# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=162

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 163

---

## [Elasticsearch cluster resiliency and availability](https://discuss.elastic.co/t/elasticsearch-cluster-resiliency-and-availability/350033)

<div class="topic-metadata">

**Author:** [@artechkey](https://discuss.elastic.co/u/artechkey)\
**Replies:** 12\
**Last updated:** [January 2, 2024, 3:56pm UTC](https://discuss.elastic.co/t/elasticsearch-cluster-resiliency-and-availability/350033 "2024-01-02T15:56:48Z")

</div>

Hi, We are currently running ES on a 4 node cluster where 2 nodes are in DC 1 & 2 in DC 2. We have a third node in DC 1 with master-voting-only role. The n/w latency b/w DC 1 & DC 2 is negligible. DC 1 - 2 nodes (all r…

---

## [Index not found in Logs](https://discuss.elastic.co/t/index-not-found-in-logs/349828)

<div class="topic-metadata">

**Author:** [@anoman](https://discuss.elastic.co/u/anoman)\
**Replies:** 2\
**Last updated:** [January 2, 2024, 3:27pm UTC](https://discuss.elastic.co/t/index-not-found-in-logs/349828 "2024-01-02T15:27:28Z")

</div>

I have installed Microsoft Defender Endpoint integration to collect logs. The agent was installed properly and the other configuration. But If I go to Elastic Search -\> Discover and try to create a new data view, I can'…

---

## [Error: Limit of total fields \[1000\] has been exceeded but index limit is higher](https://discuss.elastic.co/t/error-limit-of-total-fields-1000-has-been-exceeded-but-index-limit-is-higher/350103)

<div class="topic-metadata">

**Author:** [@MColeman](https://discuss.elastic.co/u/MColeman)\
**Replies:** 7\
**Last updated:** [January 2, 2024, 3:00pm UTC](https://discuss.elastic.co/t/error-limit-of-total-fields-1000-has-been-exceeded-but-index-limit-is-higher/350103 "2024-01-02T15:00:37Z")

</div>

I'm re-indexing some data from our old cluster into a new one. I pre-created my index (logstash-2023.10.02) and changed the total field mappings to 4000, the same as the old index on the old host. If I look at the new i…

---

## [Elasticsearch performance testing](https://discuss.elastic.co/t/elasticsearch-performance-testing/350228)

<div class="topic-metadata">

**Author:** [@jaykb77](https://discuss.elastic.co/u/jaykb77)\
**Replies:** 1\
**Last updated:** [January 2, 2024, 2:55pm UTC](https://discuss.elastic.co/t/elasticsearch-performance-testing/350228 "2024-01-02T14:55:29Z")

</div>

Hi all, We are trying to come up with performance tests, stress tests etc to calculate throughput and identify bottlenecks in our elasticsearch cluster. We are using elasticsearch exporter to export metrics from the clu…

---

## [How list index and size using python](https://discuss.elastic.co/t/how-list-index-and-size-using-python/350235)

<div class="topic-metadata">

**Author:** [@pratik\_jain163](https://discuss.elastic.co/u/pratik_jain163)\
**Replies:** 2\
**Last updated:** [January 2, 2024, 2:35pm UTC](https://discuss.elastic.co/t/how-list-index-and-size-using-python/350235 "2024-01-02T14:35:19Z")

</div>

i tried to write one Python code for get ES index and size but it gave me a huge json output and I was not able to find an exact result. how we can do this. es.indices.stats(index=index)

---

## [Null pointer exception | co.elastic.clients.elasticsearch.\_types.InlineScript](https://discuss.elastic.co/t/null-pointer-exception-co-elastic-clients-elasticsearch-types-inlinescript/350122)

<div class="topic-metadata">

**Author:** [@ravneet21](https://discuss.elastic.co/u/ravneet21)\
**Replies:** 0\
**Last updated:** [December 29, 2023, 10:15am UTC](https://discuss.elastic.co/t/null-pointer-exception-co-elastic-clients-elasticsearch-types-inlinescript/350122 "2023-12-29T10:15:47Z")

</div>

After migration from Rest High Level Client 7.17.1 to Elastic Java API client 8.6.2, I am getting nullpointer exception in InlineScript creation if any key's value is passed as null. Earlier with HLRC, the null values we…

---

## [Certificate pinning in Elasticsearch](https://discuss.elastic.co/t/certificate-pinning-in-elasticsearch/350214)

<div class="topic-metadata">

**Author:** [@jaykb77](https://discuss.elastic.co/u/jaykb77)\
**Replies:** 1\
**Last updated:** [January 2, 2024, 9:55am UTC](https://discuss.elastic.co/t/certificate-pinning-in-elasticsearch/350214 "2024-01-02T09:55:54Z")

</div>

Hi, We are using Elasticsearch 7.17.0 and using azure storage blobs for snapshots. We recently received a general notification from azure about certificate pinning. I believe we do not have any such configuration tha…

---

## [Esrally creat index error,class\_cast\_exception](https://discuss.elastic.co/t/esrally-creat-index-error-class-cast-exception/350215)

<div class="topic-metadata">

**Author:** [@zhouxuanxuan](https://discuss.elastic.co/u/zhouxuanxuan)\
**Replies:** 0\
**Last updated:** [January 2, 2024, 9:19am UTC](https://discuss.elastic.co/t/esrally-creat-index-error-class-cast-exception/350215 "2024-01-02T09:19:44Z")

</div>

\[ERROR\] Cannot race. Error in load generator \[0\] Cannot run task \[create-index\]: Request returned an error. Error type: transport, Description: class\_cast\_exception ({'error': {'root\_cause': \[{'type': 'class\_cast\_except…

---

## [Elasticsearch 7.16 shard recovery slow](https://discuss.elastic.co/t/elasticsearch-7-16-shard-recovery-slow/349952)

<div class="topic-metadata">

**Author:** [@wangxiangyu](https://discuss.elastic.co/u/wangxiangyu)\
**Replies:** 6\
**Last updated:** [January 2, 2024, 8:51am UTC](https://discuss.elastic.co/t/elasticsearch-7-16-shard-recovery-slow/349952 "2024-01-02T08:51:47Z")

</div>

hi, The elasticsearch cluster has 6 hot node and 4 cold node. One cold node is removed caused by hardware failure. So lots of missing replica shards( about 20TB) began to recover. But I found the recovery process was v…

---

## [.NET 8 - ElasticsearchClientException: The client is unable to verify that the server is Elasticsearch due to an unsuccessful product check call](https://discuss.elastic.co/t/net-8-elasticsearchclientexception-the-client-is-unable-to-verify-that-the-server-is-elasticsearch-due-to-an-unsuccessful-product-check-call/350208)

<div class="topic-metadata">

**Author:** [@Urbancsik\_Gergely](https://discuss.elastic.co/u/Urbancsik_Gergely)\
**Replies:** 0\
**Last updated:** [January 2, 2024, 8:34am UTC](https://discuss.elastic.co/t/net-8-elasticsearchclientexception-the-client-is-unable-to-verify-that-the-server-is-elasticsearch-due-to-an-unsuccessful-product-check-call/350208 "2024-01-02T08:34:37Z")

</div>

Hello. We upgrade our application to .net 8, and and we also upgrade the latest NEST library: version: \<PackageReference Include="NEST" Version="7.17.5" /\> \<PackageReference Include="NEST.JsonNetSerializer" Version="7.…

---

## [Little help understanding a document query issue](https://discuss.elastic.co/t/little-help-understanding-a-document-query-issue/350198)

<div class="topic-metadata">

**Author:** [@Oscar\_Llerena](https://discuss.elastic.co/u/Oscar_Llerena)\
**Replies:** 0\
**Last updated:** [January 2, 2024, 7:29am UTC](https://discuss.elastic.co/t/little-help-understanding-a-document-query-issue/350198 "2024-01-02T07:29:47Z")

</div>

Hi everyone, happy new year! Can somebody please help me understanding the following issue? I have Elasticsearch (Elastic Defend) & Kibana in one server and Fleet in other separated. The monitoring agents are in a virt…

---

## [Where if anywhere does ES documentation explain about metadata, specifically index creation datetimes?](https://discuss.elastic.co/t/where-if-anywhere-does-es-documentation-explain-about-metadata-specifically-index-creation-datetimes/350185)

<div class="topic-metadata">

**Author:** [@mrodent](https://discuss.elastic.co/u/mrodent)\
**Replies:** 4\
**Last updated:** [January 1, 2024, 10:57pm UTC](https://discuss.elastic.co/t/where-if-anywhere-does-es-documentation-explain-about-metadata-specifically-index-creation-datetimes/350185 "2024-01-01T22:57:57Z")

</div>

This in an application context, not "human consumption". With a bit of searching I finally found this answer. The up-to-date (v. 8.11) documentation for this appears to be here, "cat indices API". But there it says "ca…

---

## [Date Column has some rows with NULL - strict\_date\_optional\_time causes Exception](https://discuss.elastic.co/t/date-column-has-some-rows-with-null-strict-date-optional-time-causes-exception/350164)

<div class="topic-metadata">

**Author:** [@Ethan777100](https://discuss.elastic.co/u/Ethan777100)\
**Replies:** 23\
**Last updated:** [January 1, 2024, 5:11pm UTC](https://discuss.elastic.co/t/date-column-has-some-rows-with-null-strict-date-optional-time-causes-exception/350164 "2024-01-01T17:11:46Z")

</div>

All this time, I use \[strict\_date\_optional\_time||yyyy-MM-dd HH:mm:ss.SSS||yyyy-MM-dd HH:mm:ss.SS||yyyy-MM-dd HH:mm:ss||yyyy-MM-dd HH:mm:ss.S\] To parse in columns with dates. Now, I have a csv file whose columns have ro…

---

## [Does Elasticsearch clients try to request to the node that has the primary shard of a specific doc?](https://discuss.elastic.co/t/does-elasticsearch-clients-try-to-request-to-the-node-that-has-the-primary-shard-of-a-specific-doc/350181)

<div class="topic-metadata">

**Author:** [@AmirrezaRiahi](https://discuss.elastic.co/u/AmirrezaRiahi)\
**Replies:** 3\
**Last updated:** [January 1, 2024, 3:49pm UTC](https://discuss.elastic.co/t/does-elasticsearch-clients-try-to-request-to-the-node-that-has-the-primary-shard-of-a-specific-doc/350181 "2024-01-01T15:49:50Z")

</div>

From my understanding, nodes only can perform write operations on documents if they own their primary shard. Therefore if we have 2 nodes A, B and A owns the primary shard of the doc D, if the client asks node B to modif…

---

## [Why data is inserting in index in delete phase, why not new index ... are we missing any configuration?](https://discuss.elastic.co/t/why-data-is-inserting-in-index-in-delete-phase-why-not-new-index-are-we-missing-any-configuration/350054)

<div class="topic-metadata">

**Author:** [@Shahzaib\_Khan](https://discuss.elastic.co/u/Shahzaib_Khan)\
**Replies:** 3\
**Last updated:** [January 1, 2024, 7:06am UTC](https://discuss.elastic.co/t/why-data-is-inserting-in-index-in-delete-phase-why-not-new-index-are-we-missing-any-configuration/350054 "2024-01-01T07:06:07Z")

</div>

I am facing an issue with Elasticsearch where, even after the rollover phase is successfully completed and a new index is created, data continues to be inserted into the old rollover index instead of the newly created in…

---

## [Elasticserach installation on linux preferences](https://discuss.elastic.co/t/elasticserach-installation-on-linux-preferences/350169)

<div class="topic-metadata">

**Author:** [@sahere37](https://discuss.elastic.co/u/sahere37)\
**Replies:** 0\
**Last updated:** [January 1, 2024, 5:45am UTC](https://discuss.elastic.co/t/elasticserach-installation-on-linux-preferences/350169 "2024-01-01T05:45:39Z")

</div>

in order to install the latest (8.11.1) elasticsearch cluster in a production environment (oracle linux based), which method of installation is better? rpm or zip/tar.gz? in each method which user can we use ? root or …

---

## [Unable to convert \[0.0\] to long](https://discuss.elastic.co/t/unable-to-convert-0-0-to-long/350031)

<div class="topic-metadata">

**Author:** [@Ethan777100](https://discuss.elastic.co/u/Ethan777100)\
**Replies:** 9\
**Last updated:** [January 1, 2024, 4:30am UTC](https://discuss.elastic.co/t/unable-to-convert-0-0-to-long/350031 "2024-01-01T04:30:11Z")

</div>

Been a while. Things have been smooth sailing for my other data, until this set here. I am not sure why I get this error when ingesting it. \[2023-12-27T16:46:33,099\]\[WARN \]\[logstash.outputs.elasticsearch\]\[main\]\[5612df4…

---

## [ when downgrading version 8.11 to a lower version. my datanodes did restore on version downgrade but starting elastic search the data on the new nodes was not found. Is there any way to restore this data?](https://discuss.elastic.co/t/when-downgrading-version-8-11-to-a-lower-version-my-datanodes-did-restore-on-version-downgrade-but-starting-elastic-search-the-data-on-the-new-nodes-was-not-found-is-there-any-way-to-restore-this-data/350114)

<div class="topic-metadata">

**Author:** [@Cody-Test](https://discuss.elastic.co/u/Cody-Test)\
**Replies:** 3\
**Last updated:** [December 31, 2023, 4:48pm UTC](https://discuss.elastic.co/t/when-downgrading-version-8-11-to-a-lower-version-my-datanodes-did-restore-on-version-downgrade-but-starting-elastic-search-the-data-on-the-new-nodes-was-not-found-is-there-any-way-to-restore-this-data/350114 "2023-12-31T16:48:33Z")

</div>

Hello friend, currently my lab tests elasticsearch when downgrading version 8.11 to a lower version. my datanodes did restore on version downgrade but starting Elasticsearch the data on the new nodes was not found. Is th…

---

## [ERROR: Failed to determine the health of the cluster. , with exit code 69](https://discuss.elastic.co/t/error-failed-to-determine-the-health-of-the-cluster-with-exit-code-69/350150)

<div class="topic-metadata">

**Author:** [@zeynepyz](https://discuss.elastic.co/u/zeynepyz)\
**Replies:** 5\
**Last updated:** [December 31, 2023, 3:18pm UTC](https://discuss.elastic.co/t/error-failed-to-determine-the-health-of-the-cluster-with-exit-code-69/350150 "2023-12-31T15:18:35Z")

</div>

In /usr/share/elasticsearch/bin file i run "sudo ./elasticsearch-create-enrollment-token --scope kibana" command and i get this output: 03:26:10.736 \[main\] WARN org.elasticsearch.common.ssl.DiagnosticTrustManager - fai…

---

## [BM25 score when do search in multi field](https://discuss.elastic.co/t/bm25-score-when-do-search-in-multi-field/350146)

<div class="topic-metadata">

**Author:** [@r1ckC139](https://discuss.elastic.co/u/r1ckC139)\
**Replies:** 1\
**Last updated:** [December 30, 2023, 2:14pm UTC](https://discuss.elastic.co/t/bm25-score-when-do-search-in-multi-field/350146 "2023-12-30T14:14:26Z")

</div>

es\_query = { "bool": { "must": \[ {"match": {"title": title\_text}}, {"match": {"year": year\_text}} \] } } when i do search 2 field match, how elasticsearch combine score of 2 match?

---

## [Help parsing custom nginx logs using Filebeat and Ingest Pipelines](https://discuss.elastic.co/t/help-parsing-custom-nginx-logs-using-filebeat-and-ingest-pipelines/349974)

<div class="topic-metadata">

**Author:** [@BDeveloper](https://discuss.elastic.co/u/BDeveloper)\
**Replies:** 17\
**Last updated:** [December 29, 2023, 7:09pm UTC](https://discuss.elastic.co/t/help-parsing-custom-nginx-logs-using-filebeat-and-ingest-pipelines/349974 "2023-12-29T19:09:18Z")

</div>

Hi, I am new to using ELK stack. I have custom logs for my nginx access.log files and I am needing help parsing them by using filebeat and ingest pipeline (Log Files -\> Filebeat -\> (Parse with Ingest Pipeline Parse) Ela…

---

## [How to replace multiple new lines with one in Ingest Pipeline gsub](https://discuss.elastic.co/t/how-to-replace-multiple-new-lines-with-one-in-ingest-pipeline-gsub/350127)

<div class="topic-metadata">

**Author:** [@Bowfish](https://discuss.elastic.co/u/Bowfish)\
**Replies:** 3\
**Last updated:** [December 29, 2023, 4:57pm UTC](https://discuss.elastic.co/t/how-to-replace-multiple-new-lines-with-one-in-ingest-pipeline-gsub/350127 "2023-12-29T16:57:34Z")

</div>

I want to replace multiple new lines (\\n\\n+) with one single new line (\\n) with a gsub processor in the ingest pipeline. This is my gsub processor: { "gsub": { "field": "attachment.content\_processed", …

---

## [Rolling upgrade from 7.14.2 to 7.17.16 no working](https://discuss.elastic.co/t/rolling-upgrade-from-7-14-2-to-7-17-16-no-working/350106)

<div class="topic-metadata">

**Author:** [@fory](https://discuss.elastic.co/u/fory)\
**Replies:** 4\
**Last updated:** [December 29, 2023, 1:46pm UTC](https://discuss.elastic.co/t/rolling-upgrade-from-7-14-2-to-7-17-16-no-working/350106 "2023-12-29T13:46:01Z")

</div>

According to 7.17.16 documentation, upgrading from 7.14.2 to 7.17.16 can be done by rolling upgrade. I have a two node cluster both are master eligible. Following the rolling upgrade documentation, I upgraded one of the…

---

## [Need help with ScriptedMetricAggregation in Elasticsearch v8.7](https://discuss.elastic.co/t/need-help-with-scriptedmetricaggregation-in-elasticsearch-v8-7/350088)

<div class="topic-metadata">

**Author:** [@Chetan\_Ramaiah](https://discuss.elastic.co/u/Chetan_Ramaiah)\
**Replies:** 2\
**Last updated:** [December 29, 2023, 9:58am UTC](https://discuss.elastic.co/t/need-help-with-scriptedmetricaggregation-in-elasticsearch-v8-7/350088 "2023-12-29T09:58:38Z")

</div>

Hello, I am working on migrating ES 6.8 java code to ES 8.7.1 rest API java. But, I am unable to understand or find how to write script metric aggregation with ES 8.7.1. Could you please guide me using the below code fr…

---

## [Need help on aggregation and sub aggregation with ES 8.7 rest api](https://discuss.elastic.co/t/need-help-on-aggregation-and-sub-aggregation-with-es-8-7-rest-api/350093)

<div class="topic-metadata">

**Author:** [@Chetan\_Ramaiah](https://discuss.elastic.co/u/Chetan_Ramaiah)\
**Replies:** 0\
**Last updated:** [December 28, 2023, 4:59pm UTC](https://discuss.elastic.co/t/need-help-on-aggregation-and-sub-aggregation-with-es-8-7-rest-api/350093 "2023-12-28T16:59:01Z")

</div>

Hello, I am working on migrating ES 6.8 java code to ES 8.7 rest api java. While working on aggregation, I am able to construct aggregation layer but not as per the required format. ----- \*\*expected result\*\* ----- "a…

---

## [SearchPhaseExecutionException with no message or reason](https://discuss.elastic.co/t/searchphaseexecutionexception-with-no-message-or-reason/350076)

<div class="topic-metadata">

**Author:** [@Arraying](https://discuss.elastic.co/u/Arraying)\
**Replies:** 0\
**Last updated:** [December 28, 2023, 12:24pm UTC](https://discuss.elastic.co/t/searchphaseexecutionexception-with-no-message-or-reason/350076 "2023-12-28T12:24:41Z")

</div>

Hi, I'm running Elasticsearch in Docker and I'm running into an org.elasticsearch.action.search.SearchPhaseExecutionException which does not provide me with an error message. Prior to this, my cluster health changes from…

---

## [Create Alert from query](https://discuss.elastic.co/t/create-alert-from-query/350065)

<div class="topic-metadata">

**Author:** [@cperzrt10](https://discuss.elastic.co/u/cperzrt10)\
**Replies:** 0\
**Last updated:** [December 28, 2023, 9:45am UTC](https://discuss.elastic.co/t/create-alert-from-query/350065 "2023-12-28T09:45:54Z")

</div>

Hi, I'm trying to create an alert from a query that returns theese data. The query GET data/\_search { "aggs": { "0": { "terms": { "field": "uuid.keyword", "order": { "\_key": "desc"…

---

## [Elasticsearch basic license limitation on the number of nodes](https://discuss.elastic.co/t/elasticsearch-basic-license-limitation-on-the-number-of-nodes/350058)

<div class="topic-metadata">

**Author:** [@basiltitus](https://discuss.elastic.co/u/basiltitus)\
**Replies:** 1\
**Last updated:** [December 28, 2023, 9:05am UTC](https://discuss.elastic.co/t/elasticsearch-basic-license-limitation-on-the-number-of-nodes/350058 "2023-12-28T09:05:04Z")

</div>

Hi, We are using ELK as a single node cluster with Kibana and I'd been searching if there any limitation on the number of nodes for Elasticsearch free version. But i am unable to find information on these. Does ES fre…

---

## [Elasticsearch ヒープメモリ使用量増加に関する質問](https://discuss.elastic.co/t/elasticsearch/350055)

<div class="topic-metadata">

**Author:** [@yuma\_n](https://discuss.elastic.co/u/yuma_n)\
**Replies:** 0\
**Last updated:** [December 28, 2023, 8:27am UTC](https://discuss.elastic.co/t/elasticsearch/350055 "2023-12-28T08:27:23Z")

</div>

私がElasticsearchを使用している環境では、1日ごとにシャードが増加します。Logstashのoutput設定で以下のようにindexを作成しているからだと思われます。 output { elasticsearch { hosts =\> \["\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*"\] cacert =\> '\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*' user =\> "\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*" pas…

---

## [Elasticsearch JAVA API Client version 8 upsert Request](https://discuss.elastic.co/t/elasticsearch-java-api-client-version-8-upsert-request/350047)

<div class="topic-metadata">

**Author:** [@durgesh\_dp](https://discuss.elastic.co/u/durgesh_dp)\
**Replies:** 1\
**Last updated:** [December 28, 2023, 6:01am UTC](https://discuss.elastic.co/t/elasticsearch-java-api-client-version-8-upsert-request/350047 "2023-12-28T06:01:40Z")

</div>

I am doing a migration from version 7 which is deprecated to version 8 java api client , but there is no documentation regarding upsert in version 8 , i have to write a updateRequest to update a document if it exists and…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=161)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=163)
