# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=159

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 160

---

## [What's the best way to create the combined fields in Elastic Search?](https://discuss.elastic.co/t/whats-the-best-way-to-create-the-combined-fields-in-elastic-search/350843)

<div class="topic-metadata">

**Author:** [@Nomerator](https://discuss.elastic.co/u/Nomerator)\
**Replies:** 0\
**Last updated:** [January 11, 2024, 10:02am UTC](https://discuss.elastic.co/t/whats-the-best-way-to-create-the-combined-fields-in-elastic-search/350843 "2024-01-11T10:02:49Z")

</div>

For example, I have fields street, city, state, continent, planet. There is situation when I should search by combination of two fields street and city, and there is situation when I should search by combination of all …

---

## [ILM Hot, Warm, Cold not moving indexes](https://discuss.elastic.co/t/ilm-hot-warm-cold-not-moving-indexes/350756)

<div class="topic-metadata">

**Author:** [@DaddyYusk](https://discuss.elastic.co/u/DaddyYusk)\
**Replies:** 3\
**Last updated:** [January 11, 2024, 9:25am UTC](https://discuss.elastic.co/t/ilm-hot-warm-cold-not-moving-indexes/350756 "2024-01-11T09:25:26Z")

</div>

Hi, Despite the ILM policy applied to all logs (Managed), the indexes are moved to the Warm node but not deleted on the Hot node and I'm actually reaching disk capacity on the Hot node... Here is my Elastic Cluster : w…

---

## [Need help deciding how to partition data](https://discuss.elastic.co/t/need-help-deciding-how-to-partition-data/350837)

<div class="topic-metadata">

**Author:** [@favoca](https://discuss.elastic.co/u/favoca)\
**Replies:** 1\
**Last updated:** [January 11, 2024, 8:44am UTC](https://discuss.elastic.co/t/need-help-deciding-how-to-partition-data/350837 "2024-01-11T08:44:05Z")

</div>

The document in my RDMS has a schema similar to this: { PatientId: "string", Date: "date", IsAvailable: "bool", \_hospitalId: "6-digit number which can be a number or a string" } The \_hospitalId acts like a partition ke…

---

## [Elasticsearch unable to form a cluster](https://discuss.elastic.co/t/elasticsearch-unable-to-form-a-cluster/350798)

<div class="topic-metadata">

**Author:** [@ido.shoy](https://discuss.elastic.co/u/ido.shoy)\
**Replies:** 0\
**Last updated:** [January 11, 2024, 12:00am UTC](https://discuss.elastic.co/t/elasticsearch-unable-to-form-a-cluster/350798 "2024-01-11T00:00:55Z")

</div>

this is my docker-compose.yml version: '3.8' services: els01: image: docker.elastic.co/elasticsearch/elasticsearch:8.11.3 hostname: els01 volumes: - /mnt/data/els01:/usr/share/e…

---

## [Shard Count based on incomming data (MBits/sec) or max MBits/sec of Node (datastream included)?](https://discuss.elastic.co/t/shard-count-based-on-incomming-data-mbits-sec-or-max-mbits-sec-of-node-datastream-included/350788)

<div class="topic-metadata">

**Author:** [@LaszloE](https://discuss.elastic.co/u/LaszloE)\
**Replies:** 0\
**Last updated:** [January 10, 2024, 8:20pm UTC](https://discuss.elastic.co/t/shard-count-based-on-incomming-data-mbits-sec-or-max-mbits-sec-of-node-datastream-included/350788 "2024-01-10T20:20:12Z")

</div>

Let us say I have 300 GB data coming in from one client in a day. I store this data on the hot nodes and at the end of the day I move it to the warm nodes. For this 300 GB in order to have acceptable sized shards (let …

---

## [Elastic search 8.7.1 cluster is not forming, Here is yml: and command to create a token run on CENTOS7](https://discuss.elastic.co/t/elastic-search-8-7-1-cluster-is-not-forming-here-is-yml-and-command-to-create-a-token-run-on-centos7/350613)

<div class="topic-metadata">

**Author:** [@Varinder](https://discuss.elastic.co/u/Varinder)\
**Replies:** 9\
**Last updated:** [January 10, 2024, 7:10pm UTC](https://discuss.elastic.co/t/elastic-search-8-7-1-cluster-is-not-forming-here-is-yml-and-command-to-create-a-token-run-on-centos7/350613 "2024-01-10T19:10:56Z")

</div>

path.data: /var/lib/elasticsearch path.logs: /var/log/elasticsearch xpack.security.enabled: false xpack.security.enrollment.enabled: true xpack.security.http.ssl: enabled: false keystore.path: certs/http.p12 xpack…

---

## [Nagios Log Server: Cannot login](https://discuss.elastic.co/t/nagios-log-server-cannot-login/350780)

<div class="topic-metadata">

**Author:** [@riahc3](https://discuss.elastic.co/u/riahc3)\
**Replies:** 0\
**Last updated:** [January 10, 2024, 5:04pm UTC](https://discuss.elastic.co/t/nagios-log-server-cannot-login/350780 "2024-01-10T17:04:38Z")

</div>

Hello Im using Nagios Log Server (which is ELK) and the issue Im having is that when I point the data directory to a NFS share, it says invalid username or password. Doesnt matter if I even reset it, it says the same th…

---

## [Podman containers wont start after creating podman-compose](https://discuss.elastic.co/t/podman-containers-wont-start-after-creating-podman-compose/350483)

<div class="topic-metadata">

**Author:** [@Mike\_Kirby](https://discuss.elastic.co/u/Mike_Kirby)\
**Replies:** 2\
**Last updated:** [January 10, 2024, 2:55pm UTC](https://discuss.elastic.co/t/podman-containers-wont-start-after-creating-podman-compose/350483 "2024-01-10T14:55:24Z")

</div>

Hello Elastic Guru's. I am back with a new and exciting question. I am in a new project, where I am running a Podman/Docker configuration for my Elastic SIEM. I have the Kibana and Logstash installed and their contain…

---

## [Elastic for Aerospace Data](https://discuss.elastic.co/t/elastic-for-aerospace-data/350732)

<div class="topic-metadata">

**Author:** [@Samuele\_Lolli](https://discuss.elastic.co/u/Samuele_Lolli)\
**Replies:** 1\
**Last updated:** [January 10, 2024, 2:09pm UTC](https://discuss.elastic.co/t/elastic-for-aerospace-data/350732 "2024-01-10T14:09:27Z")

</div>

Hi everyone, im currently working in a project about aerospace and im considering ELK to store data and do some basic data visualization. The data are GPS coordinate, gyro data, speeds and stuff like that. Anyone have…

---

## [Enterprise-search.yml configuration](https://discuss.elastic.co/t/enterprise-search-yml-configuration/350757)

<div class="topic-metadata">

**Author:** [@awccu](https://discuss.elastic.co/u/awccu)\
**Replies:** 0\
**Last updated:** [January 10, 2024, 2:02pm UTC](https://discuss.elastic.co/t/enterprise-search-yml-configuration/350757 "2024-01-10T14:02:12Z")

</div>

I am having trouble configuring the enterprise-search.yml. Specifically, it is unclear to me how to proceed with configuring enterprise search when the ssl method of configuring the elasticsearch cluster and the kibana w…

---

## [Transform Preview fails with "Please provide a transform \[id\] or the config object"](https://discuss.elastic.co/t/transform-preview-fails-with-please-provide-a-transform-id-or-the-config-object/350730)

<div class="topic-metadata">

**Author:** [@Nightingale\_John](https://discuss.elastic.co/u/Nightingale_John)\
**Replies:** 3\
**Last updated:** [January 10, 2024, 10:59am UTC](https://discuss.elastic.co/t/transform-preview-fails-with-please-provide-a-transform-id-or-the-config-object/350730 "2024-01-10T10:59:33Z")

</div>

Hi All, I'm trying to get a transform working, my first one admittedly, but regardless of whether I do API or via browser setup it errors. An example transform preview: POST \_transform/\_preview { "source": { "ind…

---

## [Life cycle of a log submitted to elastic search](https://discuss.elastic.co/t/life-cycle-of-a-log-submitted-to-elastic-search/350605)

<div class="topic-metadata">

**Author:** [@minh.tran](https://discuss.elastic.co/u/minh.tran)\
**Replies:** 1\
**Last updated:** [January 10, 2024, 9:59am UTC](https://discuss.elastic.co/t/life-cycle-of-a-log-submitted-to-elastic-search/350605 "2024-01-10T09:59:23Z")

</div>

When a log is submitted to Elasticsearch, I was wondering what is the lifecycle. We specify the index format so we know which view it'll be picked up in kibana. But when does it get indexed, how do we know which which …

---

## [Cluster shards disbalance](https://discuss.elastic.co/t/cluster-shards-disbalance/350714)

<div class="topic-metadata">

**Author:** [@vladislav](https://discuss.elastic.co/u/vladislav)\
**Replies:** 3\
**Last updated:** [January 10, 2024, 9:41am UTC](https://discuss.elastic.co/t/cluster-shards-disbalance/350714 "2024-01-10T09:41:19Z")

</div>

Hello. Thanks in advance for any help I have a 3-nodes cluster containing different amount of shards on each node. Earlier it runs elasticsearch 8.4.3 and all was nearly-fine, but after upgrading to 8.11.1 things seems …

---

## [Elasticsearch Cluster Disk Write Performance](https://discuss.elastic.co/t/elasticsearch-cluster-disk-write-performance/350711)

<div class="topic-metadata">

**Author:** [@sheng855174](https://discuss.elastic.co/u/sheng855174)\
**Replies:** 1\
**Last updated:** [January 10, 2024, 9:22am UTC](https://discuss.elastic.co/t/elasticsearch-cluster-disk-write-performance/350711 "2024-01-10T09:22:16Z")

</div>

Hello everyone, I have an ELK cluster and encountered performance problems, which caused most data to be written 10 minutes slower than the actual time. This problem occurs occasionally. I want to know the cause of thi…

---

## [Fuziness not working when querying in larger index](https://discuss.elastic.co/t/fuziness-not-working-when-querying-in-larger-index/350503)

<div class="topic-metadata">

**Author:** [@SriramOnGrid](https://discuss.elastic.co/u/SriramOnGrid)\
**Replies:** 5\
**Last updated:** [January 10, 2024, 8:49am UTC](https://discuss.elastic.co/t/fuziness-not-working-when-querying-in-larger-index/350503 "2024-01-10T08:49:44Z")

</div>

Hi team, I wanted to fuziness for the purpose of finding the words with minor spelling mistakes. The query I am using is { "query": { "bool": { "must": \[ { "match": { "respon…

---

## [Elasticsearch Data Streams: Update Strategies, Concerns, and Alternatives](https://discuss.elastic.co/t/elasticsearch-data-streams-update-strategies-concerns-and-alternatives/350546)

<div class="topic-metadata">

**Author:** [@jainesh\_singh](https://discuss.elastic.co/u/jainesh_singh)\
**Replies:** 5\
**Last updated:** [January 10, 2024, 6:32am UTC](https://discuss.elastic.co/t/elasticsearch-data-streams-update-strategies-concerns-and-alternatives/350546 "2024-01-10T06:32:19Z")

</div>

Hi Team, I am stuck and need your help!! UseCase: I am using elasticsearch where i am storing activities in a data stream. I want to perform update operation on this Data stream. There is time based range queries tha…

---

## [Regarding encrypted communication between Elasticsearch servers](https://discuss.elastic.co/t/regarding-encrypted-communication-between-elasticsearch-servers/350621)

<div class="topic-metadata">

**Author:** [@YUUTA.INOUE-JPN](https://discuss.elastic.co/u/YUUTA.INOUE-JPN)\
**Replies:** 2\
**Last updated:** [January 10, 2024, 1:39am UTC](https://discuss.elastic.co/t/regarding-encrypted-communication-between-elasticsearch-servers/350621 "2024-01-10T01:39:35Z")

</div>

Hello from Japan I have a question for you respected engineers. I am an inexperienced Japanese engineer with Elasticsearch. I prepared three servers with Elasticsearch V8.11 installed and built an Elastic cluster. I …

---

## [Pre v5 index compatibility with Elasticsearch v8](https://discuss.elastic.co/t/pre-v5-index-compatibility-with-elasticsearch-v8/350680)

<div class="topic-metadata">

**Author:** [@buitcj](https://discuss.elastic.co/u/buitcj)\
**Replies:** 5\
**Last updated:** [January 9, 2024, 11:14pm UTC](https://discuss.elastic.co/t/pre-v5-index-compatibility-with-elasticsearch-v8/350680 "2024-01-09T23:14:55Z")

</div>

Per Upgrade Elasticsearch | Elasticsearch Guide \[8.11\] | Elastic, "indices created in 6.x or earlier...use the archive functionality" which makes it sound like any version \<= 6 should work. Maybe slightly contradictory,…

---

## [co.elastic.clients.json.JsonpMappingException: Error deserializing co.elastic.clients.elasticsearch.\_types.query\_dsl.MatchQuery: Invalid enum 'NONE'](https://discuss.elastic.co/t/co-elastic-clients-json-jsonpmappingexception-error-deserializing-co-elastic-clients-elasticsearch-types-query-dsl-matchquery-invalid-enum-none/350660)

<div class="topic-metadata">

**Author:** [@MADHAV\_JHA\_Govind](https://discuss.elastic.co/u/MADHAV_JHA_Govind)\
**Replies:** 7\
**Last updated:** [January 9, 2024, 5:13pm UTC](https://discuss.elastic.co/t/co-elastic-clients-json-jsonpmappingexception-error-deserializing-co-elastic-clients-elasticsearch-types-query-dsl-matchquery-invalid-enum-none/350660 "2024-01-09T17:13:09Z")

</div>

Hi Team, I am facing issue while sending the query as json to Elasticsearch using latest client which is 8.11.1 please help me if i Iam trying anything wrong. StringReader queryJson = new StringReader(query); SearchRes…

---

## [TLS Key location after installation](https://discuss.elastic.co/t/tls-key-location-after-installation/350615)

<div class="topic-metadata">

**Author:** [@Chris\_Stone](https://discuss.elastic.co/u/Chris_Stone)\
**Replies:** 5\
**Last updated:** [January 9, 2024, 4:06pm UTC](https://discuss.elastic.co/t/tls-key-location-after-installation/350615 "2024-01-09T16:06:09Z")

</div>

I'm on my second attempt at installing ES and Metricbeats to monitor the node (Ubuntu 22.04). I'm still unable to get Metricbeat to connect due to lack of the TLS key, which I can't locate. Per the doc at Install Elasti…

---

## [How to replace multiple newlines with two newlines in ingest pipeline gsub](https://discuss.elastic.co/t/how-to-replace-multiple-newlines-with-two-newlines-in-ingest-pipeline-gsub/350570)

<div class="topic-metadata">

**Author:** [@Bowfish](https://discuss.elastic.co/u/Bowfish)\
**Replies:** 6\
**Last updated:** [January 9, 2024, 3:56pm UTC](https://discuss.elastic.co/t/how-to-replace-multiple-newlines-with-two-newlines-in-ingest-pipeline-gsub/350570 "2024-01-09T15:56:59Z")

</div>

I want to replace multiple (more than 3) newlines (\\n\\n\\n) with two newlines (\\n\\n). If I set "\\n\\n" as a replacement string the the gsub object it replaces \\n\\n\\n\\ with nn. Here you can find my \_simulate ingest pipelin…

---

## [ElasticAbout Elasticsearch & Kibana process persistence](https://discuss.elastic.co/t/elasticabout-elasticsearch-kibana-process-persistence/350622)

<div class="topic-metadata">

**Author:** [@YUUTA.INOUE-JPN](https://discuss.elastic.co/u/YUUTA.INOUE-JPN)\
**Replies:** 1\
**Last updated:** [January 9, 2024, 2:39pm UTC](https://discuss.elastic.co/t/elasticabout-elasticsearch-kibana-process-persistence/350622 "2024-01-09T14:39:41Z")

</div>

Hello from Japan I have a question for you respected engineers. I am an inexperienced Japanese engineer with Elasticsearch. I have a question about how to make Elasticsearch & Kibana version 8.11 process persistent us…

---

## [Elastic plugin SSL handskake](https://discuss.elastic.co/t/elastic-plugin-ssl-handskake/350661)

<div class="topic-metadata">

**Author:** [@Francisco\_Javier\_Ort](https://discuss.elastic.co/u/Francisco_Javier_Ort)\
**Replies:** 0\
**Last updated:** [January 9, 2024, 1:58pm UTC](https://discuss.elastic.co/t/elastic-plugin-ssl-handskake/350661 "2024-01-09T13:58:40Z")

</div>

Hi All, We have a plugin installed in elastic that connects to an url, when trying to connbect we get an SSLHandshake exception We have deployed the application in a GKE cluster and all the certificates looks correctl…

---

## [Как в ElasticsearchOperations в UpdateQuery в скрипте достать params листом а не стрингой?](https://discuss.elastic.co/t/elasticsearchoperations-updatequery-params/350653)

<div class="topic-metadata">

**Author:** [@Marina\_S](https://discuss.elastic.co/u/Marina_S)\
**Replies:** 0\
**Last updated:** [January 9, 2024, 12:53pm UTC](https://discuss.elastic.co/t/elasticsearchoperations-updatequery-params/350653 "2024-01-09T12:53:54Z")

</div>

Я использую ElasticsearchOperations directories это лист объектов List Directory String scriptText = "if (ctx.\_source.businessPartnerParams != null) { " + "ctx.\_source.businessPartnerParams.bpName = 'test 3 ' " + "}"…

---

## [After Successful logstash execution, it's taking time to reflect the same in Kibana](https://discuss.elastic.co/t/after-successful-logstash-execution-its-taking-time-to-reflect-the-same-in-kibana/350645)

<div class="topic-metadata">

**Author:** [@Abj\_Ins](https://discuss.elastic.co/u/Abj_Ins)\
**Replies:** 3\
**Last updated:** [January 9, 2024, 12:50pm UTC](https://discuss.elastic.co/t/after-successful-logstash-execution-its-taking-time-to-reflect-the-same-in-kibana/350645 "2024-01-09T12:50:54Z")

</div>

Hi Team, After Successful logstash execution, it's taking time to reflect the same in Kibana (approx 3 hrs). Please let us know the reason why this is happening. Thanks.

---

## [Why in ElasticsearchOperations in UpdateQuery params put how string but not List object?](https://discuss.elastic.co/t/why-in-elasticsearchoperations-in-updatequery-params-put-how-string-but-not-list-object/350647)

<div class="topic-metadata">

**Author:** [@Marina\_S](https://discuss.elastic.co/u/Marina_S)\
**Replies:** 0\
**Last updated:** [January 9, 2024, 12:02pm UTC](https://discuss.elastic.co/t/why-in-elasticsearchoperations-in-updatequery-params-put-how-string-but-not-list-object/350647 "2024-01-09T12:02:06Z")

</div>

I use ElasticsearchOperations directories its the List Directory String scriptText = "if (ctx.\_source.businessPartnerParams != null) { " + "ctx.\_source.businessPartnerParams.bpName = 'test 3 ' " + "}"; HashMap\<S…

---

## [Elk setup for 6 months logs storage](https://discuss.elastic.co/t/elk-setup-for-6-months-logs-storage/350427)

<div class="topic-metadata">

**Author:** [@kriti\_dabas](https://discuss.elastic.co/u/kriti_dabas)\
**Replies:** 16\
**Last updated:** [January 9, 2024, 11:10am UTC](https://discuss.elastic.co/t/elk-setup-for-6-months-logs-storage/350427 "2024-01-09T11:10:59Z")

</div>

What should be my setup for elk if I want to keep the logs for 6 months? My flow is syslog-ng -------kafka --------logstash---------elasticsearch --------kibana . My per day data is 120GB. I want to know the number of…

---

## [Issues with complex range query](https://discuss.elastic.co/t/issues-with-complex-range-query/350643)

<div class="topic-metadata">

**Author:** [@teemukarvinen](https://discuss.elastic.co/u/teemukarvinen)\
**Replies:** 0\
**Last updated:** [January 9, 2024, 10:46am UTC](https://discuss.elastic.co/t/issues-with-complex-range-query/350643 "2024-01-09T10:46:16Z")

</div>

Hi, I have documents that contain array of allocation for person. Mapping: "Allocations": { "properties": { "endDate": { "type": "date" }, "startDate": { "type": "date" }, "state": { …

---

## [Onprem Elastic Kibana - Fleet - Kubernetes integration -No POD logs or metrics](https://discuss.elastic.co/t/onprem-elastic-kibana-fleet-kubernetes-integration-no-pod-logs-or-metrics/350642)

<div class="topic-metadata">

**Author:** [@chadleywilson](https://discuss.elastic.co/u/chadleywilson)\
**Replies:** 0\
**Last updated:** [January 9, 2024, 10:17am UTC](https://discuss.elastic.co/t/onprem-elastic-kibana-fleet-kubernetes-integration-no-pod-logs-or-metrics/350642 "2024-01-09T10:17:25Z")

</div>

Hi I have setup Elastic with Kibana on an onprem standalone server. I setup using the deb packages. I was pestered by the GUI to use Fleet Server, so after a lot of frustrating fiddling I managed to get it to work and…

---

## [Productionising ELK](https://discuss.elastic.co/t/productionising-elk/350634)

<div class="topic-metadata">

**Author:** [@anik-27](https://discuss.elastic.co/u/anik-27)\
**Replies:** 0\
**Last updated:** [January 9, 2024, 8:27am UTC](https://discuss.elastic.co/t/productionising-elk/350634 "2024-01-09T08:27:20Z")

</div>

Hello, I have done POC for following use cases using the ELK and metricbeat - a) Monitoring 5-10 servers using metric beats b) stashed data into elasticsearch from an excel files every 15 minutes and created a dashboa…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=158)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=160)
