# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=151

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 152

---

## [Knowlegde Graphs, ELK and NEO4j](https://discuss.elastic.co/t/knowlegde-graphs-elk-and-neo4j/351686)

<div class="topic-metadata">

**Author:** [@wil93](https://discuss.elastic.co/u/wil93)\
**Replies:** 4\
**Last updated:** [February 1, 2024, 2:47pm UTC](https://discuss.elastic.co/t/knowlegde-graphs-elk-and-neo4j/351686 "2024-02-01T14:47:48Z")

</div>

Hello, I would like to use ‘knowledge graph’ capabilities to detect and identify potential relationships and patterns in data (1). That data is currently stored in Elasticsearch indices. I would like to detect relation…

---

## [Meaning of packages/methods with underscore prefix in java-api library](https://discuss.elastic.co/t/meaning-of-packages-methods-with-underscore-prefix-in-java-api-library/352295)

<div class="topic-metadata">

**Author:** [@buitcj](https://discuss.elastic.co/u/buitcj)\
**Replies:** 0\
**Last updated:** [February 1, 2024, 1:44pm UTC](https://discuss.elastic.co/t/meaning-of-packages-methods-with-underscore-prefix-in-java-api-library/352295 "2024-02-01T13:44:44Z")

</div>

Just wondering why some of method calls like the following \_toQuery(), which was found in public docs, have underscore prefixes. I also saw this in some packages like \_types. Typically I see this done for internal usage,…

---

## [Snapshot creation failed](https://discuss.elastic.co/t/snapshot-creation-failed/352243)

<div class="topic-metadata">

**Author:** [@VijayIQA](https://discuss.elastic.co/u/VijayIQA)\
**Replies:** 0\
**Last updated:** [February 1, 2024, 4:51am UTC](https://discuss.elastic.co/t/snapshot-creation-failed/352243 "2024-02-01T04:51:12Z")

</div>

HI Team, I was taken snapshot of Elasticsearch version 8.8.1, Then restored that snapshot into Elasticsearch version of 8.12.0. Now Tried to take snapshot from Elasticsearch version of 8.12.0 Getting an error as {"@ti…

---

## [Elasticsearch and Kibana 8.11.3 running issue in WSL](https://discuss.elastic.co/t/elasticsearch-and-kibana-8-11-3-running-issue-in-wsl/352289)

<div class="topic-metadata">

**Author:** [@vikas.shirke](https://discuss.elastic.co/u/vikas.shirke)\
**Replies:** 2\
**Last updated:** [February 1, 2024, 1:24pm UTC](https://discuss.elastic.co/t/elasticsearch-and-kibana-8-11-3-running-issue-in-wsl/352289 "2024-02-01T13:24:51Z")

</div>

Hi I am trying to run Elasticsearch and Kibana version 8.11.3 on Windows WSL version to build custom theme. I am able to run the yarn kbn bootstrap sucessfully. I have used below commands in separate windows to start …

---

## [Remote Cluster node 9300 port cannot connect](https://discuss.elastic.co/t/remote-cluster-node-9300-port-cannot-connect/352031)

<div class="topic-metadata">

**Author:** [@rachelyang](https://discuss.elastic.co/u/rachelyang)\
**Replies:** 1\
**Last updated:** [February 1, 2024, 12:40pm UTC](https://discuss.elastic.co/t/remote-cluster-node-9300-port-cannot-connect/352031 "2024-02-01T12:40:56Z")

</div>

I am connecting a remote cluster from the local cluster. I got a connection time out error. Then I tried to curl the 9200 and 9300 port from the local cluster note to the remote cluster node. This is the response: curl …

---

## [Horizontal scaling of Elasticsearch cluster](https://discuss.elastic.co/t/horizontal-scaling-of-elasticsearch-cluster/352147)

<div class="topic-metadata">

**Author:** [@Priyanka\_chauhan](https://discuss.elastic.co/u/Priyanka_chauhan)\
**Replies:** 5\
**Last updated:** [February 1, 2024, 12:33pm UTC](https://discuss.elastic.co/t/horizontal-scaling-of-elasticsearch-cluster/352147 "2024-02-01T12:33:19Z")

</div>

if I have index size of 2tb and node size is 1tb , In that case how index will split on another nodes and if i add new data nodes so how this data can be distribute, it will do automatically? Or I can do it manually. I w…

---

## [Generates self-signed client certificates (not server certificates) for Elasticsearch clients](https://discuss.elastic.co/t/generates-self-signed-client-certificates-not-server-certificates-for-elasticsearch-clients/352182)

<div class="topic-metadata">

**Author:** [@patpanda](https://discuss.elastic.co/u/patpanda)\
**Replies:** 1\
**Last updated:** [February 1, 2024, 6:58am UTC](https://discuss.elastic.co/t/generates-self-signed-client-certificates-not-server-certificates-for-elasticsearch-clients/352182 "2024-02-01T06:58:04Z")

</div>

What I am trying to achieve Generates self-signed client certificate (not server certificates) for clients trying to connect to Elasticsearch server. What did I try: I ran this command elasticsearch/bin elasticsearc…

---

## [How to bulk migrate users and roles with native realms authentication](https://discuss.elastic.co/t/how-to-bulk-migrate-users-and-roles-with-native-realms-authentication/350476)

<div class="topic-metadata">

**Author:** [@fim](https://discuss.elastic.co/u/fim)\
**Replies:** 1\
**Last updated:** [February 1, 2024, 6:31am UTC](https://discuss.elastic.co/t/how-to-bulk-migrate-users-and-roles-with-native-realms-authentication/350476 "2024-02-01T06:31:08Z")

</div>

I'm looking for an advice how to migrate users (if possible including passwords) and roles from an old cluster to a new cluster. (Elasticsearch v8.x) I wanna perform this with Kibana DevTools. I populate users and role…

---

## [\[Filebeat\] How to read "special text + json string" to es?](https://discuss.elastic.co/t/filebeat-how-to-read-special-text-json-string-to-es/352251)

<div class="topic-metadata">

**Author:** [@uiosun](https://discuss.elastic.co/u/uiosun)\
**Replies:** 0\
**Last updated:** [February 1, 2024, 6:21am UTC](https://discuss.elastic.co/t/filebeat-how-to-read-special-text-json-string-to-es/352251 "2024-02-01T06:21:40Z")

</div>

I have the struct in log files, like there (JSON has near 60 column......): \[2024-01-29 11:10:35\] standard.INFO: {"start\_time": "1706497834.091", "remote\_addr": "www.demo.com", "remote\_user": "a\_user"} \[2024-01-29 11:10…

---

## [Daemon startup failed with exit code](https://discuss.elastic.co/t/daemon-startup-failed-with-exit-code/352221)

<div class="topic-metadata">

**Author:** [@userR](https://discuss.elastic.co/u/userR)\
**Replies:** 2\
**Last updated:** [January 31, 2024, 11:19pm UTC](https://discuss.elastic.co/t/daemon-startup-failed-with-exit-code/352221 "2024-01-31T23:19:54Z")

</div>

Hi everyone, I am testing out esrally and running into the following issues while running java17 and testing 8.7.0: \[user ~\]$ esrally race --distribution-version=8.7.0 --track=geonames \_\_\_\_ \_\_\_\_ / \_\_ \\\_\_…

---

## [FSCrawler - Indexing mix of Big and small files - HTTP Entity too large error](https://discuss.elastic.co/t/fscrawler-indexing-mix-of-big-and-small-files-http-entity-too-large-error/350939)

<div class="topic-metadata">

**Author:** [@kamalsharma](https://discuss.elastic.co/u/kamalsharma)\
**Replies:** 8\
**Last updated:** [January 31, 2024, 5:12pm UTC](https://discuss.elastic.co/t/fscrawler-indexing-mix-of-big-and-small-files-http-entity-too-large-error/350939 "2024-01-31T17:12:19Z")

</div>

I have splitted a large text file into multiple files of 50 MB each. When the setting of bulk\_size is 1 in Fscrawler \_settings.json, each file is indexed into Elasticsearch without any error. If the bulk size is increase…

---

## [Who do I contact to get a STIG checklist?](https://discuss.elastic.co/t/who-do-i-contact-to-get-a-stig-checklist/352198)

<div class="topic-metadata">

**Author:** [@chris.pyle](https://discuss.elastic.co/u/chris.pyle)\
**Replies:** 1\
**Last updated:** [January 31, 2024, 4:52pm UTC](https://discuss.elastic.co/t/who-do-i-contact-to-get-a-stig-checklist/352198 "2024-01-31T16:52:54Z")

</div>

federal@elastic.co is not a valid email address.

---

## [Regarding elasticsearch rolling upgrades](https://discuss.elastic.co/t/regarding-elasticsearch-rolling-upgrades/352056)

<div class="topic-metadata">

**Author:** [@jaykb77](https://discuss.elastic.co/u/jaykb77)\
**Replies:** 5\
**Last updated:** [January 31, 2024, 2:54pm UTC](https://discuss.elastic.co/t/regarding-elasticsearch-rolling-upgrades/352056 "2024-01-31T14:54:53Z")

</div>

Hi, We are trying to upgrade our elasticsearch cluster from 7.17 to 8.X and we will have to do it in a rolling fashion. I found the below documentation thats for 7.x version. Do we not have similar doc for 8.x or i…

---

## [Java API - what are TDocument, TPartialDocument?](https://discuss.elastic.co/t/java-api-what-are-tdocument-tpartialdocument/352199)

<div class="topic-metadata">

**Author:** [@TimWardFS](https://discuss.elastic.co/u/TimWardFS)\
**Replies:** 0\
**Last updated:** [January 31, 2024, 2:31pm UTC](https://discuss.elastic.co/t/java-api-what-are-tdocument-tpartialdocument/352199 "2024-01-31T14:31:59Z")

</div>

We're converting some code from using the old client to the new client. The new version of UpdateRequest, to pick an example, now has type parameters TDocument and TPartialDocument ... but I can't find out (after a coup…

---

## [Suggested method to extract data in bulk](https://discuss.elastic.co/t/suggested-method-to-extract-data-in-bulk/352099)

<div class="topic-metadata">

**Author:** [@yeikel](https://discuss.elastic.co/u/yeikel)\
**Replies:** 3\
**Last updated:** [January 31, 2024, 2:23pm UTC](https://discuss.elastic.co/t/suggested-method-to-extract-data-in-bulk/352099 "2024-01-31T14:23:57Z")

</div>

Hi all, I am trying to execute a full extract of the Elasticsearch data on intervals or in a monthly based (depending on what creates less load), push it to a file and then load it to another system (Hive) for analytics…

---

## [How to set query params 'from' and 'size' in latest java api 8.11](https://discuss.elastic.co/t/how-to-set-query-params-from-and-size-in-latest-java-api-8-11/352162)

<div class="topic-metadata">

**Author:** [@Darth\_vader\_22](https://discuss.elastic.co/u/Darth_vader_22)\
**Replies:** 9\
**Last updated:** [January 31, 2024, 1:58pm UTC](https://discuss.elastic.co/t/how-to-set-query-params-from-and-size-in-latest-java-api-8-11/352162 "2024-01-31T13:58:38Z")

</div>

Hello, i'm trying to send a request with a specific from and size parameters , by default there are set to ( from=0 , size=10) . here's a snippet of my code where i construct my search query Query query = NativeQuery.…

---

## [What is most stable version of 8.\*](https://discuss.elastic.co/t/what-is-most-stable-version-of-8/352189)

<div class="topic-metadata">

**Author:** [@Krishna\_Sailesh](https://discuss.elastic.co/u/Krishna_Sailesh)\
**Replies:** 2\
**Last updated:** [January 31, 2024, 1:50pm UTC](https://discuss.elastic.co/t/what-is-most-stable-version-of-8/352189 "2024-01-31T13:50:33Z")

</div>

I need to upgrade the Elasticsearch from 7.9 to 8.\* due to vulnerabilities. what is the most stable version of Elasticsearch to upgrade?

---

## [Approximate KNN, Preloading & Performance](https://discuss.elastic.co/t/approximate-knn-preloading-performance/352105)

<div class="topic-metadata">

**Author:** [@robertasg](https://discuss.elastic.co/u/robertasg)\
**Replies:** 4\
**Last updated:** [January 31, 2024, 12:27pm UTC](https://discuss.elastic.co/t/approximate-knn-preloading-performance/352105 "2024-01-31T12:27:16Z")

</div>

Hi there! I'm very excited to explore Elasticsearch as an option for both ANN and hybrid search solution. The current guides provided for tuning KNN performance have been very helpful however I feel like I'm encounterin…

---

## [Relevance Issues in Vector Search](https://discuss.elastic.co/t/relevance-issues-in-vector-search/352180)

<div class="topic-metadata">

**Author:** [@Adrien\_Corb](https://discuss.elastic.co/u/Adrien_Corb)\
**Replies:** 0\
**Last updated:** [January 31, 2024, 11:14am UTC](https://discuss.elastic.co/t/relevance-issues-in-vector-search/352180 "2024-01-31T11:14:31Z")

</div>

Hello, I am in the process of testing self-hosted solutions. I'm encountering an issue with vector search. My goal is to index pages of a website that mainly consists of a title and content. I have created two dense\_vec…

---

## [Trying to index from Logstash Kubernetes pod into an Elasticsearch Docker container](https://discuss.elastic.co/t/trying-to-index-from-logstash-kubernetes-pod-into-an-elasticsearch-docker-container/351991)

<div class="topic-metadata">

**Author:** [@rowish](https://discuss.elastic.co/u/rowish)\
**Replies:** 3\
**Last updated:** [January 31, 2024, 10:04am UTC](https://discuss.elastic.co/t/trying-to-index-from-logstash-kubernetes-pod-into-an-elasticsearch-docker-container/351991 "2024-01-31T10:04:42Z")

</div>

On the same cloud, I have an instance of Logstash 6.6.1 running within a certain Kubernetes pod that I am trying to make it index into an Elasticsearch 8.6.1 running on a Docker container hosted on an VM with IP address …

---

## [Transform is only partially updated](https://discuss.elastic.co/t/transform-is-only-partially-updated/351935)

<div class="topic-metadata">

**Author:** [@Doron\_Abramovich](https://discuss.elastic.co/u/Doron_Abramovich)\
**Replies:** 9\
**Last updated:** [January 31, 2024, 9:54am UTC](https://discuss.elastic.co/t/transform-is-only-partially-updated/351935 "2024-01-31T09:54:19Z")

</div>

Hi everyone, I have an transform that suppose to track the latest doc of some index. The transform I made is based on field called "etl\_id" and for some reason it is updated only for few "etl\_id" but not all of them, h…

---

## [Elasticsearch 7 and JVM 21](https://discuss.elastic.co/t/elasticsearch-7-and-jvm-21/351238)

<div class="topic-metadata">

**Author:** [@ondrokrc](https://discuss.elastic.co/u/ondrokrc)\
**Replies:** 3\
**Last updated:** [January 31, 2024, 9:43am UTC](https://discuss.elastic.co/t/elasticsearch-7-and-jvm-21/351238 "2024-01-31T09:43:09Z")

</div>

I noticed that elasticsearch 7.17.15 comes with bundled JDK 21.0.1. But in Support Matrix | Elastic in documentation, JDK 21 is not listed as supported. Is it an inaccuracy in the Support Matrix and should I consider J…

---

## [Where did uncounted heap memory go?](https://discuss.elastic.co/t/where-did-uncounted-heap-memory-go/352163)

<div class="topic-metadata">

**Author:** [@huajun\_qi](https://discuss.elastic.co/u/huajun_qi)\
**Replies:** 0\
**Last updated:** [January 31, 2024, 9:40am UTC](https://discuss.elastic.co/t/where-did-uncounted-heap-memory-go/352163 "2024-01-31T09:40:30Z")

</div>

our cluster keeps running in high heap memory, but we can't find where are memories consumed? here is the output from /\_cate/nodes api: id version type jdk heap.current heap.percent heap.max ram.current ram.perc…

---

## [Transformation 'pivot' has value null](https://discuss.elastic.co/t/transformation-pivot-has-value-null/351257)

<div class="topic-metadata">

**Author:** [@minova94](https://discuss.elastic.co/u/minova94)\
**Replies:** 7\
**Last updated:** [January 31, 2024, 9:19am UTC](https://discuss.elastic.co/t/transformation-pivot-has-value-null/351257 "2024-01-31T09:19:00Z")

</div>

Hello :wave: I have a question regarding transforms. There is source index which has dedicated transformation with grouping by 'pivot'. The pivot can be one field or concatenation of multiple fields. For ex: 'fullNa…

---

## [Enable wildcard for AppSearch search API](https://discuss.elastic.co/t/enable-wildcard-for-appsearch-search-api/352161)

<div class="topic-metadata">

**Author:** [@Disha\_Bodade](https://discuss.elastic.co/u/Disha_Bodade)\
**Replies:** 0\
**Last updated:** [January 31, 2024, 9:11am UTC](https://discuss.elastic.co/t/enable-wildcard-for-appsearch-search-api/352161 "2024-01-31T09:11:13Z")

</div>

Hi Team, There is already closed discussion with above requirement. I know that App Search don't support wildcard, instead it supports prefix matching. But recently we switch from some other search solution to appsear…

---

## [Elastic installation on Robin cloud](https://discuss.elastic.co/t/elastic-installation-on-robin-cloud/352158)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 1\
**Last updated:** [January 31, 2024, 8:44am UTC](https://discuss.elastic.co/t/elastic-installation-on-robin-cloud/352158 "2024-01-31T08:44:41Z")

</div>

To set up elastic (on K8s) - say platinum version on robin cloud, is there any limitations? I can see elastic set up on robin from robin's website but no details on whether the paid version can work with robin, could so…

---

## [Kibana cannot use elasticsearch normally - Cluster Red](https://discuss.elastic.co/t/kibana-cannot-use-elasticsearch-normally-cluster-red/352149)

<div class="topic-metadata">

**Author:** [@kei\_ru](https://discuss.elastic.co/u/kei_ru)\
**Replies:** 3\
**Last updated:** [January 31, 2024, 8:19am UTC](https://discuss.elastic.co/t/kibana-cannot-use-elasticsearch-normally-cluster-red/352149 "2024-01-31T08:19:24Z")

</div>

Configuration environment: es-7.17.8 kibana-7.17.8 filebeat-7.17.8 (Elasticsearch is a single node, and the data mount point is the efs file system of AWS) Problem Description: I started to find that kibanan was …

---

## [Difference in Shard & Index count during Snapshot & Restore](https://discuss.elastic.co/t/difference-in-shard-index-count-during-snapshot-restore/352154)

<div class="topic-metadata">

**Author:** [@Vadiraj\_Prahalad](https://discuss.elastic.co/u/Vadiraj_Prahalad)\
**Replies:** 0\
**Last updated:** [January 31, 2024, 6:46am UTC](https://discuss.elastic.co/t/difference-in-shard-index-count-during-snapshot-restore/352154 "2024-01-31T06:46:18Z")

</div>

Hello All, We are performing Elastic Upgrade by building parallel cluster for the existing cluster ( due to organization issues ) I have created Snapshot Policy in Source Cluster to run the snapshot at 5:30 PM PST ever…

---

## [Unable to add additional role to elastic instance in elastic cloud](https://discuss.elastic.co/t/unable-to-add-additional-role-to-elastic-instance-in-elastic-cloud/352081)

<div class="topic-metadata">

**Author:** [@RajuParipelly](https://discuss.elastic.co/u/RajuParipelly)\
**Replies:** 7\
**Last updated:** [January 31, 2024, 6:41am UTC](https://discuss.elastic.co/t/unable-to-add-additional-role-to-elastic-instance-in-elastic-cloud/352081 "2024-01-31T06:41:26Z")

</div>

Hello, I was trying to add additional role to the existing elasticsearch instance in the elastic cloud. I added node.roles : \[remote\_cluster\_client\] but while saving it throws the below error, could any one help me wit…

---

## [How to disable or enable a document when do knn search](https://discuss.elastic.co/t/how-to-disable-or-enable-a-document-when-do-knn-search/351677)

<div class="topic-metadata">

**Author:** [@r1ckC139](https://discuss.elastic.co/u/r1ckC139)\
**Replies:** 4\
**Last updated:** [January 31, 2024, 2:19am UTC](https://discuss.elastic.co/t/how-to-disable-or-enable-a-document-when-do-knn-search/351677 "2024-01-31T02:19:04Z")

</div>

Hello, in my index, there are certain documents that I want to disable or hide during a k-nearest neighbors (KNN) search. However, there may be situations where I need to enable or reveal these documents. How can I do th…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=150)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=152)
