# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=157

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 158

---

## [Failed migration of system indices for the watcher and watcher not firing after update](https://discuss.elastic.co/t/failed-migration-of-system-indices-for-the-watcher-and-watcher-not-firing-after-update/350704)

<div class="topic-metadata">

**Author:** [@AEA27](https://discuss.elastic.co/u/AEA27)\
**Replies:** 2\
**Last updated:** [January 17, 2024, 7:45am UTC](https://discuss.elastic.co/t/failed-migration-of-system-indices-for-the-watcher-and-watcher-not-firing-after-update/350704 "2024-01-17T07:45:14Z")

</div>

continuation of Failed migration of system indices (.triggered\_watches) with Upgrade Assistant using v7.17.14 Summary, upgrade assistant was giving an error for the watcher when migrating system indices. I tried deleti…

---

## [\[ElasticSearch v.7.5\] How to merge daily and weekly indexes into a monthly index?](https://discuss.elastic.co/t/elasticsearch-v-7-5-how-to-merge-daily-and-weekly-indexes-into-a-monthly-index/351210)

<div class="topic-metadata">

**Author:** [@mpniel](https://discuss.elastic.co/u/mpniel)\
**Replies:** 1\
**Last updated:** [January 16, 2024, 9:34pm UTC](https://discuss.elastic.co/t/elasticsearch-v-7-5-how-to-merge-daily-and-weekly-indexes-into-a-monthly-index/351210 "2024-01-16T21:34:55Z")

</div>

How to merge daily and weekly indexes into a monthly index? In order to free shards.

---

## [\[Ingest processor\] How to apply ingest pipeline on an index?](https://discuss.elastic.co/t/ingest-processor-how-to-apply-ingest-pipeline-on-an-index/351180)

<div class="topic-metadata">

**Author:** [@Keith\_Lin](https://discuss.elastic.co/u/Keith_Lin)\
**Replies:** 1\
**Last updated:** [January 16, 2024, 4:14pm UTC](https://discuss.elastic.co/t/ingest-processor-how-to-apply-ingest-pipeline-on-an-index/351180 "2024-01-16T16:14:58Z")

</div>

So in kibana i created an ingest pipeline. Is there a way to apply it to an index or it will be automatically applied?

---

## [Cannot restore open indices in new empty cluster](https://discuss.elastic.co/t/cannot-restore-open-indices-in-new-empty-cluster/351176)

<div class="topic-metadata">

**Author:** [@mebaj91360](https://discuss.elastic.co/u/mebaj91360)\
**Replies:** 1\
**Last updated:** [January 16, 2024, 3:43pm UTC](https://discuss.elastic.co/t/cannot-restore-open-indices-in-new-empty-cluster/351176 "2024-01-16T15:43:54Z")

</div>

Hello, I am trying to restore a snapshot on a new, empty cluster, but I get this error: \[restore-old:snapshot-2024.01.09-5ebjtwcnqksvliv3h9tcug/r4dfaUrJQXyQ0xxVa0OE8Q\] cannot restore index \[logstash-2023.09.02\] because…

---

## [Elasticsearch 8.11.4 Windows installation from zip not completing](https://discuss.elastic.co/t/elasticsearch-8-11-4-windows-installation-from-zip-not-completing/351172)

<div class="topic-metadata">

**Author:** [@Echo9Zulu](https://discuss.elastic.co/u/Echo9Zulu)\
**Replies:** 5\
**Last updated:** [January 16, 2024, 2:40pm UTC](https://discuss.elastic.co/t/elasticsearch-8-11-4-windows-installation-from-zip-not-completing/351172 "2024-01-16T14:40:42Z")

</div>

Hello! I am having difficulty installing Elasticsearch 8.11.4 on a laptop running Windows 10. Running elasticsearch.bat creates the following log in the command window. Shortly after running the command the install hang…

---

## [Maintaining "time delta" between events when reindexing](https://discuss.elastic.co/t/maintaining-time-delta-between-events-when-reindexing/351155)

<div class="topic-metadata">

**Author:** [@petlit2049](https://discuss.elastic.co/u/petlit2049)\
**Replies:** 2\
**Last updated:** [January 16, 2024, 1:53pm UTC](https://discuss.elastic.co/t/maintaining-time-delta-between-events-when-reindexing/351155 "2024-01-16T13:53:21Z")

</div>

I'm trying to work out a process for maintaining the time difference between event records when re-indexing data from one index to another but with a new "t0" using only Elasticsearch with ingest pipelines and/or logstas…

---

## [How to move from 3 node cluster to single node](https://discuss.elastic.co/t/how-to-move-from-3-node-cluster-to-single-node/351132)

<div class="topic-metadata">

**Author:** [@Mohammed\_Ahmed](https://discuss.elastic.co/u/Mohammed_Ahmed)\
**Replies:** 5\
**Last updated:** [January 16, 2024, 1:12pm UTC](https://discuss.elastic.co/t/how-to-move-from-3-node-cluster-to-single-node/351132 "2024-01-16T13:12:21Z")

</div>

i have a three node cluster below is the config cluster.name: hotels-autosuggest node.name: "es-autosuggest-3" path.logs: /var/log/elasticsearch path.data: /data/elasticsearch/data bootstrap.memory\_lock: true network.ho…

---

## [Move data directory 8.5.2](https://discuss.elastic.co/t/move-data-directory-8-5-2/351168)

<div class="topic-metadata">

**Author:** [@Chel](https://discuss.elastic.co/u/Chel)\
**Replies:** 1\
**Last updated:** [January 16, 2024, 1:00pm UTC](https://discuss.elastic.co/t/move-data-directory-8-5-2/351168 "2024-01-16T13:00:45Z")

</div>

I want to move data directory from cluster A to Cluster B. Both have documents present. I want to copy the documents from cluster A to cluster B. Both cluster have different uuid's . Is it possible to change the cluster …

---

## [Snapshots integrity on elasticsearch](https://discuss.elastic.co/t/snapshots-integrity-on-elasticsearch/351074)

<div class="topic-metadata">

**Author:** [@TIT](https://discuss.elastic.co/u/TIT)\
**Replies:** 1\
**Last updated:** [January 16, 2024, 11:10am UTC](https://discuss.elastic.co/t/snapshots-integrity-on-elasticsearch/351074 "2024-01-16T11:10:16Z")

</div>

Is There any way i can verify snapshots integrity something , the snapshots in my case are stored on an Nfs .

---

## [How to export large set data and write to csv using elasticsearch](https://discuss.elastic.co/t/how-to-export-large-set-data-and-write-to-csv-using-elasticsearch/351152)

<div class="topic-metadata">

**Author:** [@Bikash\_Hutait](https://discuss.elastic.co/u/Bikash_Hutait)\
**Replies:** 0\
**Last updated:** [January 16, 2024, 10:34am UTC](https://discuss.elastic.co/t/how-to-export-large-set-data-and-write-to-csv-using-elasticsearch/351152 "2024-01-16T10:34:13Z")

</div>

We have an application allowing users to export records based on search/filter criteria. I am looking for a solution to implement the "export all" functionality to a CSV file. I conducted a test utilizing the \_scroll AP…

---

## [Register percolate query with java api client ElasticSearch 8](https://discuss.elastic.co/t/register-percolate-query-with-java-api-client-elasticsearch-8/351084)

<div class="topic-metadata">

**Author:** [@TSCH](https://discuss.elastic.co/u/TSCH)\
**Replies:** 0\
**Last updated:** [January 15, 2024, 3:46pm UTC](https://discuss.elastic.co/t/register-percolate-query-with-java-api-client-elasticsearch-8/351084 "2024-01-15T15:46:13Z")

</div>

When trying to implement a similar usecase as the elasticsearch doicumentation for the percolate query with the java api client I ran into an issue and wonder if I'm doing things wrong, or there is something missing in t…

---

## [Elasticsearch snapshot is failing due to access denied exception](https://discuss.elastic.co/t/elasticsearch-snapshot-is-failing-due-to-access-denied-exception/350474)

<div class="topic-metadata">

**Author:** [@tykarthick](https://discuss.elastic.co/u/tykarthick)\
**Replies:** 15\
**Last updated:** [January 16, 2024, 9:28am UTC](https://discuss.elastic.co/t/elasticsearch-snapshot-is-failing-due-to-access-denied-exception/350474 "2024-01-16T09:28:25Z")

</div>

Hi Team, Greetings ! A POC is under progress for the Elasticsearch snapshot and restoration and this POC is on the Azure VM's Linux environment. The version of Elasticsearch is 8.6.2 with three node cluster setup. The…

---

## [Single node elasticsearch installation with podman and IPv6](https://discuss.elastic.co/t/single-node-elasticsearch-installation-with-podman-and-ipv6/351086)

<div class="topic-metadata">

**Author:** [@hitchalon](https://discuss.elastic.co/u/hitchalon)\
**Replies:** 2\
**Last updated:** [January 16, 2024, 8:40am UTC](https://discuss.elastic.co/t/single-node-elasticsearch-installation-with-podman-and-ipv6/351086 "2024-01-16T08:40:02Z")

</div>

Hi all, I am trying to install Elasticsearch by using podman on a IPv6 only host (RHEL 9.3, podman 4.6.3). Here is my run commands for elasticsearch and kibana podman run --name es01 --net elastic-v6 -p \[1000:1400:240…

---

## [Filebeat CEL Input Type - FIle Options](https://discuss.elastic.co/t/filebeat-cel-input-type-file-options/350812)

<div class="topic-metadata">

**Author:** [@bigdaddy0918](https://discuss.elastic.co/u/bigdaddy0918)\
**Replies:** 2\
**Last updated:** [January 15, 2024, 7:40pm UTC](https://discuss.elastic.co/t/filebeat-cel-input-type-file-options/350812 "2024-01-15T19:40:12Z")

</div>

I'm using a CEL type input in Filebeat. Currently the filebeat.yml file points at a specific directory/file. What is the syntax to wildcard a portion of the file? (i.e. for the parameter resource.url: file:///home/di…

---

## [Providing Socket tineout exception not working in elastic java api](https://discuss.elastic.co/t/providing-socket-tineout-exception-not-working-in-elastic-java-api/350923)

<div class="topic-metadata">

**Author:** [@Divy\_Garg](https://discuss.elastic.co/u/Divy_Garg)\
**Replies:** 7\
**Last updated:** [January 15, 2024, 3:56pm UTC](https://discuss.elastic.co/t/providing-socket-tineout-exception-not-working-in-elastic-java-api/350923 "2024-01-15T15:56:29Z")

</div>

Hi I am using below libraries to connect to elasticsearch from java implementation group: 'co.elastic.clients', name: 'elasticsearch-java', version: '8.11.4' implementation group: 'org.elasticsearch.client', name: 'el…

---

## [/bin/tini: error while loading shared libraries: libc.so.6: cannot open shared object file: No such file or directory](https://discuss.elastic.co/t/bin-tini-error-while-loading-shared-libraries-libc-so-6-cannot-open-shared-object-file-no-such-file-or-directory/351077)

<div class="topic-metadata">

**Author:** [@Abdeljalil\_El\_Yousso](https://discuss.elastic.co/u/Abdeljalil_El_Yousso)\
**Replies:** 0\
**Last updated:** [January 15, 2024, 2:44pm UTC](https://discuss.elastic.co/t/bin-tini-error-while-loading-shared-libraries-libc-so-6-cannot-open-shared-object-file-no-such-file-or-directory/351077 "2024-01-15T14:44:26Z")

</div>

how to resolve the following error if anybody encoutred it while running elasticserach 8.10.4 on docker in debian terminal /bin/tini: error while loading shared libraries: libc.so.6: cannot open shared object file: No s…

---

## [Query with must and should with ANd and OR Logic in Elasticsearch](https://discuss.elastic.co/t/query-with-must-and-should-with-and-and-or-logic-in-elasticsearch/351068)

<div class="topic-metadata">

**Author:** [@Rakhshunda\_Noorein\_J](https://discuss.elastic.co/u/Rakhshunda_Noorein_J)\
**Replies:** 0\
**Last updated:** [January 15, 2024, 12:35pm UTC](https://discuss.elastic.co/t/query-with-must-and-should-with-and-and-or-logic-in-elasticsearch/351068 "2024-01-15T12:35:38Z")

</div>

Hi, I want my search work like all the search terms searched with AND results first and then with OR results. example, Search term - borosil infrastructure the result should come like - borosil infrastructure boro…

---

## [ILM is deleting after rollover](https://discuss.elastic.co/t/ilm-is-deleting-after-rollover/350525)

<div class="topic-metadata">

**Author:** [@avnere](https://discuss.elastic.co/u/avnere)\
**Replies:** 4\
**Last updated:** [January 15, 2024, 11:48am UTC](https://discuss.elastic.co/t/ilm-is-deleting-after-rollover/350525 "2024-01-15T11:48:35Z")

</div>

Hi, I have set rollover after 10gb and delete after 7 days. PUT \_ilm/policy/policy1 { "policy": { "phases": { "hot": { "actions": { "rollover": { "max\_primary\_shard\_size": "10g…

---

## [Only one of the Elasticsearch Warm node is getting most of the data while shifting the data from Hot to Warm as per the ILM Policy](https://discuss.elastic.co/t/only-one-of-the-elasticsearch-warm-node-is-getting-most-of-the-data-while-shifting-the-data-from-hot-to-warm-as-per-the-ilm-policy/351064)

<div class="topic-metadata">

**Author:** [@KunwarAkanksha](https://discuss.elastic.co/u/KunwarAkanksha)\
**Replies:** 0\
**Last updated:** [January 15, 2024, 10:47am UTC](https://discuss.elastic.co/t/only-one-of-the-elasticsearch-warm-node-is-getting-most-of-the-data-while-shifting-the-data-from-hot-to-warm-as-per-the-ilm-policy/351064 "2024-01-15T10:47:22Z")

</div>

I have Multinode Cord, Master, Hot and Warm Elasticsearch Cluster, with 5 primary and 2 replica shards , but according to ILM when the Load is shifting from hot to warm, only one of the warm node is getting most of the d…

---

## [Error when recovering snapshot](https://discuss.elastic.co/t/error-when-recovering-snapshot/350640)

<div class="topic-metadata">

**Author:** [@Epic555](https://discuss.elastic.co/u/Epic555)\
**Replies:** 2\
**Last updated:** [January 15, 2024, 10:27am UTC](https://discuss.elastic.co/t/error-when-recovering-snapshot/350640 "2024-01-15T10:27:44Z")

</div>

I created a snapshot with curl from 1 cluster. When I try to recover a snapshot with curl on another cluster, 2nd Cluster cannot allocate all indices. Cluster 1 has 2 nodes, cluster 2 has 1 node. I have a file "snap-hb19…

---

## [I'm facing .elasticsearch.bootstrap.StartupException: java.lang.IllegalArgumentException: you cannot specify a keystore and key file](https://discuss.elastic.co/t/im-facing-elasticsearch-bootstrap-startupexception-java-lang-illegalargumentexception-you-cannot-specify-a-keystore-and-key-file/350942)

<div class="topic-metadata">

**Author:** [@bshiwanand](https://discuss.elastic.co/u/bshiwanand)\
**Replies:** 4\
**Last updated:** [January 15, 2024, 8:15am UTC](https://discuss.elastic.co/t/im-facing-elasticsearch-bootstrap-startupexception-java-lang-illegalargumentexception-you-cannot-specify-a-keystore-and-key-file/350942 "2024-01-15T08:15:22Z")

</div>

I'm trying to enable xpack security enable so that internal and external communication will happen on https instead of http so please guide me how I do that, and guide me how to resolve below error. Error: {"type": "de…

---

## [How to aggregate non-nested fields in a nested aggregation?](https://discuss.elastic.co/t/how-to-aggregate-non-nested-fields-in-a-nested-aggregation/351044)

<div class="topic-metadata">

**Author:** [@Chanseok](https://discuss.elastic.co/u/Chanseok)\
**Replies:** 0\
**Last updated:** [January 15, 2024, 1:33am UTC](https://discuss.elastic.co/t/how-to-aggregate-non-nested-fields-in-a-nested-aggregation/351044 "2024-01-15T01:33:05Z")

</div>

The prices.adult field in "lowest\_price" is non-nested fields in a nest. The current "lowest\_price" value is null. How can I get that value? // Aggregation code "aggs": { "destination": { "nested": { …

---

## [Creating and using custom functions in painless](https://discuss.elastic.co/t/creating-and-using-custom-functions-in-painless/351037)

<div class="topic-metadata">

**Author:** [@dat\_boi](https://discuss.elastic.co/u/dat_boi)\
**Replies:** 2\
**Last updated:** [January 15, 2024, 12:01am UTC](https://discuss.elastic.co/t/creating-and-using-custom-functions-in-painless/351037 "2024-01-15T00:01:43Z")

</div>

so here is the thing , i have this long script that define variables of type String\[\] words\_var1 = new String\[\] {'word1','word1','word1'} then i have this function that tries to assign the right word to the right doc b…

---

## [Fetch results where count of nested field is more than 1](https://discuss.elastic.co/t/fetch-results-where-count-of-nested-field-is-more-than-1/351042)

<div class="topic-metadata">

**Author:** [@Hardik\_Sharma](https://discuss.elastic.co/u/Hardik_Sharma)\
**Replies:** 0\
**Last updated:** [January 14, 2024, 11:59pm UTC](https://discuss.elastic.co/t/fetch-results-where-count-of-nested-field-is-more-than-1/351042 "2024-01-14T23:59:11Z")

</div>

So I have a mapping where "configs" is a nested field. \["configs"\]{ "type": "nested", \["properties"\]: {\[56 items\] }} Now I want to fetch docs where 'configs' have more than 1 objects. For this I am using { "scr…

---

## [Rollover not working, Filebeat default index does not have an alias](https://discuss.elastic.co/t/rollover-not-working-filebeat-default-index-does-not-have-an-alias/350655)

<div class="topic-metadata">

**Author:** [@whanklee](https://discuss.elastic.co/u/whanklee)\
**Replies:** 8\
**Last updated:** [January 14, 2024, 5:19pm UTC](https://discuss.elastic.co/t/rollover-not-working-filebeat-default-index-does-not-have-an-alias/350655 "2024-01-14T17:19:15Z")

</div>

Hello, I would like to use rollover to delete all logs, however, I always get an error message. It does not work. I can use only if turn of rollover. I do not modify anything on indexes, I use default Indexes after inst…

---

## [Elasticsearch incomplete logs](https://discuss.elastic.co/t/elasticsearch-incomplete-logs/350899)

<div class="topic-metadata">

**Author:** [@Krishna94](https://discuss.elastic.co/u/Krishna94)\
**Replies:** 1\
**Last updated:** [January 13, 2024, 1:37pm UTC](https://discuss.elastic.co/t/elasticsearch-incomplete-logs/350899 "2024-01-13T13:37:32Z")

</div>

Hi, I have filebeat to read my inputs and logstash is the shipper to elasticsearch. But could found that the data in filebeat is not sending to elasticsearch completely. Pls do help. Thank you Athira Krishna

---

## [Rollover Index Throws Exception](https://discuss.elastic.co/t/rollover-index-throws-exception/349687)

<div class="topic-metadata">

**Author:** [@krish1](https://discuss.elastic.co/u/krish1)\
**Replies:** 1\
**Last updated:** [January 13, 2024, 9:52am UTC](https://discuss.elastic.co/t/rollover-index-throws-exception/349687 "2024-01-13T09:52:04Z")

</div>

I have an index which uses ILM. The index rolls over every week. We use Spring-data to read and write for Elasticsearch. My index just rolled over today and we are having trouble with writing to it. It fails with the fol…

---

## [A node in my elasticsearch has full disk](https://discuss.elastic.co/t/a-node-in-my-elasticsearch-has-full-disk/350811)

<div class="topic-metadata">

**Author:** [@Tai\_Nguyen\_Huu](https://discuss.elastic.co/u/Tai_Nguyen_Huu)\
**Replies:** 1\
**Last updated:** [January 13, 2024, 9:12am UTC](https://discuss.elastic.co/t/a-node-in-my-elasticsearch-has-full-disk/350811 "2024-01-13T09:12:49Z")

</div>

Hi all, I have a elasticsearch cluster with 10 node, one node in my elasticsearch had full disk and it was removed from cluster by elasticsearch. the Disk of other nodes in my cluster still have 70% disk. How to I can re…

---

## [How to configure login kibana custom file build version 8.5.0?](https://discuss.elastic.co/t/how-to-configure-login-kibana-custom-file-build-version-8-5-0/351004)

<div class="topic-metadata">

**Author:** [@Cody-Test](https://discuss.elastic.co/u/Cody-Test)\
**Replies:** 0\
**Last updated:** [January 13, 2024, 4:50am UTC](https://discuss.elastic.co/t/how-to-configure-login-kibana-custom-file-build-version-8-5-0/351004 "2024-01-13T04:50:09Z")

</div>

Hello Guy, I can't configure or edit the default login page of the Kibana application on Linux using the .deb package after extracting the current storage directory at /usr/share/kibana/x-pack/plugins/security/security.…

---

## [Recreate the automatically generated certificates](https://discuss.elastic.co/t/recreate-the-automatically-generated-certificates/350987)

<div class="topic-metadata">

**Author:** [@pxeedust](https://discuss.elastic.co/u/pxeedust)\
**Replies:** 2\
**Last updated:** [January 12, 2024, 10:25pm UTC](https://discuss.elastic.co/t/recreate-the-automatically-generated-certificates/350987 "2024-01-12T22:25:55Z")

</div>

Sorry for the beginner question, but I am having trouble regenerating the certificates that were made at deployment. I'm not familiar with how certificates work so I was hoping there might be a script that just regenerat…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=156)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=158)
