# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=160

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 161

---

## [Getting this error - java.util.concurrent.CancellationException: Request execution cancelled](https://discuss.elastic.co/t/getting-this-error-java-util-concurrent-cancellationexception-request-execution-cancelled/350579)

<div class="topic-metadata">

**Author:** [@mr.fantastic](https://discuss.elastic.co/u/mr.fantastic)\
**Replies:** 2\
**Last updated:** [January 9, 2024, 7:09am UTC](https://discuss.elastic.co/t/getting-this-error-java-util-concurrent-cancellationexception-request-execution-cancelled/350579 "2024-01-09T07:09:58Z")

</div>

I am facing this issue, where my app tried to send search requests to es and encounters this issue. my client config is - \> RestClientBuilder restClientBuilder = RestClient.builder(new HttpHost(elasticSearchProps.getHo…

---

## [Unknown error while bulk indexing](https://discuss.elastic.co/t/unknown-error-while-bulk-indexing/350536)

<div class="topic-metadata">

**Author:** [@mmaccou](https://discuss.elastic.co/u/mmaccou)\
**Replies:** 2\
**Last updated:** [January 8, 2024, 7:04pm UTC](https://discuss.elastic.co/t/unknown-error-while-bulk-indexing/350536 "2024-01-08T19:04:00Z")

</div>

I'm getting some errors during bulk indexing that I cant seem to extract the reason for. Below is my code. Do you see any issues? I feel like this should be pulling out the reason given the explanation in the docs. asyn…

---

## [Enrich pipeline - how to get sum of enriched values from array](https://discuss.elastic.co/t/enrich-pipeline-how-to-get-sum-of-enriched-values-from-array/350604)

<div class="topic-metadata">

**Author:** [@pataposha](https://discuss.elastic.co/u/pataposha)\
**Replies:** 1\
**Last updated:** [January 8, 2024, 6:00pm UTC](https://discuss.elastic.co/t/enrich-pipeline-how-to-get-sum-of-enriched-values-from-array/350604 "2024-01-08T18:00:40Z")

</div>

Hi! I'm trying to apply "enrich pipeline" to my data to be able to filter/sort my main index with new fields. These fields are originally stored in a separate index. Let's say I have two indices: index1 - main index …

---

## [How to filter out results using scriptQuery?](https://discuss.elastic.co/t/how-to-filter-out-results-using-scriptquery/350607)

<div class="topic-metadata">

**Author:** [@ElasticDev1](https://discuss.elastic.co/u/ElasticDev1)\
**Replies:** 0\
**Last updated:** [January 8, 2024, 5:54pm UTC](https://discuss.elastic.co/t/how-to-filter-out-results-using-scriptquery/350607 "2024-01-08T17:54:14Z")

</div>

I am trying to filter the results returned by Elasticsearch and I am using painless script, since the data that needs to be used is on the index. My mapping looks like this: { "took": 100, "timed\_out": false, "\_sh…

---

## [DataStream Over Index with ILM](https://discuss.elastic.co/t/datastream-over-index-with-ilm/350078)

<div class="topic-metadata">

**Author:** [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Replies:** 4\
**Last updated:** [January 8, 2024, 4:26pm UTC](https://discuss.elastic.co/t/datastream-over-index-with-ilm/350078 "2024-01-08T16:26:50Z")

</div>

Hi Team, Could you please help me to understand the use of data stream over normal index on which we can apply template and ILM policy to rollover to a new Index once it meets the policy defined in ILM. Because while c…

---

## [How to close the connection using Go client?](https://discuss.elastic.co/t/how-to-close-the-connection-using-go-client/350123)

<div class="topic-metadata">

**Author:** [@elleWajexi](https://discuss.elastic.co/u/elleWajexi)\
**Replies:** 1\
**Last updated:** [January 8, 2024, 4:16pm UTC](https://discuss.elastic.co/t/how-to-close-the-connection-using-go-client/350123 "2024-01-08T16:16:43Z")

</div>

I normally connect to an elastic server, save the connection to a global variable, and reuse it in my entire app. var es \*elasticsearch.Client func elasticConnect() { cfg := elasticsearch.Config{ CloudID: …

---

## [Two node cluster - master assign](https://discuss.elastic.co/t/two-node-cluster-master-assign/350587)

<div class="topic-metadata">

**Author:** [@Oscar\_Yerpes](https://discuss.elastic.co/u/Oscar_Yerpes)\
**Replies:** 5\
**Last updated:** [January 8, 2024, 3:36pm UTC](https://discuss.elastic.co/t/two-node-cluster-master-assign/350587 "2024-01-08T15:36:02Z")

</div>

Hello all, I have a two-node cluster, with node01 designated as master: node.roles: \[ master, data, ingest \] node02 only has node.roles: \[ data, ingest \] In order to switch the master node, can I just simply move th…

---

## [Script for getting a date field and searching in a nested object both in the same object](https://discuss.elastic.co/t/script-for-getting-a-date-field-and-searching-in-a-nested-object-both-in-the-same-object/350597)

<div class="topic-metadata">

**Author:** [@metopas1991](https://discuss.elastic.co/u/metopas1991)\
**Replies:** 0\
**Last updated:** [January 8, 2024, 2:43pm UTC](https://discuss.elastic.co/t/script-for-getting-a-date-field-and-searching-in-a-nested-object-both-in-the-same-object/350597 "2024-01-08T14:43:49Z")

</div>

Hello there, I am using elasticsearch 8.11 and have an index shown below: PUT /topics/ { "settings": { "index.mapping.total\_fields.limit": 2000, "number\_of\_shards": 1, "analysis": { "filter": { …

---

## [Elastic repository problem?](https://discuss.elastic.co/t/elastic-repository-problem/350370)

<div class="topic-metadata">

**Author:** [@ramiwashere](https://discuss.elastic.co/u/ramiwashere)\
**Replies:** 6\
**Last updated:** [January 8, 2024, 2:05pm UTC](https://discuss.elastic.co/t/elastic-repository-problem/350370 "2024-01-08T14:05:22Z")

</div>

Hi, I'm currently upgrade ELK stack tot the lastest version. Yesterday I started with data nodes and master. I notice the link was very slow and at the end of the day, I had to relaunch the download few times to end it…

---

## [How many users can access Elasticsearch and Kibana at the same time?](https://discuss.elastic.co/t/how-many-users-can-access-elasticsearch-and-kibana-at-the-same-time/350392)

<div class="topic-metadata">

**Author:** [@stramzik](https://discuss.elastic.co/u/stramzik)\
**Replies:** 8\
**Last updated:** [January 8, 2024, 1:55pm UTC](https://discuss.elastic.co/t/how-many-users-can-access-elasticsearch-and-kibana-at-the-same-time/350392 "2024-01-08T13:55:27Z")

</div>

Hi, I am running a Elasticsearch and Kibana(V8.10) instance on a single windows server which has 8vCPU and 32gb of RAM. I would like to get a rough idea on how much load can the Elastic and Kibana instance can handle a…

---

## [Query slower with ES 5 compared with ES 7](https://discuss.elastic.co/t/query-slower-with-es-5-compared-with-es-7/350563)

<div class="topic-metadata">

**Author:** [@vincent2mots](https://discuss.elastic.co/u/vincent2mots)\
**Replies:** 1\
**Last updated:** [January 8, 2024, 10:05am UTC](https://discuss.elastic.co/t/query-slower-with-es-5-compared-with-es-7/350563 "2024-01-08T10:05:33Z")

</div>

Hi experts! We recently migrated from a ES 5 to a 7 version. We observed that some of our original queries became slower than before. An example of query : GET /\[index\_name\]/\_search?search\_type=dfs\_query\_then\_fetch {…

---

## [Delete by query deletes only 1000 documents, then quits](https://discuss.elastic.co/t/delete-by-query-deletes-only-1000-documents-then-quits/350529)

<div class="topic-metadata">

**Author:** [@d8d4a522fb1d394d9705](https://discuss.elastic.co/u/d8d4a522fb1d394d9705)\
**Replies:** 7\
**Last updated:** [January 8, 2024, 9:14am UTC](https://discuss.elastic.co/t/delete-by-query-deletes-only-1000-documents-then-quits/350529 "2024-01-08T09:14:41Z")

</div>

I am using the following the api to delete documents older than 60 days: POST /index\_name/\_delete\_by\_query?conflicts=proceed { "query": { "range": { "@timestamp": {"lte": "now-60d/d"} } } } My inde…

---

## [Getting incomplete request body in Elasticsearch audit log](https://discuss.elastic.co/t/getting-incomplete-request-body-in-elasticsearch-audit-log/350543)

<div class="topic-metadata">

**Author:** [@ashishshukla](https://discuss.elastic.co/u/ashishshukla)\
**Replies:** 2\
**Last updated:** [January 8, 2024, 8:41am UTC](https://discuss.elastic.co/t/getting-incomplete-request-body-in-elasticsearch-audit-log/350543 "2024-01-08T08:41:57Z")

</div>

I have executed few security APIs , for those I am getting incomplete request body in Elasticsearch Audit log. Below are the example: Query 1: POST /\_security/oauth2/token { "grant\_type": "refresh\_token", "refresh\_…

---

## [Invalid NEST response built from a unsuccessful () low level call on POST: /logs-%2A/\_search?typed\_keys=true](https://discuss.elastic.co/t/invalid-nest-response-built-from-a-unsuccessful-low-level-call-on-post-logs-2a-search-typed-keys-true/350452)

<div class="topic-metadata">

**Author:** [@Sunil\_Bisht](https://discuss.elastic.co/u/Sunil_Bisht)\
**Replies:** 3\
**Last updated:** [January 8, 2024, 8:09am UTC](https://discuss.elastic.co/t/invalid-nest-response-built-from-a-unsuccessful-low-level-call-on-post-logs-2a-search-typed-keys-true/350452 "2024-01-08T08:09:34Z")

</div>

\# Audit trail of this API call: - \[1\] ProductCheckOnStartup: Took: 00:00:03.0728820 - \[2\] ProductCheckFailure: Node: https://\*\*\*\*\*\*\*.aws.found.io:9243/ Took: 00:00:03.0531380 # OriginalException: Elasticsearch.Net.Ela…

---

## [Which installation is better for production](https://discuss.elastic.co/t/which-installation-is-better-for-production/350500)

<div class="topic-metadata">

**Author:** [@sahere37](https://discuss.elastic.co/u/sahere37)\
**Replies:** 5\
**Last updated:** [January 8, 2024, 5:30am UTC](https://discuss.elastic.co/t/which-installation-is-better-for-production/350500 "2024-01-08T05:30:20Z")

</div>

hi, I want to run ELK 8.11 on production environment on oracle linux VMs, Which type of installation is preferred for production environment? RPM based or Archive based? Also, can we use another user apart from "root" …

---

## [Use index to judge data,but not found](https://discuss.elastic.co/t/use-index-to-judge-data-but-not-found/350446)

<div class="topic-metadata">

**Author:** [@yunke\_yin](https://discuss.elastic.co/u/yunke_yin)\
**Replies:** 4\
**Last updated:** [January 8, 2024, 1:45am UTC](https://discuss.elastic.co/t/use-index-to-judge-data-but-not-found/350446 "2024-01-08T01:45:23Z")

</div>

please help me. I got many data of the same type. In some cases, the known data must exist, but I need to further confirm which index the data is under. I chose to judge in the following way, but cannot found then throw…

---

## [Slow ANN Hybrid search](https://discuss.elastic.co/t/slow-ann-hybrid-search/349837)

<div class="topic-metadata">

**Author:** [@steve\_lee](https://discuss.elastic.co/u/steve_lee)\
**Replies:** 5\
**Last updated:** [January 8, 2024, 12:42am UTC](https://discuss.elastic.co/t/slow-ann-hybrid-search/349837 "2024-01-08T00:42:35Z")

</div>

Hi, I have implemented vector hybrid search using ES dense\_vector field and KNN option in the search API. I have two index with vector field with 512 dimension embeddings (dot\_product). Each index have about 10 milli…

---

## [Elasticsearch shows float types as string in output](https://discuss.elastic.co/t/elasticsearch-shows-float-types-as-string-in-output/350535)

<div class="topic-metadata">

**Author:** [@Ata\_Zangene](https://discuss.elastic.co/u/Ata_Zangene)\
**Replies:** 2\
**Last updated:** [January 7, 2024, 6:08pm UTC](https://discuss.elastic.co/t/elasticsearch-shows-float-types-as-string-in-output/350535 "2024-01-07T18:08:53Z")

</div>

I have a sample schema like this "coordinate": { "properties": { "geo": { "type": "geo\_point" }, "latitude": { "type": "float" }, "longitude": { "type": "float" …

---

## [Unable to create an enrollment token. Elasticsearch node HTTP layer SSL configuration is not configured with a keystore](https://discuss.elastic.co/t/unable-to-create-an-enrollment-token-elasticsearch-node-http-layer-ssl-configuration-is-not-configured-with-a-keystore/350527)

<div class="topic-metadata">

**Author:** [@Ekta](https://discuss.elastic.co/u/Ekta)\
**Replies:** 1\
**Last updated:** [January 7, 2024, 2:41pm UTC](https://discuss.elastic.co/t/unable-to-create-an-enrollment-token-elasticsearch-node-http-layer-ssl-configuration-is-not-configured-with-a-keystore/350527 "2024-01-07T14:41:13Z")

</div>

Hi Team, I am upgrading elasticsearch from 7.17.0 to 8.11 on ubuntu 22.04 I have completed elasticsearch installation and x-pack while I am creating token for cluster it is showing below error Error: Unable to create …

---

## [Can you modify web scraper extraction rules for reserved field name: body\_content?](https://discuss.elastic.co/t/can-you-modify-web-scraper-extraction-rules-for-reserved-field-name-body-content/350513)

<div class="topic-metadata">

**Author:** [@mmaccou](https://discuss.elastic.co/u/mmaccou)\
**Replies:** 0\
**Last updated:** [January 6, 2024, 4:21pm UTC](https://discuss.elastic.co/t/can-you-modify-web-scraper-extraction-rules-for-reserved-field-name-body-content/350513 "2024-01-06T16:21:27Z")

</div>

By default, body\_content grabs content that's irrelevant for my use case. Instead of creating a new field with custom extraction rules, I'd rather edit the rules for body\_content to avoid creating unused fields in my doc…

---

## [How to replace unicode \\u00a0 with space with ingest pipeline processor](https://discuss.elastic.co/t/how-to-replace-unicode-u00a0-with-space-with-ingest-pipeline-processor/350484)

<div class="topic-metadata">

**Author:** [@Bowfish](https://discuss.elastic.co/u/Bowfish)\
**Replies:** 1\
**Last updated:** [January 6, 2024, 12:29pm UTC](https://discuss.elastic.co/t/how-to-replace-unicode-u00a0-with-space-with-ingest-pipeline-processor/350484 "2024-01-06T12:29:52Z")

</div>

I want to replace all non breaking space (\\u00a0) characters with a normal spaces in a gsub processor in an ingest pipeline. I tried it with this: POST \_ingest/pipeline/\_simulate { "pipeline": { "processors": \[ …

---

## [Help understanding boolean should query results](https://discuss.elastic.co/t/help-understanding-boolean-should-query-results/350495)

<div class="topic-metadata">

**Author:** [@allan.silverstein](https://discuss.elastic.co/u/allan.silverstein)\
**Replies:** 0\
**Last updated:** [January 5, 2024, 10:46pm UTC](https://discuss.elastic.co/t/help-understanding-boolean-should-query-results/350495 "2024-01-05T22:46:45Z")

</div>

Hello, I'm not understanding why the following query does not show any documents hits for the "support\_files.bgp\_evpn\_routes" field. It does show hits for the first match\_phrase (name a). As a troubleshooting test, I c…

---

## [Percolating returns more results that i expect](https://discuss.elastic.co/t/percolating-returns-more-results-that-i-expect/350481)

<div class="topic-metadata">

**Author:** [@oli.girling](https://discuss.elastic.co/u/oli.girling)\
**Replies:** 4\
**Last updated:** [January 5, 2024, 6:56pm UTC](https://discuss.elastic.co/t/percolating-returns-more-results-that-i-expect/350481 "2024-01-05T18:56:42Z")

</div>

Smashing my head against the wall with this, wondering if anyone can point anything out thats obvious. Using ES 5.6 (I know its out of date, im in the process of upgrading) I have an advert in ES GET /gb/classified/15…

---

## [How i put a response into a kibana URL](https://discuss.elastic.co/t/how-i-put-a-response-into-a-kibana-url/350410)

<div class="topic-metadata">

**Author:** [@Natanael\_Rodrigues](https://discuss.elastic.co/u/Natanael_Rodrigues)\
**Replies:** 3\
**Last updated:** [January 5, 2024, 3:25pm UTC](https://discuss.elastic.co/t/how-i-put-a-response-into-a-kibana-url/350410 "2024-01-05T15:25:06Z")

</div>

Hello all, I have a script that will execute at a Unix serve curl -X POST "htt..xxxxx/xxxxx\*/\_search?pretty=" -H 'authorization: Basic xxxxxxxx' -H 'content-type: application/json' -d '{ "aggs": { "2": { …

---

## [How to delete huge number of documents from Index? What can be better option?](https://discuss.elastic.co/t/how-to-delete-huge-number-of-documents-from-index-what-can-be-better-option/350469)

<div class="topic-metadata">

**Author:** [@msabnis79](https://discuss.elastic.co/u/msabnis79)\
**Replies:** 0\
**Last updated:** [January 5, 2024, 2:31pm UTC](https://discuss.elastic.co/t/how-to-delete-huge-number-of-documents-from-index-what-can-be-better-option/350469 "2024-01-05T14:31:48Z")

</div>

For example, we are having 2 billion documents in an index in ES and want to delete 1 billion documents based on some data from Oracle database? So i have to copy data from Oracle 1 billion records and based on Primary …

---

## [Sharding and index settings](https://discuss.elastic.co/t/sharding-and-index-settings/350457)

<div class="topic-metadata">

**Author:** [@Mertozturkk](https://discuss.elastic.co/u/Mertozturkk)\
**Replies:** 2\
**Last updated:** [January 5, 2024, 12:31pm UTC](https://discuss.elastic.co/t/sharding-and-index-settings/350457 "2024-01-05T12:31:39Z")

</div>

The 3 Node Elasticsearch we have set up currently has a 6TB index set into 16 P and 1 R shards and is slow to respond to queries. If we want to create an index from scratch that will reach a similar volume in the new ver…

---

## [LDAP Configuration - ELK 8.8.1](https://discuss.elastic.co/t/ldap-configuration-elk-8-8-1/350444)

<div class="topic-metadata">

**Author:** [@Manal\_A](https://discuss.elastic.co/u/Manal_A)\
**Replies:** 0\
**Last updated:** [January 5, 2024, 9:42am UTC](https://discuss.elastic.co/t/ldap-configuration-elk-8-8-1/350444 "2024-01-05T09:42:50Z")

</div>

I'm currently configuring the LDAP on my coordinator & Kibana nodes (8.8.1) Here are the steps I've taken: Tested the connection with the LDAP server on my coordinator, and it's successful. Configured my elasticsearc…

---

## [What is the meaning of brackets in an index name?](https://discuss.elastic.co/t/what-is-the-meaning-of-brackets-in-an-index-name/350376)

<div class="topic-metadata">

**Author:** [@mbby](https://discuss.elastic.co/u/mbby)\
**Replies:** 4\
**Last updated:** [January 5, 2024, 7:24am UTC](https://discuss.elastic.co/t/what-is-the-meaning-of-brackets-in-an-index-name/350376 "2024-01-05T07:24:22Z")

</div>

We are using heartbeat and I saw a data view like this: (synthetics-data-view),heartbeat-8,heartbeat-7\*,synthetics-\* Why is synthetics-data-view written in brackets?

---

## [Watermark sonarqube](https://discuss.elastic.co/t/watermark-sonarqube/350406)

<div class="topic-metadata">

**Author:** [@walterh91](https://discuss.elastic.co/u/walterh91)\
**Replies:** 3\
**Last updated:** [January 5, 2024, 7:17am UTC](https://discuss.elastic.co/t/watermark-sonarqube/350406 "2024-01-05T07:17:18Z")

</div>

Hello how are you? Currently, I am using two versions of SonarQube: Development environment: Community Edition Version 9.1 (build 47736) Production environment: Developer Edition Version 9.9.1 (build 69595) In both c…

---

## [Backup/Restore Indexes](https://discuss.elastic.co/t/backup-restore-indexes/350411)

<div class="topic-metadata">

**Author:** [@marcowiskhy](https://discuss.elastic.co/u/marcowiskhy)\
**Replies:** 1\
**Last updated:** [January 4, 2024, 8:31pm UTC](https://discuss.elastic.co/t/backup-restore-indexes/350411 "2024-01-04T20:31:25Z")

</div>

Hey guys, I have an Elasticsearch node in production and am experiencing issues regarding disk storage. At the moment I cannot increase computational resources or add other nodes because I depend on collaboration with a…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=159)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=161)
