# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=16

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 17

---

## [APM for third party Apps](https://discuss.elastic.co/t/apm-for-third-party-apps/382622)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 3\
**Last updated:** [October 14, 2025, 6:25am UTC](https://discuss.elastic.co/t/apm-for-third-party-apps/382622 "2025-10-14T06:25:28Z")

</div>

Hello Everyone, I would like to ask that APM is feasible for COTS(Commercial Off-The-Shelf)applications like Microsoft Office, customer relationship management (CRM) platforms such as Salesforce, design software like A…

---

## [Accurate and relevant user-defined sorting](https://discuss.elastic.co/t/accurate-and-relevant-user-defined-sorting/382611)

<div class="topic-metadata">

**Author:** [@GalacticHypernova](https://discuss.elastic.co/u/GalacticHypernova)\
**Replies:** 1\
**Last updated:** [October 13, 2025, 8:20pm UTC](https://discuss.elastic.co/t/accurate-and-relevant-user-defined-sorting/382611 "2025-10-13T20:20:19Z")

</div>

Hey guys, quite new to ES. I have an app that supports user-provided queries, user-provided filters, and user-provided sorts. The query is fine in multi\_match, and filters are good in the filter query. My main issue is …

---

## [Phrase query, using shingles(index\_phrases) results in inconsistent results with the default query method](https://discuss.elastic.co/t/phrase-query-using-shingles-index-phrases-results-in-inconsistent-results-with-the-default-query-method/382625)

<div class="topic-metadata">

**Author:** [@fangqingsong](https://discuss.elastic.co/u/fangqingsong)\
**Replies:** 1\
**Last updated:** [October 13, 2025, 12:49pm UTC](https://discuss.elastic.co/t/phrase-query-using-shingles-index-phrases-results-in-inconsistent-results-with-the-default-query-method/382625 "2025-10-13T12:49:02Z")

</div>

ES 9.1.3, geonames datasets, index name is “field-name-index-phrase-geonames” health status index uuid pri rep docs.count docs.deleted store.size pri.store.size dataset.size …

---

## [LogsDB optimized routing](https://discuss.elastic.co/t/logsdb-optimized-routing/382278)

<div class="topic-metadata">

**Author:** [@lduvnjak](https://discuss.elastic.co/u/lduvnjak)\
**Replies:** 8\
**Last updated:** [October 13, 2025, 12:36pm UTC](https://discuss.elastic.co/t/logsdb-optimized-routing/382278 "2025-10-13T12:36:42Z")

</div>

Hi Everyone, I have a couple of questions regarding LogsDB, and more specifically optimized routing. It is generally recommended to use low cardinality fields for LogsDB index sorting, but there are no pointers on what…

---

## [Dense\_vector slow in ES 9.1.3](https://discuss.elastic.co/t/dense-vector-slow-in-es-9-1-3/381855)

<div class="topic-metadata">

**Author:** [@glund0](https://discuss.elastic.co/u/glund0)\
**Replies:** 16\
**Last updated:** [October 13, 2025, 10:42am UTC](https://discuss.elastic.co/t/dense-vector-slow-in-es-9-1-3/381855 "2025-10-13T10:42:49Z")

</div>

We’ve been using ES 8.9.0 and are looking to upgrade, so I started testing performance with 9.1.3 and found it to be very slow. So, I went back to 8.19.3 and found that it’s performance is fine. But we’d like to not be…

---

## [/etc/elasticsearch/trust.yml is mandatory and optional. I am using it On-Premises](https://discuss.elastic.co/t/etc-elasticsearch-trust-yml-is-mandatory-and-optional-i-am-using-it-on-premises/382591)

<div class="topic-metadata">

**Author:** [@Varinder](https://discuss.elastic.co/u/Varinder)\
**Replies:** 6\
**Last updated:** [October 11, 2025, 7:04pm UTC](https://discuss.elastic.co/t/etc-elasticsearch-trust-yml-is-mandatory-and-optional-i-am-using-it-on-premises/382591 "2025-10-11T19:04:50Z")

</div>

Hi Folks, Thanks to all members for their help and support. I need opinion for both Single Node and Cluster in Elasticsearch. “Is not using the /etc/elasticsearch/trust.yml file in /etc/elasticsearch/elasticsearch.yml …

---

## [Nagios & Elastic Stack Project Student](https://discuss.elastic.co/t/nagios-elastic-stack-project-student/382596)

<div class="topic-metadata">

**Author:** [@Isy212](https://discuss.elastic.co/u/Isy212)\
**Replies:** 2\
**Last updated:** [October 11, 2025, 4:27pm UTC](https://discuss.elastic.co/t/nagios-elastic-stack-project-student/382596 "2025-10-11T16:27:44Z")

</div>

Hi there! Hope you are all well, I need some advice and information regarding a project I am working on trying to bridge both Nagios and Elastic Stack. I am quite new to elastic stack and was wondering if there is a way …

---

## [Do we really need these cipher settings in elasticsearch.yml file according to ES official documentaion i version 8.19.3](https://discuss.elastic.co/t/do-we-really-need-these-cipher-settings-in-elasticsearch-yml-file-according-to-es-official-documentaion-i-version-8-19-3/382549)

<div class="topic-metadata">

**Author:** [@Varinder](https://discuss.elastic.co/u/Varinder)\
**Replies:** 2\
**Last updated:** [October 10, 2025, 5:31pm UTC](https://discuss.elastic.co/t/do-we-really-need-these-cipher-settings-in-elasticsearch-yml-file-according-to-es-official-documentaion-i-version-8-19-3/382549 "2025-10-10T17:31:23Z")

</div>

set\_yaml "${elasticsearch\_conf}" "\[xpack.security.transport.ssl.cipher\_suites\].\[0\]" "TLS\_ECDHE\_RSA\_WITH\_AES\_256\_GCM\_SHA384" && set\_yaml "${elasticsearch\_conf}" "\[xpack.security.transport.ssl.cipher\_suites\].\[1\]" "TLS\_ECD…

---

## [Using fluent lambda expressions with a scroll search request](https://discuss.elastic.co/t/using-fluent-lambda-expressions-with-a-scroll-search-request/382562)

<div class="topic-metadata">

**Author:** [@TSlump](https://discuss.elastic.co/u/TSlump)\
**Replies:** 2\
**Last updated:** [October 10, 2025, 3:31pm UTC](https://discuss.elastic.co/t/using-fluent-lambda-expressions-with-a-scroll-search-request/382562 "2025-10-10T15:31:07Z")

</div>

I’ve been unable to use fluent lambda expressions when searching with a scroll. I have the code working using direct creations of the request objects: public async Task\<List\<int\>\> GetAllElasticIds() { var ids = new L…

---

## [How to 'empty' a big index?](https://discuss.elastic.co/t/how-to-empty-a-big-index/382586)

<div class="topic-metadata">

**Author:** [@smm](https://discuss.elastic.co/u/smm)\
**Replies:** 1\
**Last updated:** [October 10, 2025, 2:09pm UTC](https://discuss.elastic.co/t/how-to-empty-a-big-index/382586 "2025-10-10T14:09:52Z")

</div>

Hi there, I am in the situation to have a regular index (not a time-series index & not a data stream). This index got really big - about 13GB. Because of its nature I cannot use ILM. What can I do instead to have an e…

---

## [Data too large, data for \[\<http\_request\>\] would be \[4238960092/3.9gb\], which is larger than the limit of \[3006477107/2.7gb\], real usage: \[4238959160/3.9gb\], new bytes reserved: \[932/932b\], usages \[request=0/0b, inflight\_requests=932/932b, model\_inference=](https://discuss.elastic.co/t/data-too-large-data-for-http-request-would-be-4238960092-3-9gb-which-is-larger-than-the-limit-of-3006477107-2-7gb-real-usage-4238959160-3-9gb-new-bytes-reserved-932-932b-usages-request-0-0b-inflight-requests-932-932b-model-inference/382547)

<div class="topic-metadata">

**Author:** [@Pallavi\_K\_V](https://discuss.elastic.co/u/Pallavi_K_V)\
**Replies:** 1\
**Last updated:** [October 10, 2025, 7:13am UTC](https://discuss.elastic.co/t/data-too-large-data-for-http-request-would-be-4238960092-3-9gb-which-is-larger-than-the-limit-of-3006477107-2-7gb-real-usage-4238959160-3-9gb-new-bytes-reserved-932-932b-usages-request-0-0b-inflight-requests-932-932b-model-inference/382547 "2025-10-10T07:13:40Z")

</div>

Because of which Elastic search is going down aand restarting by itself what could be the issue

---

## [Anomaly detection](https://discuss.elastic.co/t/anomaly-detection/382487)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 1\
**Last updated:** [October 8, 2025, 11:15pm UTC](https://discuss.elastic.co/t/anomaly-detection/382487 "2025-10-08T23:15:37Z")

</div>

I got metrics ingested into elastic for each process. Some metrics are \>95%. I have created a ML job on max(cpu). You can see in the image how the spikes are for cpu. but I see no anomalies are found. why so? Please help…

---

## [File.hash.sha256 encoded as UTF‑16LE](https://discuss.elastic.co/t/file-hash-sha256-encoded-as-utf-16le/382196)

<div class="topic-metadata">

**Author:** [@dynamicint](https://discuss.elastic.co/u/dynamicint)\
**Replies:** 1\
**Last updated:** [October 8, 2025, 10:31am UTC](https://discuss.elastic.co/t/file-hash-sha256-encoded-as-utf-16le/382196 "2025-10-08T10:31:00Z")

</div>

The following field: file.hash.sha256 Which is (now) the same as: winlog.user\_data.FileHash Has an encoding problem in Elastic 9.1.4. It's encoded with UTF‑16LE, which means that the first bytes with the proper sha25…

---

## [Watcher error using 'terms' query with metadata array input](https://discuss.elastic.co/t/watcher-error-using-terms-query-with-metadata-array-input/382513)

<div class="topic-metadata">

**Author:** [@Simriti\_Bundhoo](https://discuss.elastic.co/u/Simriti_Bundhoo)\
**Replies:** 1\
**Last updated:** [October 8, 2025, 4:05am UTC](https://discuss.elastic.co/t/watcher-error-using-terms-query-with-metadata-array-input/382513 "2025-10-08T04:05:14Z")

</div>

Hi everyone, I'm trying to use an array from the watch metadata in a terms query for one of my watchers. I want to use a Mustache search template-style query as described here: :link: https://www.elastic.co/docs/soluti…

---

## [Regarding client and server version alignment](https://discuss.elastic.co/t/regarding-client-and-server-version-alignment/382486)

<div class="topic-metadata">

**Author:** [@yeikel](https://discuss.elastic.co/u/yeikel)\
**Replies:** 3\
**Last updated:** [October 7, 2025, 5:39pm UTC](https://discuss.elastic.co/t/regarding-client-and-server-version-alignment/382486 "2025-10-07T17:39:27Z")

</div>

We discovered through MissingRequiredPropertyException in PIT query · Issue #921 · elastic/elasticsearch-java · GitHub that even minor version mismatches between the Elasticsearch server and client can lead to issues. B…

---

## [Elastic won't start after upgrade to 8.19.4](https://discuss.elastic.co/t/elastic-wont-start-after-upgrade-to-8-19-4/382328)

<div class="topic-metadata">

**Author:** [@artschooldropout](https://discuss.elastic.co/u/artschooldropout)\
**Replies:** 22\
**Last updated:** [October 7, 2025, 1:36pm UTC](https://discuss.elastic.co/t/elastic-wont-start-after-upgrade-to-8-19-4/382328 "2025-10-07T13:36:00Z")

</div>

We recently attempted to upgrade our cluster from 8.17.4 to 8.19.4 using apt. After the upgrade, the service won’t start and we see this line in the logs: java.lang.IllegalStateException: Failed to parse mappings for in…

---

## [Dense Vector Field Extremely Large](https://discuss.elastic.co/t/dense-vector-field-extremely-large/382380)

<div class="topic-metadata">

**Author:** [@nicky](https://discuss.elastic.co/u/nicky)\
**Replies:** 12\
**Last updated:** [October 6, 2025, 11:57pm UTC](https://discuss.elastic.co/t/dense-vector-field-extremely-large/382380 "2025-10-06T23:57:16Z")

</div>

Hi all, Have been experimenting with applying both forms of compression to our dense vectors and doing performance comparisons, but while bbq\_hnsw has been performing relatively well at 1-3s per query average, int8 has …

---

## [Watcher: Support for Keystore Variables in Watch Definitions](https://discuss.elastic.co/t/watcher-support-for-keystore-variables-in-watch-definitions/382362)

<div class="topic-metadata">

**Author:** [@console\_fulcrum](https://discuss.elastic.co/u/console_fulcrum)\
**Replies:** 5\
**Last updated:** [October 6, 2025, 2:33pm UTC](https://discuss.elastic.co/t/watcher-support-for-keystore-variables-in-watch-definitions/382362 "2025-10-06T14:33:53Z")

</div>

Currently working on Elasticsearch 8.17.1 with Watcher + DataDog integration. While xpack.watcher.encrypt\_sensitive\_data=true encrypts stored watches, the initial watch definition still requires plaintext credentials. C…

---

## [How to avoid initializing\_shards during restarts](https://discuss.elastic.co/t/how-to-avoid-initializing-shards-during-restarts/382152)

<div class="topic-metadata">

**Author:** [@sukur55](https://discuss.elastic.co/u/sukur55)\
**Replies:** 14\
**Last updated:** [October 6, 2025, 11:34am UTC](https://discuss.elastic.co/t/how-to-avoid-initializing-shards-during-restarts/382152 "2025-10-06T11:34:27Z")

</div>

Hi Folks, so we have 3 node ElastichSearch cluster, when we do rollout restart we see a case like there are shards which was primary on restarted node A and now the replica on other node B promoted as primary and we see …

---

## [How to best handle large Elastic indexes](https://discuss.elastic.co/t/how-to-best-handle-large-elastic-indexes/382412)

<div class="topic-metadata">

**Author:** [@Moni\_Hazarika](https://discuss.elastic.co/u/Moni_Hazarika)\
**Replies:** 3\
**Last updated:** [October 4, 2025, 12:34pm UTC](https://discuss.elastic.co/t/how-to-best-handle-large-elastic-indexes/382412 "2025-10-04T12:34:27Z")

</div>

Hi Team, We are on Elasticsearch version 8.x and we have this index which for data isolation, security etc reasons we kept as 1 index per tenant. On the index creation since we don’t specify the number of shards, we get…

---

## [Problem with "Result window is too large, from + size must be less than or equal to"](https://discuss.elastic.co/t/problem-with-result-window-is-too-large-from-size-must-be-less-than-or-equal-to/382411)

<div class="topic-metadata">

**Author:** [@Mario\_22](https://discuss.elastic.co/u/Mario_22)\
**Replies:** 0\
**Last updated:** [October 4, 2025, 9:40am UTC](https://discuss.elastic.co/t/problem-with-result-window-is-too-large-from-size-must-be-less-than-or-equal-to/382411 "2025-10-04T09:40:51Z")

</div>

Hi, I need help. After upgrading Elastic Stack from 8.18.2 to 9.1.4, I got an error while monitoring Elastic. Specifically, the built-in rules: CCR read exceptions Cluster health CPU usage Elasticsearch version mis…

---

## [Deploying a Persistent Fleet Server on the Same Docker Network as Elasticsearch and Kibana Containers](https://discuss.elastic.co/t/deploying-a-persistent-fleet-server-on-the-same-docker-network-as-elasticsearch-and-kibana-containers/382387)

<div class="topic-metadata">

**Author:** [@Simriti\_Bundhoo](https://discuss.elastic.co/u/Simriti_Bundhoo)\
**Replies:** 0\
**Last updated:** [October 3, 2025, 3:56am UTC](https://discuss.elastic.co/t/deploying-a-persistent-fleet-server-on-the-same-docker-network-as-elasticsearch-and-kibana-containers/382387 "2025-10-03T03:56:33Z")

</div>

Hi everyone, I’m trying to deploy a persistent Fleet Server in Docker, ensuring it runs on the same Docker network as my Elasticsearch and Kibana containers. Both Elasticsearch and Kibana are already up and running in s…

---

## [Using custom script engine in Elasticclient 8](https://discuss.elastic.co/t/using-custom-script-engine-in-elasticclient-8/382197)

<div class="topic-metadata">

**Author:** [@priyankaMS](https://discuss.elastic.co/u/priyankaMS)\
**Replies:** 2\
**Last updated:** [October 2, 2025, 12:36pm UTC](https://discuss.elastic.co/t/using-custom-script-engine-in-elasticclient-8/382197 "2025-10-02T12:36:08Z")

</div>

Hello We are updating our code from NEST to elastic client. We have a custom written script engine in Java for indexing documents to elasticsearch. But we realised in elasticclient there is no way to pass script names w…

---

## [Elasticsearch upgrade admission webhook error elastic-es-validation-v1.k8s.elastic.co](https://discuss.elastic.co/t/elasticsearch-upgrade-admission-webhook-error-elastic-es-validation-v1-k8s-elastic-co/382367)

<div class="topic-metadata">

**Author:** [@astingengo](https://discuss.elastic.co/u/astingengo)\
**Replies:** 0\
**Last updated:** [October 2, 2025, 6:56am UTC](https://discuss.elastic.co/t/elasticsearch-upgrade-admission-webhook-error-elastic-es-validation-v1-k8s-elastic-co/382367 "2025-10-02T06:56:27Z")

</div>

Hi there, I’m having elasticsearch deployed inside Kubernetes (v1.32.7) Operator version was 2.16.1 and stack version 0.4.0 Upgraded them to 3.1.0 and 0.14.1 and now having below error on operator and ES not deployed …

---

## [CSV Processor (Ingest pipelines): Tab Separator](https://discuss.elastic.co/t/csv-processor-ingest-pipelines-tab-separator/382361)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 4\
**Last updated:** [October 1, 2025, 8:23pm UTC](https://discuss.elastic.co/t/csv-processor-ingest-pipelines-tab-separator/382361 "2025-10-01T20:23:43Z")

</div>

Is there a way for CSV processor to accept TSV?

---

## [Dealing with nested fields from aggregations](https://discuss.elastic.co/t/dealing-with-nested-fields-from-aggregations/382346)

<div class="topic-metadata">

**Author:** [@Sam\_Moss](https://discuss.elastic.co/u/Sam_Moss)\
**Replies:** 0\
**Last updated:** [October 1, 2025, 9:54am UTC](https://discuss.elastic.co/t/dealing-with-nested-fields-from-aggregations/382346 "2025-10-01T09:54:34Z")

</div>

I am trying to build a central inventory index pulling data from a variety of different places, this means that there are a few aggregations on the way to the final index, which leads to lovely field names such as “wmi.w…

---

## [How to check Elasticsearch license history or past activations (Platinum/Enterprise)?](https://discuss.elastic.co/t/how-to-check-elasticsearch-license-history-or-past-activations-platinum-enterprise/382323)

<div class="topic-metadata">

**Author:** [@Musab\_Dogan](https://discuss.elastic.co/u/Musab_Dogan)\
**Replies:** 2\
**Last updated:** [October 1, 2025, 4:54am UTC](https://discuss.elastic.co/t/how-to-check-elasticsearch-license-history-or-past-activations-platinum-enterprise/382323 "2025-10-01T04:54:11Z")

</div>

Five years ago, one of my customers purchased an Elastic license. The renewal date has now arrived, and they asked me to verify the current license status of their clusters. When I checked, all clusters with GET /\_licens…

---

## [\[BUG\] A replica shard in POST\_RECOVERY state, when promoted to primary, will be stuck](https://discuss.elastic.co/t/bug-a-replica-shard-in-post-recovery-state-when-promoted-to-primary-will-be-stuck/382333)

<div class="topic-metadata">

**Author:** [@Govind\_Balaji\_S](https://discuss.elastic.co/u/Govind_Balaji_S)\
**Replies:** 1\
**Last updated:** [September 30, 2025, 9:16pm UTC](https://discuss.elastic.co/t/bug-a-replica-shard-in-post-recovery-state-when-promoted-to-primary-will-be-stuck/382333 "2025-09-30T21:16:17Z")

</div>

EDIT: I think I mixed up ShardRoutingState and IndexShardState. I think this introduced a bug - A replica can be promoted and started in one cluster state update by bleskes · Pull Request #32042 · elastic/elasticsearch …

---

## [Help with upgrade assistant api command](https://discuss.elastic.co/t/help-with-upgrade-assistant-api-command/382331)

<div class="topic-metadata">

**Author:** [@dominbdg](https://discuss.elastic.co/u/dominbdg)\
**Replies:** 1\
**Last updated:** [September 30, 2025, 8:13pm UTC](https://discuss.elastic.co/t/help-with-upgrade-assistant-api-command/382331 "2025-09-30T20:13:47Z")

</div>

Hello, I have issue, from curl I need to go to upgrade assistant api, from documentation it is: /api/upgrade\_assistant/status my command for that from curl is: curl -XGET -k -uelastic:"$(bin/elasticsearch-keystore…

---

## [Aggregated sorted search with top hits and paging - items missing](https://discuss.elastic.co/t/aggregated-sorted-search-with-top-hits-and-paging-items-missing/382225)

<div class="topic-metadata">

**Author:** [@irkallacz](https://discuss.elastic.co/u/irkallacz)\
**Replies:** 6\
**Last updated:** [September 30, 2025, 2:34pm UTC](https://discuss.elastic.co/t/aggregated-sorted-search-with-top-hits-and-paging-items-missing/382225 "2025-09-30T14:34:11Z")

</div>

My intend is to have paged list of all categories presented by cheapest product, sorted by price. I have search terms aggregation by product category, sorted by min aggregation on price: "aggs": { "count":{"car…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=15)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=17)
