# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=158

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 159

---

## [Recreate the automatically generated certificates](https://discuss.elastic.co/t/recreate-the-automatically-generated-certificates/350987)

<div class="topic-metadata">

**Author:** [@pxeedust](https://discuss.elastic.co/u/pxeedust)\
**Replies:** 2\
**Last updated:** [January 12, 2024, 10:25pm UTC](https://discuss.elastic.co/t/recreate-the-automatically-generated-certificates/350987 "2024-01-12T22:25:55Z")

</div>

Sorry for the beginner question, but I am having trouble regenerating the certificates that were made at deployment. I'm not familiar with how certificates work so I was hoping there might be a script that just regenerat…

---

## [Support for script\_score in function\_score in Golang client](https://discuss.elastic.co/t/support-for-script-score-in-function-score-in-golang-client/350991)

<div class="topic-metadata">

**Author:** [@rajivhs](https://discuss.elastic.co/u/rajivhs)\
**Replies:** 0\
**Last updated:** [January 12, 2024, 9:34pm UTC](https://discuss.elastic.co/t/support-for-script-score-in-function-score-in-golang-client/350991 "2024-01-12T21:34:41Z")

</div>

Hi. The docs show the following example for using script\_score within function\_score: "query" : { "score\_mode": "multiply", "rescore\_query" : { "function\_score" : { "script\_s…

---

## [Force new field to type "keyword" or "text"](https://discuss.elastic.co/t/force-new-field-to-type-keyword-or-text/349665)

<div class="topic-metadata">

**Author:** [@yquirion](https://discuss.elastic.co/u/yquirion)\
**Replies:** 3\
**Last updated:** [January 12, 2024, 8:49pm UTC](https://discuss.elastic.co/t/force-new-field-to-type-keyword-or-text/349665 "2024-01-12T20:49:30Z")

</div>

Hello, I'm currently struggling with an annoying problem who lead to many lost logs into my Elastic cluster. The problem happen when a field that hasn't been defined into the default filebeat template is created. When …

---

## [Errors: reason\\":\\"Unrecognized compile-time parameter(s)](https://discuss.elastic.co/t/errors-reason-unrecognized-compile-time-parameter-s/350988)

<div class="topic-metadata">

**Author:** [@ElasticDev1](https://discuss.elastic.co/u/ElasticDev1)\
**Replies:** 0\
**Last updated:** [January 12, 2024, 8:28pm UTC](https://discuss.elastic.co/t/errors-reason-unrecognized-compile-time-parameter-s/350988 "2024-01-12T20:28:40Z")

</div>

I have written a scriptquery that should work but I keep getting this error "Unrecognized compile-time parameter(s)". I have even super simplified my script where I just "return true", and continue to get the same error…

---

## [Return just some fields using Transform](https://discuss.elastic.co/t/return-just-some-fields-using-transform/350887)

<div class="topic-metadata">

**Author:** [@jcruz](https://discuss.elastic.co/u/jcruz)\
**Replies:** 7\
**Last updated:** [January 12, 2024, 7:24pm UTC](https://discuss.elastic.co/t/return-just-some-fields-using-transform/350887 "2024-01-12T19:24:41Z")

</div>

Hi there! I'm setting up a latest transform, and I would like to know if is it possible to return just some fields (from the original index) into the new transform index. I've tried to copy those needed fields and then …

---

## [Setting default number of replicas for new indexes?](https://discuss.elastic.co/t/setting-default-number-of-replicas-for-new-indexes/350835)

<div class="topic-metadata">

**Author:** [@emoxam](https://discuss.elastic.co/u/emoxam)\
**Replies:** 4\
**Last updated:** [January 12, 2024, 4:49pm UTC](https://discuss.elastic.co/t/setting-default-number-of-replicas-for-new-indexes/350835 "2024-01-12T16:49:49Z")

</div>

addidng index.number\_of\_replicas: 0 to /etc/elasticsearch/elasticsearch.yml doesn't work. With this option elasticsearch doesn't start. at the log i see fatal exception while booting Elasticsearch java.lang.IllegalArgu…

---

## [Declaring static string array](https://discuss.elastic.co/t/declaring-static-string-array/350880)

<div class="topic-metadata">

**Author:** [@dat\_boi](https://discuss.elastic.co/u/dat_boi)\
**Replies:** 2\
**Last updated:** [January 12, 2024, 3:57pm UTC](https://discuss.elastic.co/t/declaring-static-string-array/350880 "2024-01-12T15:57:07Z")

</div>

So i'v been trying to create a very simple array of strings like so : String\[\] painfull\_lang = \[ "word1","word2","word3"\]; but i keep getting syntax errors Cannot cast from \[java.util.ArrayList\] to \[java.lang.String…

---

## [\[Upgrade from 7.6.2 to 7.17.15\] Cannot find symbol import org.elasticsearch.client.RestClientBuilder;](https://discuss.elastic.co/t/upgrade-from-7-6-2-to-7-17-15-cannot-find-symbol-import-org-elasticsearch-client-restclientbuilder/350894)

<div class="topic-metadata">

**Author:** [@chrisssss](https://discuss.elastic.co/u/chrisssss)\
**Replies:** 0\
**Last updated:** [January 12, 2024, 12:55am UTC](https://discuss.elastic.co/t/upgrade-from-7-6-2-to-7-17-15-cannot-find-symbol-import-org-elasticsearch-client-restclientbuilder/350894 "2024-01-12T00:55:16Z")

</div>

Hello, I am trying to upgrade the elasticsearch for java from 7.6.2 to 7.16.15, but the following classes seem to be deprecated: .......Producer.java:15: error: cannot find symbol import org.elasticsearch.client.RestCl…

---

## [Time range based on timestamp in DSL query](https://discuss.elastic.co/t/time-range-based-on-timestamp-in-dsl-query/350962)

<div class="topic-metadata">

**Author:** [@LeCalve](https://discuss.elastic.co/u/LeCalve)\
**Replies:** 3\
**Last updated:** [January 12, 2024, 2:57pm UTC](https://discuss.elastic.co/t/time-range-based-on-timestamp-in-dsl-query/350962 "2024-01-12T14:57:31Z")

</div>

Hello, I want to make a filter based on the time of a timestamp. I would like to extract all timestamps which have a time \< 8 or time \> 20. I don't know how to make the DSL query for that :slight\_smile: {

---

## [Utilize serilog sinks to elastic search](https://discuss.elastic.co/t/utilize-serilog-sinks-to-elastic-search/350969)

<div class="topic-metadata">

**Author:** [@minh.tran](https://discuss.elastic.co/u/minh.tran)\
**Replies:** 0\
**Last updated:** [January 12, 2024, 2:36pm UTC](https://discuss.elastic.co/t/utilize-serilog-sinks-to-elastic-search/350969 "2024-01-12T14:36:01Z")

</div>

Hi there, we are currently using seirlog elastic sink. Details can be found here GitHub - serilog-contrib/serilog-sinks-elasticsearch: A Serilog sink that writes events to Elasticsearch Is there a way we can make the si…

---

## [Facing issue in elasticsearch - /usr/share/elasticsearch/config/elasticsearch.keystore: Device or resource busy](https://discuss.elastic.co/t/facing-issue-in-elasticsearch-usr-share-elasticsearch-config-elasticsearch-keystore-device-or-resource-busy/350905)

<div class="topic-metadata">

**Author:** [@Akshay04](https://discuss.elastic.co/u/Akshay04)\
**Replies:** 1\
**Last updated:** [January 12, 2024, 2:23pm UTC](https://discuss.elastic.co/t/facing-issue-in-elasticsearch-usr-share-elasticsearch-config-elasticsearch-keystore-device-or-resource-busy/350905 "2024-01-12T14:23:49Z")

</div>

Hello, I'm trying to enable Google OAuth with Elasticsearch using - Set up OpenID Connect with Azure, Google, or Okta | Elasticsearch Service Documentation | Elastic I'm deploying this to Kubernetes and using Elastic …

---

## [How can I implement this with the latest Elasticsearch C# client version, v8?](https://discuss.elastic.co/t/how-can-i-implement-this-with-the-latest-elasticsearch-c-client-version-v8/350951)

<div class="topic-metadata">

**Author:** [@David\_Silwal](https://discuss.elastic.co/u/David_Silwal)\
**Replies:** 0\
**Last updated:** [January 12, 2024, 12:49pm UTC](https://discuss.elastic.co/t/how-can-i-implement-this-with-the-latest-elasticsearch-c-client-version-v8/350951 "2024-01-12T12:49:04Z")

</div>

How can I implement this with the latest Elasticsearch C# client version, v8? var searchResponse = elasticClient .Search\<Case\>(s =\> s .Index(IndexNames.Cases) .Query(q =\> q .Match(m =\> m .Field("Description") .Query(que…

---

## [Transfer indices to new cluster](https://discuss.elastic.co/t/transfer-indices-to-new-cluster/350946)

<div class="topic-metadata">

**Author:** [@JimJ](https://discuss.elastic.co/u/JimJ)\
**Replies:** 0\
**Last updated:** [January 12, 2024, 12:40pm UTC](https://discuss.elastic.co/t/transfer-indices-to-new-cluster/350946 "2024-01-12T12:40:19Z")

</div>

I put in place a new Elastic cluster v8.7 to replace an old one in v7.12. In Elastic cluster v8.7, I started using Datastreams. My question: what is the best way to transfer indices' data from old cluster to datastream…

---

## [System indexes stuck initializing state](https://discuss.elastic.co/t/system-indexes-stuck-initializing-state/350937)

<div class="topic-metadata">

**Author:** [@joao-subtil](https://discuss.elastic.co/u/joao-subtil)\
**Replies:** 0\
**Last updated:** [January 12, 2024, 11:24am UTC](https://discuss.elastic.co/t/system-indexes-stuck-initializing-state/350937 "2024-01-12T11:24:58Z")

</div>

Hello, I am using Elastic 8.11 and was attempting to setup a cluster with ilm for hot/warm/cold. However after creating the instance and roles and users I get the system indices stuck in initializing state and cannot m…

---

## [Very slow queries always take 1s](https://discuss.elastic.co/t/very-slow-queries-always-take-1s/350933)

<div class="topic-metadata">

**Author:** [@matthijs1](https://discuss.elastic.co/u/matthijs1)\
**Replies:** 0\
**Last updated:** [January 12, 2024, 11:02am UTC](https://discuss.elastic.co/t/very-slow-queries-always-take-1s/350933 "2024-01-12T11:02:06Z")

</div>

Hi All, I'm not that experienced in Elastic Search, but I have a problem and I'm out of ideas to try. In a test setup, I have a 3-node cluster running ES6.8.22 on windows. Until a windows reboot (for updates) 2 days a…

---

## [Silent failures with delete-by-query](https://discuss.elastic.co/t/silent-failures-with-delete-by-query/350925)

<div class="topic-metadata">

**Author:** [@mrodent](https://discuss.elastic.co/u/mrodent)\
**Replies:** 0\
**Last updated:** [January 12, 2024, 9:38am UTC](https://discuss.elastic.co/t/silent-failures-with-delete-by-query/350925 "2024-01-12T09:38:27Z")

</div>

I've examined all the questions on this subject. None seems to address the problem I'm having. I need to loop through doing multiple delete\_by\_queries. As I've set things up for experimenting, just a handful. The proble…

---

## [Transform destination index rollover](https://discuss.elastic.co/t/transform-destination-index-rollover/350578)

<div class="topic-metadata">

**Author:** [@veryelastic](https://discuss.elastic.co/u/veryelastic)\
**Replies:** 2\
**Last updated:** [January 12, 2024, 9:25am UTC](https://discuss.elastic.co/t/transform-destination-index-rollover/350578 "2024-01-12T09:25:38Z")

</div>

Hello, It has been a while (I think) since this question came up on here, so I thought I'd check whether the answer had changed or not. I have a transform which produces consolidated data with a time-series element to …

---

## [Curl XPOST not working after upgrading from Elastic v7 to Elastic v8](https://discuss.elastic.co/t/curl-xpost-not-working-after-upgrading-from-elastic-v7-to-elastic-v8/350706)

<div class="topic-metadata">

**Author:** [@zeninuxx](https://discuss.elastic.co/u/zeninuxx)\
**Replies:** 3\
**Last updated:** [January 12, 2024, 8:51am UTC](https://discuss.elastic.co/t/curl-xpost-not-working-after-upgrading-from-elastic-v7-to-elastic-v8/350706 "2024-01-12T08:51:00Z")

</div>

This is an example of a json file I am trying to POST into elasticsearch: {"index": {}} {"topic": "example1", "size": 2192, "timestamp": "2024-01-10"} {"index": {}} {"topic": "example2", "size": 2052, "timestamp": "2024…

---

## [BigQuery to ElasticSearch using DataFlow template, Not working](https://discuss.elastic.co/t/bigquery-to-elasticsearch-using-dataflow-template-not-working/350759)

<div class="topic-metadata">

**Author:** [@aji.shinde7](https://discuss.elastic.co/u/aji.shinde7)\
**Replies:** 1\
**Last updated:** [January 12, 2024, 8:19am UTC](https://discuss.elastic.co/t/bigquery-to-elasticsearch-using-dataflow-template-not-working/350759 "2024-01-12T08:19:26Z")

</div>

Hello Experts, Please Help, I followed this article to pull data from Google BigQuery into Elastic using Google DataFlow : Ingest data directly from Google BigQuery into Elastic using Google Dataflow | Elastic Blog I …

---

## [Unable to connect filbeat to logstash](https://discuss.elastic.co/t/unable-to-connect-filbeat-to-logstash/350912)

<div class="topic-metadata">

**Author:** [@dark\_header](https://discuss.elastic.co/u/dark_header)\
**Replies:** 0\
**Last updated:** [January 12, 2024, 7:32am UTC](https://discuss.elastic.co/t/unable-to-connect-filbeat-to-logstash/350912 "2024-01-12T07:32:56Z")

</div>

hi team , installed in ELK ( Elasticsearch , logstash , kibana and filebeat ) in same server unable to connect from filebeat to logstash , getting error below {"log.level":"error","timestamp":"2024-01-11T17:49:55.606+0…

---

## [Elastic Canvas: Discrepancy on data using ES SQL](https://discuss.elastic.co/t/elastic-canvas-discrepancy-on-data-using-es-sql/350882)

<div class="topic-metadata">

**Author:** [@pikaia](https://discuss.elastic.co/u/pikaia)\
**Replies:** 0\
**Last updated:** [January 11, 2024, 6:35pm UTC](https://discuss.elastic.co/t/elastic-canvas-discrepancy-on-data-using-es-sql/350882 "2024-01-11T18:35:24Z")

</div>

Hi, I've been uploading vulnerabilities to Elastic where the fields are already mapped to ECS, and so far, everything has been working fine. Now, I have the need to generate a report at the beginning of each month to pr…

---

## [Normalization or denormalization structure(Notification to multiple recipients - business logic)](https://discuss.elastic.co/t/normalization-or-denormalization-structure-notification-to-multiple-recipients-business-logic/350877)

<div class="topic-metadata">

**Author:** [@Behemo1h](https://discuss.elastic.co/u/Behemo1h)\
**Replies:** 0\
**Last updated:** [January 11, 2024, 6:09pm UTC](https://discuss.elastic.co/t/normalization-or-denormalization-structure-notification-to-multiple-recipients-business-logic/350877 "2024-01-11T18:09:27Z")

</div>

Hello all. I can't decide whether to "normalize" the data or not. I have notification datas in my app. When notification can be triggered for whole complay, user, or user in company. My current data looks like: Its o…

---

## [Index\_not\_found\_exception](https://discuss.elastic.co/t/index-not-found-exception/350736)

<div class="topic-metadata">

**Author:** [@e-ferrari](https://discuss.elastic.co/u/e-ferrari)\
**Replies:** 2\
**Last updated:** [January 11, 2024, 4:57pm UTC](https://discuss.elastic.co/t/index-not-found-exception/350736 "2024-01-11T16:57:55Z")

</div>

Hi, i'm following Parsing Logs with Logstash | Logstash Reference \[8.11\] | Elastic. When i try, as mentioned in the text curl -k -u elastic:xxxxxxxxxxxxxxxxxxxxx -XGET 'https://localhost:9200/2024.01.10/\_search?pretty&q…

---

## [Error: can not write type \[class java.time.LocalDate\] - Elasticsearch v8.10](https://discuss.elastic.co/t/error-can-not-write-type-class-java-time-localdate-elasticsearch-v8-10/350868)

<div class="topic-metadata">

**Author:** [@Abhishek](https://discuss.elastic.co/u/Abhishek)\
**Replies:** 0\
**Last updated:** [January 11, 2024, 2:39pm UTC](https://discuss.elastic.co/t/error-can-not-write-type-class-java-time-localdate-elasticsearch-v8-10/350868 "2024-01-11T14:39:34Z")

</div>

Hi Everyone, I have recently upgraded from es 5.6 to es 8.10. Following script field is working fine in es5.6 "script\_fields": { "customDate": { "script": { "inline": "def i ; if(params.\_source.cu…

---

## [What is the recommended memory:data ratio for a cold zone?](https://discuss.elastic.co/t/what-is-the-recommended-memory-data-ratio-for-a-cold-zone/349755)

<div class="topic-metadata">

**Author:** [@calin](https://discuss.elastic.co/u/calin)\
**Replies:** 8\
**Last updated:** [January 11, 2024, 1:31pm UTC](https://discuss.elastic.co/t/what-is-the-recommended-memory-data-ratio-for-a-cold-zone/349755 "2024-01-11T13:31:48Z")

</div>

I see for the hot zone it's 30. For a warm zone it's 160. I haven't seen a value for cold zone. And how exactly is that calculated ? Thank you.

---

## [Windows two Node Cluster stuck on tring to determine master](https://discuss.elastic.co/t/windows-two-node-cluster-stuck-on-tring-to-determine-master/350691)

<div class="topic-metadata">

**Author:** [@bytelink](https://discuss.elastic.co/u/bytelink)\
**Replies:** 11\
**Last updated:** [January 11, 2024, 1:28pm UTC](https://discuss.elastic.co/t/windows-two-node-cluster-stuck-on-tring-to-determine-master/350691 "2024-01-11T13:28:07Z")

</div>

I have been trying to install a new two node cluster on two windows servers and no matter what I have tried I get a situation where the two nodes do not seem to be able to determine which should be the master. I have tr…

---

## [Single Node Cluster - Basic or Minimal Security](https://discuss.elastic.co/t/single-node-cluster-basic-or-minimal-security/350586)

<div class="topic-metadata">

**Author:** [@randomnamegenerator](https://discuss.elastic.co/u/randomnamegenerator)\
**Replies:** 7\
**Last updated:** [January 11, 2024, 12:37pm UTC](https://discuss.elastic.co/t/single-node-cluster-basic-or-minimal-security/350586 "2024-01-11T12:37:41Z")

</div>

Hello All, I am looking for a little best practice guidance for our single node cluster on a customer site. The main aim is to create roles in kibana so that we can lock down access to certain individuals and groups. M…

---

## [Update jsonString with UpdateRequest through new java client\[8+ version\]](https://discuss.elastic.co/t/update-jsonstring-with-updaterequest-through-new-java-client-8-version/350855)

<div class="topic-metadata">

**Author:** [@pankaj\_sen](https://discuss.elastic.co/u/pankaj_sen)\
**Replies:** 0\
**Last updated:** [January 11, 2024, 12:31pm UTC](https://discuss.elastic.co/t/update-jsonstring-with-updaterequest-through-new-java-client-8-version/350855 "2024-01-11T12:31:47Z")

</div>

Getting below error while trying to update json string through update request. \[x\_content\_parse\_exception\] \[1:8\] \[UpdateRequest\] doc doesn't support values of type: VALUE\_STRING Below is my code snnipt client.update(g…

---

## [Elastic Unstable](https://discuss.elastic.co/t/elastic-unstable/350593)

<div class="topic-metadata">

**Author:** [@Dea\_Agra](https://discuss.elastic.co/u/Dea_Agra)\
**Replies:** 16\
**Last updated:** [January 11, 2024, 10:38am UTC](https://discuss.elastic.co/t/elastic-unstable/350593 "2024-01-11T10:38:34Z")

</div>

Hi Team Elastic, I have been stressful latelty because my logs are coming to Elasticsearch delay for about 10 hours. I have 3 nodes, Node 1: master, ingest, transform, resource: 16vCPU, 16GB, 500GB Node 2: data\_hot, …

---

## [Elasticsearch doesn't work!](https://discuss.elastic.co/t/elasticsearch-doesnt-work/350842)

<div class="topic-metadata">

**Author:** [@boubou](https://discuss.elastic.co/u/boubou)\
**Replies:** 1\
**Last updated:** [January 11, 2024, 10:28am UTC](https://discuss.elastic.co/t/elasticsearch-doesnt-work/350842 "2024-01-11T10:28:20Z")

</div>

I am having difficulties using Elasticsearch. I am on Linux and I have installed Elasticsearch 8.2. I have modified my elasticsearch.yml and here is what it contains: cluster.name: elasticsearch-prod node.name: myserve…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=157)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=159)
