# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=163

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 164

---

## [Chunking large documents using HTML during ingest?](https://discuss.elastic.co/t/chunking-large-documents-using-html-during-ingest/350039)

<div class="topic-metadata">

**Author:** [@mmaccou](https://discuss.elastic.co/u/mmaccou)\
**Replies:** 0\
**Last updated:** [December 28, 2023, 1:51am UTC](https://discuss.elastic.co/t/chunking-large-documents-using-html-during-ingest/350039 "2023-12-28T01:51:02Z")

</div>

I recently game across this article that talks about a strategy to chunk large documents by breaking it up at the sentence level. Is it possible to create a script using HTML so chunking can occur first at the header lev…

---

## [Elasticsearch cloud does not receive logs from Serilog](https://discuss.elastic.co/t/elasticsearch-cloud-does-not-receive-logs-from-serilog/349452)

<div class="topic-metadata">

**Author:** [@Zsombor\_Veres-Lakos](https://discuss.elastic.co/u/Zsombor_Veres-Lakos)\
**Replies:** 0\
**Last updated:** [December 15, 2023, 12:47pm UTC](https://discuss.elastic.co/t/elasticsearch-cloud-does-not-receive-logs-from-serilog/349452 "2023-12-15T12:47:02Z")

</div>

Yesterday I was trying to set minimal privileges for Apikey, so I built a dummy logging application. I used that application from 10:00-19:00 and then the Elastic search stopped showing logs. Since yesterday 19:00 I am …

---

## [How can I search for the latest data entered in the indexes? ](https://discuss.elastic.co/t/how-can-i-search-for-the-latest-data-entered-in-the-indexes/349972)

<div class="topic-metadata">

**Author:** [@deep1](https://discuss.elastic.co/u/deep1)\
**Replies:** 17\
**Last updated:** [December 27, 2023, 5:32pm UTC](https://discuss.elastic.co/t/how-can-i-search-for-the-latest-data-entered-in-the-indexes/349972 "2023-12-27T17:32:15Z")

</div>

For example, I want to search in 100,000 documents from each index, and it is not possible to add to that, and they are first loaded into the cache, then only this data is searched

---

## [Gather Data from Yesterday Until Today](https://discuss.elastic.co/t/gather-data-from-yesterday-until-today/349740)

<div class="topic-metadata">

**Author:** [@hi\_xavier](https://discuss.elastic.co/u/hi_xavier)\
**Replies:** 2\
**Last updated:** [December 27, 2023, 4:19pm UTC](https://discuss.elastic.co/t/gather-data-from-yesterday-until-today/349740 "2023-12-27T16:19:48Z")

</div>

Hello, I'm currently using the elk api to gather data between yesterday and today (12/19 @ 00:00:000 -- 12/20@00:00:000) Would this be the equivalent of that using a range query? "range": { "timestamp": { …

---

## [Different results of aggregation query on same version](https://discuss.elastic.co/t/different-results-of-aggregation-query-on-same-version/349872)

<div class="topic-metadata">

**Author:** [@apari](https://discuss.elastic.co/u/apari)\
**Replies:** 1\
**Last updated:** [December 27, 2023, 3:17pm UTC](https://discuss.elastic.co/t/different-results-of-aggregation-query-on-same-version/349872 "2023-12-27T15:17:24Z")

</div>

I am running the following query on multiple servers, same build (same hash, build date, and version number) of ES. 7.16.2 { "size": 0, "query": { "terms": { "FileFeedID": \[ // Some values …

---

## [Removing master node permanently](https://discuss.elastic.co/t/removing-master-node-permanently/350002)

<div class="topic-metadata">

**Author:** [@artechkey](https://discuss.elastic.co/u/artechkey)\
**Replies:** 4\
**Last updated:** [December 27, 2023, 2:31pm UTC](https://discuss.elastic.co/t/removing-master-node-permanently/350002 "2023-12-27T14:31:14Z")

</div>

Hi, We currently have a 2 node + master-voting only node cluster. We are expanding the cluster by adding 3 more nodes to it. As part of the expansion, we want to designate one of the new nodes as a master and take out t…

---

## [Optimizing Elasticsearch Snapshot Recovery for Node Disk Space Utilization](https://discuss.elastic.co/t/optimizing-elasticsearch-snapshot-recovery-for-node-disk-space-utilization/350013)

<div class="topic-metadata">

**Author:** [@jakub0011](https://discuss.elastic.co/u/jakub0011)\
**Replies:** 1\
**Last updated:** [December 27, 2023, 2:15pm UTC](https://discuss.elastic.co/t/optimizing-elasticsearch-snapshot-recovery-for-node-disk-space-utilization/350013 "2023-12-27T14:15:01Z")

</div>

I'm seeking advice on optimizing the snapshot recovery process in our Elasticsearch cluster, which consists of 8 nodes. Currently, when recovering various snapshots, the indices are restored to nodes based on the percent…

---

## [Dropdown select element not effect to essql while select value](https://discuss.elastic.co/t/dropdown-select-element-not-effect-to-essql-while-select-value/349995)

<div class="topic-metadata">

**Author:** [@Dy\_Vanrith](https://discuss.elastic.co/u/Dy_Vanrith)\
**Replies:** 0\
**Last updated:** [December 27, 2023, 4:42am UTC](https://discuss.elastic.co/t/dropdown-select-element-not-effect-to-essql-while-select-value/349995 "2023-12-27T04:42:27Z")

</div>

My expression dropdown element esdocs index="2023.12.22" fields="startAdminDate" | dropdownControl valueColumn="startAdminDate" filterColumn="startAdminDate" filterGroup="VTM" | render table element filters group="VT…

---

## [ELK Stack: Logstash shows that it's receiving log entries from Filebeat, but Elasticsearch is not creating my index](https://discuss.elastic.co/t/elk-stack-logstash-shows-that-its-receiving-log-entries-from-filebeat-but-elasticsearch-is-not-creating-my-index/349826)

<div class="topic-metadata">

**Author:** [@BDeveloper](https://discuss.elastic.co/u/BDeveloper)\
**Replies:** 8\
**Last updated:** [December 26, 2023, 4:40pm UTC](https://discuss.elastic.co/t/elk-stack-logstash-shows-that-its-receiving-log-entries-from-filebeat-but-elasticsearch-is-not-creating-my-index/349826 "2023-12-26T16:40:57Z")

</div>

I am new to the ELK stack and I wanted to try and test it out to see if I wanted to use it. I have elasticsearch, kibana, and logstash installed on one virtual machine and I have filebeat and nginx installed on another v…

---

## [Display the last 100k documents](https://discuss.elastic.co/t/display-the-last-100k-documents/349961)

<div class="topic-metadata">

**Author:** [@1337](https://discuss.elastic.co/u/1337)\
**Replies:** 3\
**Last updated:** [December 26, 2023, 3:58pm UTC](https://discuss.elastic.co/t/display-the-last-100k-documents/349961 "2023-12-26T15:58:24Z")

</div>

I want to display the last 100k documents for all indices. Each index with the last 100k

---

## [I want to search only the last data entered. That is, the search is in only 100,000 per index you have, I want to search, these data are loaded into the cache and are searched only ](https://discuss.elastic.co/t/i-want-to-search-only-the-last-data-entered-that-is-the-search-is-in-only-100-000-per-index-you-have-i-want-to-search-these-data-are-loaded-into-the-cache-and-are-searched-only/349970)

<div class="topic-metadata">

**Author:** [@deep111](https://discuss.elastic.co/u/deep111)\
**Replies:** 1\
**Last updated:** [December 26, 2023, 3:56pm UTC](https://discuss.elastic.co/t/i-want-to-search-only-the-last-data-entered-that-is-the-search-is-in-only-100-000-per-index-you-have-i-want-to-search-these-data-are-loaded-into-the-cache-and-are-searched-only/349970 "2023-12-26T15:56:26Z")

</div>

Json format

---

## [Index Life Cycle Management](https://discuss.elastic.co/t/index-life-cycle-management/349964)

<div class="topic-metadata">

**Author:** [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Replies:** 3\
**Last updated:** [December 26, 2023, 3:10pm UTC](https://discuss.elastic.co/t/index-life-cycle-management/349964 "2023-12-26T15:10:24Z")

</div>

HI Team, Can Index rollover happened on the basis of field value of attribute instead of calendar date. Thanks, Debasis

---

## [Elastic Agent](https://discuss.elastic.co/t/elastic-agent/349925)

<div class="topic-metadata">

**Author:** [@Phyo\_WaThone\_Win](https://discuss.elastic.co/u/Phyo_WaThone_Win)\
**Replies:** 1\
**Last updated:** [December 26, 2023, 12:55pm UTC](https://discuss.elastic.co/t/elastic-agent/349925 "2023-12-26T12:55:16Z")

</div>

Dear team, In my current organization have at least 5000 employees. So, when I use the ELK for security information and event management, is it ok for all employees? Thanks and regards,

---

## [Can not create a custom normalizer using char filter \[html\_strip\]](https://discuss.elastic.co/t/can-not-create-a-custom-normalizer-using-char-filter-html-strip/349939)

<div class="topic-metadata">

**Author:** [@voaix](https://discuss.elastic.co/u/voaix)\
**Replies:** 1\
**Last updated:** [December 26, 2023, 12:45pm UTC](https://discuss.elastic.co/t/can-not-create-a-custom-normalizer-using-char-filter-html-strip/349939 "2023-12-26T12:45:20Z")

</div>

Hello, I try to save the custom normalizer as part of composite template. Receiving below error: illegal\_argument\_exception', 'Custom normalizer \[lower\_normalizer\] may not use char filter \[html\_strip\] Normalizer is de…

---

## [Using must query in filter section of DSl elastic](https://discuss.elastic.co/t/using-must-query-in-filter-section-of-dsl-elastic/349953)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 1\
**Last updated:** [December 26, 2023, 12:20pm UTC](https://discuss.elastic.co/t/using-must-query-in-filter-section-of-dsl-elastic/349953 "2023-12-26T12:20:25Z")

</div>

GET rds\_database-\*/\_search { "\_source": \["failure\_error\_text"\], "query": { "bool": { "filter": \[ { "must":\[ { "term":{ "status.keyword":"F" …

---

## [Using toJson in big search template](https://discuss.elastic.co/t/using-tojson-in-big-search-template/349951)

<div class="topic-metadata">

**Author:** [@bertie](https://discuss.elastic.co/u/bertie)\
**Replies:** 0\
**Last updated:** [December 26, 2023, 11:51am UTC](https://discuss.elastic.co/t/using-tojson-in-big-search-template/349951 "2023-12-26T11:51:18Z")

</div>

I cannot figure out how I should use the toJson when prototyping templates in the kibana dev console. If I simply use it like others mustache functions like the following example Kibana simply classifies it as a "bad str…

---

## [Sort is incorrect](https://discuss.elastic.co/t/sort-is-incorrect/349906)

<div class="topic-metadata">

**Author:** [@Binh\_Phan\_Thanh](https://discuss.elastic.co/u/Binh_Phan_Thanh)\
**Replies:** 12\
**Last updated:** [December 26, 2023, 10:45am UTC](https://discuss.elastic.co/t/sort-is-incorrect/349906 "2023-12-26T10:45:04Z")

</div>

My mapping: { "my\_index": { "mappings": { "properties": { "attributesRecommend": { "type": "text", "fields": { "keyword": { "type": "keyword", …

---

## [Add another one sorting to lift 3 docs to positions 3,4,5](https://discuss.elastic.co/t/add-another-one-sorting-to-lift-3-docs-to-positions-3-4-5/349918)

<div class="topic-metadata">

**Author:** [@sahkdevel](https://discuss.elastic.co/u/sahkdevel)\
**Replies:** 2\
**Last updated:** [December 26, 2023, 8:49am UTC](https://discuss.elastic.co/t/add-another-one-sorting-to-lift-3-docs-to-positions-3-4-5/349918 "2023-12-26T08:49:48Z")

</div>

I have a query with several sortings. Here is the sorting part: "sort": \[ "isHistorical", "\_score", { "\_script": { "type": "number", "script": { …

---

## [Elasticsearch Java Client Aggregation Exception - all shards failed](https://discuss.elastic.co/t/elasticsearch-java-client-aggregation-exception-all-shards-failed/349860)

<div class="topic-metadata">

**Author:** [@bharath.krishn2](https://discuss.elastic.co/u/bharath.krishn2)\
**Replies:** 7\
**Last updated:** [December 26, 2023, 7:10am UTC](https://discuss.elastic.co/t/elasticsearch-java-client-aggregation-exception-all-shards-failed/349860 "2023-12-26T07:10:28Z")

</div>

Hi, I'm trying to create an aggregation on Elasticsearch through Java client using this below link But I'm getting the exception: co.elastic.clients.elasticsearch.\_types.ElasticsearchException: \[es/search\] failed: \[…

---

## [I can not login elastic](https://discuss.elastic.co/t/i-can-not-login-elastic/348450)

<div class="topic-metadata">

**Author:** [@miladmohabati](https://discuss.elastic.co/u/miladmohabati)\
**Replies:** 32\
**Last updated:** [December 25, 2023, 8:10pm UTC](https://discuss.elastic.co/t/i-can-not-login-elastic/348450 "2023-12-25T20:10:10Z")

</div>

hi my disk space is full and I can not login to elastic web how can I clear cache disk plz help me

---

## [Elasticsearch Aggregations Pagination](https://discuss.elastic.co/t/elasticsearch-aggregations-pagination/349915)

<div class="topic-metadata">

**Author:** [@Azizi\_BESSEM](https://discuss.elastic.co/u/Azizi_BESSEM)\
**Replies:** 0\
**Last updated:** [December 25, 2023, 9:54am UTC](https://discuss.elastic.co/t/elasticsearch-aggregations-pagination/349915 "2023-12-25T09:54:21Z")

</div>

Dear Elasticsearch Team, I hope this message finds you well. I am currently working with an alert index in Elasticsearch, which contains information such as "device-ref" and "alert type." My goal is to retrieve the late…

---

## [Change duration after which warning "Datafeed has been retrieving no data for a while" appears](https://discuss.elastic.co/t/change-duration-after-which-warning-datafeed-has-been-retrieving-no-data-for-a-while-appears/348501)

<div class="topic-metadata">

**Author:** [@marmai16](https://discuss.elastic.co/u/marmai16)\
**Replies:** 1\
**Last updated:** [December 24, 2023, 2:36pm UTC](https://discuss.elastic.co/t/change-duration-after-which-warning-datafeed-has-been-retrieving-no-data-for-a-while-appears/348501 "2023-12-24T14:36:53Z")

</div>

Hello everyone, is it possible to change the duration, after which the warning "Datafeed has been retrieving no data for a while" appears relating to an anomaly detection job? It is perfectly fine, that the datafeed oc…

---

## [.ds indices creating automatically in our env](https://discuss.elastic.co/t/ds-indices-creating-automatically-in-our-env/349861)

<div class="topic-metadata">

**Author:** [@Siva\_Karan](https://discuss.elastic.co/u/Siva_Karan)\
**Replies:** 1\
**Last updated:** [December 24, 2023, 2:24pm UTC](https://discuss.elastic.co/t/ds-indices-creating-automatically-in-our-env/349861 "2023-12-24T14:24:59Z")

</div>

Hi Team, After upgrdation of elasticearch from 7.3.2 to 7.17.16 .ds\* index automatically creating like below .ds-ilm-history-5-2023.12.18-000002 .ds-.logs-deprecation.elasticsearch-default-2023.11.18-000001 How to st…

---

## [Restoring the snapshot in our local cluster](https://discuss.elastic.co/t/restoring-the-snapshot-in-our-local-cluster/349845)

<div class="topic-metadata">

**Author:** [@Shashank\_Nagumantri](https://discuss.elastic.co/u/Shashank_Nagumantri)\
**Replies:** 3\
**Last updated:** [December 24, 2023, 10:31am UTC](https://discuss.elastic.co/t/restoring-the-snapshot-in-our-local-cluster/349845 "2023-12-24T10:31:58Z")

</div>

So, I have an elastic cloud account in which I have created dashboards and stored indices to work with. But now I have installed Elastic Search and Kibana in my local system and I don't want to use the cloud anymore. So,…

---

## [Invalid or malformed certificate using caFingerprint](https://discuss.elastic.co/t/invalid-or-malformed-certificate-using-cafingerprint/349754)

<div class="topic-metadata">

**Author:** [@joe\_recra](https://discuss.elastic.co/u/joe_recra)\
**Replies:** 11\
**Last updated:** [December 23, 2023, 12:54am UTC](https://discuss.elastic.co/t/invalid-or-malformed-certificate-using-cafingerprint/349754 "2023-12-23T00:54:34Z")

</div>

hi, I generated a CA certificate using: ./elasticsearch-certutil ca --pem --out /certs/ca.zip and then generated a cert using: ./bin/elasticsearch-certutil cert \\ --out /var/snap/amazon-ssm-agent/7628/elasticsearch-8…

---

## [Migrating from Nest to Elastic.Client.Elasticsearch QueryContainer not longer available](https://discuss.elastic.co/t/migrating-from-nest-to-elastic-client-elasticsearch-querycontainer-not-longer-available/349864)

<div class="topic-metadata">

**Author:** [@ricocsharp](https://discuss.elastic.co/u/ricocsharp)\
**Replies:** 0\
**Last updated:** [December 22, 2023, 3:17pm UTC](https://discuss.elastic.co/t/migrating-from-nest-to-elastic-client-elasticsearch-querycontainer-not-longer-available/349864 "2023-12-22T15:17:16Z")

</div>

I’m rewriting our code for the new Elastic.Client.Elasticsearch and I’m trying to find some code examples how to do that. here I'm letting an example of code to be converted, the main problem is that QueryContainer is n…

---

## [Failed to indices:data/write/bulk\[s\] on replica because of Netty4TcpChannel / CompositeBytesReference more than 2GB](https://discuss.elastic.co/t/failed-to-indices-data-write-bulk-s-on-replica-because-of-netty4tcpchannel-compositebytesreference-more-than-2gb/349797)

<div class="topic-metadata">

**Author:** [@Martin\_Berlin](https://discuss.elastic.co/u/Martin_Berlin)\
**Replies:** 5\
**Last updated:** [December 22, 2023, 3:11pm UTC](https://discuss.elastic.co/t/failed-to-indices-data-write-bulk-s-on-replica-because-of-netty4tcpchannel-compositebytesreference-more-than-2gb/349797 "2023-12-22T15:11:59Z")

</div>

While Indexing to our Cluster sometimes this error occures turning the cluster in red & yellow state: One node is trying to "perform indices:data/write/bulk\[s\] on replica" on another node but fails because of "exception…

---

## [Challenges while migrating elasticsearch client 6.8 to 8.7 (is mandatory)](https://discuss.elastic.co/t/challenges-while-migrating-elasticsearch-client-6-8-to-8-7-is-mandatory/349856)

<div class="topic-metadata">

**Author:** [@Chetan\_Ramaiah](https://discuss.elastic.co/u/Chetan_Ramaiah)\
**Replies:** 0\
**Last updated:** [December 22, 2023, 1:36pm UTC](https://discuss.elastic.co/t/challenges-while-migrating-elasticsearch-client-6-8-to-8-7-is-mandatory/349856 "2023-12-22T13:36:39Z")

</div>

Hello, Currently, I am in the midst of transitioning from Elasticsearch HLRC 6.8 to Elasticsearch REST API Java Client 8.7 within a Spring Boot application. This migration aligns with the broader upgrade of the Spring v…

---

## [Disk usage grows indefinitely over time](https://discuss.elastic.co/t/disk-usage-grows-indefinitely-over-time/349751)

<div class="topic-metadata">

**Author:** [@Tommaso\_Parisi](https://discuss.elastic.co/u/Tommaso_Parisi)\
**Replies:** 2\
**Last updated:** [December 22, 2023, 1:29pm UTC](https://discuss.elastic.co/t/disk-usage-grows-indefinitely-over-time/349751 "2023-12-22T13:29:14Z")

</div>

Hello, as you see in the screenshot above the disk usage of my index grows indefinitely over time. If I close the index and then reopen it the usage drops, as you can see from the graph. I did a \_close followed by a…

---

## [co.elastic.clients.elasticsearch.core.BulkRequest does not work against the Elasticsearch 8.11](https://discuss.elastic.co/t/co-elastic-clients-elasticsearch-core-bulkrequest-does-not-work-against-the-elasticsearch-8-11/349769)

<div class="topic-metadata">

**Author:** [@Gegata](https://discuss.elastic.co/u/Gegata)\
**Replies:** 6\
**Last updated:** [December 22, 2023, 12:30pm UTC](https://discuss.elastic.co/t/co-elastic-clients-elasticsearch-core-bulkrequest-does-not-work-against-the-elasticsearch-8-11/349769 "2023-12-22T12:30:29Z")

</div>

The issue: After the upgrade of our Elasticsearch server from version 8.6 to version 8.11 one of our services stopped working. The following errors we are receiving on this BulkRequest: POST /\_bulk \[{"update":{"\_id":"…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=162)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=164)
