# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=15

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 16

---

## [Remove corrupted shard](https://discuss.elastic.co/t/remove-corrupted-shard/383026)

<div class="topic-metadata">

**Author:** [@ALIT](https://discuss.elastic.co/u/ALIT)\
**Replies:** 3\
**Last updated:** [October 28, 2025, 2:04pm UTC](https://discuss.elastic.co/t/remove-corrupted-shard/383026 "2025-10-28T14:04:05Z")

</div>

Hi, we are using ES 8.19.2 on 30 data nodes with ~100TB data. We don’t have any snapshots. Shards per index is 30. Someone accidentally deleted some indices from filesystem of some of the nodes. (/data/indices/XYZ). Ye…

---

## [Which architecture is better for the Elasticsearch structure?](https://discuss.elastic.co/t/which-architecture-is-better-for-the-elasticsearch-structure/383008)

<div class="topic-metadata">

**Author:** [@celikbaris61](https://discuss.elastic.co/u/celikbaris61)\
**Replies:** 12\
**Last updated:** [October 28, 2025, 11:49am UTC](https://discuss.elastic.co/t/which-architecture-is-better-for-the-elasticsearch-structure/383008 "2025-10-28T11:49:10Z")

</div>

Hello everyone,I'm going to set up a cluster for Elasticsearch. My data size is approximately 50 TB and will continue to grow. I will primarily use it for search and cross-queries. My question is:I will be using virtual …

---

## [Clear out old alerts](https://discuss.elastic.co/t/clear-out-old-alerts/383019)

<div class="topic-metadata">

**Author:** [@dot-mike](https://discuss.elastic.co/u/dot-mike)\
**Replies:** 2\
**Last updated:** [October 27, 2025, 3:54pm UTC](https://discuss.elastic.co/t/clear-out-old-alerts/383019 "2025-10-27T15:54:35Z")

</div>

Hi community, is it safe to remove the indicies .internal.alerts-observability.logs.alerts-default-\<id\> or .internal.alerts-observability.metrics.alerts-default-\<id\> to clear out old alerts? I want to start from scratc…

---

## [Could not pack/validate JSON response](https://discuss.elastic.co/t/could-not-pack-validate-json-response/382538)

<div class="topic-metadata">

**Author:** [@mahesh.hemke24](https://discuss.elastic.co/u/mahesh.hemke24)\
**Replies:** 3\
**Last updated:** [October 27, 2025, 7:19am UTC](https://discuss.elastic.co/t/could-not-pack-validate-json-response/382538 "2025-10-27T07:19:58Z")

</div>

Hi Team, Hope you are doing well.. I am getting below error in fluentbit.log for some indexes these logs/indexes are getting from application servers and we are managing this on our elasticsearch servers which consist …

---

## [Agentic AI](https://discuss.elastic.co/t/agentic-ai/382945)

<div class="topic-metadata">

**Author:** [@Ankita\_Pachauri](https://discuss.elastic.co/u/Ankita_Pachauri)\
**Replies:** 1\
**Last updated:** [October 26, 2025, 1:12am UTC](https://discuss.elastic.co/t/agentic-ai/382945 "2025-10-26T01:12:43Z")

</div>

Hi Team, How can i leverage Agentic AI in elk stack? //Ankita

---

## [Can ELSER generate Elasticsearch aggregation queries from natural-language input?](https://discuss.elastic.co/t/can-elser-generate-elasticsearch-aggregation-queries-from-natural-language-input/382962)

<div class="topic-metadata">

**Author:** [@Mohan\_Kumar\_Reddy\_Ak](https://discuss.elastic.co/u/Mohan_Kumar_Reddy_Ak)\
**Replies:** 0\
**Last updated:** [October 24, 2025, 6:10pm UTC](https://discuss.elastic.co/t/can-elser-generate-elasticsearch-aggregation-queries-from-natural-language-input/382962 "2025-10-24T18:10:53Z")

</div>

Hi team, I’m exploring a hybrid setup where LLMs (like GPT-4 or GPT-5) convert natural-language questions into Elasticsearch DSL queries — including aggregations such as avg, terms, and date\_histogram. However, I’m fac…

---

## [\[search\_phase\_execution\_exception\] without a root reason](https://discuss.elastic.co/t/search-phase-execution-exception-without-a-root-reason/382922)

<div class="topic-metadata">

**Author:** [@al123od](https://discuss.elastic.co/u/al123od)\
**Replies:** 10\
**Last updated:** [October 23, 2025, 2:20pm UTC](https://discuss.elastic.co/t/search-phase-execution-exception-without-a-root-reason/382922 "2025-10-23T14:20:37Z")

</div>

Hello. I’m using Elasticsearch 9.1.3, access with java client (no security, almost all setting but cluster name are default). If to execute query\_string query with wrong syntax like GET test/\_search { "query": {…

---

## [Compatibility of Elasticsearch 8.17.0 with Amazon Corretto 17 / 21](https://discuss.elastic.co/t/compatibility-of-elasticsearch-8-17-0-with-amazon-corretto-17-21/382858)

<div class="topic-metadata">

**Author:** [@babudurairaji](https://discuss.elastic.co/u/babudurairaji)\
**Replies:** 4\
**Last updated:** [October 23, 2025, 4:35am UTC](https://discuss.elastic.co/t/compatibility-of-elasticsearch-8-17-0-with-amazon-corretto-17-21/382858 "2025-10-23T04:35:28Z")

</div>

Hi, We are currently using Elasticsearch version 8.17.0 for data auditing purposes. We would like to know whether this version is compatible with Amazon Corretto 17 or 21, instead of using Oracle JDK 17. Could anyone p…

---

## [Peer Recovery does not respect indices.recovery.use\_snapshots=false or use\_for\_peer\_recovery=false - misleading documentation? (ES 8.13.4)](https://discuss.elastic.co/t/peer-recovery-does-not-respect-indices-recovery-use-snapshots-false-or-use-for-peer-recovery-false-misleading-documentation-es-8-13-4/382879)

<div class="topic-metadata">

**Author:** [@doitMLU](https://discuss.elastic.co/u/doitMLU)\
**Replies:** 5\
**Last updated:** [October 22, 2025, 4:18pm UTC](https://discuss.elastic.co/t/peer-recovery-does-not-respect-indices-recovery-use-snapshots-false-or-use-for-peer-recovery-false-misleading-documentation-es-8-13-4/382879 "2025-10-22T16:18:41Z")

</div>

Hi everyone, We recently had a big spike in S3 transfers and subsequently costs, which let me to troubleshoot the configuration of our elastic stack. I’ve found the cluster setting indices.recovery.use\_snapshots which d…

---

## [BUG: Ignore unmapped is not working in geo polygon query (ES 8.15.5)](https://discuss.elastic.co/t/bug-ignore-unmapped-is-not-working-in-geo-polygon-query-es-8-15-5/382878)

<div class="topic-metadata">

**Author:** [@ma\_br](https://discuss.elastic.co/u/ma_br)\
**Replies:** 3\
**Last updated:** [October 22, 2025, 3:27pm UTC](https://discuss.elastic.co/t/bug-ignore-unmapped-is-not-working-in-geo-polygon-query-es-8-15-5/382878 "2025-10-22T15:27:08Z")

</div>

my goal is to replace some deprecated geo\_polygon queries with geo\_shape queries. And because some of the geo shape can get big, i want to use indexed shapes old query: GET /entity\_\*/\_search { "query": { "nested"…

---

## [Not able to access Lab in Strigo](https://discuss.elastic.co/t/not-able-to-access-lab-in-strigo/382835)

<div class="topic-metadata">

**Author:** [@Deepthi.KS](https://discuss.elastic.co/u/Deepthi.KS)\
**Replies:** 1\
**Last updated:** [October 21, 2025, 4:04am UTC](https://discuss.elastic.co/t/not-able-to-access-lab-in-strigo/382835 "2025-10-21T04:04:50Z")

</div>

I am not able to access lab in Elastic learning portal as the Strigo says I am logged in but not able to access. I need access as soon as possible as I dont have much time. HELP

---

## [Should filters be used for fields with high cardinality?](https://discuss.elastic.co/t/should-filters-be-used-for-fields-with-high-cardinality/382773)

<div class="topic-metadata">

**Author:** [@yeikel](https://discuss.elastic.co/u/yeikel)\
**Replies:** 1\
**Last updated:** [October 20, 2025, 8:34pm UTC](https://discuss.elastic.co/t/should-filters-be-used-for-fields-with-high-cardinality/382773 "2025-10-20T20:34:44Z")

</div>

Hi all, Should Elasticsearch query filters be applied to fields with high cardinality? From what I understand, filters are not scored, and they are cached. However, I’m wondering if it’s better to cache only filters o…

---

## [How to properly detect and handle transport errors in Elasticsearch logging (latest versions)](https://discuss.elastic.co/t/how-to-properly-detect-and-handle-transport-errors-in-elasticsearch-logging-latest-versions/382790)

<div class="topic-metadata">

**Author:** [@Guido\_hernan\_Gagliar](https://discuss.elastic.co/u/Guido_hernan_Gagliar)\
**Replies:** 2\
**Last updated:** [October 20, 2025, 11:28am UTC](https://discuss.elastic.co/t/how-to-properly-detect-and-handle-transport-errors-in-elasticsearch-logging-latest-versions/382790 "2025-10-20T11:28:49Z")

</div>

Hi everyone! :waving\_hand: I'm new to Elasticsearch and still learning, so I’d really appreciate some guidance. I’m trying to understand the best way to detect and handle transport errors when sending logs to Elasticse…

---

## [Error: rejected execution of coordinating operation \[coordinating\_and\_primary\_bytes=0, replica\_bytes=0, all\_bytes=0, coordinating\_operation\_bytes=130953165, max\_coordinating\_bytes=107374182\]"](https://discuss.elastic.co/t/error-rejected-execution-of-coordinating-operation-coordinating-and-primary-bytes-0-replica-bytes-0-all-bytes-0-coordinating-operation-bytes-130953165-max-coordinating-bytes-107374182/382813)

<div class="topic-metadata">

**Author:** [@Peng\_Dong](https://discuss.elastic.co/u/Peng_Dong)\
**Replies:** 0\
**Last updated:** [October 18, 2025, 9:14pm UTC](https://discuss.elastic.co/t/error-rejected-execution-of-coordinating-operation-coordinating-and-primary-bytes-0-replica-bytes-0-all-bytes-0-coordinating-operation-bytes-130953165-max-coordinating-bytes-107374182/382813 "2025-10-18T21:14:00Z")

</div>

Hi, was trying to re-index in elastic. Using the command below: POST \_reindex?wait\_for\_completion=false&requests\_per\_second=50 { "source": { "index": "prod-application-2025", "size": 200 }, "dest": { …

---

## [ELK Stack upgrade to version 9.1.5](https://discuss.elastic.co/t/elk-stack-upgrade-to-version-9-1-5/382734)

<div class="topic-metadata">

**Author:** [@M311ow](https://discuss.elastic.co/u/M311ow)\
**Replies:** 5\
**Last updated:** [October 18, 2025, 8:09am UTC](https://discuss.elastic.co/t/elk-stack-upgrade-to-version-9-1-5/382734 "2025-10-18T08:09:06Z")

</div>

Hi All, We planned to upgrade the ELK Stack to the latest version (9.1.5) and encountered an issue where logs disappeared. After upgrading Elasticsearch and Kibana to version 9.1.5, the system continued to function. Ho…

---

## [Error while join a node, no subject alternative names](https://discuss.elastic.co/t/error-while-join-a-node-no-subject-alternative-names/382590)

<div class="topic-metadata">

**Author:** [@gbschenkel](https://discuss.elastic.co/u/gbschenkel)\
**Replies:** 4\
**Last updated:** [October 17, 2025, 3:38pm UTC](https://discuss.elastic.co/t/error-while-join-a-node-no-subject-alternative-names/382590 "2025-10-17T15:38:28Z")

</div>

I have a 6 node cluster, 3 masters, 3 data, and I am trying to add 4 more data nodes. The cluster was created using version 8.18.x and I have upgrade it to 9.1.5. It was installed using .RPM, but since I got liberation…

---

## [Strange/inaccurate deprecated role/index privilege error?](https://discuss.elastic.co/t/strange-inaccurate-deprecated-role-index-privilege-error/382807)

<div class="topic-metadata">

**Author:** [@delfuego](https://discuss.elastic.co/u/delfuego)\
**Replies:** 0\
**Last updated:** [October 17, 2025, 2:24pm UTC](https://discuss.elastic.co/t/strange-inaccurate-deprecated-role-index-privilege-error/382807 "2025-10-17T14:24:59Z")

</div>

I’m getting an error in my Elasticsearch logs telling me that one of my roles has index privileges covering an alias that don’t cover some of the pointed-to indices… but it doesn’t make a lot of sense, given that the con…

---

## [Delete\_by\_query vs client managed batches send to be deleted](https://discuss.elastic.co/t/delete-by-query-vs-client-managed-batches-send-to-be-deleted/382747)

<div class="topic-metadata">

**Author:** [@marekott](https://discuss.elastic.co/u/marekott)\
**Replies:** 4\
**Last updated:** [October 17, 2025, 10:46am UTC](https://discuss.elastic.co/t/delete-by-query-vs-client-managed-batches-send-to-be-deleted/382747 "2025-10-17T10:46:24Z")

</div>

Hi, first lets make some assumptions. We have an index containing 90 000 000 documents. Due to application logic we need to delete 30 000 000 docs (30% of data). Now I know that the best solution in terms of performance …

---

## [Best practice: Using Winston vs. native Elasticsearch client for logging?](https://discuss.elastic.co/t/best-practice-using-winston-vs-native-elasticsearch-client-for-logging/382788)

<div class="topic-metadata">

**Author:** [@Guido\_hernan\_Gagliar](https://discuss.elastic.co/u/Guido_hernan_Gagliar)\
**Replies:** 2\
**Last updated:** [October 30, 2025, 2:22pm UTC](https://discuss.elastic.co/t/best-practice-using-winston-vs-native-elasticsearch-client-for-logging/382788 "2025-10-30T14:22:10Z")

</div>

Hello everyone! Good morning, I'm new to Elasticsearch and still learning the basics. I have a question — I’ve been reading that maybe the best way to send logs to Elasticsearch is by using the native Elasticsearch cli…

---

## [Alternatives or making search filtering more efficient](https://discuss.elastic.co/t/alternatives-or-making-search-filtering-more-efficient/382796)

<div class="topic-metadata">

**Author:** [@daveoap](https://discuss.elastic.co/u/daveoap)\
**Replies:** 1\
**Last updated:** [October 17, 2025, 1:44am UTC](https://discuss.elastic.co/t/alternatives-or-making-search-filtering-more-efficient/382796 "2025-10-17T01:44:10Z")

</div>

Hi, I have a query which uses function score and filters to modify the weight of the results so i can order the results based on which filter the doc matches. The issue is that in these filters i need to use a terms\_set…

---

## [Sum the sub buckets returned results in transform](https://discuss.elastic.co/t/sum-the-sub-buckets-returned-results-in-transform/382769)

<div class="topic-metadata">

**Author:** [@Hamza\_Rajput](https://discuss.elastic.co/u/Hamza_Rajput)\
**Replies:** 1\
**Last updated:** [October 16, 2025, 4:24pm UTC](https://discuss.elastic.co/t/sum-the-sub-buckets-returned-results-in-transform/382769 "2025-10-16T16:24:45Z")

</div>

Here is my transform preview: POST \_transform/\_preview { "source": { "index": ".ds-metrics-ap.clients-default-\*", "query": { "range": { "@timestamp": { "gte": "now/d", "lt": "…

---

## [Elastic Fleet Agent stops processing TCP ingest, UDP continues](https://discuss.elastic.co/t/elastic-fleet-agent-stops-processing-tcp-ingest-udp-continues/382756)

<div class="topic-metadata">

**Author:** [@essinghigh](https://discuss.elastic.co/u/essinghigh)\
**Replies:** 3\
**Last updated:** [October 16, 2025, 7:02am UTC](https://discuss.elastic.co/t/elastic-fleet-agent-stops-processing-tcp-ingest-udp-continues/382756 "2025-10-16T07:02:01Z")

</div>

Hi All, I’m running an Elastic Agent (8.19.3) configuration with multiple Generic TCP and UDP inputs. Deployed onto Ubuntu Server. I’ve noticed that yesterday at around 10:30 (Oct 14th), the TCP ingest has stopped comp…

---

## [ES 8.19.5 encountered a NotEntitledException when attach to the ES process using Arthas](https://discuss.elastic.co/t/es-8-19-5-encountered-a-notentitledexception-when-attach-to-the-es-process-using-arthas/382742)

<div class="topic-metadata">

**Author:** [@ZLEternity](https://discuss.elastic.co/u/ZLEternity)\
**Replies:** 1\
**Last updated:** [October 15, 2025, 11:31pm UTC](https://discuss.elastic.co/t/es-8-19-5-encountered-a-notentitledexception-when-attach-to-the-es-process-using-arthas/382742 "2025-10-15T23:31:29Z")

</div>

elasticsearch8.19.5 use Entitlements module，Arthas fails to attach. Entitlement Policy Configuration (arthas-entitlement-policy.yaml): versions: 8.19.5 policy: ALL-UNNAMED: file: read: paths: …

---

## [Best option for bulk refresh: alias blue/green vs single-index + version filter](https://discuss.elastic.co/t/best-option-for-bulk-refresh-alias-blue-green-vs-single-index-version-filter/382441)

<div class="topic-metadata">

**Author:** [@alper](https://discuss.elastic.co/u/alper)\
**Replies:** 2\
**Last updated:** [October 15, 2025, 4:20pm UTC](https://discuss.elastic.co/t/best-option-for-bulk-refresh-alias-blue-green-vs-single-index-version-filter/382441 "2025-10-15T16:20:37Z")

</div>

Hi everyone, We develop an e-commerce search on Elasticsearch 8.x (Java client). Three indices: product, category, brand. ~50k products/day arrive via API (multiple times/day). We want to add/update docs; remove produc…

---

## [504 ERROR when using utf-16le](https://discuss.elastic.co/t/504-error-when-using-utf-16le/382745)

<div class="topic-metadata">

**Author:** [@SIEMdeJong](https://discuss.elastic.co/u/SIEMdeJong)\
**Replies:** 0\
**Last updated:** [October 15, 2025, 12:51pm UTC](https://discuss.elastic.co/t/504-error-when-using-utf-16le/382745 "2025-10-15T12:51:10Z")

</div>

Hello, We use Elastic 9.1.4. We want to monitor deadlocks in Elastic. The method that consistently works for us is to enable DBCC TRACEON(1222, -1); on MSSQL. This causes the deadlocks to be written to the ERRORLOG. A…

---

## [Comparison of data between two indices](https://discuss.elastic.co/t/comparison-of-data-between-two-indices/382719)

<div class="topic-metadata">

**Author:** [@s.buksa](https://discuss.elastic.co/u/s.buksa)\
**Replies:** 3\
**Last updated:** [October 15, 2025, 11:22am UTC](https://discuss.elastic.co/t/comparison-of-data-between-two-indices/382719 "2025-10-15T11:22:14Z")

</div>

Hello, I'm looking for suggestions. I have two indices, for example: index-a-2025 index-b-2025 Both indices contain Beat host names on which they are deployed. I want to compare both indices to identify any missing …

---

## [Logs ingestion](https://discuss.elastic.co/t/logs-ingestion/382715)

<div class="topic-metadata">

**Author:** [@eirc](https://discuss.elastic.co/u/eirc)\
**Replies:** 1\
**Last updated:** [October 15, 2025, 6:55am UTC](https://discuss.elastic.co/t/logs-ingestion/382715 "2025-10-15T06:55:51Z")

</div>

I’m trying to setup logs ingestion for multiple systems. I have installed filebeat on all hosts and pushed all system logs with journald and container logs with a filestream for \`/var/lib/docker/containers/\*/\*.log\`. Ever…

---

## [Elastic Logging - How to Trace a Request Across Multiple Remote Clusters (v8.10.2)](https://discuss.elastic.co/t/elastic-logging-how-to-trace-a-request-across-multiple-remote-clusters-v8-10-2/382634)

<div class="topic-metadata">

**Author:** [@sakshijain](https://discuss.elastic.co/u/sakshijain)\
**Replies:** 1\
**Last updated:** [October 14, 2025, 2:10pm UTC](https://discuss.elastic.co/t/elastic-logging-how-to-trace-a-request-across-multiple-remote-clusters-v8-10-2/382634 "2025-10-14T14:10:28Z")

</div>

We have a cross-cluster setup with the following components: 2 coordinator clusters Multiple remote (data) clusters We’ve enabled slow logs on the remote clusters to capture details such as: Search execution …

---

## [What version of elasticsearch-hadoop should I be using with spark 4.0.1](https://discuss.elastic.co/t/what-version-of-elasticsearch-hadoop-should-i-be-using-with-spark-4-0-1/382679)

<div class="topic-metadata">

**Author:** [@Thomas\_Butterfield](https://discuss.elastic.co/u/Thomas_Butterfield)\
**Replies:** 1\
**Last updated:** [October 14, 2025, 1:13pm UTC](https://discuss.elastic.co/t/what-version-of-elasticsearch-hadoop-should-i-be-using-with-spark-4-0-1/382679 "2025-10-14T13:13:53Z")

</div>

Using Scala version 2.13.16 (OpenJDK 64-Bit Server VM, Java 17.0.16) I'm getting this error when writing to an ES 8.19.3 cluster: java.lang.NoSuchMethodError: 'org.apache.spark.sql.SQLContext org.apache.spark.sql.Datase…

---

## [Alert: Oracle JRE 25 (jrt-fs.jar) Detected in Official Elasticsearch 8.19.5 Docker Image](https://discuss.elastic.co/t/alert-oracle-jre-25-jrt-fs-jar-detected-in-official-elasticsearch-8-19-5-docker-image/382691)

<div class="topic-metadata">

**Author:** [@Elex\_Edward](https://discuss.elastic.co/u/Elex_Edward)\
**Replies:** 2\
**Last updated:** [October 14, 2025, 12:57pm UTC](https://discuss.elastic.co/t/alert-oracle-jre-25-jrt-fs-jar-detected-in-official-elasticsearch-8-19-5-docker-image/382691 "2025-10-14T12:57:46Z")

</div>

After a recent internal security review, we received an alert regarding the official Elasticsearch 8.19.5 Docker image. The report indicates the presence of a vulnerable component — Oracle JRE 25 (jrt-fs.jar). Here are …

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=14)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=16)
