# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=148

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 149

---

## [Shrink do not proceed because of number of shard filter](https://discuss.elastic.co/t/shrink-do-not-proceed-because-of-number-of-shard-filter/352861)

<div class="topic-metadata">

**Author:** [@Teoman\_Sevinc](https://discuss.elastic.co/u/Teoman_Sevinc)\
**Replies:** 3\
**Last updated:** [February 8, 2024, 3:27pm UTC](https://discuss.elastic.co/t/shrink-do-not-proceed-because-of-number-of-shard-filter/352861 "2024-02-08T15:27:37Z")

</div>

Hi Community, I'm trying to shrink my indices with a curator. This is my action.yml content: actions: 1: action: shrink description: "Shrink indices starting with mylog older than two days" options: …

---

## [Lifecycle is not workin - no errors](https://discuss.elastic.co/t/lifecycle-is-not-workin-no-errors/352875)

<div class="topic-metadata">

**Author:** [@Nathan\_Borik1](https://discuss.elastic.co/u/Nathan_Borik1)\
**Replies:** 0\
**Last updated:** [February 8, 2024, 3:25pm UTC](https://discuss.elastic.co/t/lifecycle-is-not-workin-no-errors/352875 "2024-02-08T15:25:51Z")

</div>

Elastic version 7.17.1 Looks like all the settings are ok, no errors but the lifecycle is not running. Not moving to warm or cold and no deletion as specified in the Index Lifecycle Policies. { "lx-logs-be-01" : { …

---

## [Shard allocated / total](https://discuss.elastic.co/t/shard-allocated-total/352868)

<div class="topic-metadata">

**Author:** [@Samuele\_Lolli](https://discuss.elastic.co/u/Samuele_Lolli)\
**Replies:** 0\
**Last updated:** [February 8, 2024, 2:02pm UTC](https://discuss.elastic.co/t/shard-allocated-total/352868 "2024-02-08T14:02:30Z")

</div>

Hi everyone, im doing some check on my system and im analyzing the number of shard on my deployment. Im using two "command" to check how many shard im using. With the command GET /\_stats?level=cluster&filter\_path=\_sh…

---

## [Using Elastic Search Latest Version Throw Exception](https://discuss.elastic.co/t/using-elastic-search-latest-version-throw-exception/352739)

<div class="topic-metadata">

**Author:** [@GANESHAN\_RAMAN](https://discuss.elastic.co/u/GANESHAN_RAMAN)\
**Replies:** 3\
**Last updated:** [February 8, 2024, 1:54pm UTC](https://discuss.elastic.co/t/using-elastic-search-latest-version-throw-exception/352739 "2024-02-08T13:54:50Z")

</div>

Hi, My application with Elasticsearch was working fine until Elasticsearch version 7.17.9, As there is a vulnerability issue with this version as reported by black duck i changed to the recent version 8.12.0, Once i c…

---

## [How Can I generate Root-ca.pem for Elasticsearch for integrating with wazuh](https://discuss.elastic.co/t/how-can-i-generate-root-ca-pem-for-elasticsearch-for-integrating-with-wazuh/352835)

<div class="topic-metadata">

**Author:** [@fahim2024](https://discuss.elastic.co/u/fahim2024)\
**Replies:** 3\
**Last updated:** [February 8, 2024, 1:28pm UTC](https://discuss.elastic.co/t/how-can-i-generate-root-ca-pem-for-elasticsearch-for-integrating-with-wazuh/352835 "2024-02-08T13:28:00Z")

</div>

It would be great if someone help me with step by step guidance with explanation

---

## [Slowness in Kibana and high CPU utilization usage](https://discuss.elastic.co/t/slowness-in-kibana-and-high-cpu-utilization-usage/352824)

<div class="topic-metadata">

**Author:** [@Seemant\_Bind](https://discuss.elastic.co/u/Seemant_Bind)\
**Replies:** 8\
**Last updated:** [February 8, 2024, 1:26pm UTC](https://discuss.elastic.co/t/slowness-in-kibana-and-high-cpu-utilization-usage/352824 "2024-02-08T13:26:55Z")

</div>

Hi, I am facing slowness in Kibana Production. Discover and dashboard is taking too much time to load and sometimes getting the error as shown in the first screenshot. I checked the cluster status from the stack mon…

---

## [Multiple Inner\_hit on knn](https://discuss.elastic.co/t/multiple-inner-hit-on-knn/351893)

<div class="topic-metadata">

**Author:** [@Tommaso\_FAVARON](https://discuss.elastic.co/u/Tommaso_FAVARON)\
**Replies:** 4\
**Last updated:** [February 8, 2024, 1:11pm UTC](https://discuss.elastic.co/t/multiple-inner-hit-on-knn/351893 "2024-02-08T13:11:35Z")

</div>

here my index mapping: { "chunker2": { "aliases": {}, "mappings": { "properties": { "creation\_time": { "type": "date" }, "full\_text": { "type": "text" …

---

## [How to setup a multi-node elasticsearch cluster in separate machines with ip specified in docker-compose.yml](https://discuss.elastic.co/t/how-to-setup-a-multi-node-elasticsearch-cluster-in-separate-machines-with-ip-specified-in-docker-compose-yml/352854)

<div class="topic-metadata">

**Author:** [@elasticheart](https://discuss.elastic.co/u/elasticheart)\
**Replies:** 1\
**Last updated:** [February 8, 2024, 12:12pm UTC](https://discuss.elastic.co/t/how-to-setup-a-multi-node-elasticsearch-cluster-in-separate-machines-with-ip-specified-in-docker-compose-yml/352854 "2024-02-08T12:12:15Z")

</div>

Hi guys, I would like to setup a multi-node elasticsearch v8.11.4 cluster using docker compose, "not in a single machine / host". I have 3 machines with IP 192.168.0.101, 192.168.0.102 and 192.168.0.103, and I want my …

---

## [Cannot build logstash-output-elasticsearch plugin locally](https://discuss.elastic.co/t/cannot-build-logstash-output-elasticsearch-plugin-locally/352845)

<div class="topic-metadata">

**Author:** [@amaciejk](https://discuss.elastic.co/u/amaciejk)\
**Replies:** 0\
**Last updated:** [February 8, 2024, 9:57am UTC](https://discuss.elastic.co/t/cannot-build-logstash-output-elasticsearch-plugin-locally/352845 "2024-02-08T09:57:03Z")

</div>

I'm attempting to build this plugin locally: However it fails seemingly due to a gemspec dependency issue: logstash-output-elasticsearch % jruby -S bundle install Fetching gem metadata from https://rubygems.org/.....…

---

## [Reindex vs Split Speed and Storage Requirements](https://discuss.elastic.co/t/reindex-vs-split-speed-and-storage-requirements/352719)

<div class="topic-metadata">

**Author:** [@zalseryani](https://discuss.elastic.co/u/zalseryani)\
**Replies:** 1\
**Last updated:** [February 8, 2024, 9:43am UTC](https://discuss.elastic.co/t/reindex-vs-split-speed-and-storage-requirements/352719 "2024-02-08T09:43:06Z")

</div>

I have seen a previous topic discussing the difference in speed between reindexing and splitting for an index Reindex vs Split index speeds if splitting is much faster than reindexing since it is hard-linking the under…

---

## [Aggregation with script code with previous result](https://discuss.elastic.co/t/aggregation-with-script-code-with-previous-result/352836)

<div class="topic-metadata">

**Author:** [@Fnizou](https://discuss.elastic.co/u/Fnizou)\
**Replies:** 0\
**Last updated:** [February 8, 2024, 9:11am UTC](https://discuss.elastic.co/t/aggregation-with-script-code-with-previous-result/352836 "2024-02-08T09:11:51Z")

</div>

Hello everyone I would like to know if it is possible in 1 single request, in the aggregations, to make a script which calculates an aggs based on the previous results: I need to dynamically calculate the interval th…

---

## [Metricbeat error](https://discuss.elastic.co/t/metricbeat-error/352828)

<div class="topic-metadata">

**Author:** [@miiroslavkardos](https://discuss.elastic.co/u/miiroslavkardos)\
**Replies:** 1\
**Last updated:** [February 8, 2024, 8:58am UTC](https://discuss.elastic.co/t/metricbeat-error/352828 "2024-02-08T08:58:11Z")

</div>

Hello, Could anyone please tell me what kind of error is this : It is in my elasticsearch log /var/log/elasticsearch/elktest01.log. \[2024-02-08T09:03:07,475\]\[WARN \]\[o.e.x.m.MonitoringService\] \[testdata01\] monitoring …

---

## [Can minimum\_should\_match be 'boxed'](https://discuss.elastic.co/t/can-minimum-should-match-be-boxed/352417)

<div class="topic-metadata">

**Author:** [@bbaronas](https://discuss.elastic.co/u/bbaronas)\
**Replies:** 3\
**Last updated:** [February 7, 2024, 4:53pm UTC](https://discuss.elastic.co/t/can-minimum-should-match-be-boxed/352417 "2024-02-07T16:53:00Z")

</div>

Is it possible to use minimum\_should\_match to control an overabundance of should clauses in a boolean query? For context: I made a query builder that allows a user to add multiple texts that get translated into individ…

---

## [Realtime aggregations per application transaction](https://discuss.elastic.co/t/realtime-aggregations-per-application-transaction/352708)

<div class="topic-metadata">

**Author:** [@abduimrn](https://discuss.elastic.co/u/abduimrn)\
**Replies:** 6\
**Last updated:** [February 8, 2024, 5:01am UTC](https://discuss.elastic.co/t/realtime-aggregations-per-application-transaction/352708 "2024-02-08T05:01:40Z")

</div>

Hello all, I was wondering about whether Elasticsearch is the meant to be used for real time aggregations PER application transaction request? Is this one of use cases? application transaction request = incoming reques…

---

## [Multiple aggregation in single query or single single aggregation in multiple query which will perform better](https://discuss.elastic.co/t/multiple-aggregation-in-single-query-or-single-single-aggregation-in-multiple-query-which-will-perform-better/352799)

<div class="topic-metadata">

**Author:** [@kuldeep\_gupta](https://discuss.elastic.co/u/kuldeep_gupta)\
**Replies:** 0\
**Last updated:** [February 7, 2024, 8:05pm UTC](https://discuss.elastic.co/t/multiple-aggregation-in-single-query-or-single-single-aggregation-in-multiple-query-which-will-perform-better/352799 "2024-02-07T20:05:09Z")

</div>

I Have to perform two aggregation let's say query1 = { "aggs": { "traffic": { "date\_histogram": { "field": "@timestamp", "fixed\_interval": "30s", …

---

## [AWS CloudFront Ingest Pipeline Failing](https://discuss.elastic.co/t/aws-cloudfront-ingest-pipeline-failing/352678)

<div class="topic-metadata">

**Author:** [@DougR](https://discuss.elastic.co/u/DougR)\
**Replies:** 3\
**Last updated:** [February 7, 2024, 6:50pm UTC](https://discuss.elastic.co/t/aws-cloudfront-ingest-pipeline-failing/352678 "2024-02-07T18:50:13Z")

</div>

I am having an issue with logs ingesting into logs-aws.cloudfront\_logs-\* from a specific account, using Elastic Serverless Forwarder. In one specific account and this account only, I am receiving the following error in …

---

## [Error writing to Elastic search from Databricks](https://discuss.elastic.co/t/error-writing-to-elastic-search-from-databricks/352696)

<div class="topic-metadata">

**Author:** [@kichcha](https://discuss.elastic.co/u/kichcha)\
**Replies:** 5\
**Last updated:** [February 7, 2024, 6:34pm UTC](https://discuss.elastic.co/t/error-writing-to-elastic-search-from-databricks/352696 "2024-02-07T18:34:06Z")

</div>

Hello, I am an Elasticsearch newbie trying to connect to Elasticsearch on GCP from databricks on AWS. I tried following instructions provided by databricks (unable to post link here). However, I am now running into th…

---

## [Elastic Lucene Qeuery](https://discuss.elastic.co/t/elastic-lucene-qeuery/352784)

<div class="topic-metadata">

**Author:** [@RavaliJ](https://discuss.elastic.co/u/RavaliJ)\
**Replies:** 0\
**Last updated:** [February 7, 2024, 4:50pm UTC](https://discuss.elastic.co/t/elastic-lucene-qeuery/352784 "2024-02-07T16:50:58Z")

</div>

Hi I have Elasticsearch integrated as a datasource for my Grafana dashboard. I can see my raw data as below laong with few other feilds: Name Time\_Taken(in ms) abc 245 def 6 erg 58 How do i get …

---

## [How to reference Elasticsearch variable remotely](https://discuss.elastic.co/t/how-to-reference-elasticsearch-variable-remotely/352773)

<div class="topic-metadata">

**Author:** [@Stan\_Kendzior](https://discuss.elastic.co/u/Stan_Kendzior)\
**Replies:** 0\
**Last updated:** [February 7, 2024, 3:00pm UTC](https://discuss.elastic.co/t/how-to-reference-elasticsearch-variable-remotely/352773 "2024-02-07T15:00:52Z")

</div>

I am trying to include a reference to a variable that I have defined on the Elasticsearch side within a query. Running this query in the Dev Tools within Kibana works correctly. However, when I try to execute it through …

---

## [Error while running PUT https://\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.us-central1.gcp.cloud.es.io//home/rahul/Downloads/epfile\_documents](https://discuss.elastic.co/t/error-while-running-put-https-us-central1-gcp-cloud-es-io-home-rahul-downloads-epfile-documents/352713)

<div class="topic-metadata">

**Author:** [@Rahul\_Patel1](https://discuss.elastic.co/u/Rahul_Patel1)\
**Replies:** 1\
**Last updated:** [February 7, 2024, 1:21pm UTC](https://discuss.elastic.co/t/error-while-running-put-https-us-central1-gcp-cloud-es-io-home-rahul-downloads-epfile-documents/352713 "2024-02-07T13:21:38Z")

</div>

Hello, I am getting following error on starting the FSCrawler. 13:53:09,247 DEBUG \[f.p.e.c.f.c.ElasticsearchClient\] get version 13:53:10,062 DEBUG \[f.p.e.c.f.c.ElasticsearchClient\] get version returns 8.12.1 and 8 as t…

---

## [Is it elasticsearch going to be licensed](https://discuss.elastic.co/t/is-it-elasticsearch-going-to-be-licensed/352718)

<div class="topic-metadata">

**Author:** [@MahithaSarala](https://discuss.elastic.co/u/MahithaSarala)\
**Replies:** 1\
**Last updated:** [February 7, 2024, 11:45am UTC](https://discuss.elastic.co/t/is-it-elasticsearch-going-to-be-licensed/352718 "2024-02-07T11:45:31Z")

</div>

Hi Team, Is Elasticsearch going to be paid version going forward, currently we are using elasticsearch 8.5.3 . Could you provide more on this. Thanks, Sarala K

---

## [Guaranteed higher scores from one should query over another](https://discuss.elastic.co/t/guaranteed-higher-scores-from-one-should-query-over-another/352728)

<div class="topic-metadata">

**Author:** [@andy\_j](https://discuss.elastic.co/u/andy_j)\
**Replies:** 1\
**Last updated:** [February 7, 2024, 11:07am UTC](https://discuss.elastic.co/t/guaranteed-higher-scores-from-one-should-query-over-another/352728 "2024-02-07T11:07:43Z")

</div>

I have a Elasticsearch query with three should queries of declining importance. How can I assert that documents returned from each should query has higher score than those of less importance? Maybe this could be solved …

---

## [DataStream does not roll over on primary shard max size](https://discuss.elastic.co/t/datastream-does-not-roll-over-on-primary-shard-max-size/352732)

<div class="topic-metadata">

**Author:** [@Roura\_Antoine](https://discuss.elastic.co/u/Roura_Antoine)\
**Replies:** 1\
**Last updated:** [February 7, 2024, 10:57am UTC](https://discuss.elastic.co/t/datastream-does-not-roll-over-on-primary-shard-max-size/352732 "2024-02-07T10:57:35Z")

</div>

Hello, I'm new to Elastic. I am trying to configure a DataStream that must roll over when the primary shard size reach 1MB (it is a functional test), but it does not. Here is my ILM : PUT \_ilm/policy/short\_life\_policy…

---

## [\[lpseg2p\] \[spc\]\[0\], node\[r1Sz\_DsNSZ-wbxR35IPMpg\], \[P\], v\[20\], s\[STARTED\], a\[id=DEhEGi5WRZG5DiEHg7uvUw\]: failed to execute \[org.elasticsearch.action.percolate.PercolateRequest@350ed365\] RemoteTransportException\[\[lpseg2p\]\[11.22.23.19:9300\]\[indices:data/read](https://discuss.elastic.co/t/lpseg2p-spc-0-node-r1sz-dsnsz-wbxr35ipmpg-p-v-20-s-started-a-id-dehegi5wrzg5diehg7uvuw-failed-to-execute-org-elasticsearch-action-percolate-percolaterequest-350ed365-remotetransportexception-lpseg2p-11-22-23-19-9300-indices-data-read/352702)

<div class="topic-metadata">

**Author:** [@mobistar](https://discuss.elastic.co/u/mobistar)\
**Replies:** 4\
**Last updated:** [February 7, 2024, 9:02am UTC](https://discuss.elastic.co/t/lpseg2p-spc-0-node-r1sz-dsnsz-wbxr35ipmpg-p-v-20-s-started-a-id-dehegi5wrzg5diehg7uvuw-failed-to-execute-org-elasticsearch-action-percolate-percolaterequest-350ed365-remotetransportexception-lpseg2p-11-22-23-19-9300-indices-data-read/352702 "2024-02-07T09:02:40Z")

</div>

Hi Friend, I am getting given erron on elasticsearch can some one help to resove it. It have a big data on shared and we just recover shard \[0\] after renaming translog directory \\BR Manoj Kumar

---

## [ILM and curator](https://discuss.elastic.co/t/ilm-and-curator/352706)

<div class="topic-metadata">

**Author:** [@Youssef\_Shehadeh](https://discuss.elastic.co/u/Youssef_Shehadeh)\
**Replies:** 0\
**Last updated:** [February 7, 2024, 7:55am UTC](https://discuss.elastic.co/t/ilm-and-curator/352706 "2024-02-07T07:55:03Z")

</div>

Hello All, I have a few questions about snapshots and restoring snapshots. Please consider this scenario: if I have an elastic cluster deployed in a production environment and to reduce storage, I take snapshots for ind…

---

## [Calculate differences between documents in a query](https://discuss.elastic.co/t/calculate-differences-between-documents-in-a-query/351519)

<div class="topic-metadata">

**Author:** [@mbby](https://discuss.elastic.co/u/mbby)\
**Replies:** 4\
**Last updated:** [February 7, 2024, 7:23am UTC](https://discuss.elastic.co/t/calculate-differences-between-documents-in-a-query/351519 "2024-02-07T07:23:55Z")

</div>

I need to calculate the MTBF of our systems which are monitored using the observatiblity uptime feature of Elasticsearch. Let's say that I've an index with the following values: time, system-name, state 10:00, system1…

---

## [HSTS Missing From HTTPS Server for elasticsearch](https://discuss.elastic.co/t/hsts-missing-from-https-server-for-elasticsearch/352694)

<div class="topic-metadata">

**Author:** [@kam89](https://discuss.elastic.co/u/kam89)\
**Replies:** 1\
**Last updated:** [February 7, 2024, 4:47am UTC](https://discuss.elastic.co/t/hsts-missing-from-https-server-for-elasticsearch/352694 "2024-02-07T04:47:20Z")

</div>

Hi everyone, Good day and hope all of you are doing great! I am setting up an ELKStack server (version 8.12.0), mainly to do for testing purpose for data ingestion and our IT security team had run an assessment test be…

---

## [To use the full set of free features in this distribution of Kibana, please update Elasticsearch to the default distribution](https://discuss.elastic.co/t/to-use-the-full-set-of-free-features-in-this-distribution-of-kibana-please-update-elasticsearch-to-the-default-distribution/352572)

<div class="topic-metadata">

**Author:** [@e-ferrari](https://discuss.elastic.co/u/e-ferrari)\
**Replies:** 8\
**Last updated:** [February 6, 2024, 10:05pm UTC](https://discuss.elastic.co/t/to-use-the-full-set-of-free-features-in-this-distribution-of-kibana-please-update-elasticsearch-to-the-default-distribution/352572 "2024-02-06T22:05:13Z")

</div>

Hi, from what i understand it seems i have the OSS version of elasticsearch installed, but not the OSS version of Kibana. So i need now this "default distribution". Where do i get it ? And now trying to connect to Kib…

---

## [Setting number\_of\_replicas on existing template](https://discuss.elastic.co/t/setting-number-of-replicas-on-existing-template/352672)

<div class="topic-metadata">

**Author:** [@parisila](https://discuss.elastic.co/u/parisila)\
**Replies:** 3\
**Last updated:** [February 6, 2024, 8:09pm UTC](https://discuss.elastic.co/t/setting-number-of-replicas-on-existing-template/352672 "2024-02-06T20:09:31Z")

</div>

Apologize for the screenshot but my elasticsearch instance is in a secure environment with only a jumphost browser that cannot copy anything out. Elastic Stack version 7.17.4 single node I am trying to update an index …

---

## [Snapshot is deleted automatically once I stop the docker container](https://discuss.elastic.co/t/snapshot-is-deleted-automatically-once-i-stop-the-docker-container/352603)

<div class="topic-metadata">

**Author:** [@susnato](https://discuss.elastic.co/u/susnato)\
**Replies:** 4\
**Last updated:** [February 6, 2024, 5:30pm UTC](https://discuss.elastic.co/t/snapshot-is-deleted-automatically-once-i-stop-the-docker-container/352603 "2024-02-06T17:30:32Z")

</div>

(Hi, I am totally new to Elastic search, so sorry if this is very basic question.) I had an Elasticsearch store running in background using docker. I had used haystack to add some files and embeddings to it. Then I…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=147)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=149)
