# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=144

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 145

---

## [Failed to restore an incremental snapshot](https://discuss.elastic.co/t/failed-to-restore-an-incremental-snapshot/353657)

<div class="topic-metadata">

**Author:** [@praval\_singhal](https://discuss.elastic.co/u/praval_singhal)\
**Replies:** 6\
**Last updated:** [February 20, 2024, 11:42am UTC](https://discuss.elastic.co/t/failed-to-restore-an-incremental-snapshot/353657 "2024-02-20T11:42:38Z")

</div>

I have been trying to restore an incremental snapshot for my ES cluster stored in azure storage account. I am getting this error {"error":{"root\_cause":\[{"type":"snapshot\_restore\_exception","reason":"\[elasticsearch\_sna…

---

## [Get only one fileld that is common accoss different indices, like SQL join on tables](https://discuss.elastic.co/t/get-only-one-fileld-that-is-common-accoss-different-indices-like-sql-join-on-tables/353677)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 0\
**Last updated:** [February 20, 2024, 11:08am UTC](https://discuss.elastic.co/t/get-only-one-fileld-that-is-common-accoss-different-indices-like-sql-join-on-tables/353677 "2024-02-20T11:08:14Z")

</div>

Hello All, Can someone please let me know I have a requirement to make dashboard which shows which usecases/ index are critical to be shown with status Heathy in green color and Red Critical. Below is image I have achi…

---

## [Elasticsaerch Query with exact match with stemmer apply](https://discuss.elastic.co/t/elasticsaerch-query-with-exact-match-with-stemmer-apply/353675)

<div class="topic-metadata">

**Author:** [@Mohan\_T](https://discuss.elastic.co/u/Mohan_T)\
**Replies:** 0\
**Last updated:** [February 20, 2024, 11:03am UTC](https://discuss.elastic.co/t/elasticsaerch-query-with-exact-match-with-stemmer-apply/353675 "2024-02-20T11:03:40Z")

</div>

To fetch the exact match I have applied Ex: keywords.keyword\_values.keyword mappings: "keywords": { "type": "object", "enabled": True, "properties": { "keyword\_values": { "type": "text"…

---

## [How to refer doc\_count in MovingFunctions.ewma aggregation bucket path?](https://discuss.elastic.co/t/how-to-refer-doc-count-in-movingfunctions-ewma-aggregation-bucket-path/353602)

<div class="topic-metadata">

**Author:** [@Abinash\_Raja](https://discuss.elastic.co/u/Abinash_Raja)\
**Replies:** 1\
**Last updated:** [February 20, 2024, 10:47am UTC](https://discuss.elastic.co/t/how-to-refer-doc-count-in-movingfunctions-ewma-aggregation-bucket-path/353602 "2024-02-20T10:47:32Z")

</div>

Hi, Is there a way to directly refer the doc\_count of date histogram(over time\_millis field) bucket(s) in MovingFunctions.ewma bucket path, instead of creating a separate value\_count aggregation (for the same field time…

---

## [Illegal\_state\_exception: no rollover info found for \[logstash-2024.02.16\] with rollover target \[logstash-\], the index has not yet rolled over with that target](https://discuss.elastic.co/t/illegal-state-exception-no-rollover-info-found-for-logstash-2024-02-16-with-rollover-target-logstash-the-index-has-not-yet-rolled-over-with-that-target/353667)

<div class="topic-metadata">

**Author:** [@martianzz](https://discuss.elastic.co/u/martianzz)\
**Replies:** 0\
**Last updated:** [February 20, 2024, 9:46am UTC](https://discuss.elastic.co/t/illegal-state-exception-no-rollover-info-found-for-logstash-2024-02-16-with-rollover-target-logstash-the-index-has-not-yet-rolled-over-with-that-target/353667 "2024-02-20T09:46:00Z")

</div>

illegal\_state\_exception: no rollover info found for \[logstash-2024.02.16\] with rollover target \[logstash-\], the index has not yet rolled over with that target. Why is this error always coming. How to solve it

---

## [Hardware profiles for Hot/Warm tiers](https://discuss.elastic.co/t/hardware-profiles-for-hot-warm-tiers/353582)

<div class="topic-metadata">

**Author:** [@intrepid1](https://discuss.elastic.co/u/intrepid1)\
**Replies:** 2\
**Last updated:** [February 20, 2024, 9:01am UTC](https://discuss.elastic.co/t/hardware-profiles-for-hot-warm-tiers/353582 "2024-02-20T09:01:40Z")

</div>

Hi there, We are in the process of moving our on-premise logging cluster to AWS on EC2 and would like to use a hot/warm architecture. The aim is to place the data on the hardware that is most suited to, allowing multipl…

---

## [Failed to load SSL configuration \[xpack.security.transport.ssl\] - cannot read configured \[PKCS12\]](https://discuss.elastic.co/t/failed-to-load-ssl-configuration-xpack-security-transport-ssl-cannot-read-configured-pkcs12/352840)

<div class="topic-metadata">

**Author:** [@Jerry-yz](https://discuss.elastic.co/u/Jerry-yz)\
**Replies:** 3\
**Last updated:** [February 20, 2024, 1:54am UTC](https://discuss.elastic.co/t/failed-to-load-ssl-configuration-xpack-security-transport-ssl-cannot-read-configured-pkcs12/352840 "2024-02-20T01:54:49Z")

</div>

wehn i run es with docker; my docker run cmd is: docker run -itd -p 9200:9200 -m 2GB --privileged=true -v $PWD/config/elasticsearch.yml:/usr/share/elasticsearch/config/elasticsearch.yml -v $PWD/data:/usr/share/elasticse…

---

## [Issue with setting \`\_tier\_preference\` in index template](https://discuss.elastic.co/t/issue-with-setting-tier-preference-in-index-template/353631)

<div class="topic-metadata">

**Author:** [@Sebastian\_Veliz\_MQ](https://discuss.elastic.co/u/Sebastian_Veliz_MQ)\
**Replies:** 0\
**Last updated:** [February 19, 2024, 8:02pm UTC](https://discuss.elastic.co/t/issue-with-setting-tier-preference-in-index-template/353631 "2024-02-19T20:02:10Z")

</div>

Hello We are encountering an issue while trying to set the \_tier\_preference in an index template. Despite updating the setting in the index template edit page, the preview shows that \_tier\_preference is set to null inst…

---

## [Allow requests to elastic deployment only from AWS EC2 instances in VPN](https://discuss.elastic.co/t/allow-requests-to-elastic-deployment-only-from-aws-ec2-instances-in-vpn/353618)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 1\
**Last updated:** [February 19, 2024, 6:02pm UTC](https://discuss.elastic.co/t/allow-requests-to-elastic-deployment-only-from-aws-ec2-instances-in-vpn/353618 "2024-02-19T18:02:39Z")

</div>

Is it possible to restrict access to elastic deployment only from AWS EC2 instances that are part of a particular VPN?

---

## [Security minimal setup 7.9.0](https://discuss.elastic.co/t/security-minimal-setup-7-9-0/353304)

<div class="topic-metadata">

**Author:** [@mwitsas](https://discuss.elastic.co/u/mwitsas)\
**Replies:** 2\
**Last updated:** [February 19, 2024, 3:32pm UTC](https://discuss.elastic.co/t/security-minimal-setup-7-9-0/353304 "2024-02-19T15:32:12Z")

</div>

Can anyone confirm this procedure is valid for 7.9.0 and should work? Or can anyone highlight any issues with trying this on 7.9.0? I see the page only exists in documentation from 7.12.0 onwards - "This page is not a…

---

## [fatal exception while booting Elasticsearch](https://discuss.elastic.co/t/fatal-exception-while-booting-elasticsearch/353620)

<div class="topic-metadata">

**Author:** [@carrot016](https://discuss.elastic.co/u/carrot016)\
**Replies:** 0\
**Last updated:** [February 19, 2024, 3:15pm UTC](https://discuss.elastic.co/t/fatal-exception-while-booting-elasticsearch/353620 "2024-02-19T15:15:24Z")

</div>

elasticsearch-1 | {"@timestamp":"2024-02-19T12:02:08.108Z", "log.level":"ERROR", "message":"fatal exception while booting Elasticsearch", "ecs.version": "1.2.0","service.name":"ES\_ECS","event.dataset":"elasticsearch.serv…

---

## [Data tiers vs searchable snapshot \[platinum license elastic onprem\]](https://discuss.elastic.co/t/data-tiers-vs-searchable-snapshot-platinum-license-elastic-onprem/353541)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 14\
**Last updated:** [February 19, 2024, 3:07pm UTC](https://discuss.elastic.co/t/data-tiers-vs-searchable-snapshot-platinum-license-elastic-onprem/353541 "2024-02-19T15:07:58Z")

</div>

Hello team! I want to make use of the hot, warm, cold, frozen tiers for my onprem elastic deployment. I can see from this link that data tier is possible with platinum licensing. However I see 'searchable snapshots' ca…

---

## [Autoscaling](https://discuss.elastic.co/t/autoscaling/353616)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 0\
**Last updated:** [February 19, 2024, 2:59pm UTC](https://discuss.elastic.co/t/autoscaling/353616 "2024-02-19T14:59:40Z")

</div>

I see from documentation that elastic autoscaling works based on storage and there is no scaling available based on cpu. has anyone done scripting to automate scaling based on cpu?

---

## [Is there a way I can store recent data on partitions?](https://discuss.elastic.co/t/is-there-a-way-i-can-store-recent-data-on-partitions/353581)

<div class="topic-metadata">

**Author:** [@Ravi\_Pattar](https://discuss.elastic.co/u/Ravi_Pattar)\
**Replies:** 3\
**Last updated:** [February 19, 2024, 2:02pm UTC](https://discuss.elastic.co/t/is-there-a-way-i-can-store-recent-data-on-partitions/353581 "2024-02-19T14:02:12Z")

</div>

Hello, Is there a way so that I can have ELK keep say the last 50 or more GB on one partition and everything else on a different partition? In general I was thinking of putting all recent logs on SSD and after X age/tim…

---

## ['took' time fast, curl sometimes slow](https://discuss.elastic.co/t/took-time-fast-curl-sometimes-slow/353422)

<div class="topic-metadata">

**Author:** [@ryans](https://discuss.elastic.co/u/ryans)\
**Replies:** 6\
**Last updated:** [February 19, 2024, 1:59pm UTC](https://discuss.elastic.co/t/took-time-fast-curl-sometimes-slow/353422 "2024-02-19T13:59:04Z")

</div>

I am using Elastic Cloud for my Elasticsearch instance. My issue is that sometimes (rarely) I'm seeing strange behavior where the curl time (round trip from my web server to Elastic Cloud) is taking 8+ seconds but the '…

---

## [Histogram query over calculated field](https://discuss.elastic.co/t/histogram-query-over-calculated-field/353586)

<div class="topic-metadata">

**Author:** [@marinavictoria](https://discuss.elastic.co/u/marinavictoria)\
**Replies:** 0\
**Last updated:** [February 19, 2024, 12:22pm UTC](https://discuss.elastic.co/t/histogram-query-over-calculated-field/353586 "2024-02-19T12:22:42Z")

</div>

My case is the following: doc1: event.type (keyword): a doc2: event.type: aa doc3: event.type: aa doc4: event.type: aaaa I want to create a query that gives me in the Y axis the count of event.type and in the X …

---

## [Updating the documents through the Ingest Pipeline](https://discuss.elastic.co/t/updating-the-documents-through-the-ingest-pipeline/353583)

<div class="topic-metadata">

**Author:** [@ksaimohan2k](https://discuss.elastic.co/u/ksaimohan2k)\
**Replies:** 0\
**Last updated:** [February 19, 2024, 11:45am UTC](https://discuss.elastic.co/t/updating-the-documents-through-the-ingest-pipeline/353583 "2024-02-19T11:45:10Z")

</div>

Is there any way to update documents using the ingest pipeline? We are trying to ingest documents using a custom API through the Ingest pipeline. We are looking to identify the duplicate records. We used the "fingerprin…

---

## [CaptureBody invalid format](https://discuss.elastic.co/t/capturebody-invalid-format/353579)

<div class="topic-metadata">

**Author:** [@Kirtash](https://discuss.elastic.co/u/Kirtash)\
**Replies:** 0\
**Last updated:** [February 19, 2024, 11:36am UTC](https://discuss.elastic.co/t/capturebody-invalid-format/353579 "2024-02-19T11:36:32Z")

</div>

Good morning, I have updated the version of elasticstack to the version 8.12.0 and I capture the body in the APM transactions. But now the field http.request.body is different and appears the body inside the field "ori…

---

## [How to Handle Large Indices when non-time series data](https://discuss.elastic.co/t/how-to-handle-large-indices-when-non-time-series-data/353535)

<div class="topic-metadata">

**Author:** [@tusharnemade](https://discuss.elastic.co/u/tusharnemade)\
**Replies:** 4\
**Last updated:** [February 19, 2024, 10:30am UTC](https://discuss.elastic.co/t/how-to-handle-large-indices-when-non-time-series-data/353535 "2024-02-19T10:30:27Z")

</div>

Hello Everyone: We are using Elasticsearch v7.8.0 and some clusters of version 8.10.4. We are having Indices storing 40 millions of records in each , having shards -5 primary shards at the time of each index creation. …

---

## [\["org.apache.lucene.index.CorruptIndexException: checksum failed (hardware problem?)](https://discuss.elastic.co/t/org-apache-lucene-index-corruptindexexception-checksum-failed-hardware-problem/353558)

<div class="topic-metadata">

**Author:** [@Kesavan](https://discuss.elastic.co/u/Kesavan)\
**Replies:** 0\
**Last updated:** [February 19, 2024, 10:13am UTC](https://discuss.elastic.co/t/org-apache-lucene-index-corruptindexexception-checksum-failed-hardware-problem/353558 "2024-02-19T10:13:59Z")

</div>

We are facing the CorruptIndexException and also UnavailableShardsException in elastic log. In our system for all index the number of shards is 5. While QA testing we are facing the index elated exception below are the …

---

## [Reindex multiple downsampled indexes into one cause invalid start/end\_time](https://discuss.elastic.co/t/reindex-multiple-downsampled-indexes-into-one-cause-invalid-start-end-time/353546)

<div class="topic-metadata">

**Author:** [@VietDuc](https://discuss.elastic.co/u/VietDuc)\
**Replies:** 0\
**Last updated:** [February 19, 2024, 7:01am UTC](https://discuss.elastic.co/t/reindex-multiple-downsampled-indexes-into-one-cause-invalid-start-end-time/353546 "2024-02-19T07:01:41Z")

</div>

Hi Everyone, I have a TSDS index and already downsample many backing indexes. Now, i want to reindex some of my downsampled indexes into 1 index (to reduce number of backing index). While it is possible by using POST \_r…

---

## [Semantic search on help documents](https://discuss.elastic.co/t/semantic-search-on-help-documents/353468)

<div class="topic-metadata">

**Author:** [@9d224d4833094bd482cf](https://discuss.elastic.co/u/9d224d4833094bd482cf)\
**Replies:** 2\
**Last updated:** [February 19, 2024, 6:46am UTC](https://discuss.elastic.co/t/semantic-search-on-help-documents/353468 "2024-02-19T06:46:30Z")

</div>

Hello, We have a help documents on our website for our web application. This help documents on our websites are well documented (with text and images). It has a list of Topics and each topic has its own url with sub to…

---

## [Can the Snapshot Restore restores all my data just once](https://discuss.elastic.co/t/can-the-snapshot-restore-restores-all-my-data-just-once/353538)

<div class="topic-metadata">

**Author:** [@JasonREC](https://discuss.elastic.co/u/JasonREC)\
**Replies:** 2\
**Last updated:** [February 19, 2024, 6:31am UTC](https://discuss.elastic.co/t/can-the-snapshot-restore-restores-all-my-data-just-once/353538 "2024-02-19T06:31:43Z")

</div>

Hi I have a question about the snapshot restore mechanism, Senerio, I create an index, and it has data keep indexing in it and I have set the Elasticsearch to take snapshot once per night specficly for this index, let …

---

## [Why is segment not merged when deleted over 33%?](https://discuss.elastic.co/t/why-is-segment-not-merged-when-deleted-over-33/353537)

<div class="topic-metadata">

**Author:** [@missingcat92](https://discuss.elastic.co/u/missingcat92)\
**Replies:** 0\
**Last updated:** [February 19, 2024, 4:17am UTC](https://discuss.elastic.co/t/why-is-segment-not-merged-when-deleted-over-33/353537 "2024-02-19T04:17:38Z")

</div>

We have an ES v7.10 instance, and every config about merge is default. Now we have a segment, which include 37% deleted doc (docs.count=6513192,docs.deleted=3902050), the segment is now 4.8gb, and it's not merged for ab…

---

## [Understanding the Impacts of Manual Operations on Elasticsearch Indices Controlled by ILM](https://discuss.elastic.co/t/understanding-the-impacts-of-manual-operations-on-elasticsearch-indices-controlled-by-ilm/353531)

<div class="topic-metadata">

**Author:** [@gwapoo92](https://discuss.elastic.co/u/gwapoo92)\
**Replies:** 0\
**Last updated:** [February 19, 2024, 1:01am UTC](https://discuss.elastic.co/t/understanding-the-impacts-of-manual-operations-on-elasticsearch-indices-controlled-by-ilm/353531 "2024-02-19T01:01:40Z")

</div>

Hey Elasticsearch enthusiasts! I'm currently exploring the possibilities of implementing Index Lifecycle Management (ILM) in Elasticsearch. As I delve into this feature, a question has been lingering in my mind: What ha…

---

## [Sparse vector embeddings](https://discuss.elastic.co/t/sparse-vector-embeddings/353498)

<div class="topic-metadata">

**Author:** [@mwon](https://discuss.elastic.co/u/mwon)\
**Replies:** 4\
**Last updated:** [February 18, 2024, 3:40pm UTC](https://discuss.elastic.co/t/sparse-vector-embeddings/353498 "2024-02-18T15:40:50Z")

</div>

Hi, Is there any plan to re-introduce sparse vector fields? It was depreciated and there is this discussion about it. I would like to use sparse vectors to search by sparse vector embeddings. For example, I would like…

---

## [Elastic badrequest error: contains unrecognized parameter: \[type\]](https://discuss.elastic.co/t/elastic-badrequest-error-contains-unrecognized-parameter-type/353427)

<div class="topic-metadata">

**Author:** [@Vicapelli](https://discuss.elastic.co/u/Vicapelli)\
**Replies:** 4\
**Last updated:** [February 17, 2024, 9:45pm UTC](https://discuss.elastic.co/t/elastic-badrequest-error-contains-unrecognized-parameter-type/353427 "2024-02-17T21:45:37Z")

</div>

I am using Elasticsearch in a Rails application through the Elasticsearch-rails gem. After creating the indexes, I want to import the data into these indexes. But I am getting the following error: Elastic::Transport::T…

---

## [Elasticsearch Query: search result not same when am searching for wooden door and wooden doors](https://discuss.elastic.co/t/elasticsearch-query-search-result-not-same-when-am-searching-for-wooden-door-and-wooden-doors/353504)

<div class="topic-metadata">

**Author:** [@Mohan\_T](https://discuss.elastic.co/u/Mohan_T)\
**Replies:** 1\
**Last updated:** [February 17, 2024, 12:15pm UTC](https://discuss.elastic.co/t/elasticsearch-query-search-result-not-same-when-am-searching-for-wooden-door-and-wooden-doors/353504 "2024-02-17T12:15:25Z")

</div>

when am search for wooden door and wooden doors results not show the same. Query which i have used to fetch the data { "query": { "bool": { "should": \[ { "mat…

---

## [Elastic-filebeat-nginx-kibana-docker compose](https://discuss.elastic.co/t/elastic-filebeat-nginx-kibana-docker-compose/353457)

<div class="topic-metadata">

**Author:** [@v.popov](https://discuss.elastic.co/u/v.popov)\
**Replies:** 4\
**Last updated:** [February 16, 2024, 8:14pm UTC](https://discuss.elastic.co/t/elastic-filebeat-nginx-kibana-docker-compose/353457 "2024-02-16T20:14:53Z")

</div>

Попробуем сначала на русском. Всем привет, я работаю с Elastic через docker compose. У меня сейчас 2 вопроса: 1- Почему у меня огромное количество отдаваемых логов от nginx? После создания index filebeat-\* перехожу к л…

---

## [Add context to suggestions field while re-indexing](https://discuss.elastic.co/t/add-context-to-suggestions-field-while-re-indexing/353407)

<div class="topic-metadata">

**Author:** [@dat\_boi](https://discuss.elastic.co/u/dat_boi)\
**Replies:** 6\
**Last updated:** [February 16, 2024, 7:18pm UTC](https://discuss.elastic.co/t/add-context-to-suggestions-field-while-re-indexing/353407 "2024-02-16T19:18:25Z")

</div>

so i'v been trying to add suggester to my old index which had docs with the fields -name --\> text -category --\> long -status --\> long i created a new index with the same mapping as the old one and i add the suggestio…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=143)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=145)
