# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=136

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 137

---

## [Elastic serach going unresponsive](https://discuss.elastic.co/t/elastic-serach-going-unresponsive/354505)

<div class="topic-metadata">

**Author:** [@thenmozhi](https://discuss.elastic.co/u/thenmozhi)\
**Replies:** 12\
**Last updated:** [March 13, 2024, 4:45am UTC](https://discuss.elastic.co/t/elastic-serach-going-unresponsive/354505 "2024-03-13T04:45:57Z")

</div>

16GB RAM, 112 memory server with elastic 7.0.15 installed. when ever elastic running the website is going ideal

---

## [Unable to authenticate using custom realm example code security-example-spi-extension](https://discuss.elastic.co/t/unable-to-authenticate-using-custom-realm-example-code-security-example-spi-extension/355151)

<div class="topic-metadata">

**Author:** [@buitcj](https://discuss.elastic.co/u/buitcj)\
**Replies:** 4\
**Last updated:** [March 13, 2024, 1:25am UTC](https://discuss.elastic.co/t/unable-to-authenticate-using-custom-realm-example-code-security-example-spi-extension/355151 "2024-03-13T01:25:26Z")

</div>

I've installed the provided security-example-spi-extension plugin (elasticsearch/x-pack/qa/security-example-spi-extension at 8.12 · elastic/elasticsearch · GitHub) and when I attempt to authenticate, it goes through Cust…

---

## [AWS clouldtrail user activity logs to elasticcloud](https://discuss.elastic.co/t/aws-clouldtrail-user-activity-logs-to-elasticcloud/355198)

<div class="topic-metadata">

**Author:** [@joshuskarki](https://discuss.elastic.co/u/joshuskarki)\
**Replies:** 3\
**Last updated:** [March 12, 2024, 11:13pm UTC](https://discuss.elastic.co/t/aws-clouldtrail-user-activity-logs-to-elasticcloud/355198 "2024-03-12T23:13:29Z")

</div>

Has anyone here successfully ingested AWS CloudTrail user activity logs into Elastic using CloudTrail integration and pulled data from SQS (CloudTrail -\> S3 -\> SQS with SNS enabled)? I am specifically wondering about th…

---

## [Points: when we plan to upgrade the ELK](https://discuss.elastic.co/t/points-when-we-plan-to-upgrade-the-elk/354771)

<div class="topic-metadata">

**Author:** [@Ravi\_Pattar](https://discuss.elastic.co/u/Ravi_Pattar)\
**Replies:** 4\
**Last updated:** [March 12, 2024, 8:34pm UTC](https://discuss.elastic.co/t/points-when-we-plan-to-upgrade-the-elk/354771 "2024-03-12T20:34:30Z")

</div>

Hello all, Need some clarifications. Kindly suggest with your inputs. If we plan to upgrade the full ELK stack to version 8.11 or the latest from version 7.17? Note: There’s a catch here as the main ELK server is run…

---

## [How to add created\_at and updated\_at fields](https://discuss.elastic.co/t/how-to-add-created-at-and-updated-at-fields/355178)

<div class="topic-metadata">

**Author:** [@Marco\_Solari](https://discuss.elastic.co/u/Marco_Solari)\
**Replies:** 18\
**Last updated:** [March 12, 2024, 7:46pm UTC](https://discuss.elastic.co/t/how-to-add-created-at-and-updated-at-fields/355178 "2024-03-12T19:46:20Z")

</div>

Hi. I'm quite new to Elasticsearch. I'm using the python client (v8.12.0). I'd like to add to my index the timestamp fields created\_at and updated\_at for every document. Reading various docs I think I have to use Ing…

---

## [Lookup in elasticsearch](https://discuss.elastic.co/t/lookup-in-elasticsearch/355229)

<div class="topic-metadata">

**Author:** [@hans\_hupe](https://discuss.elastic.co/u/hans_hupe)\
**Replies:** 5\
**Last updated:** [March 12, 2024, 2:48pm UTC](https://discuss.elastic.co/t/lookup-in-elasticsearch/355229 "2024-03-12T14:48:17Z")

</div>

In relational databases I am used to refer to descriptive fields by a key, and then make a lookup in order to retrieve the description. So updating the description doesn't have an impact on the query logic. How is this …

---

## [Issue with thread\_pool.write.queue\_size](https://discuss.elastic.co/t/issue-with-thread-pool-write-queue-size/354951)

<div class="topic-metadata">

**Author:** [@cesar.hernandez.a3se](https://discuss.elastic.co/u/cesar.hernandez.a3se)\
**Replies:** 12\
**Last updated:** [March 12, 2024, 2:39pm UTC](https://discuss.elastic.co/t/issue-with-thread-pool-write-queue-size/354951 "2024-03-12T14:39:43Z")

</div>

Hi He have been experiencing issues the last days on all nodes of our ES cluster, we see lots of these messages: \[2024-03-05T01:07:37,648\]\[WARN \]\[o.e.x.m.e.l.LocalExporter\] \[elastic-loggerpro05\] unexpected error while …

---

## [Is Update mapping API atomic?](https://discuss.elastic.co/t/is-update-mapping-api-atomic/354738)

<div class="topic-metadata">

**Author:** [@svtd](https://discuss.elastic.co/u/svtd)\
**Replies:** 2\
**Last updated:** [March 12, 2024, 1:17pm UTC](https://discuss.elastic.co/t/is-update-mapping-api-atomic/354738 "2024-03-12T13:17:41Z")

</div>

Hi! If I send Update mapping request targeting alias will that be executed atomically? Or can if happen that part of the indices are adjusted and others not (e.g. because of some failure)? Thank you, Svetlana

---

## [Problem elastic. uneven distribution of the data node](https://discuss.elastic.co/t/problem-elastic-uneven-distribution-of-the-data-node/352409)

<div class="topic-metadata">

**Author:** [@San9](https://discuss.elastic.co/u/San9)\
**Replies:** 13\
**Last updated:** [March 12, 2024, 1:03pm UTC](https://discuss.elastic.co/t/problem-elastic-uneven-distribution-of-the-data-node/352409 "2024-03-12T13:03:58Z")

</div>

Hi Team! I'm using the elastic version 8.11.1. Recently I began to notice an uneven distribution of indexes across data nodes. Alert: Node v-elk-ed02 is reporting disk usage of 90% at February 2, 2024 3:44 PM EET …

---

## [Score highlighted fields](https://discuss.elastic.co/t/score-highlighted-fields/355213)

<div class="topic-metadata">

**Author:** [@Sudipta\_Bhowmick](https://discuss.elastic.co/u/Sudipta_Bhowmick)\
**Replies:** 6\
**Last updated:** [March 12, 2024, 12:17pm UTC](https://discuss.elastic.co/t/score-highlighted-fields/355213 "2024-03-12T12:17:59Z")

</div>

Hi, Unable to get solution for the following requirement. Can anyone suggest on this please ? I have a ES query that searches for 4 fields in my index and provides highlighted result. But i want to score the highlighte…

---

## [RAG - how is it used? - Context window - does it work out out of the box?](https://discuss.elastic.co/t/rag-how-is-it-used-context-window-does-it-work-out-out-of-the-box/355028)

<div class="topic-metadata">

**Author:** [@Chenko](https://discuss.elastic.co/u/Chenko)\
**Replies:** 4\
**Last updated:** [March 12, 2024, 11:30am UTC](https://discuss.elastic.co/t/rag-how-is-it-used-context-window-does-it-work-out-out-of-the-box/355028 "2024-03-12T11:30:13Z")

</div>

I am wondering how RAG is used, I see it has a context window in which it adds context, however what is this context? Another questions I am having is, does RAG work out of the box? if so how? if not, what would need …

---

## [Cluster data retention settings](https://discuss.elastic.co/t/cluster-data-retention-settings/354993)

<div class="topic-metadata">

**Author:** [@gunlomboy](https://discuss.elastic.co/u/gunlomboy)\
**Replies:** 3\
**Last updated:** [March 12, 2024, 11:00am UTC](https://discuss.elastic.co/t/cluster-data-retention-settings/354993 "2024-03-12T11:00:21Z")

</div>

Hi, I am migrating from ILM to using the data retention settings. The documentation states: Currently, it defaults to max\_age=auto,max\_primary\_shard\_size=50gb,min\_docs=1,max\_primary\_shard\_docs=200000000 These setting…

---

## [Report shows less data than shown in search results](https://discuss.elastic.co/t/report-shows-less-data-than-shown-in-search-results/355020)

<div class="topic-metadata">

**Author:** [@Atul\_Chadha](https://discuss.elastic.co/u/Atul_Chadha)\
**Replies:** 9\
**Last updated:** [March 12, 2024, 10:24am UTC](https://discuss.elastic.co/t/report-shows-less-data-than-shown-in-search-results/355020 "2024-03-12T10:24:14Z")

</div>

We are running 7.17.x Elasticsearch and have setup a reporting for a search query. The team needs a weekly dump and it appears the number of results are not matching the one shown in search query results For example: 7 …

---

## [How to capture http response from elasticsearch watcher action block?](https://discuss.elastic.co/t/how-to-capture-http-response-from-elasticsearch-watcher-action-block/355132)

<div class="topic-metadata">

**Author:** [@Souvik\_Das](https://discuss.elastic.co/u/Souvik_Das)\
**Replies:** 1\
**Last updated:** [March 12, 2024, 9:45am UTC](https://discuss.elastic.co/t/how-to-capture-http-response-from-elasticsearch-watcher-action-block/355132 "2024-03-12T09:45:56Z")

</div>

Hi All, I'm struggling to capture the http response coming from execution of an action block. Is there any way to store it in a separate index? "actions": { "my\_webhook": { "webhook": { "method": "post", …

---

## [After expunge command still docs.deleted is not reducing](https://discuss.elastic.co/t/after-expunge-command-still-docs-deleted-is-not-reducing/355207)

<div class="topic-metadata">

**Author:** [@Siva\_Karan](https://discuss.elastic.co/u/Siva_Karan)\
**Replies:** 3\
**Last updated:** [March 12, 2024, 9:52am UTC](https://discuss.elastic.co/t/after-expunge-command-still-docs-deleted-is-not-reducing/355207 "2024-03-12T09:52:36Z")

</div>

HI Team, In one of our index we are going to remove the docs.deleted documents,but after the execution still the docs.deleted is not reducing health status index uuid pri rep docs.count docs.deleted …

---

## [About big data seach](https://discuss.elastic.co/t/about-big-data-seach/354891)

<div class="topic-metadata">

**Author:** [@vahid\_alvandi](https://discuss.elastic.co/u/vahid_alvandi)\
**Replies:** 0\
**Last updated:** [March 6, 2024, 11:36pm UTC](https://discuss.elastic.co/t/about-big-data-seach/354891 "2024-03-06T23:36:54Z")

</div>

Following this link, I have decided to index all the information in elasticsearch in addition to the main database of the site, and then the information displayed to the users of the site will be taken from Elasticsearch…

---

## [Replacement of NamedXContentRegistry in Java API Client](https://discuss.elastic.co/t/replacement-of-namedxcontentregistry-in-java-api-client/355209)

<div class="topic-metadata">

**Author:** [@roypiyali92](https://discuss.elastic.co/u/roypiyali92)\
**Replies:** 0\
**Last updated:** [March 12, 2024, 7:50am UTC](https://discuss.elastic.co/t/replacement-of-namedxcontentregistry-in-java-api-client/355209 "2024-03-12T07:50:59Z")

</div>

I am using the Java Api Client and need to write Mockito Test Cases where I can read a Json file and convert it into a SearchResponse Object . With the High Level Rest Client this was possible using the NamedXContentRegi…

---

## [Who ate my memory](https://discuss.elastic.co/t/who-ate-my-memory/355208)

<div class="topic-metadata">

**Author:** [@lu\_pan](https://discuss.elastic.co/u/lu_pan)\
**Replies:** 0\
**Last updated:** [March 12, 2024, 7:14am UTC](https://discuss.elastic.co/t/who-ate-my-memory/355208 "2024-03-12T07:14:24Z")

</div>

In my production environment, the ES cluster frequently encounters data too large exception. When I dumped the heap memory and analyzed it through MAT, I found the following confusing points: There are a large number …

---

## [High CPU Utilisation in 8.11.4](https://discuss.elastic.co/t/high-cpu-utilisation-in-8-11-4/354564)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 6\
**Last updated:** [March 12, 2024, 6:11am UTC](https://discuss.elastic.co/t/high-cpu-utilisation-in-8-11-4/354564 "2024-03-12T06:11:00Z")

</div>

We are using ELK version 8.11.4 and we have 6 hot nodes and 3 warm nodes and 3 master nodes 2 coordinator nodes When users try to query in kibana discover for example field : value OR field1 : value2 , in the backend (…

---

## [Automate ELSER v2 Trained Models download](https://discuss.elastic.co/t/automate-elser-v2-trained-models-download/355177)

<div class="topic-metadata">

**Author:** [@GlebCA](https://discuss.elastic.co/u/GlebCA)\
**Replies:** 3\
**Last updated:** [March 12, 2024, 3:27am UTC](https://discuss.elastic.co/t/automate-elser-v2-trained-models-download/355177 "2024-03-12T03:27:19Z")

</div>

Hi, I need to automate ELSER v2 Machine Learning Trained Models download into Elastic for integration testing purposes. There is documentation on how to download ELSER v2 from local files https://www.elastic.co/guide/e…

---

## [The calculated node size\_in\_bytes value is very different from the actual df value](https://discuss.elastic.co/t/the-calculated-node-size-in-bytes-value-is-very-different-from-the-actual-df-value/354706)

<div class="topic-metadata">

**Author:** [@524186aa](https://discuss.elastic.co/u/524186aa)\
**Replies:** 4\
**Last updated:** [March 12, 2024, 3:15am UTC](https://discuss.elastic.co/t/the-calculated-node-size-in-bytes-value-is-very-different-from-the-actual-df-value/354706 "2024-03-12T03:15:08Z")

</div>

The calculated node size\_in\_bytes value is very different from the actual df value I use "size\_in\_bytes" to check the usage of 2.6tb The usage of du is 3.7 TB What's extra? It will be released when it reboots

---

## [Some log missing in elasticsearch](https://discuss.elastic.co/t/some-log-missing-in-elasticsearch/355122)

<div class="topic-metadata">

**Author:** [@Frances\_Chu](https://discuss.elastic.co/u/Frances_Chu)\
**Replies:** 1\
**Last updated:** [March 12, 2024, 1:49am UTC](https://discuss.elastic.co/t/some-log-missing-in-elasticsearch/355122 "2024-03-12T01:49:56Z")

</div>

I try to transfer logs from filebeat to logstash at time A The log is located in the filebeat server //filebeatserver/log/LogtoLogstash/\* (including log before time A) The log is OK starting from time A. However, it …

---

## [Shared custom integration repository](https://discuss.elastic.co/t/shared-custom-integration-repository/355194)

<div class="topic-metadata">

**Author:** [@Ross\_Wakelin](https://discuss.elastic.co/u/Ross_Wakelin)\
**Replies:** 0\
**Last updated:** [March 11, 2024, 8:39pm UTC](https://discuss.elastic.co/t/shared-custom-integration-repository/355194 "2024-03-11T20:39:19Z")

</div>

Morning I was wondering if there is a location anywhere that hosts a public repository of custom Elastic integrations, ingest pipelines, Logstash configs etc. I have created ingest pipelines for MS DNS logs, MS NPS log…

---

## [Different result ordering with regard to 10000 limitation](https://discuss.elastic.co/t/different-result-ordering-with-regard-to-10000-limitation/355171)

<div class="topic-metadata">

**Author:** [@sliu](https://discuss.elastic.co/u/sliu)\
**Replies:** 2\
**Last updated:** [March 11, 2024, 6:18pm UTC](https://discuss.elastic.co/t/different-result-ordering-with-regard-to-10000-limitation/355171 "2024-03-11T18:18:46Z")

</div>

I have a search that has lot results, only "first" 10000 are accessible as commonly known. If I allow users change the ordering of search results (for instance, "order by column 1", "order by column 2", etc.), will user …

---

## [Installing ELSER Model on Docker Instance Fails](https://discuss.elastic.co/t/installing-elser-model-on-docker-instance-fails/354988)

<div class="topic-metadata">

**Author:** [@Steve\_Stefanovich](https://discuss.elastic.co/u/Steve_Stefanovich)\
**Replies:** 8\
**Last updated:** [March 11, 2024, 5:00pm UTC](https://discuss.elastic.co/t/installing-elser-model-on-docker-instance-fails/354988 "2024-03-11T17:00:26Z")

</div>

I followed the official documentation to create a single-node 8.12.2 cluster. Trial license is activated. When I attempt to deploy the elser\_model\_2\_linux-x86\_64 model, I receive the following 429 error: Could not start …

---

## [Case Insensitive aggregation not working](https://discuss.elastic.co/t/case-insensitive-aggregation-not-working/354633)

<div class="topic-metadata">

**Author:** [@raanup](https://discuss.elastic.co/u/raanup)\
**Replies:** 4\
**Last updated:** [March 11, 2024, 4:56pm UTC](https://discuss.elastic.co/t/case-insensitive-aggregation-not-working/354633 "2024-03-11T16:56:34Z")

</div>

ES version - 7.17.7 I've an index for which I' running an aggregation to get all field matching certain regex. This should be case-insensitive i.e. new york should match New York and NEW YORK and New YORK Have added a…

---

## [org.elasticsearch.hadoop.EsHadoopException: Could not write all entries for bulk operation \[1/1\]. Error sample (first \[5\] error messages):](https://discuss.elastic.co/t/org-elasticsearch-hadoop-eshadoopexception-could-not-write-all-entries-for-bulk-operation-1-1-error-sample-first-5-error-messages/355175)

<div class="topic-metadata">

**Author:** [@programmer\_123](https://discuss.elastic.co/u/programmer_123)\
**Replies:** 0\
**Last updated:** [March 11, 2024, 4:53pm UTC](https://discuss.elastic.co/t/org-elasticsearch-hadoop-eshadoopexception-could-not-write-all-entries-for-bulk-operation-1-1-error-sample-first-5-error-messages/355175 "2024-03-11T16:53:44Z")

</div>

Hi @all, I am using pyspark program to write the data into elastic index by using upsert operation (sample code snippet below). def writeDataToES(final\_df): write\_options = { "es.nodes": elastic\_host, "es.net.ssl":…

---

## [Reindex throttled after a few hours](https://discuss.elastic.co/t/reindex-throttled-after-a-few-hours/355059)

<div class="topic-metadata">

**Author:** [@elijah\_voigt](https://discuss.elastic.co/u/elijah_voigt)\
**Replies:** 3\
**Last updated:** [March 11, 2024, 4:45pm UTC](https://discuss.elastic.co/t/reindex-throttled-after-a-few-hours/355059 "2024-03-11T16:45:42Z")

</div>

I am on my 3rd attempt at re-indexing an index. The re-index task reliably demonstrates the following failure mode: The re-index task starts with high throughput, processing ~12,000 documents per second. After ~12-24 h…

---

## [How to stop ELK logging?](https://discuss.elastic.co/t/how-to-stop-elk-logging/355170)

<div class="topic-metadata">

**Author:** [@shrm](https://discuss.elastic.co/u/shrm)\
**Replies:** 0\
**Last updated:** [March 11, 2024, 3:07pm UTC](https://discuss.elastic.co/t/how-to-stop-elk-logging/355170 "2024-03-11T15:07:07Z")

</div>

I ran the elastic stack on docker compose and it is running well. But after a week 50GB of storage was filled with the service without any additional data. I did not provide any content yet, and it was completely clean. …

---

## [Elasticsearch transform configuration must specify exactly 1 function error](https://discuss.elastic.co/t/elasticsearch-transform-configuration-must-specify-exactly-1-function-error/355165)

<div class="topic-metadata">

**Author:** [@rvadiga](https://discuss.elastic.co/u/rvadiga)\
**Replies:** 0\
**Last updated:** [March 11, 2024, 1:48pm UTC](https://discuss.elastic.co/t/elasticsearch-transform-configuration-must-specify-exactly-1-function-error/355165 "2024-03-11T13:48:18Z")

</div>

Hello Team, I have a scenario in Elasticsearch transform where I need to ignore all duplicate items from the source index and apply few aggregation after ignore the duplicate documents. Could you please suggest any bes…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=135)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=137)
