# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=154

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 155

---

## [Runtime Field issue in indexes that contain nested objects](https://discuss.elastic.co/t/runtime-field-issue-in-indexes-that-contain-nested-objects/351737)

<div class="topic-metadata">

**Author:** [@victorhmorales](https://discuss.elastic.co/u/victorhmorales)\
**Replies:** 0\
**Last updated:** [January 24, 2024, 3:52pm UTC](https://discuss.elastic.co/t/runtime-field-issue-in-indexes-that-contain-nested-objects/351737 "2024-01-24T15:52:45Z")

</div>

Hello there, I'm trying to use Runtime Fields in indexes that contain nested objects, but it's not working. I tried to add them by 'Discover', 'Lens Editor, 'Data View management' and also 'Kibana Dev Tools'. I'm runni…

---

## [Upgrade Elasticsearch 8.2 to 8.x leads to ssl problems](https://discuss.elastic.co/t/upgrade-elasticsearch-8-2-to-8-x-leads-to-ssl-problems/351724)

<div class="topic-metadata">

**Author:** [@Ljapunov](https://discuss.elastic.co/u/Ljapunov)\
**Replies:** 1\
**Last updated:** [January 24, 2024, 3:14pm UTC](https://discuss.elastic.co/t/upgrade-elasticsearch-8-2-to-8-x-leads-to-ssl-problems/351724 "2024-01-24T15:14:38Z")

</div>

Hi everyone, I tried to upgrade two different clusters containing 3 or 5 nodes. Both are running elasticsearch 8.2.0 and I tried upgrading to different versions 8.11.4, 8.5.3 and 8.4.3. But all attempts failed with the …

---

## [ILM to delete only doc counts in a simple indice elasticsearch](https://discuss.elastic.co/t/ilm-to-delete-only-doc-counts-in-a-simple-indice-elasticsearch/351714)

<div class="topic-metadata">

**Author:** [@Musled](https://discuss.elastic.co/u/Musled)\
**Replies:** 2\
**Last updated:** [January 24, 2024, 1:59pm UTC](https://discuss.elastic.co/t/ilm-to-delete-only-doc-counts-in-a-simple-indice-elasticsearch/351714 "2024-01-24T13:59:24Z")

</div>

Hi there ! I'm working on a lifecycle for my indices in elasticsearch. To put you in context, I recover the logs of 20 applications with the ELK stack but I notice that my storage disk is filling up very quickly. Ther…

---

## [Best practice to install elastic on premise](https://discuss.elastic.co/t/best-practice-to-install-elastic-on-premise/351715)

<div class="topic-metadata">

**Author:** [@elasticexpert](https://discuss.elastic.co/u/elasticexpert)\
**Replies:** 0\
**Last updated:** [January 24, 2024, 1:54pm UTC](https://discuss.elastic.co/t/best-practice-to-install-elastic-on-premise/351715 "2024-01-24T13:54:23Z")

</div>

Hey! I have an elasticsearch cluster and I have a really serious problem which you can see here. Maybe this comment will exlplain it:. I have 10 servers with 750 GB RAM and 72 Cores and 8 disks. Right now, Elasticse…

---

## [Merge failed errors from indices with quantized vectors](https://discuss.elastic.co/t/merge-failed-errors-from-indices-with-quantized-vectors/351412)

<div class="topic-metadata">

**Author:** [@Louis\_Liu](https://discuss.elastic.co/u/Louis_Liu)\
**Replies:** 3\
**Last updated:** [January 24, 2024, 12:20pm UTC](https://discuss.elastic.co/t/merge-failed-errors-from-indices-with-quantized-vectors/351412 "2024-01-24T12:20:52Z")

</div>

I just upgraded our es cluster to 8.12.0. I created indices with quantized vectors, and started to migrate data. After few hours of data insert, the servers reports marking and sending shard failed due to \[shard failur…

---

## [Elasticsearch unstable cluster](https://discuss.elastic.co/t/elasticsearch-unstable-cluster/350157)

<div class="topic-metadata">

**Author:** [@elasticexpert](https://discuss.elastic.co/u/elasticexpert)\
**Replies:** 26\
**Last updated:** [January 24, 2024, 9:55am UTC](https://discuss.elastic.co/t/elasticsearch-unstable-cluster/350157 "2024-01-24T09:55:18Z")

</div>

Hey! I have an elastic cluster (version 8.11.1, upgraded from 8.5.3 but the problem is before the upgrade) with 10 datanode physical servers that is unstable (node are disconnecting and connecting automaticly) with two r…

---

## [Logs proccessed via Filebeat](https://discuss.elastic.co/t/logs-proccessed-via-filebeat/351698)

<div class="topic-metadata">

**Author:** [@Pavlo\_Pylypiv](https://discuss.elastic.co/u/Pavlo_Pylypiv)\
**Replies:** 0\
**Last updated:** [January 24, 2024, 8:58am UTC](https://discuss.elastic.co/t/logs-proccessed-via-filebeat/351698 "2024-01-24T08:58:51Z")

</div>

Hi! I would like to ask you what filebeat does with logs, which are not related to module? For example, I have Barracuda WAF and Barracuda FW running through Filebeat Barracuda Module (it works only for WAF). Will filebe…

---

## [Elasticsearch Cluster health is RED](https://discuss.elastic.co/t/elasticsearch-cluster-health-is-red/351622)

<div class="topic-metadata">

**Author:** [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Replies:** 3\
**Last updated:** [January 24, 2024, 8:02am UTC](https://discuss.elastic.co/t/elasticsearch-cluster-health-is-red/351622 "2024-01-24T08:02:17Z")

</div>

Hi Team, We had Elasticsearch with two node and due to some infra issues the server went down . Once it become online , I started the service and it was successful. But while checking the log showing below error. Could…

---

## [SSL Cert in MySQL Connector](https://discuss.elastic.co/t/ssl-cert-in-mysql-connector/351687)

<div class="topic-metadata">

**Author:** [@DEXUAN\_ZHU](https://discuss.elastic.co/u/DEXUAN_ZHU)\
**Replies:** 0\
**Last updated:** [January 24, 2024, 7:38am UTC](https://discuss.elastic.co/t/ssl-cert-in-mysql-connector/351687 "2024-01-24T07:38:21Z")

</div>

Hi, I just wanna confirm the source of this SSL cert in MySQL. Is it elasticsearch cluster SSL or MySQL server SSL? Thanks I tried both, but got some connection issue.

---

## [Error while running pyspark connecting to elastic search](https://discuss.elastic.co/t/error-while-running-pyspark-connecting-to-elastic-search/351195)

<div class="topic-metadata">

**Author:** [@kashi\_mn](https://discuss.elastic.co/u/kashi_mn)\
**Replies:** 2\
**Last updated:** [January 24, 2024, 5:03am UTC](https://discuss.elastic.co/t/error-while-running-pyspark-connecting-to-elastic-search/351195 "2024-01-24T05:03:36Z")

</div>

I am new to Pyspark and currently running pyspark and trying to connect to elasticsearch running on localhost. Below are the details : Elastic Details : localhost Port : 9200 No https. Code : from pyspark.sql impor…

---

## [How to retrieve data from a data stream using Elasticsearch API keys](https://discuss.elastic.co/t/how-to-retrieve-data-from-a-data-stream-using-elasticsearch-api-keys/351343)

<div class="topic-metadata">

**Author:** [@YUUTA.INOUE-JPN](https://discuss.elastic.co/u/YUUTA.INOUE-JPN)\
**Replies:** 2\
**Last updated:** [January 24, 2024, 12:41am UTC](https://discuss.elastic.co/t/how-to-retrieve-data-from-a-data-stream-using-elasticsearch-api-keys/351343 "2024-01-24T00:41:54Z")

</div>

Hello from Japan I have a question for you respected engineers. I would like to know about Elasticsearch API keys. I am using Winlogbeat (Ver8.11.1) to send Windows log information to Elasticsearch (Ver8.11.1). I wou…

---

## [Elastic Search causing major page memory errors on Azure Kubernetes (AKS)](https://discuss.elastic.co/t/elastic-search-causing-major-page-memory-errors-on-azure-kubernetes-aks/351670)

<div class="topic-metadata">

**Author:** [@DavidDean](https://discuss.elastic.co/u/DavidDean)\
**Replies:** 2\
**Last updated:** [January 23, 2024, 9:35pm UTC](https://discuss.elastic.co/t/elastic-search-causing-major-page-memory-errors-on-azure-kubernetes-aks/351670 "2024-01-23T21:35:18Z")

</div>

ES version: 7.17.5.1 Hosting: Azure Kubernetes (AKS) Kubernetes: 1.24.9 Virtual machine: D8ads v5 (8 vCPUs, 32 GB RAM) Virtual machine OS: Ubuntu 18.04.6 LTS Prometheus is reporting very high rates of major memory p…

---

## [Elastic Cluster Balancing](https://discuss.elastic.co/t/elastic-cluster-balancing/351456)

<div class="topic-metadata">

**Author:** [@Elk\_huh](https://discuss.elastic.co/u/Elk_huh)\
**Replies:** 3\
**Last updated:** [January 23, 2024, 5:18pm UTC](https://discuss.elastic.co/t/elastic-cluster-balancing/351456 "2024-01-23T17:18:02Z")

</div>

ELK stack 8.11, How do i get my cluster to balance by available disk space, 1 node keeps hitting the watermark while the other 3 nodes have 2TB available Here are the Cluster settings { "persistent": { "cluster"…

---

## [\`null\` is returned for sort instead of field value](https://discuss.elastic.co/t/null-is-returned-for-sort-instead-of-field-value/351642)

<div class="topic-metadata">

**Author:** [@sashatrn](https://discuss.elastic.co/u/sashatrn)\
**Replies:** 0\
**Last updated:** [January 23, 2024, 3:33pm UTC](https://discuss.elastic.co/t/null-is-returned-for-sort-instead-of-field-value/351642 "2024-01-23T15:33:19Z")

</div>

We have a strange behavior with sorting. The value returned for sorting is null. We decided to add a sub-field lowercase for all fields to support case-insensitive sorting. We did the following: Added custom lowercase…

---

## [Speeding up deep pagination for large ids query](https://discuss.elastic.co/t/speeding-up-deep-pagination-for-large-ids-query/351636)

<div class="topic-metadata">

**Author:** [@dsc](https://discuss.elastic.co/u/dsc)\
**Replies:** 0\
**Last updated:** [January 23, 2024, 2:45pm UTC](https://discuss.elastic.co/t/speeding-up-deep-pagination-for-large-ids-query/351636 "2024-01-23T14:45:08Z")

</div>

I've got an Elasticsearch index with ~100M documents, and typically need to search within a subset of them using an IDs query combined with other search terms/filters. These subsets of IDs are dynamic and come from an e…

---

## [Updating dateparts of timestamp using query update and/or reindex/pipeline](https://discuss.elastic.co/t/updating-dateparts-of-timestamp-using-query-update-and-or-reindex-pipeline/351618)

<div class="topic-metadata">

**Author:** [@petlit2049](https://discuss.elastic.co/u/petlit2049)\
**Replies:** 1\
**Last updated:** [January 23, 2024, 2:41pm UTC](https://discuss.elastic.co/t/updating-dateparts-of-timestamp-using-query-update-and-or-reindex-pipeline/351618 "2024-01-23T14:41:08Z")

</div>

I have log-data from various sources that have been pre-indexed into "master indices". I'd like to re-use that data by copying/re-indexing it into new indices but with parts of the timestamp updated - year, month, day to…

---

## [Create independent indices](https://discuss.elastic.co/t/create-independent-indices/351603)

<div class="topic-metadata">

**Author:** [@marotaal](https://discuss.elastic.co/u/marotaal)\
**Replies:** 3\
**Last updated:** [January 23, 2024, 2:00pm UTC](https://discuss.elastic.co/t/create-independent-indices/351603 "2024-01-23T14:00:40Z")

</div>

Hello, I am setting up a lab for log collection (Apache, Sophos, ...) I want to create different indices for each device (Apache, Sophos, Windows, Linux, ...) Is it possible to create independent indices? How can thi…

---

## [Size parameter ignored in nested knn search](https://discuss.elastic.co/t/size-parameter-ignored-in-nested-knn-search/350285)

<div class="topic-metadata">

**Author:** [@Jasper\_Simon](https://discuss.elastic.co/u/Jasper_Simon)\
**Replies:** 2\
**Last updated:** [January 23, 2024, 12:34pm UTC](https://discuss.elastic.co/t/size-parameter-ignored-in-nested-knn-search/350285 "2024-01-23T12:34:34Z")

</div>

I noticed the quote below in the documentation, about the limitation to retrieve only the best match vector regardless of the "size" parameter in the inner\_hits section of the search request. inner\_hits for kNN will on…

---

## [Data nodes not ingesting new documents for over 10 min](https://discuss.elastic.co/t/data-nodes-not-ingesting-new-documents-for-over-10-min/351462)

<div class="topic-metadata">

**Author:** [@luana](https://discuss.elastic.co/u/luana)\
**Replies:** 4\
**Last updated:** [January 23, 2024, 12:10pm UTC](https://discuss.elastic.co/t/data-nodes-not-ingesting-new-documents-for-over-10-min/351462 "2024-01-23T12:10:00Z")

</div>

Hi, I've got about 10 data nodes (this value fluctuates throughout the day) that are triggering my "no new documents" alert, that'll trigger if a node doesn't ingest documents for over 10 minutes. When checking the logs…

---

## [Retrieving or saving matching document ID when using percolate](https://discuss.elastic.co/t/retrieving-or-saving-matching-document-id-when-using-percolate/351555)

<div class="topic-metadata">

**Author:** [@Krikkits](https://discuss.elastic.co/u/Krikkits)\
**Replies:** 1\
**Last updated:** [January 23, 2024, 10:32am UTC](https://discuss.elastic.co/t/retrieving-or-saving-matching-document-id-when-using-percolate/351555 "2024-01-23T10:32:59Z")

</div>

I am unfamiliar with percolate and honestly a bit confused. My idea is to use percolate on an existing index and not only getting how many match the query, but also which exact ones. The field "\_percolator\_document\_slot"…

---

## [Cound not run org.elasticsearch.bootstrap.Elasticsearch(v8.12.0) directly in Intellij Idea](https://discuss.elastic.co/t/cound-not-run-org-elasticsearch-bootstrap-elasticsearch-v8-12-0-directly-in-intellij-idea/351594)

<div class="topic-metadata">

**Author:** [@Henkel](https://discuss.elastic.co/u/Henkel)\
**Replies:** 2\
**Last updated:** [January 23, 2024, 9:10am UTC](https://discuss.elastic.co/t/cound-not-run-org-elasticsearch-bootstrap-elasticsearch-v8-12-0-directly-in-intellij-idea/351594 "2024-01-23T09:10:11Z")

</div>

Hi guys: with elasticsearch version 7.16.0, I can run org.elasticsearch.bootstrap.Elasticsearch directly in Intellij Idea.The configuration of Intellij Idea is as follows： However, with elasticsearch version 8.12.0,…

---

## [Sub aggregating top\_hits](https://discuss.elastic.co/t/sub-aggregating-top-hits/351163)

<div class="topic-metadata">

**Author:** [@Vivek\_Burman](https://discuss.elastic.co/u/Vivek_Burman)\
**Replies:** 6\
**Last updated:** [January 23, 2024, 7:51am UTC](https://discuss.elastic.co/t/sub-aggregating-top-hits/351163 "2024-01-23T07:51:19Z")

</div>

Hi, I've the below Query { "query": { "bool": { "filter": \[ { "term": { "is\_deleted": 0 } }, …

---

## [./elastic-agent: 2: Syntax error: word unexpected (expecting ")")](https://discuss.elastic.co/t/elastic-agent-2-syntax-error-word-unexpected-expecting/351589)

<div class="topic-metadata">

**Author:** [@axiescholar](https://discuss.elastic.co/u/axiescholar)\
**Replies:** 1\
**Last updated:** [January 23, 2024, 4:44am UTC](https://discuss.elastic.co/t/elastic-agent-2-syntax-error-word-unexpected-expecting/351589 "2024-01-23T04:44:31Z")

</div>

i am getting this error when i am installing agent on kali linux. ./elastic-agent: 1: ./elastic-agent: 1: ELF: not found O@8: not found ./elastic-agent: 2: Syntax error: word unexpected (expecting ")") i am using a V…

---

## [Which crptographic hash algo does elasticsearch 8.7.0 use?](https://discuss.elastic.co/t/which-crptographic-hash-algo-does-elasticsearch-8-7-0-use/351361)

<div class="topic-metadata">

**Author:** [@sahadev\_d](https://discuss.elastic.co/u/sahadev_d)\
**Replies:** 1\
**Last updated:** [January 23, 2024, 12:28am UTC](https://discuss.elastic.co/t/which-crptographic-hash-algo-does-elasticsearch-8-7-0-use/351361 "2024-01-23T00:28:01Z")

</div>

Hi community, just wanted to know which hashing algo does elasticsearch 8.7.0 uses for internal hashing. also does it by any chance use sha1 or sha0 Please let me know how can i check the version

---

## [Adding an array of events even if there is only one](https://discuss.elastic.co/t/adding-an-array-of-events-even-if-there-is-only-one/351567)

<div class="topic-metadata">

**Author:** [@ylevaill](https://discuss.elastic.co/u/ylevaill)\
**Replies:** 1\
**Last updated:** [January 23, 2024, 12:07am UTC](https://discuss.elastic.co/t/adding-an-array-of-events-even-if-there-is-only-one/351567 "2024-01-23T00:07:38Z")

</div>

Hello, I use this filter : json { source =\> "message" add\_field =\> { "\[events\]\[id\]" =\> "%{\_id}" } add\_field =\> { "\[events\]\[nom\]" =\> "%{eventName}" } add\_field =\> { "\[events\]\[timestamp\]" =\> "%{ti…

---

## [How to resolve ILM errors about missing "scaling\_factor"?](https://discuss.elastic.co/t/how-to-resolve-ilm-errors-about-missing-scaling-factor/345937)

<div class="topic-metadata">

**Author:** [@jerrac](https://discuss.elastic.co/u/jerrac)\
**Replies:** 18\
**Last updated:** [January 22, 2024, 9:13pm UTC](https://discuss.elastic.co/t/how-to-resolve-ilm-errors-about-missing-scaling-factor/345937 "2024-01-22T21:13:32Z")

</div>

My ILM policy is configured to downsample metrics. The policy does work, and I have metrics being downsampled, but a few indices are stuck with lifecycle errors. Specifically several .ds-metrics-docker.memory-default... …

---

## [Kibana Discover / Dashboards Read Only](https://discuss.elastic.co/t/kibana-discover-dashboards-read-only/351286)

<div class="topic-metadata">

**Author:** [@randomnamegenerator](https://discuss.elastic.co/u/randomnamegenerator)\
**Replies:** 6\
**Last updated:** [January 22, 2024, 8:35pm UTC](https://discuss.elastic.co/t/kibana-discover-dashboards-read-only/351286 "2024-01-22T20:35:20Z")

</div>

Hello All, We wish to lock down access on a customer sites ELK in a way that they can view the Analytics/Discover & Dashboards but not edit. The indices already exist. I have created a space,role and user with this aim…

---

## [Index deleted by lifecycle after snapshot restore](https://discuss.elastic.co/t/index-deleted-by-lifecycle-after-snapshot-restore/351569)

<div class="topic-metadata">

**Author:** [@lee.clemens](https://discuss.elastic.co/u/lee.clemens)\
**Replies:** 1\
**Last updated:** [January 22, 2024, 6:46pm UTC](https://discuss.elastic.co/t/index-deleted-by-lifecycle-after-snapshot-restore/351569 "2024-01-22T18:46:26Z")

</div>

Hello, I recently struggled with waking up to see a restore completed, but the restored index was missing. Is there a way to remove the lifecycle policy after the restore (I resorted to a script to do so after waiting f…

---

## [Re-Allow Write After Index Shrink](https://discuss.elastic.co/t/re-allow-write-after-index-shrink/351568)

<div class="topic-metadata">

**Author:** [@ktbishop](https://discuss.elastic.co/u/ktbishop)\
**Replies:** 3\
**Last updated:** [January 22, 2024, 6:36pm UTC](https://discuss.elastic.co/t/re-allow-write-after-index-shrink/351568 "2024-01-22T18:36:57Z")

</div>

Hello all! Currently on Elasticsearch 7.17. I have a data stream with an ILM policy that rolls data over from Hot to Warm after a period of time. Once an index rolls over to the Warm phase it is shrunk, which I understa…

---

## [FSCrawler - Tika Configuration for escape quotes in TextandCSVParser](https://discuss.elastic.co/t/fscrawler-tika-configuration-for-escape-quotes-in-textandcsvparser/351273)

<div class="topic-metadata">

**Author:** [@kamalsharma](https://discuss.elastic.co/u/kamalsharma)\
**Replies:** 4\
**Last updated:** [January 22, 2024, 1:39pm UTC](https://discuss.elastic.co/t/fscrawler-tika-configuration-for-escape-quotes-in-textandcsvparser/351273 "2024-01-22T13:39:25Z")

</div>

When I am ingesting a csv file using FSCrawler, I am getting the error "IOException reading next record: java.io.IOException: (line 131664) invalid char between encapsulated token and delimiter -\> (line 131664) invalid c…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=153)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=155)
