# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=161

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 162

---

## [\[Elasticsearch user settings and extensions\] Increase http.max\_initial\_line\_length](https://discuss.elastic.co/t/elasticsearch-user-settings-and-extensions-increase-http-max-initial-line-length/350387)

<div class="topic-metadata">

**Author:** [@Xavier\_Huberdeau](https://discuss.elastic.co/u/Xavier_Huberdeau)\
**Replies:** 1\
**Last updated:** [January 4, 2024, 4:53pm UTC](https://discuss.elastic.co/t/elasticsearch-user-settings-and-extensions-increase-http-max-initial-line-length/350387 "2024-01-04T16:53:46Z")

</div>

Hello, I'm trying to change the elasticsearch settings yml configuration from elastic.co When I put http.max\_initial\_line\_length: 32kb, it says: Your changes cannot be applied Elasticsearch - 'http.max\_initial\_li…

---

## [Kindly suggest hardware sizing](https://discuss.elastic.co/t/kindly-suggest-hardware-sizing/350348)

<div class="topic-metadata">

**Author:** [@sakda.pk](https://discuss.elastic.co/u/sakda.pk)\
**Replies:** 0\
**Last updated:** [January 4, 2024, 4:12am UTC](https://discuss.elastic.co/t/kindly-suggest-hardware-sizing/350348 "2024-01-04T04:12:28Z")

</div>

I have size of data is 850 GB per day and must keep data in 91 days. Total size about 77 TB. pleased help to suggest. - quantity node - quantity shade of index per day Additional Question - how maximum space of n…

---

## [How to modify total memory of existing nodes?](https://discuss.elastic.co/t/how-to-modify-total-memory-of-existing-nodes/349958)

<div class="topic-metadata">

**Author:** [@SanthoshKMurugadass](https://discuss.elastic.co/u/SanthoshKMurugadass)\
**Replies:** 8\
**Last updated:** [January 4, 2024, 3:51pm UTC](https://discuss.elastic.co/t/how-to-modify-total-memory-of-existing-nodes/349958 "2024-01-04T15:51:32Z")

</div>

Hi, I am new to elasticresearch. I have set up 3 node cluster following docker setup procedure explained as per section: Section Start a multi-node cluster with Docker Compose in below help link Here is my cluster nod…

---

## [Maximum timeout reached while retrying request. Call: Status code unknown from](https://discuss.elastic.co/t/maximum-timeout-reached-while-retrying-request-call-status-code-unknown-from/350378)

<div class="topic-metadata">

**Author:** [@ali\_haider](https://discuss.elastic.co/u/ali_haider)\
**Replies:** 0\
**Last updated:** [January 4, 2024, 12:14pm UTC](https://discuss.elastic.co/t/maximum-timeout-reached-while-retrying-request-call-status-code-unknown-from/350378 "2024-01-04T12:14:31Z")

</div>

Hi, I have installed Elasticsearch 7.17.7 version on Windows Server 2022 I am facing the following error and exception Index goes to red zone after this exception. In Elasticsearch logs it's says that that indices fi…

---

## [I facing error while setup elasticsearch cluster in docker using 2 host server those servers from azure ERROR i am getting like this Peer{transportAddress=10.33.8.79:9300, discoveryNode=null, peersRequestInFlight=false} connection failed org.elasticsearc](https://discuss.elastic.co/t/i-facing-error-while-setup-elasticsearch-cluster-in-docker-using-2-host-server-those-servers-from-azure-error-i-am-getting-like-this-peer-transportaddress-10-33-8-79-9300-discoverynode-null-peersrequestinflight-false-connection-failed-org-elasticsearc/350369)

<div class="topic-metadata">

**Author:** [@Pasupuleti\_siva](https://discuss.elastic.co/u/Pasupuleti_siva)\
**Replies:** 4\
**Last updated:** [January 4, 2024, 10:08am UTC](https://discuss.elastic.co/t/i-facing-error-while-setup-elasticsearch-cluster-in-docker-using-2-host-server-those-servers-from-azure-error-i-am-getting-like-this-peer-transportaddress-10-33-8-79-9300-discoverynode-null-peersrequestinflight-false-connection-failed-org-elasticsearc/350369 "2024-01-04T10:08:37Z")

</div>

ERROR: \[2024-01-04T09:04:24,575\]\[DEBUG\]\[o.e.d.PeerFinder \] \[odfe-node2\] Peer{transportAddress=10.33.8.79:9300, discoveryNode=null, peersRequestInFlight=false} connection failed org.elasticsearch.transport.Connect…

---

## [I want to know details about how we reduced the heap usage per shard](https://discuss.elastic.co/t/i-want-to-know-details-about-how-we-reduced-the-heap-usage-per-shard/350346)

<div class="topic-metadata">

**Author:** [@emmning](https://discuss.elastic.co/u/emmning)\
**Replies:** 1\
**Last updated:** [January 4, 2024, 9:28am UTC](https://discuss.elastic.co/t/i-want-to-know-details-about-how-we-reduced-the-heap-usage-per-shard/350346 "2024-01-04T09:28:15Z")

</div>

Through this blog I see that starting from 8.3, we have significantly reduced Usage of each shard of the heap. I would like to know more details about how we can reduce the heap usage per shard. Anyone knows a PR or blog…

---

## [Backup large indexes to other locations on a time-by-time basis and clean up the index](https://discuss.elastic.co/t/backup-large-indexes-to-other-locations-on-a-time-by-time-basis-and-clean-up-the-index/350191)

<div class="topic-metadata">

**Author:** [@sqq](https://discuss.elastic.co/u/sqq)\
**Replies:** 12\
**Last updated:** [January 4, 2024, 7:42am UTC](https://discuss.elastic.co/t/backup-large-indexes-to-other-locations-on-a-time-by-time-basis-and-clean-up-the-index/350191 "2024-01-04T07:42:25Z")

</div>

Backup large indexes to other locations on a time-by-time basis and clean up the index

---

## [Is dfs\_query\_then\_fetch automatically disabled on single shard?](https://discuss.elastic.co/t/is-dfs-query-then-fetch-automatically-disabled-on-single-shard/350351)

<div class="topic-metadata">

**Author:** [@Yukha\_Dharmeswara](https://discuss.elastic.co/u/Yukha_Dharmeswara)\
**Replies:** 0\
**Last updated:** [January 4, 2024, 5:17am UTC](https://discuss.elastic.co/t/is-dfs-query-then-fetch-automatically-disabled-on-single-shard/350351 "2024-01-04T05:17:34Z")

</div>

When we specify search\_type=dfs\_query\_then\_fetch in querystring, does Elasticsearch automatically disable dfs\_query\_then\_fetch when there's only 1 shard in single node mode? Or do i have to use query\_then\_fetch to trigge…

---

## [Configure ingest pipeline to add both GeoLite2-City AND GeoLite2-ASN fields](https://discuss.elastic.co/t/configure-ingest-pipeline-to-add-both-geolite2-city-and-geolite2-asn-fields/350339)

<div class="topic-metadata">

**Author:** [@jbrowe](https://discuss.elastic.co/u/jbrowe)\
**Replies:** 1\
**Last updated:** [January 4, 2024, 12:00am UTC](https://discuss.elastic.co/t/configure-ingest-pipeline-to-add-both-geolite2-city-and-geolite2-asn-fields/350339 "2024-01-04T00:00:58Z")

</div>

I have and event stream that contains IP addresses. I wish to add meta-data from the GeoLite2 Max Mind databases. I can successfully add the city data. I can also successfully add the ASN data. Somehow, I cannot add both…

---

## [Rollup or downsampling](https://discuss.elastic.co/t/rollup-or-downsampling/350342)

<div class="topic-metadata">

**Author:** [@EdRayQO](https://discuss.elastic.co/u/EdRayQO)\
**Replies:** 0\
**Last updated:** [January 3, 2024, 11:17pm UTC](https://discuss.elastic.co/t/rollup-or-downsampling/350342 "2024-01-03T23:17:07Z")

</div>

I'm trying to compress log data I have in a monitoring cluster and that is configured to be erased after 7 days, and I'm not sure which path should I follow between rollup jobs and down sampling in order to compress that…

---

## [Error log curl: (52) Empty reply from server in v8.11.3](https://discuss.elastic.co/t/error-log-curl-52-empty-reply-from-server-in-v8-11-3/350338)

<div class="topic-metadata">

**Author:** [@ACodingfreak](https://discuss.elastic.co/u/ACodingfreak)\
**Replies:** 2\
**Last updated:** [January 3, 2024, 8:18pm UTC](https://discuss.elastic.co/t/error-log-curl-52-empty-reply-from-server-in-v8-11-3/350338 "2024-01-03T20:18:34Z")

</div>

Hi All, I am new to ELK and started using the same via docker compose. I have used the standard docker-compose.yaml file which is available in below link. As shown in below logs all containers are up and running $ …

---

## [ES SQL custom mappings](https://discuss.elastic.co/t/es-sql-custom-mappings/349980)

<div class="topic-metadata">

**Author:** [@ES\_SQL\_HELP](https://discuss.elastic.co/u/ES_SQL_HELP)\
**Replies:** 6\
**Last updated:** [January 3, 2024, 5:08pm UTC](https://discuss.elastic.co/t/es-sql-custom-mappings/349980 "2024-01-03T17:08:54Z")

</div>

Hello, I'm wondering if it's possible to use ES SQL on custom field mappings for types e.g. long, integer, doubles.

---

## [Inconsistencies between platforms](https://discuss.elastic.co/t/inconsistencies-between-platforms/350261)

<div class="topic-metadata">

**Author:** [@nml1988](https://discuss.elastic.co/u/nml1988)\
**Replies:** 11\
**Last updated:** [January 3, 2024, 3:35pm UTC](https://discuss.elastic.co/t/inconsistencies-between-platforms/350261 "2024-01-03T15:35:06Z")

</div>

Hello! I need help with a problem I'm having between 2 versions of ELK. These versions correspond to two different platforms that consume data from the same source. The first image corresponds to an ELK stack 7.9, where…

---

## [How to use Filters, Facets and Group By feature in .NET client?](https://discuss.elastic.co/t/how-to-use-filters-facets-and-group-by-feature-in-net-client/350322)

<div class="topic-metadata">

**Author:** [@RamuAnnamalai](https://discuss.elastic.co/u/RamuAnnamalai)\
**Replies:** 0\
**Last updated:** [January 3, 2024, 3:21pm UTC](https://discuss.elastic.co/t/how-to-use-filters-facets-and-group-by-feature-in-net-client/350322 "2024-01-03T15:21:48Z")

</div>

I have integrated Elastic Search feature in .NET 6.0 API framework. I need to know how to use filters, facets & group by features in REST API .NET Client? Do you have any documentation for this? Thanks, Ramu

---

## [Delete by query conflict](https://discuss.elastic.co/t/delete-by-query-conflict/350320)

<div class="topic-metadata">

**Author:** [@Hariharan](https://discuss.elastic.co/u/Hariharan)\
**Replies:** 0\
**Last updated:** [January 3, 2024, 3:06pm UTC](https://discuss.elastic.co/t/delete-by-query-conflict/350320 "2024-01-03T15:06:35Z")

</div>

Hey folks, I have a quick question on how to handle a particular scenario I'm running into. So we have a sync between a person's calendar events and Elasticsearch to index the events from Calendar and build some sort of…

---

## [Connectors Relationship with Db](https://discuss.elastic.co/t/connectors-relationship-with-db/349611)

<div class="topic-metadata">

**Author:** [@aisyaharifin](https://discuss.elastic.co/u/aisyaharifin)\
**Replies:** 1\
**Last updated:** [January 3, 2024, 2:23pm UTC](https://discuss.elastic.co/t/connectors-relationship-with-db/349611 "2024-01-03T14:23:21Z")

</div>

Hello Elastic, I want to ask, I have issue where I've been configuring Connectors in Production environment which specifically Microsoft SQL connectors to pull the data into Elasticsearch Indices and it seems like it co…

---

## [ELSER2 | Spell check before creating embeddings](https://discuss.elastic.co/t/elser2-spell-check-before-creating-embeddings/350303)

<div class="topic-metadata">

**Author:** [@Rakesh\_Nayak](https://discuss.elastic.co/u/Rakesh_Nayak)\
**Replies:** 1\
**Last updated:** [January 3, 2024, 2:07pm UTC](https://discuss.elastic.co/t/elser2-spell-check-before-creating-embeddings/350303 "2024-01-03T14:07:16Z")

</div>

Hello Team, Any suggestion of doing spell check before creating embeddings? e.g. if the query is misspelt "toiket rolls" instead of "toilet rolls" can we create the embeddings for "toilet rolls" using ELSER2 model POST…

---

## [Production configuration question](https://discuss.elastic.co/t/production-configuration-question/350302)

<div class="topic-metadata">

**Author:** [@Aleksandar\_Aleksand1](https://discuss.elastic.co/u/Aleksandar_Aleksand1)\
**Replies:** 3\
**Last updated:** [January 3, 2024, 1:07pm UTC](https://discuss.elastic.co/t/production-configuration-question/350302 "2024-01-03T13:07:42Z")

</div>

Hi all, I am preparing the following elasticsearch cluster architecture: Total 6 Nodes: 1 Node with roles: master and remote\_cluster\_client 3 Nodes with roles: data, data\_hot, data\_content and ingest 1 Node with role…

---

## [ES curator not deleting the indices data](https://discuss.elastic.co/t/es-curator-not-deleting-the-indices-data/350241)

<div class="topic-metadata">

**Author:** [@Ravi\_Pattar](https://discuss.elastic.co/u/Ravi_Pattar)\
**Replies:** 2\
**Last updated:** [January 3, 2024, 12:49pm UTC](https://discuss.elastic.co/t/es-curator-not-deleting-the-indices-data/350241 "2024-01-03T12:49:26Z")

</div>

Hello, I have installed the ES-curator and below are my curator.yml and action.yml. I am seeing below errors while running the dry run and also when I tried with the cronjob entries. Because I don't see the indices dat…

---

## [Kibana 7.17.6 \> 8 Kibana\_system 403 unauthorized?](https://discuss.elastic.co/t/kibana-7-17-6-8-kibana-system-403-unauthorized/350288)

<div class="topic-metadata">

**Author:** [@grumo35](https://discuss.elastic.co/u/grumo35)\
**Replies:** 3\
**Last updated:** [January 3, 2024, 11:10am UTC](https://discuss.elastic.co/t/kibana-7-17-6-8-kibana-system-403-unauthorized/350288 "2024-01-03T11:10:32Z")

</div>

Hi everyone ! i've been upgrading my cluster recently everything went well until i got kibana HTTP 403 Errors with both kibana\_system and elastic users. Am i supposed to create a user with \[manage\] \[manage\_all\] perms i…

---

## [TopHits aggregation | How to get strong type from Java API?](https://discuss.elastic.co/t/tophits-aggregation-how-to-get-strong-type-from-java-api/341343)

<div class="topic-metadata">

**Author:** [@denbo](https://discuss.elastic.co/u/denbo)\
**Replies:** 2\
**Last updated:** [January 3, 2024, 10:52am UTC](https://discuss.elastic.co/t/tophits-aggregation-how-to-get-strong-type-from-java-api/341343 "2024-01-03T10:52:09Z")

</div>

I am extracting the hits from a TopHits aggregation using the Java API: Map\<String, Aggregate\> aggregations = searchResponse.aggregations(); TopHitsAggregate topHitsAggregate = searchResponse.aggregations().get("topHits…

---

## [Elasticsearch: What's the best way to store big-data cost effective](https://discuss.elastic.co/t/elasticsearch-whats-the-best-way-to-store-big-data-cost-effective/350289)

<div class="topic-metadata">

**Author:** [@basiltitus](https://discuss.elastic.co/u/basiltitus)\
**Replies:** 1\
**Last updated:** [January 3, 2024, 9:26am UTC](https://discuss.elastic.co/t/elasticsearch-whats-the-best-way-to-store-big-data-cost-effective/350289 "2024-01-03T09:26:06Z")

</div>

We are using Basic Elasticsearch v7.4 on a single node with nearly 2TB of data. We planning to increase our retention however we are constrained by it's storage capacity. While adding disks and using multiple data path i…

---

## [Retrieve inner\_hits when searching multiple kNN fields in same nested document](https://discuss.elastic.co/t/retrieve-inner-hits-when-searching-multiple-knn-fields-in-same-nested-document/350024)

<div class="topic-metadata">

**Author:** [@Jasper\_Simon](https://discuss.elastic.co/u/Jasper_Simon)\
**Replies:** 3\
**Last updated:** [January 3, 2024, 8:20am UTC](https://discuss.elastic.co/t/retrieve-inner-hits-when-searching-multiple-knn-fields-in-same-nested-document/350024 "2024-01-03T08:20:42Z")

</div>

I've got this use case (examples here are simplified to the essentials) where I want to do a knn search on multiple vectors of the same nested document inside a larger document, and be able to distinguish which of the ne…

---

## [Low footprint way of importing Windows Service Data](https://discuss.elastic.co/t/low-footprint-way-of-importing-windows-service-data/350282)

<div class="topic-metadata">

**Author:** [@randomnamegenerator](https://discuss.elastic.co/u/randomnamegenerator)\
**Replies:** 0\
**Last updated:** [January 3, 2024, 7:56am UTC](https://discuss.elastic.co/t/low-footprint-way-of-importing-windows-service-data/350282 "2024-01-03T07:56:40Z")

</div>

Hello All, We are looking to import windows server service status (on or off etc) data into our ELK stack from client servers which currently have filebeat installed. Is there a way of doing this without installing met…

---

## [Identify the reasons of not active indexes](https://discuss.elastic.co/t/identify-the-reasons-of-not-active-indexes/350268)

<div class="topic-metadata">

**Author:** [@Clyo\_Michel\_Mayela\_R](https://discuss.elastic.co/u/Clyo_Michel_Mayela_R)\
**Replies:** 0\
**Last updated:** [January 3, 2024, 1:20am UTC](https://discuss.elastic.co/t/identify-the-reasons-of-not-active-indexes/350268 "2024-01-03T01:20:34Z")

</div>

Getting this error message "ElasticsearchException: not all primary shards of \[.geoip\_databases\] index are active" how to found the root case that is causing this problem?

---

## [Parent Circuit Breaking Exception](https://discuss.elastic.co/t/parent-circuit-breaking-exception/350165)

<div class="topic-metadata">

**Author:** [@Brad\_Baker](https://discuss.elastic.co/u/Brad_Baker)\
**Replies:** 3\
**Last updated:** [January 2, 2024, 10:01pm UTC](https://discuss.elastic.co/t/parent-circuit-breaking-exception/350165 "2024-01-02T22:01:10Z")

</div>

We setup some monitoring to watch for parent circuit breaker trips in Elasticsearch and its going off like crazy. What I am trying to figure out is how to determine what is causing it. From what I have read and understan…

---

## [Unable to do anything properly with ES](https://discuss.elastic.co/t/unable-to-do-anything-properly-with-es/350244)

<div class="topic-metadata">

**Author:** [@hich\_testone](https://discuss.elastic.co/u/hich_testone)\
**Replies:** 18\
**Last updated:** [January 2, 2024, 9:13pm UTC](https://discuss.elastic.co/t/unable-to-do-anything-properly-with-es/350244 "2024-01-02T21:13:19Z")

</div>

Dear All, I followed exactly the guide here to install ES :slight\_smile: But when I run : sudo /usr/share/elasticsearch/bin/elasticsearch-create-enrollment-token -s node I keep getting this error : ERROR: Failed to …

---

## [Updating Indexed Entities](https://discuss.elastic.co/t/updating-indexed-entities/348287)

<div class="topic-metadata">

**Author:** [@Muhammad\_namjas](https://discuss.elastic.co/u/Muhammad_namjas)\
**Replies:** 3\
**Last updated:** [January 2, 2024, 8:14pm UTC](https://discuss.elastic.co/t/updating-indexed-entities/348287 "2024-01-02T20:14:56Z")

</div>

I created a new entity connected to Hibernate Elastic Search and indexed it. Upon retrieving the indexed data, I noticed that updating the entity using the student ID resulted in deleting the existing data and re-inserti…

---

## [Elasticsearch query](https://discuss.elastic.co/t/elasticsearch-query/350260)

<div class="topic-metadata">

**Author:** [@Bibhudutta\_Mohanty](https://discuss.elastic.co/u/Bibhudutta_Mohanty)\
**Replies:** 0\
**Last updated:** [January 2, 2024, 7:13pm UTC](https://discuss.elastic.co/t/elasticsearch-query/350260 "2024-01-02T19:13:54Z")

</div>

I have a field called @editors in my index . It has multiple values like , i would like only show the last editor name in last\_editors field . I want to write a query where i can only fetch the the last editor name in e…

---

## [ElasticSearch Nested Search Analyzer not working](https://discuss.elastic.co/t/elasticsearch-nested-search-analyzer-not-working/350256)

<div class="topic-metadata">

**Author:** [@pasupathi-raja](https://discuss.elastic.co/u/pasupathi-raja)\
**Replies:** 2\
**Last updated:** [January 2, 2024, 4:57pm UTC](https://discuss.elastic.co/t/elasticsearch-nested-search-analyzer-not-working/350256 "2024-01-02T16:57:25Z")

</div>

Index Creation I'm creating index with nested property and assigning analyzers to it both index and search time as follows. PUT /test\_index\_pasu { "settings": { "analysis": { "analyzer": { "keyword\_…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=160)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=162)
