# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=141

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 142

---

## [Finding documents with message field exceeding 1 mln characters](https://discuss.elastic.co/t/finding-documents-with-message-field-exceeding-1-mln-characters/353788)

<div class="topic-metadata">

**Author:** [@elk1985](https://discuss.elastic.co/u/elk1985)\
**Replies:** 4\
**Last updated:** [February 27, 2024, 8:47am UTC](https://discuss.elastic.co/t/finding-documents-with-message-field-exceeding-1-mln-characters/353788 "2024-02-27T08:47:17Z")

</div>

Hello. I'm getting error regarding exceeded message field length (over 1 mln characters). I want to identify them. I found a script in painless language: GET /your\_index/\_search { "query": { "bool": { "mu…

---

## [Unable to run elasticsearch rally in docker](https://discuss.elastic.co/t/unable-to-run-elasticsearch-rally-in-docker/354174)

<div class="topic-metadata">

**Author:** [@uttamkrpanda](https://discuss.elastic.co/u/uttamkrpanda)\
**Replies:** 1\
**Last updated:** [February 27, 2024, 8:16am UTC](https://discuss.elastic.co/t/unable-to-run-elasticsearch-rally-in-docker/354174 "2024-02-27T08:16:30Z")

</div>

I am unable to run elasticsearch rally with docker its getting "No such file or directory" error . How can i fix this ? docker run elastic/rally race --track=nyc\_taxis --test-mode --pipeline=benchmark-only --target-hos…

---

## [Windows Elastic-Agent Group Deployment](https://discuss.elastic.co/t/windows-elastic-agent-group-deployment/354149)

<div class="topic-metadata">

**Author:** [@Patrick.kirk](https://discuss.elastic.co/u/Patrick.kirk)\
**Replies:** 1\
**Last updated:** [February 26, 2024, 10:18pm UTC](https://discuss.elastic.co/t/windows-elastic-agent-group-deployment/354149 "2024-02-26T22:18:13Z")

</div>

I’m looking at doing a mass deployment of the windows elastic agent (1000+ workstations) and looking for a “best or recommend” way. I have not seen an MSI for the agent. What are the recommendations for this?

---

## [Error about schema casting when updating documents attributes different than the error ones](https://discuss.elastic.co/t/error-about-schema-casting-when-updating-documents-attributes-different-than-the-error-ones/354142)

<div class="topic-metadata">

**Author:** [@alexandervcc](https://discuss.elastic.co/u/alexandervcc)\
**Replies:** 0\
**Last updated:** [February 26, 2024, 5:44pm UTC](https://discuss.elastic.co/t/error-about-schema-casting-when-updating-documents-attributes-different-than-the-error-ones/354142 "2024-02-26T17:44:33Z")

</div>

Hello, I got some issue with elastic. I have a request which updates docs on elastics. this looks like: POST /index/\_update\_by\_query { "query":{ "match":{ "load": "sync" } }, …

---

## [How To Fix : code 429 - circuit\_breaking\_exception - Data too large, data for \[indices:data/write/bulk\[s\]\]](https://discuss.elastic.co/t/how-to-fix-code-429-circuit-breaking-exception-data-too-large-data-for-indices-data-write-bulk-s/354138)

<div class="topic-metadata">

**Author:** [@Leo\_K](https://discuss.elastic.co/u/Leo_K)\
**Replies:** 0\
**Last updated:** [February 26, 2024, 4:37pm UTC](https://discuss.elastic.co/t/how-to-fix-code-429-circuit-breaking-exception-data-too-large-data-for-indices-data-write-bulk-s/354138 "2024-02-26T16:37:23Z")

</div>

Hello everyone, Configuration : Elastic Cloud - ES 8.11 I've been benchmarking Elastic for the past days and had multiple errors coming up and I couldn't find a viable answer on the most annoying one : { \_index: 'MY\_I…

---

## [Updating elasticsearch CA but \_ssl/certificates return wrong result](https://discuss.elastic.co/t/updating-elasticsearch-ca-but-ssl-certificates-return-wrong-result/354085)

<div class="topic-metadata">

**Author:** [@petertw6235](https://discuss.elastic.co/u/petertw6235)\
**Replies:** 5\
**Last updated:** [February 26, 2024, 1:08pm UTC](https://discuss.elastic.co/t/updating-elasticsearch-ca-but-ssl-certificates-return-wrong-result/354085 "2024-02-26T13:08:29Z")

</div>

Hi, Elasticsearch version: 7.17.9 I tried to update the TLS certificate because the CA will expire this year. I found this guide \[same CA\] (Update certificates with the same CA | Elasticsearch Guide \[7.17\] | Elastic) …

---

## [Elastic stack change from GCP to AWS](https://discuss.elastic.co/t/elastic-stack-change-from-gcp-to-aws/354098)

<div class="topic-metadata">

**Author:** [@Vilius\_Dudenas](https://discuss.elastic.co/u/Vilius_Dudenas)\
**Replies:** 1\
**Last updated:** [February 26, 2024, 11:52am UTC](https://discuss.elastic.co/t/elastic-stack-change-from-gcp-to-aws/354098 "2024-02-26T11:52:09Z")

</div>

Hey, I am currently investigating what would be the best approach to migrate current deployment from GCP to AWS. As I see snapshots are tied to the provider and it does not allow me to restore on another provider (prob…

---

## [Snapshot name from original index name as a suffix](https://discuss.elastic.co/t/snapshot-name-from-original-index-name-as-a-suffix/353353)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 3\
**Last updated:** [February 26, 2024, 11:08am UTC](https://discuss.elastic.co/t/snapshot-name-from-original-index-name-as-a-suffix/353353 "2024-02-26T11:08:00Z")

</div>

Hi Is it possible to make configuration for shift the name from original index to snapshot name? I need such config because many of index are generate with name in date order so I want to know which one index has snapsh…

---

## [Elastic Search curator not working](https://discuss.elastic.co/t/elastic-search-curator-not-working/354114)

<div class="topic-metadata">

**Author:** [@Akash\_Rai](https://discuss.elastic.co/u/Akash_Rai)\
**Replies:** 0\
**Last updated:** [February 26, 2024, 10:42am UTC](https://discuss.elastic.co/t/elastic-search-curator-not-working/354114 "2024-02-26T10:42:34Z")

</div>

Hi , I am trying to install elastisearch -curator but its not working. kind: CronJob metadata: name: curator labels: app: curator spec: schedule: "\* \* \* \* \*" successfulJobsHistoryLimit: 1 failedJobsHistoryLimit…

---

## [Datastream under a policy behaving unstable](https://discuss.elastic.co/t/datastream-under-a-policy-behaving-unstable/353144)

<div class="topic-metadata">

**Author:** [@Mubolio](https://discuss.elastic.co/u/Mubolio)\
**Replies:** 1\
**Last updated:** [February 26, 2024, 10:35am UTC](https://discuss.elastic.co/t/datastream-under-a-policy-behaving-unstable/353144 "2024-02-26T10:35:55Z")

</div>

Hello, I have a datastream that should keep data only for the latest 15 days, documents that are older than 15 days will be deleted(based on the @timestamp field). This is the index template attached to the datastream: …

---

## [Python client multisearch with different fields weights](https://discuss.elastic.co/t/python-client-multisearch-with-different-fields-weights/354064)

<div class="topic-metadata">

**Author:** [@Marco\_Solari](https://discuss.elastic.co/u/Marco_Solari)\
**Replies:** 5\
**Last updated:** [February 26, 2024, 10:13am UTC](https://discuss.elastic.co/t/python-client-multisearch-with-different-fields-weights/354064 "2024-02-26T10:13:05Z")

</div>

I'm quite new to elasticsearch... I created my first index (to be used for italian language), and basic search functionality, for my cooking recipes database. I now am trying to implement some more advanced search feat…

---

## [ECK : can't have green elasticsearch cluster](https://discuss.elastic.co/t/eck-cant-have-green-elasticsearch-cluster/354106)

<div class="topic-metadata">

**Author:** [@Bobflyer](https://discuss.elastic.co/u/Bobflyer)\
**Replies:** 0\
**Last updated:** [February 26, 2024, 9:55am UTC](https://discuss.elastic.co/t/eck-cant-have-green-elasticsearch-cluster/354106 "2024-02-26T09:55:40Z")

</div>

Hello, I try to deploy an elasticsearch cluster on my docker-desktop kubernetes test cluster. The final goal is to deploy it in a k3s cluster on my raspberry pies. Here my kubernetes manifest : apiVersion: elasticsear…

---

## [Elastic Search UI - Adding filter returns all results](https://discuss.elastic.co/t/elastic-search-ui-adding-filter-returns-all-results/354095)

<div class="topic-metadata">

**Author:** [@jackfrost](https://discuss.elastic.co/u/jackfrost)\
**Replies:** 0\
**Last updated:** [February 26, 2024, 8:11am UTC](https://discuss.elastic.co/t/elastic-search-ui-adding-filter-returns-all-results/354095 "2024-02-26T08:11:21Z")

</div>

Hey All. I am use Elasticsearch ui with the @elastic/search-ui-elasticsearch-connector. I currently have the search up and running. I am able to do a search for something like a name, and get one exact result back. All …

---

## [The number of my es's file descriptor keep growing,I need help](https://discuss.elastic.co/t/the-number-of-my-ess-file-descriptor-keep-growing-i-need-help/354080)

<div class="topic-metadata">

**Author:** [@SKYWALKER-STAR](https://discuss.elastic.co/u/SKYWALKER-STAR)\
**Replies:** 1\
**Last updated:** [February 26, 2024, 5:55am UTC](https://discuss.elastic.co/t/the-number-of-my-ess-file-descriptor-keep-growing-i-need-help/354080 "2024-02-26T05:55:50Z")

</div>

The number of my es's file descriptor keep growing.How can i reduce the my file descriptor number used by my es cluster.

---

## [ILM Policy on No alias](https://discuss.elastic.co/t/ilm-policy-on-no-alias/354077)

<div class="topic-metadata">

**Author:** [@Suresh\_Ghatuwa](https://discuss.elastic.co/u/Suresh_Ghatuwa)\
**Replies:** 0\
**Last updated:** [February 26, 2024, 4:11am UTC](https://discuss.elastic.co/t/ilm-policy-on-no-alias/354077 "2024-02-26T04:11:34Z")

</div>

Hello, I am trying to implement the ILM policy on index not having an alias. ILM policy need to be trigger on removing an alias from index immediately. Could you please suggest if that is possible ? Thanks in advance. …

---

## [Dynamic way of building aggregation query using java api client](https://discuss.elastic.co/t/dynamic-way-of-building-aggregation-query-using-java-api-client/353946)

<div class="topic-metadata">

**Author:** [@prasad.ram1431](https://discuss.elastic.co/u/prasad.ram1431)\
**Replies:** 1\
**Last updated:** [February 26, 2024, 3:48am UTC](https://discuss.elastic.co/t/dynamic-way-of-building-aggregation-query-using-java-api-client/353946 "2024-02-26T03:48:23Z")

</div>

Hi Team, Can someone please help with sample code to create aggregate query dynamically based on the given list of fields using Elasticsearch Java API Client. Unfortunately I couldn't get much documentation help on this…

---

## [Issue with Elasticsearch Cluster](https://discuss.elastic.co/t/issue-with-elasticsearch-cluster/354075)

<div class="topic-metadata">

**Author:** [@Jimmy\_Wang](https://discuss.elastic.co/u/Jimmy_Wang)\
**Replies:** 0\
**Last updated:** [February 26, 2024, 3:28am UTC](https://discuss.elastic.co/t/issue-with-elasticsearch-cluster/354075 "2024-02-26T03:28:43Z")

</div>

Hello, I am currently setting up an Elasticsearch cluster with three nodes and encountering an issue with cluster formation. Here's the setup: elastic01: 10G network interface with VLAN configured, able to join the clu…

---

## [Dynamic template copy\_to does not work with flattened type](https://discuss.elastic.co/t/dynamic-template-copy-to-does-not-work-with-flattened-type/354026)

<div class="topic-metadata">

**Author:** [@s.moran](https://discuss.elastic.co/u/s.moran)\
**Replies:** 1\
**Last updated:** [February 25, 2024, 11:36pm UTC](https://discuss.elastic.co/t/dynamic-template-copy-to-does-not-work-with-flattened-type/354026 "2024-02-25T23:36:16Z")

</div>

I have a field of flattened type that contains a subfield that I want to do numeric range searches on. I am trying to use a dynamic template to copy the field's value to a top level field that I can use for range queries…

---

## [ES|QL CIDR\_MATCH not working (or more likely I'm doing something wrong)?](https://discuss.elastic.co/t/es-ql-cidr-match-not-working-or-more-likely-im-doing-something-wrong/350035)

<div class="topic-metadata">

**Author:** [@BenB196](https://discuss.elastic.co/u/BenB196)\
**Replies:** 1\
**Last updated:** [February 25, 2024, 8:05pm UTC](https://discuss.elastic.co/t/es-ql-cidr-match-not-working-or-more-likely-im-doing-something-wrong/350035 "2024-02-25T20:05:55Z")

</div>

Hi All, I've been messing around with ES|QL a bit, but I'm having an issue with the CIDR\_MATCH function, I'm hoping someone can help with. At a minimum, I have a document that looks like: { "host": { "name": "ip…

---

## [Regarding issues related to the ES SSPL protocol](https://discuss.elastic.co/t/regarding-issues-related-to-the-es-sspl-protocol/354058)

<div class="topic-metadata">

**Author:** [@liruileay](https://discuss.elastic.co/u/liruileay)\
**Replies:** 2\
**Last updated:** [February 25, 2024, 7:47pm UTC](https://discuss.elastic.co/t/regarding-issues-related-to-the-es-sspl-protocol/354058 "2024-02-25T19:47:02Z")

</div>

The customer service within the company based on ES encapsulation belongs to the provision of products as services to the outside world. Do we need commercial authorization or open source code

---

## [How to gain insight into what management tasks are running?](https://discuss.elastic.co/t/how-to-gain-insight-into-what-management-tasks-are-running/354067)

<div class="topic-metadata">

**Author:** [@bruce289](https://discuss.elastic.co/u/bruce289)\
**Replies:** 0\
**Last updated:** [February 25, 2024, 7:22pm UTC](https://discuss.elastic.co/t/how-to-gain-insight-into-what-management-tasks-are-running/354067 "2024-02-25T19:22:02Z")

</div>

Hey, We can see that some of the nodes in our cluster have many more completed tasks in the management thread pool than others. Is there anyway to find out what exactly these management tasks are/were? Whenever I run \_c…

---

## [Logs are not visible in Kibana](https://discuss.elastic.co/t/logs-are-not-visible-in-kibana/353789)

<div class="topic-metadata">

**Author:** [@moep](https://discuss.elastic.co/u/moep)\
**Replies:** 3\
**Last updated:** [February 24, 2024, 8:35pm UTC](https://discuss.elastic.co/t/logs-are-not-visible-in-kibana/353789 "2024-02-24T20:35:42Z")

</div>

Hello, do test some logs Logstash configurations I want to use this docker-compose.yml and I'm running Debian 12 . Docker version 25.0.3, build 4debf41 docker-compose version 1.29.2 my user is in the docker group, to …

---

## [Wildcard query on keyword vs N-gram analyzer + multi-match](https://discuss.elastic.co/t/wildcard-query-on-keyword-vs-n-gram-analyzer-multi-match/354038)

<div class="topic-metadata">

**Author:** [@you-last-did](https://discuss.elastic.co/u/you-last-did)\
**Replies:** 0\
**Last updated:** [February 24, 2024, 6:06pm UTC](https://discuss.elastic.co/t/wildcard-query-on-keyword-vs-n-gram-analyzer-multi-match/354038 "2024-02-24T18:06:54Z")

</div>

Hi everyone. I have benefited a lot from the forum and now it's my first post :slight\_smile: So I have some fields which look like these: orderId: ABC-DEF-1234 date: 2024-02-24 lastUpdatedTime: 2024-02-24T12:09:48.7…

---

## [Elasticsaerch Query Exact match](https://discuss.elastic.co/t/elasticsaerch-query-exact-match/353696)

<div class="topic-metadata">

**Author:** [@Mohan\_T](https://discuss.elastic.co/u/Mohan_T)\
**Replies:** 6\
**Last updated:** [February 21, 2024, 2:38pm UTC](https://discuss.elastic.co/t/elasticsaerch-query-exact-match/353696 "2024-02-21T14:38:25Z")

</div>

to find the exact match mappings "keywords": { "type": "object", "enabled": True, "properties": { "keyword\_values": { "type": "text", "analyzer": "synonym\_stemmer\_bad\_words\_a…

---

## [Can't create histogram for summed values](https://discuss.elastic.co/t/cant-create-histogram-for-summed-values/353929)

<div class="topic-metadata">

**Author:** [@tomek\_z](https://discuss.elastic.co/u/tomek_z)\
**Replies:** 2\
**Last updated:** [February 23, 2024, 8:08pm UTC](https://discuss.elastic.co/t/cant-create-histogram-for-summed-values/353929 "2024-02-23T20:08:22Z")

</div>

Can't create histogram for summed values I'cant figure out how to create histogram for sumemd values. This query gives me sum of events time per user: GET /events/\_search { "size": 0, "aggregations": { "by\_use…

---

## [Problems with dynamic mapping](https://discuss.elastic.co/t/problems-with-dynamic-mapping/353940)

<div class="topic-metadata">

**Author:** [@Russell\_Fulton](https://discuss.elastic.co/u/Russell_Fulton)\
**Replies:** 1\
**Last updated:** [February 23, 2024, 7:38pm UTC](https://discuss.elastic.co/t/problems-with-dynamic-mapping/353940 "2024-02-23T19:38:49Z")

</div>

I have some ECS formatted data that I want to put into a new data stream. I created an index template with default parameters: (no setting, mappings or aliases) but when I try and put data into it using the ruby api I g…

---

## [Nested bool querie](https://discuss.elastic.co/t/nested-bool-querie/354015)

<div class="topic-metadata">

**Author:** [@eirik](https://discuss.elastic.co/u/eirik)\
**Replies:** 0\
**Last updated:** [February 23, 2024, 6:36pm UTC](https://discuss.elastic.co/t/nested-bool-querie/354015 "2024-02-23T18:36:44Z")

</div>

Hi, I'm pretty new to queries in elastic and need some help to understand how the post\_filter below is executed for both when a document has the \_id field and when it doesn't have it :slight\_smile: "post\_filter": { …

---

## [Collect router-specific syslog data](https://discuss.elastic.co/t/collect-router-specific-syslog-data/354013)

<div class="topic-metadata">

**Author:** [@Saullus](https://discuss.elastic.co/u/Saullus)\
**Replies:** 0\
**Last updated:** [February 23, 2024, 6:29pm UTC](https://discuss.elastic.co/t/collect-router-specific-syslog-data/354013 "2024-02-23T18:29:05Z")

</div>

Hello community. I activated Syslog on a Cisco 3725 router and need to connect to Elasticsearch/Logstash to collect the logs. I need to collect memory, CPU and UP/DOWN events from the router. How can I filter this infor…

---

## [Logstash error "logstash.codecs.json"](https://discuss.elastic.co/t/logstash-error-logstash-codecs-json/354001)

<div class="topic-metadata">

**Author:** [@Antonio\_Lopez](https://discuss.elastic.co/u/Antonio_Lopez)\
**Replies:** 0\
**Last updated:** [February 23, 2024, 4:09pm UTC](https://discuss.elastic.co/t/logstash-error-logstash-codecs-json/354001 "2024-02-23T16:09:15Z")

</div>

Hi everybody, I'm using Logstash version 7.12.0, and I'm experiencing issues processing the input data. The logs are stored in an NFS, and Logstash has access to them. The data is formatted in JSON, and I'm using the c…

---

## [Issue with the example from the ES blog](https://discuss.elastic.co/t/issue-with-the-example-from-the-es-blog/354000)

<div class="topic-metadata">

**Author:** [@profuel](https://discuss.elastic.co/u/profuel)\
**Replies:** 1\
**Last updated:** [February 23, 2024, 3:57pm UTC](https://discuss.elastic.co/t/issue-with-the-example-from-the-es-blog/354000 "2024-02-23T15:57:20Z")

</div>

Hi there! I'm trying to setup a proper search for the Japanese audience. I found this blog post - How to implement Japanese full-text search in Elasticsearch | Elastic Blog, though the example here is not accepted neit…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=140)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=142)
