# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=146

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 147

---

## [Highlighting performance issues with stored field and fvh highlighter](https://discuss.elastic.co/t/highlighting-performance-issues-with-stored-field-and-fvh-highlighter/353240)

<div class="topic-metadata">

**Author:** [@jsfi](https://discuss.elastic.co/u/jsfi)\
**Replies:** 2\
**Last updated:** [February 14, 2024, 1:58pm UTC](https://discuss.elastic.co/t/highlighting-performance-issues-with-stored-field-and-fvh-highlighter/353240 "2024-02-14T13:58:42Z")

</div>

Hello, I'm having a very similar issue to Elastic query takes over 1 minute due to time spent in "HighlightPhase" I have documents with an optional attachments text field that for some documents can be quite big (up to…

---

## [Network Connections from ES Cluster](https://discuss.elastic.co/t/network-connections-from-es-cluster/353287)

<div class="topic-metadata">

**Author:** [@neophilipp](https://discuss.elastic.co/u/neophilipp)\
**Replies:** 0\
**Last updated:** [February 14, 2024, 1:44pm UTC](https://discuss.elastic.co/t/network-connections-from-es-cluster/353287 "2024-02-14T13:44:41Z")

</div>

Hi, i am relativ new with the ELK Stack. For Security Reasons I need to know, if there is a communication needed FROM Elasticsearch to Fleet Server, Kibana or something else in ELK Stack. We want put our ES Cluster in a…

---

## [\[.NET SDK v7\] IsValid vs ThrowExceptions and bulk](https://discuss.elastic.co/t/net-sdk-v7-isvalid-vs-throwexceptions-and-bulk/353281)

<div class="topic-metadata">

**Author:** [@mnj](https://discuss.elastic.co/u/mnj)\
**Replies:** 0\
**Last updated:** [February 14, 2024, 1:28pm UTC](https://discuss.elastic.co/t/net-sdk-v7-isvalid-vs-throwexceptions-and-bulk/353281 "2024-02-14T13:28:03Z")

</div>

The docs say: By default, the client won’t throw on any ElasticsearchClientException but instead return an invalid response that can be detected by checking the .IsValid property on the response. You can change this be…

---

## [Elasticsearch 7.17 Java RestHighLevelClient to Elasticsearch 8.10.0 server communication issue](https://discuss.elastic.co/t/elasticsearch-7-17-java-resthighlevelclient-to-elasticsearch-8-10-0-server-communication-issue/353048)

<div class="topic-metadata">

**Author:** [@Muthukumaran\_Kothand](https://discuss.elastic.co/u/Muthukumaran_Kothand)\
**Replies:** 2\
**Last updated:** [February 14, 2024, 9:16am UTC](https://discuss.elastic.co/t/elasticsearch-7-17-java-resthighlevelclient-to-elasticsearch-8-10-0-server-communication-issue/353048 "2024-02-14T09:16:41Z")

</div>

Hi, Since we have a large Java Client codebase, our migration to 8.x Java Client would take time and as intermediary solution, we are constrained to use Elasticsearch 7.17.x client in combination with 8.10.0 server I a…

---

## [Elasticsearch\[7.7\] Does not update data or takes time to update the data](https://discuss.elastic.co/t/elasticsearch-7-7-does-not-update-data-or-takes-time-to-update-the-data/353085)

<div class="topic-metadata">

**Author:** [@Akki\_Kulkarni](https://discuss.elastic.co/u/Akki_Kulkarni)\
**Replies:** 7\
**Last updated:** [February 14, 2024, 8:30am UTC](https://discuss.elastic.co/t/elasticsearch-7-7-does-not-update-data-or-takes-time-to-update-the-data/353085 "2024-02-14T08:30:27Z")

</div>

In my application, we are updating more than one document at a time for a index\_x. When queried for updated documents, it does not return updated data for few document, immediately. e.g. If I am updating 10 documents, 1 …

---

## [Ingest Rate in Elasticsearch is Slow](https://discuss.elastic.co/t/ingest-rate-in-elasticsearch-is-slow/352820)

<div class="topic-metadata">

**Author:** [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Replies:** 9\
**Last updated:** [February 14, 2024, 6:47am UTC](https://discuss.elastic.co/t/ingest-rate-in-elasticsearch-is-slow/352820 "2024-02-14T06:47:08Z")

</div>

Hi Team, We had scenario where we want to load 1 billion data to elastic cluster (consists of two node) and this process we are doing through filebeat process. As per Kibana dashboard we are checking it is below 5k/s . …

---

## [Data Ingestion in Elastic Search](https://discuss.elastic.co/t/data-ingestion-in-elastic-search/353189)

<div class="topic-metadata">

**Author:** [@fatima1](https://discuss.elastic.co/u/fatima1)\
**Replies:** 3\
**Last updated:** [February 14, 2024, 6:26am UTC](https://discuss.elastic.co/t/data-ingestion-in-elastic-search/353189 "2024-02-14T06:26:39Z")

</div>

Can someone provide guidance on the process of ingesting data into Elastic Search using Logstash from MongoDB and then visualizing it in Siren? I would appreciate any assistance or guidance on this matter. Thank you.

---

## [Multiple small Index vs Single Index](https://discuss.elastic.co/t/multiple-small-index-vs-single-index/353168)

<div class="topic-metadata">

**Author:** [@Lovin\_Saini](https://discuss.elastic.co/u/Lovin_Saini)\
**Replies:** 2\
**Last updated:** [February 14, 2024, 5:29am UTC](https://discuss.elastic.co/t/multiple-small-index-vs-single-index/353168 "2024-02-14T05:29:00Z")

</div>

We do have a use case of full text search of application data. There are many clients for which we are going to manage data. Total clients will be around 100 and client data size will be from 1 GB to 50 GB. Data will hav…

---

## [Connecting Logstash To Elasticsearch via SSL (Docker Container)](https://discuss.elastic.co/t/connecting-logstash-to-elasticsearch-via-ssl-docker-container/353221)

<div class="topic-metadata">

**Author:** [@Dhiwakar\_Ravikumar](https://discuss.elastic.co/u/Dhiwakar_Ravikumar)\
**Replies:** 0\
**Last updated:** [February 14, 2024, 4:29am UTC](https://discuss.elastic.co/t/connecting-logstash-to-elasticsearch-via-ssl-docker-container/353221 "2024-02-14T04:29:50Z")

</div>

My environment consists of 2 docker containers, one running Logstash and another running Elasticsearch on the SAME host & SAME docker network. I am trying to setup SSL between the 2 of them (this is because Elasticsearc…

---

## [Solving too\_many\_nested\_clauses with maxClauseCount set to 1024](https://discuss.elastic.co/t/solving-too-many-nested-clauses-with-maxclausecount-set-to-1024/353218)

<div class="topic-metadata">

**Author:** [@sreekanth\_makam](https://discuss.elastic.co/u/sreekanth_makam)\
**Replies:** 0\
**Last updated:** [February 14, 2024, 4:12am UTC](https://discuss.elastic.co/t/solving-too-many-nested-clauses-with-maxclausecount-set-to-1024/353218 "2024-02-14T04:12:18Z")

</div>

Hi Team, We are hitting below error and we understand that we are hitting this limit somewhere in our query. "too\_many\_nested\_clauses: Query contains too many nested clauses; maxClauseCount is set to 1024" Question: …

---

## [Sharepoint Online sync error](https://discuss.elastic.co/t/sharepoint-online-sync-error/352874)

<div class="topic-metadata">

**Author:** [@Sheida](https://discuss.elastic.co/u/Sheida)\
**Replies:** 3\
**Last updated:** [February 13, 2024, 4:00pm UTC](https://discuss.elastic.co/t/sharepoint-online-sync-error/352874 "2024-02-13T16:00:54Z")

</div>

I have elasticsearch integrated with sharepoint online via elasticserach connector. connector reads documents correctly. however, it encounters an object named "wte" and an error occurs. the description of this object …

---

## [Painless syntax doc inconsistancy](https://discuss.elastic.co/t/painless-syntax-doc-inconsistancy/353190)

<div class="topic-metadata">

**Author:** [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Replies:** 0\
**Last updated:** [February 13, 2024, 4:00pm UTC](https://discuss.elastic.co/t/painless-syntax-doc-inconsistancy/353190 "2024-02-13T16:00:21Z")

</div>

It's probably my lack of understanding, but in the doc document fields are sometimes referenced (top of link, in the conditional) as: doc\[item\] and other times (bottom of the linked page) as ctx.\_source.item It s…

---

## [Can I avoid elasticsearch monitoring index from moving to my temporary nodes?](https://discuss.elastic.co/t/can-i-avoid-elasticsearch-monitoring-index-from-moving-to-my-temporary-nodes/353128)

<div class="topic-metadata">

**Author:** [@Churchill](https://discuss.elastic.co/u/Churchill)\
**Replies:** 10\
**Last updated:** [February 13, 2024, 3:47pm UTC](https://discuss.elastic.co/t/can-i-avoid-elasticsearch-monitoring-index-from-moving-to-my-temporary-nodes/353128 "2024-02-13T15:47:15Z")

</div>

Good day, I'm currently maintaining a cluster with 4 permanent nodes and 3 temporary nodes. How it works is, during work hours, our temporary nodes will be started automatically, and will be shutdown after work hours. T…

---

## [Elastic query when executed from dev tools gives top 1 record, when same through logstash gives many record in Index](https://discuss.elastic.co/t/elastic-query-when-executed-from-dev-tools-gives-top-1-record-when-same-through-logstash-gives-many-record-in-index/353067)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 1\
**Last updated:** [February 13, 2024, 7:12am UTC](https://discuss.elastic.co/t/elastic-query-when-executed-from-dev-tools-gives-top-1-record-when-same-through-logstash-gives-many-record-in-index/353067 "2024-02-13T07:12:38Z")

</div>

Hello All, I am trying to send two fields from mis-monitoring-webserver to new index mis-monitoring-webui. Issue faced: This webserver index gets data every 10 seconds and from this my expectation is- I have written sp…

---

## [Timeout errors Elastic GitHub Workflow Runner](https://discuss.elastic.co/t/timeout-errors-elastic-github-workflow-runner/353064)

<div class="topic-metadata">

**Author:** [@christos-P](https://discuss.elastic.co/u/christos-P)\
**Replies:** 2\
**Last updated:** [February 13, 2024, 2:18pm UTC](https://discuss.elastic.co/t/timeout-errors-elastic-github-workflow-runner/353064 "2024-02-13T14:18:58Z")

</div>

Hi all, We have our code hosted in GitHub, and we utilize GitHub workflows for our CI/CD pipeline. On each push in a feature branch, based on a docker compose file , in which we describe two services, two services are s…

---

## [Data fs grows forever after full snapshot is taken](https://discuss.elastic.co/t/data-fs-grows-forever-after-full-snapshot-is-taken/353139)

<div class="topic-metadata">

**Author:** [@TinaMartiello](https://discuss.elastic.co/u/TinaMartiello)\
**Replies:** 4\
**Last updated:** [February 13, 2024, 1:10pm UTC](https://discuss.elastic.co/t/data-fs-grows-forever-after-full-snapshot-is-taken/353139 "2024-02-13T13:10:42Z")

</div>

Hi, we have 3 elasticsearch nodes, elasticsearch-8.11.1-1.x86\_64 and CentOS Linux release 7.3.1611 (Core) o.s. are installed on premis. We have very busy read/write systems. We are taking a full snapshot once a day, o…

---

## [Export/Import ES 7 to ES 8](https://discuss.elastic.co/t/export-import-es-7-to-es-8/353159)

<div class="topic-metadata">

**Author:** [@omegaziv](https://discuss.elastic.co/u/omegaziv)\
**Replies:** 1\
**Last updated:** [February 13, 2024, 1:03pm UTC](https://discuss.elastic.co/t/export-import-es-7-to-es-8/353159 "2024-02-13T13:03:12Z")

</div>

Hello. we have ES 7 with 3 GB of data. We will migrate to ES 8. and we are looking for the best way. is there an upgrade procedure without moving the data? we tried to export the data for later import - but it took o…

---

## [Downsampling policy](https://discuss.elastic.co/t/downsampling-policy/353106)

<div class="topic-metadata">

**Author:** [@noambe991](https://discuss.elastic.co/u/noambe991)\
**Replies:** 0\
**Last updated:** [February 12, 2024, 8:08pm UTC](https://discuss.elastic.co/t/downsampling-policy/353106 "2024-02-12T20:08:34Z")

</div>

Hello, I'm trying to define a policy for my time-series data stream as follows: "policy": { "phases": { "warm": { "min\_age": "0d", "actions": { "readonly": {}, …

---

## [Script.painless.regex.enabled: true Is not enough to disable limits](https://discuss.elastic.co/t/script-painless-regex-enabled-true-is-not-enough-to-disable-limits/353153)

<div class="topic-metadata">

**Author:** [@Saief](https://discuss.elastic.co/u/Saief)\
**Replies:** 0\
**Last updated:** [February 13, 2024, 10:49am UTC](https://discuss.elastic.co/t/script-painless-regex-enabled-true-is-not-enough-to-disable-limits/353153 "2024-02-13T10:49:42Z")

</div>

Hello, ES vesion : 8.12.0 I want to use scripting when search documents. I activated "script.painless.regex.enabled: true" in purpose to avoid limiting chars, But in my cluster settings, I still see : "painless":{"re…

---

## [Performance problem because of read IOPS increase](https://discuss.elastic.co/t/performance-problem-because-of-read-iops-increase/353074)

<div class="topic-metadata">

**Author:** [@jnegredo](https://discuss.elastic.co/u/jnegredo)\
**Replies:** 4\
**Last updated:** [February 13, 2024, 9:28am UTC](https://discuss.elastic.co/t/performance-problem-because-of-read-iops-increase/353074 "2024-02-13T09:28:55Z")

</div>

Hi, I've a elasticsearch cluster with 3 nodes (version 6.8.0). It's deployed on 3 virtual machines with 16GB RAM and 4 cores, in Google Cloud. Usually we have a lot more wirting IOPS than reading (40-50 vs 0-5) without …

---

## [Primary shard not available](https://discuss.elastic.co/t/primary-shard-not-available/352938)

<div class="topic-metadata">

**Author:** [@Manal\_A](https://discuss.elastic.co/u/Manal_A)\
**Replies:** 3\
**Last updated:** [February 12, 2024, 7:41pm UTC](https://discuss.elastic.co/t/primary-shard-not-available/352938 "2024-02-12T19:41:34Z")

</div>

Hi after i've receive disk full i try to remove some indices from this path: elasticsearch/indices/ after the status of the cluster become red and give below errors: is there any way to fix it please?

---

## [Sorting of classes while getting top 10 classes by each category using aggregation](https://discuss.elastic.co/t/sorting-of-classes-while-getting-top-10-classes-by-each-category-using-aggregation/352620)

<div class="topic-metadata">

**Author:** [@Vaibhav\_Vidhate](https://discuss.elastic.co/u/Vaibhav_Vidhate)\
**Replies:** 1\
**Last updated:** [February 12, 2024, 7:10pm UTC](https://discuss.elastic.co/t/sorting-of-classes-while-getting-top-10-classes-by-each-category-using-aggregation/352620 "2024-02-12T19:10:50Z")

</div>

We are using Elasticsearch for searching classes and showing a list of featured classes. Each class can have many categories assigned. For each class, sort order is defined within each category assigned. We need to ret…

---

## [.net client (8.12) converts params data properties to camelCase but i use PascalCase](https://discuss.elastic.co/t/net-client-8-12-converts-params-data-properties-to-camelcase-but-i-use-pascalcase/353101)

<div class="topic-metadata">

**Author:** [@Nazim\_Kirma](https://discuss.elastic.co/u/Nazim_Kirma)\
**Replies:** 0\
**Last updated:** [February 12, 2024, 7:05pm UTC](https://discuss.elastic.co/t/net-client-8-12-converts-params-data-properties-to-camelcase-but-i-use-pascalcase/353101 "2024-02-12T19:05:13Z")

</div>

Hi all, I use .net client to index my documents. I use nested field to update arrays and add new objects. I use the PascalCase configuration for Properties. This is my configuration : var node = new SingleNodePool(new…

---

## [Moving shapshot between computers (again)](https://discuss.elastic.co/t/moving-shapshot-between-computers-again/352963)

<div class="topic-metadata">

**Author:** [@kwalcock](https://discuss.elastic.co/u/kwalcock)\
**Replies:** 7\
**Last updated:** [February 12, 2024, 6:43pm UTC](https://discuss.elastic.co/t/moving-shapshot-between-computers-again/352963 "2024-02-12T18:43:11Z")

</div>

I know things like this have been discussed here, but I do not find any complete answer that matches the situation or what I observe on the screen, so I have to ask again. If I make a snapshot of an index on one compute…

---

## [Massive index compression](https://discuss.elastic.co/t/massive-index-compression/352926)

<div class="topic-metadata">

**Author:** [@revelc33](https://discuss.elastic.co/u/revelc33)\
**Replies:** 10\
**Last updated:** [February 12, 2024, 5:47pm UTC](https://discuss.elastic.co/t/massive-index-compression/352926 "2024-02-12T17:47:29Z")

</div>

How can I easily compress 140 indices (some of which are up to 100 GB)? I have tried closing the indices, changing the codec to 'best\_compression,' and then executing a forcemerge on the index. The forcemerge task fi…

---

## [Get available fields in index](https://discuss.elastic.co/t/get-available-fields-in-index/353091)

<div class="topic-metadata">

**Author:** [@kaismax](https://discuss.elastic.co/u/kaismax)\
**Replies:** 0\
**Last updated:** [February 12, 2024, 5:08pm UTC](https://discuss.elastic.co/t/get-available-fields-in-index/353091 "2024-02-12T17:08:29Z")

</div>

Hello, community, I want to get the available fields from an index, like taking the last 500 documents and returning a list of non-null fields. thanks.

---

## [Shape mapping, only return certain type(s) on a query](https://discuss.elastic.co/t/shape-mapping-only-return-certain-type-s-on-a-query/352552)

<div class="topic-metadata">

**Author:** [@paul5](https://discuss.elastic.co/u/paul5)\
**Replies:** 8\
**Last updated:** [February 12, 2024, 1:23pm UTC](https://discuss.elastic.co/t/shape-mapping-only-return-certain-type-s-on-a-query/352552 "2024-02-12T13:23:39Z")

</div>

I don't see a way for a query on mapping type shape to only return certain shapes. Something like this: POST /example/\_doc { "location" : { "type" : "point", "coordinates" : \[-377.03653, 389.897676\] }, "ret…

---

## [Update security certificates with a different CA](https://discuss.elastic.co/t/update-security-certificates-with-a-different-ca/352766)

<div class="topic-metadata">

**Author:** [@amitjadhav0384](https://discuss.elastic.co/u/amitjadhav0384)\
**Replies:** 5\
**Last updated:** [February 12, 2024, 1:00pm UTC](https://discuss.elastic.co/t/update-security-certificates-with-a-different-ca/352766 "2024-02-12T13:00:53Z")

</div>

I am trying to update new CA which are signed using trusted source given by our organization. ./bin/elasticsearch-certutil cert --ca-cert ca/ca.crt --ca-key ca/ca.key While trying to create new certificate using the ab…

---

## [Alerts to ServiceNow Generic Pipeline](https://discuss.elastic.co/t/alerts-to-servicenow-generic-pipeline/352631)

<div class="topic-metadata">

**Author:** [@sajmeister](https://discuss.elastic.co/u/sajmeister)\
**Replies:** 4\
**Last updated:** [February 12, 2024, 12:50pm UTC](https://discuss.elastic.co/t/alerts-to-servicenow-generic-pipeline/352631 "2024-02-12T12:50:48Z")

</div>

Hi, We use the free edition of Elasticsearch and don't use watchers. Would like to know is there a generic pipeline code that can be used to send alerts to ServiceNow ? If yes, please provide code so can test it. Che…

---

## [Elasticsearch Enterprise On-Prem Licensing details](https://discuss.elastic.co/t/elasticsearch-enterprise-on-prem-licensing-details/353057)

<div class="topic-metadata">

**Author:** [@Rehmat](https://discuss.elastic.co/u/Rehmat)\
**Replies:** 4\
**Last updated:** [February 12, 2024, 12:23pm UTC](https://discuss.elastic.co/t/elasticsearch-enterprise-on-prem-licensing-details/353057 "2024-02-12T12:23:56Z")

</div>

Hi Everyone, can someone share some detail about Elasticsearch Enterprise License On-Prem, will allow how many nodes, cluster, storage capacity per bare-metal node/vm, CPU/RAM ? thanks in advance

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=145)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=147)
