# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=150

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 151

---

## [NearRealTime aggregation on recent inserted document](https://discuss.elastic.co/t/nearrealtime-aggregation-on-recent-inserted-document/352481)

<div class="topic-metadata">

**Author:** [@abduimrn](https://discuss.elastic.co/u/abduimrn)\
**Replies:** 4\
**Last updated:** [February 5, 2024, 5:20am UTC](https://discuss.elastic.co/t/nearrealtime-aggregation-on-recent-inserted-document/352481 "2024-02-05T05:20:50Z")

</div>

Hello, Elasticsearch is Near Real Time. Which in short it indicates that after issuing an insert request, it will not directly appear to all search and aggregation queries. In my application I first insert a document t…

---

## [Wallboard display](https://discuss.elastic.co/t/wallboard-display/352495)

<div class="topic-metadata">

**Author:** [@Ross\_Wakelin](https://discuss.elastic.co/u/Ross_Wakelin)\
**Replies:** 1\
**Last updated:** [February 4, 2024, 10:31pm UTC](https://discuss.elastic.co/t/wallboard-display/352495 "2024-02-04T22:31:39Z")

</div>

Hi We are setting up a new Security management room, and want to have some dashboards etc. from Kibana displayed permanently on a wall screen. I can't seem to find any hints or tips anywhere on how to set up autologon …

---

## [About reindex](https://discuss.elastic.co/t/about-reindex/350833)

<div class="topic-metadata">

**Author:** [@jevonsnotes](https://discuss.elastic.co/u/jevonsnotes)\
**Replies:** 6\
**Last updated:** [February 4, 2024, 9:21am UTC](https://discuss.elastic.co/t/about-reindex/350833 "2024-02-04T09:21:53Z")

</div>

I have a concern when reindex, which is how to ensure seamless integration during the re indexing process as the original index continues to write data?

---

## [How to fix Index Lifecycle Rollover Alias is empty or not defined](https://discuss.elastic.co/t/how-to-fix-index-lifecycle-rollover-alias-is-empty-or-not-defined/351675)

<div class="topic-metadata">

**Author:** [@roman-tasi](https://discuss.elastic.co/u/roman-tasi)\
**Replies:** 28\
**Last updated:** [February 4, 2024, 1:10am UTC](https://discuss.elastic.co/t/how-to-fix-index-lifecycle-rollover-alias-is-empty-or-not-defined/351675 "2024-02-04T01:10:54Z")

</div>

I've been running this (uses date math) but it doesn't seem to be working: PUT /%3Cos-linux-%7Bnow%2Fd%7D-000001%3E { "aliases": { "os-linux": { "is\_write\_index": true } } } which pr…

---

## [Elastic hive configuration](https://discuss.elastic.co/t/elastic-hive-configuration/352458)

<div class="topic-metadata">

**Author:** [@John\_Papadopoulos](https://discuss.elastic.co/u/John_Papadopoulos)\
**Replies:** 0\
**Last updated:** [February 3, 2024, 12:47pm UTC](https://discuss.elastic.co/t/elastic-hive-configuration/352458 "2024-02-03T12:47:37Z")

</div>

Hello. What i have is elastic running in a host windows server and i want to install hive from a WSL ubuntu which will be hosted in the windows server. My elastic config file only accepts https connections. SO i have set…

---

## [Monitoring ES JVM with jolokia javaagent](https://discuss.elastic.co/t/monitoring-es-jvm-with-jolokia-javaagent/352454)

<div class="topic-metadata">

**Author:** [@Kalpesh\_Shekhat](https://discuss.elastic.co/u/Kalpesh_Shekhat)\
**Replies:** 0\
**Last updated:** [February 3, 2024, 9:39am UTC](https://discuss.elastic.co/t/monitoring-es-jvm-with-jolokia-javaagent/352454 "2024-02-03T09:39:38Z")

</div>

Hi, I want to monitor ES JVM using jolokia java agent. I have configured below options in /etc/elasticsearch/jvm.options.d/jmx.options -javaagent:/opt/jolokia/jolokia-agent-jvm-javaagent.jar=port=8081,host=localhost a…

---

## [Does elastic have a timestamp field as part of metadata as to when was the document written to index?](https://discuss.elastic.co/t/does-elastic-have-a-timestamp-field-as-part-of-metadata-as-to-when-was-the-document-written-to-index/352449)

<div class="topic-metadata">

**Author:** [@Rachana\_Maniyar](https://discuss.elastic.co/u/Rachana_Maniyar)\
**Replies:** 1\
**Last updated:** [February 3, 2024, 2:32am UTC](https://discuss.elastic.co/t/does-elastic-have-a-timestamp-field-as-part-of-metadata-as-to-when-was-the-document-written-to-index/352449 "2024-02-03T02:32:28Z")

</div>

Does elastic have a timestamp field as part of metadata as to when was the document written to index ? current meta fields that i see are only these - I have a usecase where the timestamps in the records could be diffe…

---

## [Problems Joining a Cluster](https://discuss.elastic.co/t/problems-joining-a-cluster/351904)

<div class="topic-metadata">

**Author:** [@bryanrood](https://discuss.elastic.co/u/bryanrood)\
**Replies:** 32\
**Last updated:** [February 2, 2024, 8:03pm UTC](https://discuss.elastic.co/t/problems-joining-a-cluster/351904 "2024-02-02T20:03:04Z")

</div>

Hi Everyone, I think I posted my first post in the wrong elasticsearch category. I'm trying to get my new cluster up and working and I'm really struggling with order of operation. I have tried a whole bunch of things bu…

---

## [Elasticsearch issue when indexing nanoseconds](https://discuss.elastic.co/t/elasticsearch-issue-when-indexing-nanoseconds/352345)

<div class="topic-metadata">

**Author:** [@kannan\_raj](https://discuss.elastic.co/u/kannan_raj)\
**Replies:** 2\
**Last updated:** [February 2, 2024, 7:57pm UTC](https://discuss.elastic.co/t/elasticsearch-issue-when-indexing-nanoseconds/352345 "2024-02-02T19:57:32Z")

</div>

Hi Team, Could not able to index the nanaseconds? PUT \_template/datenanos { "index\_patterns": \["datenanos"\], "mappings": { "properties": { "timestamp": { "type": "date\_nanos" } } } } …

---

## [How to do a distance sort over entities which each have multiple locations](https://discuss.elastic.co/t/how-to-do-a-distance-sort-over-entities-which-each-have-multiple-locations/352439)

<div class="topic-metadata">

**Author:** [@BradDotyBWell](https://discuss.elastic.co/u/BradDotyBWell)\
**Replies:** 12\
**Last updated:** [February 2, 2024, 7:30pm UTC](https://discuss.elastic.co/t/how-to-do-a-distance-sort-over-entities-which-each-have-multiple-locations/352439 "2024-02-02T19:30:50Z")

</div>

Your product is simple-minded when it comes to distance searches. We have organizations who have multiple locations each. When a user does a search, we MUST use the closest location for each org to that user. Your pro…

---

## [Half\_float for Dense vector field](https://discuss.elastic.co/t/half-float-for-dense-vector-field/352387)

<div class="topic-metadata">

**Author:** [@mwon](https://discuss.elastic.co/u/mwon)\
**Replies:** 2\
**Last updated:** [February 2, 2024, 6:42pm UTC](https://discuss.elastic.co/t/half-float-for-dense-vector-field/352387 "2024-02-02T18:42:58Z")

</div>

Hi, Currently, Dense vector field is restricted to float (32bit) or byte (int8). Is there any plan to add half\_float option? Thanks

---

## [How to exclude a template from Elasticsearch Auto index creation](https://discuss.elastic.co/t/how-to-exclude-a-template-from-elasticsearch-auto-index-creation/352392)

<div class="topic-metadata">

**Author:** [@Veysel\_yuksel](https://discuss.elastic.co/u/Veysel_yuksel)\
**Replies:** 1\
**Last updated:** [February 2, 2024, 5:16pm UTC](https://discuss.elastic.co/t/how-to-exclude-a-template-from-elasticsearch-auto-index-creation/352392 "2024-02-02T17:16:29Z")

</div>

Hello everyone, I have beats index template in my cluster. Auto index creation (\*) is enabled for all templates in this cluster. And I decided to setup new cluster for beats data. But I need to prevent access to old clu…

---

## [Which is the best suggested to be used either Java API client or Java High Level Rest Client](https://discuss.elastic.co/t/which-is-the-best-suggested-to-be-used-either-java-api-client-or-java-high-level-rest-client/352355)

<div class="topic-metadata">

**Author:** [@prasad.ram1431](https://discuss.elastic.co/u/prasad.ram1431)\
**Replies:** 4\
**Last updated:** [February 2, 2024, 4:57pm UTC](https://discuss.elastic.co/t/which-is-the-best-suggested-to-be-used-either-java-api-client-or-java-high-level-rest-client/352355 "2024-02-02T16:57:31Z")

</div>

Hi Team, Can you please help in identifying the best one to use among Java API Client and Java High Level Rest Client (as I can see HLRC is deprecated). Also, just wanted to know whether HLRC is permanently deprecated …

---

## [Painless scripted field with nested IF statment](https://discuss.elastic.co/t/painless-scripted-field-with-nested-if-statment/352091)

<div class="topic-metadata">

**Author:** [@auato](https://discuss.elastic.co/u/auato)\
**Replies:** 0\
**Last updated:** [January 30, 2024, 1:20pm UTC](https://discuss.elastic.co/t/painless-scripted-field-with-nested-if-statment/352091 "2024-01-30T13:20:11Z")

</div>

I have these two working scripted fields: def M3 = doc\['obj'\].value.splitOnToken('\_'); return M3.length \>= 4 ? M3\[3\] : null; def M2 = doc\['obj'\].value.splitOnToken('\_'); return M2.length \>= 4 ? M2\[2\] : null; that I wo…

---

## [S3 Repository](https://discuss.elastic.co/t/s3-repository/352282)

<div class="topic-metadata">

**Author:** [@Haytham\_Shammout](https://discuss.elastic.co/u/Haytham_Shammout)\
**Replies:** 1\
**Last updated:** [February 2, 2024, 4:43pm UTC](https://discuss.elastic.co/t/s3-repository/352282 "2024-02-02T16:43:34Z")

</div>

Hello Dears, We are new to S3 repository and taking snapshots in ELK, we faced a case as below appreciate your support on it. First of all we implement policy to take snapshots as below SC. after taking 2 snapshots…

---

## [Cannot run curator from cron in docker container as the elasticsearch user](https://discuss.elastic.co/t/cannot-run-curator-from-cron-in-docker-container-as-the-elasticsearch-user/352039)

<div class="topic-metadata">

**Author:** [@silentfilm](https://discuss.elastic.co/u/silentfilm)\
**Replies:** 10\
**Last updated:** [February 2, 2024, 4:08pm UTC](https://discuss.elastic.co/t/cannot-run-curator-from-cron-in-docker-container-as-the-elasticsearch-user/352039 "2024-02-02T16:08:46Z")

</div>

In my 8.8.2 Elasticsearch container, I have this cron job in the cron table: \* 1 \* \* \* su elasticsearch /bin/bash -c "export ES\_CURATOR\_USERNAME=curator ES\_CURATOR\_PASSWORD=xxxxx; /usr/local/bin/curator --config /config…

---

## [Data inconsistencty shown in ELK](https://discuss.elastic.co/t/data-inconsistencty-shown-in-elk/350963)

<div class="topic-metadata">

**Author:** [@Ravi\_Pattar](https://discuss.elastic.co/u/Ravi_Pattar)\
**Replies:** 4\
**Last updated:** [February 2, 2024, 3:50pm UTC](https://discuss.elastic.co/t/data-inconsistencty-shown-in-elk/350963 "2024-02-02T15:50:22Z")

</div>

Hello, I am running with ELK version 7.17.15. # curl -X GET "localhost:9200" { "name" : "ip", "cluster\_name" : "name", "cluster\_uuid" : "uudi", "version" : { "number" : "7.17.15", "build\_flavor" : "defa…

---

## [What is the best procedure to delete indices?](https://discuss.elastic.co/t/what-is-the-best-procedure-to-delete-indices/351778)

<div class="topic-metadata">

**Author:** [@7a6b6f](https://discuss.elastic.co/u/7a6b6f)\
**Replies:** 2\
**Last updated:** [February 2, 2024, 3:17pm UTC](https://discuss.elastic.co/t/what-is-the-best-procedure-to-delete-indices/351778 "2024-02-02T15:17:38Z")

</div>

Hello everyone, I have a question regarding the deletion of indices in an ELK (Elasticsearch, Logstash, Kibana) Docker-compose stack. Specifically, I would like to know the recommended procedure for deleting indices, an…

---

## [Query on ELK stack version 8.12: post installation](https://discuss.elastic.co/t/query-on-elk-stack-version-8-12-post-installation/352304)

<div class="topic-metadata">

**Author:** [@Ravi\_Pattar](https://discuss.elastic.co/u/Ravi_Pattar)\
**Replies:** 1\
**Last updated:** [February 2, 2024, 1:44pm UTC](https://discuss.elastic.co/t/query-on-elk-stack-version-8-12-post-installation/352304 "2024-02-02T13:44:00Z")

</div>

Hello, I have installed ELK stack version 8.12 on one of the test instance. The purpose was to assign the existing ILM policy set for ver 7.17, as I could see new indices are being built with filebeat version 8.x on a p…

---

## [BulkInsert fails with knn\_vector data type](https://discuss.elastic.co/t/bulkinsert-fails-with-knn-vector-data-type/352390)

<div class="topic-metadata">

**Author:** [@CodeNinja](https://discuss.elastic.co/u/CodeNinja)\
**Replies:** 0\
**Last updated:** [February 2, 2024, 11:58am UTC](https://discuss.elastic.co/t/bulkinsert-fails-with-knn-vector-data-type/352390 "2024-02-02T11:58:44Z")

</div>

Hello All, I am using BulkInsert (Java client) to ingest with an Index that has knn\_vector Data Type. Currently, I am able to ingest when I create document with a POJO Class object for every row that insert into Index. …

---

## [How we can drop transport event type in Elasticsearch 8.12 version](https://discuss.elastic.co/t/how-we-can-drop-transport-event-type-in-elasticsearch-8-12-version/352358)

<div class="topic-metadata">

**Author:** [@ashishshukla](https://discuss.elastic.co/u/ashishshukla)\
**Replies:** 1\
**Last updated:** [February 2, 2024, 5:43am UTC](https://discuss.elastic.co/t/how-we-can-drop-transport-event-type-in-elasticsearch-8-12-version/352358 "2024-02-02T05:43:40Z")

</div>

Hi Team, I am getting system generated log in Elasticsearch Audit logs file. can you please provide me solution to avoid the system generated logs in audit log. I did below configuration in elasticsearch.yml file Mi…

---

## [Getting Error in Elasticsearch 8.12 version](https://discuss.elastic.co/t/getting-error-in-elasticsearch-8-12-version/352371)

<div class="topic-metadata">

**Author:** [@ashishshukla](https://discuss.elastic.co/u/ashishshukla)\
**Replies:** 1\
**Last updated:** [February 2, 2024, 8:07am UTC](https://discuss.elastic.co/t/getting-error-in-elasticsearch-8-12-version/352371 "2024-02-02T08:07:34Z")

</div>

I am getting error while starting the Elasticsearch please provide the solution for this. Error java.lang.IllegalArgumentException: unknown setting \[xpack.security.audit.logfile.events.ignore\_filters.users\] please chec…

---

## [Should I increase my amount of RAM?](https://discuss.elastic.co/t/should-i-increase-my-amount-of-ram/352214)

<div class="topic-metadata">

**Author:** [@louisdeveloper](https://discuss.elastic.co/u/louisdeveloper)\
**Replies:** 9\
**Last updated:** [February 2, 2024, 1:57am UTC](https://discuss.elastic.co/t/should-i-increase-my-amount-of-ram/352214 "2024-02-02T01:57:22Z")

</div>

I noticed that the RAM usage percentage of my nodes is quite high. Based on these logs, should I increase the amount of RAM on my servers? The master is usually the master-01 machine, but in the log it is as master-02,…

---

## [How to Azure Entra ID Groups for SAML SSO?](https://discuss.elastic.co/t/how-to-azure-entra-id-groups-for-saml-sso/352340)

<div class="topic-metadata">

**Author:** [@World\_Python](https://discuss.elastic.co/u/World_Python)\
**Replies:** 1\
**Last updated:** [February 1, 2024, 11:38pm UTC](https://discuss.elastic.co/t/how-to-azure-entra-id-groups-for-saml-sso/352340 "2024-02-01T23:38:50Z")

</div>

Following these docs: Config: xpack: security: authc: realms: saml: saml1: order: 3 attributes.dn: "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddr…

---

## [‏how to display the documents of an index in kibana 7.5?](https://discuss.elastic.co/t/how-to-display-the-documents-of-an-index-in-kibana-7-5/352118)

<div class="topic-metadata">

**Author:** [@mpniel](https://discuss.elastic.co/u/mpniel)\
**Replies:** 4\
**Last updated:** [February 1, 2024, 10:59pm UTC](https://discuss.elastic.co/t/how-to-display-the-documents-of-an-index-in-kibana-7-5/352118 "2024-02-01T22:59:34Z")

</div>

‏how to list the contents and view the documents of an index in kibana 7.5, using index management or api?

---

## [Api calls for Kibana](https://discuss.elastic.co/t/api-calls-for-kibana/352328)

<div class="topic-metadata">

**Author:** [@alon\_carmelly](https://discuss.elastic.co/u/alon_carmelly)\
**Replies:** 2\
**Last updated:** [February 1, 2024, 7:45pm UTC](https://discuss.elastic.co/t/api-calls-for-kibana/352328 "2024-02-01T19:45:17Z")

</div>

Hi there, I am setting up Elk stack on a eks cluster using helm charts. In regards to the helm chart and in general. What configuration elements should be enabled to allow me to set data views with a simple api call? I…

---

## [After Reindex, no more new records](https://discuss.elastic.co/t/after-reindex-no-more-new-records/352335)

<div class="topic-metadata">

**Author:** [@rachelyang](https://discuss.elastic.co/u/rachelyang)\
**Replies:** 0\
**Last updated:** [February 1, 2024, 6:09pm UTC](https://discuss.elastic.co/t/after-reindex-no-more-new-records/352335 "2024-02-01T18:09:12Z")

</div>

I want to change the type of the geo field, so I reindex the current index. The reindex was successful. I have recovered all the records in the past. But no more new record are coming in. The docs.count and store.size do…

---

## [How do I store the data from an Elasticsearch store](https://discuss.elastic.co/t/how-do-i-store-the-data-from-an-elasticsearch-store/351597)

<div class="topic-metadata">

**Author:** [@susnato](https://discuss.elastic.co/u/susnato)\
**Replies:** 4\
**Last updated:** [February 1, 2024, 6:07pm UTC](https://discuss.elastic.co/t/how-do-i-store-the-data-from-an-elasticsearch-store/351597 "2024-02-01T18:07:01Z")

</div>

(Hi, I am totally new to Elastic search, so sorry if this is very basic question.) I have an Elasticsearch store running in background using docker. I have added some files and corresponding embeddings to it and now…

---

## [How to segregate from which source elastic is receiving messages?](https://discuss.elastic.co/t/how-to-segregate-from-which-source-elastic-is-receiving-messages/352323)

<div class="topic-metadata">

**Author:** [@Sanjay\_Kumar2](https://discuss.elastic.co/u/Sanjay_Kumar2)\
**Replies:** 0\
**Last updated:** [February 1, 2024, 3:53pm UTC](https://discuss.elastic.co/t/how-to-segregate-from-which-source-elastic-is-receiving-messages/352323 "2024-02-01T15:53:41Z")

</div>

As a part of ELK migration we are trying to setup our new cluster in a shared AKS cluster. Issue is, we have the flow as Filebeat -\> Ingress -\> Logstash entry -\> Logstash indexing -\> Kafka -\> Elastic. Currently as a part…

---

## [I get status: Red page when connecting to kibana](https://discuss.elastic.co/t/i-get-status-red-page-when-connecting-to-kibana/352317)

<div class="topic-metadata">

**Author:** [@mpniel](https://discuss.elastic.co/u/mpniel)\
**Replies:** 0\
**Last updated:** [February 1, 2024, 3:26pm UTC](https://discuss.elastic.co/t/i-get-status-red-page-when-connecting-to-kibana/352317 "2024-02-01T15:26:13Z")

</div>

I get status: Red page when connecting to kibana. The elasticsearch log say that not enough master nodes discovered. The cluster have 3 nodes and only one node is up. I tried to power on the other nodes but after a whi…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=149)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=151)
