# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=145

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 146

---

## [Very High Cpu Usage for search](https://discuss.elastic.co/t/very-high-cpu-usage-for-search/352110)

<div class="topic-metadata">

**Author:** [@bharat\_bhushan\_ship](https://discuss.elastic.co/u/bharat_bhushan_ship)\
**Replies:** 8\
**Last updated:** [February 16, 2024, 6:14pm UTC](https://discuss.elastic.co/t/very-high-cpu-usage-for-search/352110 "2024-02-16T18:14:44Z")

</div>

I have a cluster (ES version 7.0.3) with 3 nodes with ubuntu servers and i have not declare any node as a master or data node, by default it elect one master and other data nodes itself. And i have only one index on this…

---

## [Elastic agent an system Integrations generate infinite void indixes with infinite rollover](https://discuss.elastic.co/t/elastic-agent-an-system-integrations-generate-infinite-void-indixes-with-infinite-rollover/353478)

<div class="topic-metadata">

**Author:** [@hectorGC](https://discuss.elastic.co/u/hectorGC)\
**Replies:** 0\
**Last updated:** [February 16, 2024, 3:36pm UTC](https://discuss.elastic.co/t/elastic-agent-an-system-integrations-generate-infinite-void-indixes-with-infinite-rollover/353478 "2024-02-16T15:36:00Z")

</div>

Suddenly after normal work of the team we suffered a big amount of metrics logs, looking at that we discovered that the integrations of elastic-agent and system indexes started to make rollover of all namespaces. Continu…

---

## [Once Filebeat/Elasticsearch has ingested log files, can the logs themselves be deleted?](https://discuss.elastic.co/t/once-filebeat-elasticsearch-has-ingested-log-files-can-the-logs-themselves-be-deleted/353473)

<div class="topic-metadata">

**Author:** [@artschooldropout](https://discuss.elastic.co/u/artschooldropout)\
**Replies:** 2\
**Last updated:** [February 16, 2024, 2:49pm UTC](https://discuss.elastic.co/t/once-filebeat-elasticsearch-has-ingested-log-files-can-the-logs-themselves-be-deleted/353473 "2024-02-16T14:49:37Z")

</div>

I'm using Filebeat/Elasticsearch to index Zeek network traffic logs. I'm missing a key piece of understanding about Filebeat/Elasticsearch. Once the logs have been ingested and indexed, are the logs themselves accessed t…

---

## [When filebeat logs are deleted, does this delete Elasticsearch indices?](https://discuss.elastic.co/t/when-filebeat-logs-are-deleted-does-this-delete-elasticsearch-indices/353408)

<div class="topic-metadata">

**Author:** [@artschooldropout](https://discuss.elastic.co/u/artschooldropout)\
**Replies:** 5\
**Last updated:** [February 16, 2024, 2:21pm UTC](https://discuss.elastic.co/t/when-filebeat-logs-are-deleted-does-this-delete-elasticsearch-indices/353408 "2024-02-16T14:21:52Z")

</div>

I have an elasticsearch cluster which ingests logs from Filebeat. I'm trying to limit the total size of the indices. If I delete the raw files that filebeat is ingesting, will the corresponding Elasticsearch indices be d…

---

## [Very uneven distribution of docs accross shards](https://discuss.elastic.co/t/very-uneven-distribution-of-docs-accross-shards/353463)

<div class="topic-metadata">

**Author:** [@Emil](https://discuss.elastic.co/u/Emil)\
**Replies:** 8\
**Last updated:** [February 16, 2024, 1:30pm UTC](https://discuss.elastic.co/t/very-uneven-distribution-of-docs-accross-shards/353463 "2024-02-16T13:30:44Z")

</div>

We've been indexing documents to an index with 20 primary shards, but the shards have grown to have uneven sizes (smallest is 3.2 GB, largest 31.7GB, so 10 times as large) Investigating, I found out that while the total…

---

## [Elastic Search 2.4.1 Windows Service](https://discuss.elastic.co/t/elastic-search-2-4-1-windows-service/353453)

<div class="topic-metadata">

**Author:** [@Franco.dicarlo](https://discuss.elastic.co/u/Franco.dicarlo)\
**Replies:** 1\
**Last updated:** [February 16, 2024, 12:46pm UTC](https://discuss.elastic.co/t/elastic-search-2-4-1-windows-service/353453 "2024-02-16T12:46:23Z")

</div>

Hi to all, I have a 2.4.1 Elastic Search installed as a service on a windows server. I was working with ES in c#, I was trying to delete items in a specific index. Unfortunately I deleted more data than necessary,I im…

---

## [Master not discovered or elected yet, when stopping Elasticsearch service](https://discuss.elastic.co/t/master-not-discovered-or-elected-yet-when-stopping-elasticsearch-service/353377)

<div class="topic-metadata">

**Author:** [@andrejze](https://discuss.elastic.co/u/andrejze)\
**Replies:** 18\
**Last updated:** [February 16, 2024, 12:45pm UTC](https://discuss.elastic.co/t/master-not-discovered-or-elected-yet-when-stopping-elasticsearch-service/353377 "2024-02-16T12:45:50Z")

</div>

OS: Debian 10 (buster), 4.19.0-25-amd64 #1 SMP Debian 4.19.289-2 (2023-08-08) Elasticsearch: 8.12.0 Cluster: 3 nodes, all master eligible When stopping Elasticsearch service on any node, operation gets stuck with err…

---

## [Can we add two differen types of visulization in one visulization only?](https://discuss.elastic.co/t/can-we-add-two-differen-types-of-visulization-in-one-visulization-only/353366)

<div class="topic-metadata">

**Author:** [@2328943\_dc](https://discuss.elastic.co/u/2328943_dc)\
**Replies:** 3\
**Last updated:** [February 16, 2024, 5:51am UTC](https://discuss.elastic.co/t/can-we-add-two-differen-types-of-visulization-in-one-visulization-only/353366 "2024-02-16T05:51:57Z")

</div>

Hi, is it possible in KIBANA To add two different types of visualization in one visualization only ? For example : can we combine data table and line graph in one visualization ?

---

## [Exclude field from request if it is empty](https://discuss.elastic.co/t/exclude-field-from-request-if-it-is-empty/353410)

<div class="topic-metadata">

**Author:** [@rijexe9501](https://discuss.elastic.co/u/rijexe9501)\
**Replies:** 0\
**Last updated:** [February 15, 2024, 8:57pm UTC](https://discuss.elastic.co/t/exclude-field-from-request-if-it-is-empty/353410 "2024-02-15T20:57:21Z")

</div>

Hi all. Please tell me, I have a request like this (request 1) and if field2 in it is empty, then I want to exclude it from the selection so that a request like this will be executed (request 2). How can I do this? Requ…

---

## [100% io utilization after migrating to XFS from EXT4](https://discuss.elastic.co/t/100-io-utilization-after-migrating-to-xfs-from-ext4/353404)

<div class="topic-metadata">

**Author:** [@Brandon\_Kauffman](https://discuss.elastic.co/u/Brandon_Kauffman)\
**Replies:** 1\
**Last updated:** [February 15, 2024, 5:36pm UTC](https://discuss.elastic.co/t/100-io-utilization-after-migrating-to-xfs-from-ext4/353404 "2024-02-15T17:36:36Z")

</div>

We recently switched from EXT4 to XFS in an upgrade from rhel7 to 9. Both were using LVM and RAID-0. We noticed that IO utilization stays near 100% Before it was near 30% That being said, disk performance seems to …

---

## [Elasticsearch Alerts Timing Edge Case](https://discuss.elastic.co/t/elasticsearch-alerts-timing-edge-case/353400)

<div class="topic-metadata">

**Author:** [@spatel68](https://discuss.elastic.co/u/spatel68)\
**Replies:** 0\
**Last updated:** [February 15, 2024, 4:45pm UTC](https://discuss.elastic.co/t/elasticsearch-alerts-timing-edge-case/353400 "2024-02-15T16:45:10Z")

</div>

We’re currently using Elasticsearch Alerts to get notified for the number of documents that were ingested each minute. The alert runs on an interval of 1m. We were concerned about timing edge cases since this could lead …

---

## [ElasticSearch creating new index is unassigned even though it says that it can allocate](https://discuss.elastic.co/t/elasticsearch-creating-new-index-is-unassigned-even-though-it-says-that-it-can-allocate/353374)

<div class="topic-metadata">

**Author:** [@ChrisWohlert](https://discuss.elastic.co/u/ChrisWohlert)\
**Replies:** 0\
**Last updated:** [February 15, 2024, 1:16pm UTC](https://discuss.elastic.co/t/elasticsearch-creating-new-index-is-unassigned-even-though-it-says-that-it-can-allocate/353374 "2024-02-15T13:16:26Z")

</div>

We have a setup running ECK in AWS running version 8.10.2. Any attempt to create an index results in the shards not being assigned. I can manually assign them, but that is not a solution. GET \_cat/shards?v=true&h=index,…

---

## [Update by query in ES with option conflicts=proceed](https://discuss.elastic.co/t/update-by-query-in-es-with-option-conflicts-proceed/353169)

<div class="topic-metadata">

**Author:** [@sdv](https://discuss.elastic.co/u/sdv)\
**Replies:** 1\
**Last updated:** [February 15, 2024, 12:58pm UTC](https://discuss.elastic.co/t/update-by-query-in-es-with-option-conflicts-proceed/353169 "2024-02-15T12:58:54Z")

</div>

Hi Team, I have below two questions for 'update\_by\_query' API with option 'conflicts=proceed'. Basically if we allow processing documents with 'conflicts=proceed' option and still have a retry based on 'VersionConfli…

---

## [Kibana won't up](https://discuss.elastic.co/t/kibana-wont-up/352648)

<div class="topic-metadata">

**Author:** [@sanjeev1895](https://discuss.elastic.co/u/sanjeev1895)\
**Replies:** 4\
**Last updated:** [February 15, 2024, 12:19pm UTC](https://discuss.elastic.co/t/kibana-wont-up/352648 "2024-02-15T12:19:49Z")

</div>

Hi, few month back I was configured the elk stack on aws ubuntu instance and it's works fine without any issue. But due to some VPC related reason, I was taken the AMI from that elk stack instance and launched the new i…

---

## [Moving avg counts](https://discuss.elastic.co/t/moving-avg-counts/353367)

<div class="topic-metadata">

**Author:** [@2328943\_dc](https://discuss.elastic.co/u/2328943_dc)\
**Replies:** 1\
**Last updated:** [February 15, 2024, 12:13pm UTC](https://discuss.elastic.co/t/moving-avg-counts/353367 "2024-02-15T12:13:39Z")

</div>

we have created visualization to fetch counts average count but as attached in screenshot for in place of highlighted field we want previous timeframes average count so,...is it possible to find count lik this?

---

## [Array in Response](https://discuss.elastic.co/t/array-in-response/353334)

<div class="topic-metadata">

**Author:** [@Shreya\_Chandak](https://discuss.elastic.co/u/Shreya_Chandak)\
**Replies:** 1\
**Last updated:** [February 15, 2024, 11:04am UTC](https://discuss.elastic.co/t/array-in-response/353334 "2024-02-15T11:04:06Z")

</div>

Hello Community , I am new to querying elastic , there is a requirement -\> I have logs on elk with field names request(string) and average response time (Number) , I want to first specify a date\_range in query and find …

---

## [S3 compatible with repository\_verification\_exception](https://discuss.elastic.co/t/s3-compatible-with-repository-verification-exception/353360)

<div class="topic-metadata">

**Author:** [@Omizollo](https://discuss.elastic.co/u/Omizollo)\
**Replies:** 0\
**Last updated:** [February 15, 2024, 10:31am UTC](https://discuss.elastic.co/t/s3-compatible-with-repository-verification-exception/353360 "2024-02-15T10:31:32Z")

</div>

I have a custom s3 storage which I can communicate with using AWS sdk. I have configured the repository with Elasticsearch v7.17 and it is working fine, but after upgrade to the version v8.11 the verification to the repo…

---

## [Shard routing while active indexing](https://discuss.elastic.co/t/shard-routing-while-active-indexing/353326)

<div class="topic-metadata">

**Author:** [@Prashant\_Rana](https://discuss.elastic.co/u/Prashant_Rana)\
**Replies:** 3\
**Last updated:** [February 15, 2024, 10:27am UTC](https://discuss.elastic.co/t/shard-routing-while-active-indexing/353326 "2024-02-15T10:27:06Z")

</div>

What happens if I explicitly route a shard to a different node while the indexing happens to that shard in the original shard? Should I stop indexing in that shard?

---

## [Cluster.initial\_master\_nodes Settings](https://discuss.elastic.co/t/cluster-initial-master-nodes-settings/353303)

<div class="topic-metadata">

**Author:** [@pras](https://discuss.elastic.co/u/pras)\
**Replies:** 2\
**Last updated:** [February 15, 2024, 8:25am UTC](https://discuss.elastic.co/t/cluster-initial-master-nodes-settings/353303 "2024-02-15T08:25:46Z")

</div>

Hi guys I have three node cluster using Elastic 8.6. It is in operation for more than a year. We are going to upgrade to 8.8 soon. I this regard I have a question on cluster.initial\_master\_nodes setting. This setting is…

---

## [Elasticsearch and Kibana upgrade to v8.12.0 from v8.0.0](https://discuss.elastic.co/t/elasticsearch-and-kibana-upgrade-to-v8-12-0-from-v8-0-0/353170)

<div class="topic-metadata">

**Author:** [@Gaurav\_kr](https://discuss.elastic.co/u/Gaurav_kr)\
**Replies:** 3\
**Last updated:** [February 15, 2024, 8:18am UTC](https://discuss.elastic.co/t/elasticsearch-and-kibana-upgrade-to-v8-12-0-from-v8-0-0/353170 "2024-02-15T08:18:45Z")

</div>

Hi Team, We are planning to upgrade elasticsearch and Kibana to v8.12.0 from v8.0.0 For beats and ELK communication wea re using ssl true and we are using API key in yaml file of beats like metricbeat. Wanted to know …

---

## [Create ILM on the timestamp field](https://discuss.elastic.co/t/create-ilm-on-the-timestamp-field/353172)

<div class="topic-metadata">

**Author:** [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Replies:** 4\
**Last updated:** [February 15, 2024, 7:12am UTC](https://discuss.elastic.co/t/create-ilm-on-the-timestamp-field/353172 "2024-02-15T07:12:52Z")

</div>

Hi Team, I want to create a ILM on the timestamp field (which received as field in the log file itself as epoch time). So I want create the ILM on basis of that field. Could you please let me know how we can achieve the…

---

## [Why my query cannot return any result althought the key exist in the message](https://discuss.elastic.co/t/why-my-query-cannot-return-any-result-althought-the-key-exist-in-the-message/353330)

<div class="topic-metadata">

**Author:** [@baber1223](https://discuss.elastic.co/u/baber1223)\
**Replies:** 1\
**Last updated:** [February 15, 2024, 6:44am UTC](https://discuss.elastic.co/t/why-my-query-cannot-return-any-result-althought-the-key-exist-in-the-message/353330 "2024-02-15T06:44:21Z")

</div>

Dear Hi This is my log sample \<log realm="channel/192.168.20.10:61615" at="2024-02-14T15:25:04.930" lifespan="383ms"\> \<receive\> \<isomsg direction="incoming"\> \<!-- com.middle.gateway.packager.ShetabISO87APa…

---

## [Question about ILM Delete phrase](https://discuss.elastic.co/t/question-about-ilm-delete-phrase/353319)

<div class="topic-metadata">

**Author:** [@JasonREC](https://discuss.elastic.co/u/JasonREC)\
**Replies:** 0\
**Last updated:** [February 15, 2024, 3:14am UTC](https://discuss.elastic.co/t/question-about-ilm-delete-phrase/353319 "2024-02-15T03:14:50Z")

</div>

Hi, I have a question about the delete phrase in ILM. I have the ILM policy set when the max 15gb limit is reached in the primary shard then do the roll over and then I want that index to be completely deleted after 3 m…

---

## [Can I use these step to generate elastic search root-ca.pem](https://discuss.elastic.co/t/can-i-use-these-step-to-generate-elastic-search-root-ca-pem/353238)

<div class="topic-metadata">

**Author:** [@fahim2024](https://discuss.elastic.co/u/fahim2024)\
**Replies:** 1\
**Last updated:** [February 15, 2024, 1:20am UTC](https://discuss.elastic.co/t/can-i-use-these-step-to-generate-elastic-search-root-ca-pem/353238 "2024-02-15T01:20:02Z")

</div>

./elasticsearch-certutil ca ./elasticsearch-certutil cert --ca elastic-stack-ca.p12 openssl pkcs12 -in elastic-certificates.p12 -clcerts -nokeys -out certificate.pem openssl pkcs12 -in elastic-certificates.p12 -nocert…

---

## [Mimecast integration no longer ingesting siem logs](https://discuss.elastic.co/t/mimecast-integration-no-longer-ingesting-siem-logs/353192)

<div class="topic-metadata">

**Author:** [@jeffmaley](https://discuss.elastic.co/u/jeffmaley)\
**Replies:** 1\
**Last updated:** [February 14, 2024, 5:27pm UTC](https://discuss.elastic.co/t/mimecast-integration-no-longer-ingesting-siem-logs/353192 "2024-02-14T17:27:51Z")

</div>

I'm using the Mimecast integration and it's suddenly stopped ingesting the siem logs. The logs on the elastic agent indicate that events are being published, but they are not showing up in the index in ELK. Has anyone ru…

---

## [Top\_hits sort within the nested bucket](https://discuss.elastic.co/t/top-hits-sort-within-the-nested-bucket/353302)

<div class="topic-metadata">

**Author:** [@mavwolverine](https://discuss.elastic.co/u/mavwolverine)\
**Replies:** 0\
**Last updated:** [February 14, 2024, 5:16pm UTC](https://discuss.elastic.co/t/top-hits-sort-within-the-nested-bucket/353302 "2024-02-14T17:16:45Z")

</div>

document has categories array with \[{"categoryId": 123, "sortOrder": 456},{"categoryId": 124, "sortOrder": 12}\] Used terms to create buckets on categoryId, now I want to sort using sortOrder inside each bucket for that …

---

## [Creating a second index with subset of fields from first index](https://discuss.elastic.co/t/creating-a-second-index-with-subset-of-fields-from-first-index/353265)

<div class="topic-metadata">

**Author:** [@yago82](https://discuss.elastic.co/u/yago82)\
**Replies:** 2\
**Last updated:** [February 14, 2024, 4:15pm UTC](https://discuss.elastic.co/t/creating-a-second-index-with-subset-of-fields-from-first-index/353265 "2024-02-14T16:15:55Z")

</div>

Hello Elastic community, I'm seeking advice on how to efficiently create a second index containing only a subset of fields from a primary index based on certain conditions. To provide some context, let's say I have a p…

---

## [Elastic search server do not respond on curl request](https://discuss.elastic.co/t/elastic-search-server-do-not-respond-on-curl-request/353258)

<div class="topic-metadata">

**Author:** [@Shahram](https://discuss.elastic.co/u/Shahram)\
**Replies:** 3\
**Last updated:** [February 14, 2024, 4:05pm UTC](https://discuss.elastic.co/t/elastic-search-server-do-not-respond-on-curl-request/353258 "2024-02-14T16:05:22Z")

</div>

I noticed my Elasticsearch could not be accessible via curl, so I started from scratch on a new vm. I used this config file for docker-compose.yml: version: '3.6' services: Elasticsearch: image: elasticsearch:7.1…

---

## [Delete\_by\_query returns empty](https://discuss.elastic.co/t/delete-by-query-returns-empty/353294)

<div class="topic-metadata">

**Author:** [@rachelyang](https://discuss.elastic.co/u/rachelyang)\
**Replies:** 1\
**Last updated:** [February 14, 2024, 4:01pm UTC](https://discuss.elastic.co/t/delete-by-query-returns-empty/353294 "2024-02-14T16:01:05Z")

</div>

I try to delete the old records in my index, but the delete\_by\_query returns empty to me. I have a lot of data in the index, it should not be zero. Please help me to check where the problem is. Thank you! Here is my cur…

---

## [Size of the facet in the query affects the number of results of specific facet](https://discuss.elastic.co/t/size-of-the-facet-in-the-query-affects-the-number-of-results-of-specific-facet/353296)

<div class="topic-metadata">

**Author:** [@Daniel\_Botran\_Quiros](https://discuss.elastic.co/u/Daniel_Botran_Quiros)\
**Replies:** 0\
**Last updated:** [February 14, 2024, 3:51pm UTC](https://discuss.elastic.co/t/size-of-the-facet-in-the-query-affects-the-number-of-results-of-specific-facet/353296 "2024-02-14T15:51:27Z")

</div>

Hello, I am implementing App Search for an e-commerce, and I've just realized that the size of the facet in the queries affects to certain counts in the response. My query is like this: { "query": "galletas", "pa…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=144)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=146)
