch/355527)

<div class="topic-metadata">

**Author:** [@victor\_gonzalez](https://discuss.elastic.co/u/victor_gonzalez)\
**Replies:** 5\
**Last updated:** [March 18, 2024, 10:00pm UTC](https://discuss.elastic.co/t/unexpected-behavior-with-date-fields-in-elasticsearch/355527 "2024-03-18T22:00:42Z")

</div>

I'm encountering an unexpected behavior with date fields in Elasticsearch. After converting date fields to text fields in SQL Server and indexing them in Elasticsearch, we noticed that Elasticsearch seems to adjust the d…

---

## [Field count v. performance](https://discuss.elastic.co/t/field-count-v-performance/355439)

<div class="topic-metadata">

**Author:** [@rsk0](https://discuss.elastic.co/u/rsk0)\
**Replies:** 10\
**Last updated:** [March 18, 2024, 8:50pm UTC](https://discuss.elastic.co/t/field-count-v-performance/355439 "2024-03-18T20:50:22Z")

</div>

Is indexing speed affected by the total number of fields in an index? I understand there are costs from a few areas: cluster state size disk efficiency Lucene resources And the "Mappings limit settings" doc says many…

---

## [Field name limitations](https://discuss.elastic.co/t/field-name-limitations/355522)

<div class="topic-metadata">

**Author:** [@rsk0](https://discuss.elastic.co/u/rsk0)\
**Replies:** 2\
**Last updated:** [March 18, 2024, 7:08pm UTC](https://discuss.elastic.co/t/field-name-limitations/355522 "2024-03-18T19:08:34Z")

</div>

I'm wondering what the limitations are for field names. I've seen some crazy things in our dynamic mappings, so I bet Lucene and ES are super flexible. For example, can you use a leading underscore? I notice that ES m…

---

## [Searching dashboards](https://discuss.elastic.co/t/searching-dashboards/355649)

<div class="topic-metadata">

**Author:** [@griffer98](https://discuss.elastic.co/u/griffer98)\
**Replies:** 0\
**Last updated:** [March 18, 2024, 6:40pm UTC](https://discuss.elastic.co/t/searching-dashboards/355649 "2024-03-18T18:40:57Z")

</div>

I have a production cluster and a monitoring cluster. I have set up cross cluster search but I can only search indices it seems and want I want to use in the get object api. I have logs on the monitoring that tell me the…

---

## [Cloud metadata](https://discuss.elastic.co/t/cloud-metadata/355634)

<div class="topic-metadata">

**Author:** [@tegerei](https://discuss.elastic.co/u/tegerei)\
**Replies:** 0\
**Last updated:** [March 18, 2024, 4:46pm UTC](https://discuss.elastic.co/t/cloud-metadata/355634 "2024-03-18T16:46:45Z")

</div>

Hello, I am collecting logs using filebeat from a VM in proxmox I created using generic cloud images for Debian. The issue I have is the fields are not properly populated on Kibana, such as the image attached. How do …

---

## [Image signature on elasticsearch images](https://discuss.elastic.co/t/image-signature-on-elasticsearch-images/355630)

<div class="topic-metadata">

**Author:** [@Vijeya\_Nidhi](https://discuss.elastic.co/u/Vijeya_Nidhi)\
**Replies:** 0\
**Last updated:** [March 18, 2024, 4:12pm UTC](https://discuss.elastic.co/t/image-signature-on-elasticsearch-images/355630 "2024-03-18T16:12:34Z")

</div>

Is it possible to add some signature when the docker image is built so that when the image is consumed from docker hub, we can verify the image to ensure it is the image built by elastic team and then use it in our syste…

---

## [Custom document scoring with a secondary 'penalization' query](https://discuss.elastic.co/t/custom-document-scoring-with-a-secondary-penalization-query/355541)

<div class="topic-metadata">

**Author:** [@ChapterSevenSeeds](https://discuss.elastic.co/u/ChapterSevenSeeds)\
**Replies:** 2\
**Last updated:** [March 18, 2024, 4:08pm UTC](https://discuss.elastic.co/t/custom-document-scoring-with-a-secondary-penalization-query/355541 "2024-03-18T16:08:14Z")

</div>

I recently heard about a rather unique method that a company is using to rank documents from a query. First, the queries that this company uses control the scoring down to a T by replacing the document scores with the in…

---

## [Index Search while using alias](https://discuss.elastic.co/t/index-search-while-using-alias/355035)

<div class="topic-metadata">

**Author:** [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Replies:** 17\
**Last updated:** [March 18, 2024, 3:24pm UTC](https://discuss.elastic.co/t/index-search-while-using-alias/355035 "2024-03-18T15:24:30Z")

</div>

Hi Team, We had below situation, where we created a alias (emp) on top of five index (employee\_01..employee\_05 which contains similar kind of data). While searching particualr key,value as mentioned below. We expect i…

---

## [How to configure direct\_max\_in\_bytes](https://discuss.elastic.co/t/how-to-configure-direct-max-in-bytes/355603)

<div class="topic-metadata">

**Author:** [@randomnamegenerator](https://discuss.elastic.co/u/randomnamegenerator)\
**Replies:** 1\
**Last updated:** [March 18, 2024, 2:35pm UTC](https://discuss.elastic.co/t/how-to-configure-direct-max-in-bytes/355603 "2024-03-18T14:35:59Z")

</div>

Hello All, I am wanting to adjust the direct\_max\_in\_bytes value , the documentation I have read deals with how adjust the jvm heap size but not the off heap size? \*\* \*\* If anyone can advise that would be greatly…

---

## [Downgrade the license to basic](https://discuss.elastic.co/t/downgrade-the-license-to-basic/355509)

<div class="topic-metadata">

**Author:** [@vinholla](https://discuss.elastic.co/u/vinholla)\
**Replies:** 4\
**Last updated:** [March 18, 2024, 2:15pm UTC](https://discuss.elastic.co/t/downgrade-the-license-to-basic/355509 "2024-03-18T14:15:34Z")

</div>

how to downgrade license from - trial to basic as we are getting below error {"error":{"root\_cause":\[{"type":"security\_exception","reason":"current license is non-compliant for \[security\]","license.expired.feature":"sec…

---

## [Failed shard on node \[bnK31ibrRG6bSpw\_pYK2BA\]: shard failure, reason \[corrupt file (source: \[index id\[CTR0CY4BdvDW7Z2cSc8C\] origin\[PRIMARY\] seq#\[27209007\]\])\], failure org.apache.lucene.store.AlreadyClosedException: this IndexWriter is closed](https://discuss.elastic.co/t/failed-shard-on-node-bnk31ibrrg6bspw-pyk2ba-shard-failure-reason-corrupt-file-source-index-id-ctr0cy4bdvdw7z2csc8c-origin-primary-seq-27209007-failure-org-apache-lucene-store-alreadyclosedexception-this-indexwriter-is-closed/354711)

<div class="topic-metadata">

**Author:** [@kishor1](https://discuss.elastic.co/u/kishor1)\
**Replies:** 8\
**Last updated:** [March 18, 2024, 2:00pm UTC](https://discuss.elastic.co/t/failed-shard-on-node-bnk31ibrrg6bspw-pyk2ba-shard-failure-reason-corrupt-file-source-index-id-ctr0cy4bdvdw7z2csc8c-origin-primary-seq-27209007-failure-org-apache-lucene-store-alreadyclosedexception-this-indexwriter-is-closed/354711 "2024-03-18T14:00:03Z")

</div>

I have deployed my elasticsearch,kibana and filebeat in kuberntes 3 days before through ECK operator. i was able to access it through kibana dashboard. but now when i am trying to access this elasticsearch showing sta…

---

## [How do I create a composite aggregate in c#](https://discuss.elastic.co/t/how-do-i-create-a-composite-aggregate-in-c/355563)

<div class="topic-metadata">

**Author:** [@Eric\_Paul](https://discuss.elastic.co/u/Eric_Paul)\
**Replies:** 1\
**Last updated:** [March 18, 2024, 11:47am UTC](https://discuss.elastic.co/t/how-do-i-create-a-composite-aggregate-in-c/355563 "2024-03-18T11:47:52Z")

</div>

I have been trying for days now to duplicate the following query in c# POST /traces-apm\*/\_async\_search { "size": 0, "query": { "bool": { "must": \[ { "wildcard": { "url.origina…

---

## [Error : no handler found for uri](https://discuss.elastic.co/t/error-no-handler-found-for-uri/355588)

<div class="topic-metadata">

**Author:** [@1\_1](https://discuss.elastic.co/u/1_1)\
**Replies:** 0\
**Last updated:** [March 18, 2024, 10:11am UTC](https://discuss.elastic.co/t/error-no-handler-found-for-uri/355588 "2024-03-18T10:11:17Z")

</div>

I have error when try to get data from elastic. MacBook Pro 16 M1Pro JetBrains Rider 2023.3.3 project: net6.0 c#10 using Nest client version: 7.13.2 remote elastic version: "version" : { "7.17.8" } Invalid NEST response…

---

## [Refreshes happening due to the Update API](https://discuss.elastic.co/t/refreshes-happening-due-to-the-update-api/355423)

<div class="topic-metadata">

**Author:** [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Replies:** 4\
**Last updated:** [March 18, 2024, 9:13am UTC](https://discuss.elastic.co/t/refreshes-happening-due-to-the-update-api/355423 "2024-03-18T09:13:53Z")

</div>

Hey, I have found a case where an unintended refresh happens, when you try to update a document, that has not been refreshed yet. Take the following example: DELETE test PUT test {"settings":{"refresh\_interval":"1h"}…

---

## [How to properly map fields from a CSV file in Elastic Custom Log Integration?](https://discuss.elastic.co/t/how-to-properly-map-fields-from-a-csv-file-in-elastic-custom-log-integration/355578)

<div class="topic-metadata">

**Author:** [@TEllegaard](https://discuss.elastic.co/u/TEllegaard)\
**Replies:** 0\
**Last updated:** [March 18, 2024, 6:54am UTC](https://discuss.elastic.co/t/how-to-properly-map-fields-from-a-csv-file-in-elastic-custom-log-integration/355578 "2024-03-18T06:54:35Z")

</div>

In Elastic, I have created a "Custom log integration", installed it on the agent and everything is working as it should. I have custom programme that dumps status information into a csv-file. Example data is: "@timestam…

---

## [ElasticSearch 7.17 FIPS (BouncyCastle)](https://discuss.elastic.co/t/elasticsearch-7-17-fips-bouncycastle/355499)

<div class="topic-metadata">

**Author:** [@Siva\_Karan](https://discuss.elastic.co/u/Siva_Karan)\
**Replies:** 1\
**Last updated:** [March 18, 2024, 5:17am UTC](https://discuss.elastic.co/t/elasticsearch-7-17-fips-bouncycastle/355499 "2024-03-18T05:17:45Z")

</div>

Hi Team, I need to FIPS enable for our Elasticsearch. may i know the clear steps to enable the FIPS for the Elasticsearch

---

## [Upgrading OS version](https://discuss.elastic.co/t/upgrading-os-version/355571)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 0\
**Last updated:** [March 18, 2024, 3:44am UTC](https://discuss.elastic.co/t/upgrading-os-version/355571 "2024-03-18T03:44:34Z")

</div>

Hello guys, does anyone have experience upgrading the OS version on the Elk server? how's the upgrade? can you tell me the method? my cluster consists of 3 data nodes and 2 logstash Thanks

---

## [Cost by indicies](https://discuss.elastic.co/t/cost-by-indicies/355558)

<div class="topic-metadata">

**Author:** [@rreknar](https://discuss.elastic.co/u/rreknar)\
**Replies:** 3\
**Last updated:** [March 17, 2024, 10:41pm UTC](https://discuss.elastic.co/t/cost-by-indicies/355558 "2024-03-17T22:41:33Z")

</div>

Hello, I a working with one of the use cases where in I need to know what is the actual cost I am paying to elastic based on indices. For example, if I have 5 indices Index1,Index2,index3,index4 and index5 I would like …

---

## [How to fix the issue Master node not identified during the Elk upgrade from 6.8 to 7.13.2](https://discuss.elastic.co/t/how-to-fix-the-issue-master-node-not-identified-during-the-elk-upgrade-from-6-8-to-7-13-2/355562)

<div class="topic-metadata">

**Author:** [@arun.natha](https://discuss.elastic.co/u/arun.natha)\
**Replies:** 1\
**Last updated:** [March 17, 2024, 9:18pm UTC](https://discuss.elastic.co/t/how-to-fix-the-issue-master-node-not-identified-during-the-elk-upgrade-from-6-8-to-7-13-2/355562 "2024-03-17T21:18:52Z")

</div>

Hello everyone, I need a help. During the elastic migration from ELK 6.8 to 7.13.2 The problem that we are facing is that when the data is present cluster unique id is not present that's why it cannot connect.

---

## [Unable to extract PDF content](https://discuss.elastic.co/t/unable-to-extract-pdf-content/354481)

<div class="topic-metadata">

**Author:** [@NitzaAg](https://discuss.elastic.co/u/NitzaAg)\
**Replies:** 4\
**Last updated:** [March 12, 2024, 10:41pm UTC](https://discuss.elastic.co/t/unable-to-extract-pdf-content/354481 "2024-03-12T22:41:40Z")

</div>

I'm trying to extract text from a pdf, but I get the following: Unable to extract PDF content -\> Unable to end a page -\> I regret that I couldn't find an OCR parser to handle image/ocr-png.Please set the OCR\_STRATEGY to…

---

## [Plugins Instllation](https://discuss.elastic.co/t/plugins-instllation/355550)

<div class="topic-metadata">

**Author:** [@fatima1](https://discuss.elastic.co/u/fatima1)\
**Replies:** 3\
**Last updated:** [March 17, 2024, 12:10pm UTC](https://discuss.elastic.co/t/plugins-instllation/355550 "2024-03-17T12:10:43Z")

</div>

How can I correctly install Elasticsearch plugins in Elasticsearch 7.17.9?please some one guide me

---

## [When i use "systemctl start elasticsearch.service", don't work](https://discuss.elastic.co/t/when-i-use-systemctl-start-elasticsearch-service-dont-work/355530)

<div class="topic-metadata">

**Author:** [@nperez51](https://discuss.elastic.co/u/nperez51)\
**Replies:** 9\
**Last updated:** [March 17, 2024, 1:27am UTC](https://discuss.elastic.co/t/when-i-use-systemctl-start-elasticsearch-service-dont-work/355530 "2024-03-17T01:27:16Z")

</div>

Hello, i can't start elasticsearch in a ubuntu 22.04 vm in azure, there is the output of comands, thank you. systemctl status elasticsearch.service hive@TheHiveVM:~$ systemctl status elasticsearch.service × elasticsear…

---

## [Cluster currently has \[1000\]/\[1000\] maximum normal shards open](https://discuss.elastic.co/t/cluster-currently-has-1000-1000-maximum-normal-shards-open/354830)

<div class="topic-metadata">

**Author:** [@diselkgd7](https://discuss.elastic.co/u/diselkgd7)\
**Replies:** 5\
**Last updated:** [March 16, 2024, 9:51am UTC](https://discuss.elastic.co/t/cluster-currently-has-1000-1000-maximum-normal-shards-open/354830 "2024-03-16T09:51:38Z")

</div>

I have what is like a Newbee question, I hope it makes sense how I explain it. I noticed that logs are not being ingested by my 1 node cluster and logstash complains about the maximum normal shards open - can you help m…

---

## [Inconsistencies in value count aggregation](https://discuss.elastic.co/t/inconsistencies-in-value-count-aggregation/355308)

<div class="topic-metadata">

**Author:** [@Atefeh](https://discuss.elastic.co/u/Atefeh)\
**Replies:** 3\
**Last updated:** [March 16, 2024, 8:10am UTC](https://discuss.elastic.co/t/inconsistencies-in-value-count-aggregation/355308 "2024-03-16T08:10:56Z")

</div>

I am using the Value count aggregation on a fixed interval, (the shards data doesn't change within this interval). However, I am encountering varying results with each query execution. Is it possible that I am obtaining …

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=133)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=135)
