# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=165

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 166

---

## [How to mock handlers for elastic search client v8.11.0](https://discuss.elastic.co/t/how-to-mock-handlers-for-elastic-search-client-v8-11-0/349614)

<div class="topic-metadata">

**Author:** [@yoss\_fazwaz](https://discuss.elastic.co/u/yoss_fazwaz)\
**Replies:** 1\
**Last updated:** [December 19, 2023, 5:30am UTC](https://discuss.elastic.co/t/how-to-mock-handlers-for-elastic-search-client-v8-11-0/349614 "2023-12-19T05:30:56Z")

</div>

Hi, guys, I have updated my Elasticsearch client from V7 to V8, and it seems that the setHandler is removed. I have no idea how to set it in version 8.

---

## [Should I deploy elasticsearch in docker on one machine?](https://discuss.elastic.co/t/should-i-deploy-elasticsearch-in-docker-on-one-machine/349115)

<div class="topic-metadata">

**Author:** [@sigmastar](https://discuss.elastic.co/u/sigmastar)\
**Replies:** 13\
**Last updated:** [December 19, 2023, 2:06am UTC](https://discuss.elastic.co/t/should-i-deploy-elasticsearch-in-docker-on-one-machine/349115 "2023-12-19T02:06:57Z")

</div>

I wanna achive the best performance for Elasticsearch on a single machine. But right now, I'm running three Elasticsearch instance in docker on only one machine. Shoud I keep this for better performance or I should deplo…

---

## [Issue in Advanced Sync Rules for JOIN Query](https://discuss.elastic.co/t/issue-in-advanced-sync-rules-for-join-query/349605)

<div class="topic-metadata">

**Author:** [@aisyaharifin](https://discuss.elastic.co/u/aisyaharifin)\
**Replies:** 0\
**Last updated:** [December 19, 2023, 1:47am UTC](https://discuss.elastic.co/t/issue-in-advanced-sync-rules-for-join-query/349605 "2023-12-19T01:47:12Z")

</div>

Hi Elastic, I have a question to ask where I've encountered issue with the Advanced Sync Rules Query : So I have an application lets call it myStaff, where I've been pulling multiple tables from the db using Microso…

---

## [Validation Failed: 1: this action would add \[8\] total shards, but this cluster currently has \[3997\]/\[4000\] maximum shards open](https://discuss.elastic.co/t/validation-failed-1-this-action-would-add-8-total-shards-but-this-cluster-currently-has-3997-4000-maximum-shards-open/349527)

<div class="topic-metadata">

**Author:** [@HyebinHong](https://discuss.elastic.co/u/HyebinHong)\
**Replies:** 5\
**Last updated:** [December 18, 2023, 11:12pm UTC](https://discuss.elastic.co/t/validation-failed-1-this-action-would-add-8-total-shards-but-this-cluster-currently-has-3997-4000-maximum-shards-open/349527 "2023-12-18T23:12:26Z")

</div>

Hello, Elastic! I'm facing the trouble while indexing data. I run both ES 8.11 and OpenSearch 2.11 but both have same issues. Please help me. I found out my shards had reached the maximum(1000 shards per nodes). My da…

---

## [Secure ELK Stack with cloudflare wildcard SSL Failing on an ubuntu setup](https://discuss.elastic.co/t/secure-elk-stack-with-cloudflare-wildcard-ssl-failing-on-an-ubuntu-setup/349597)

<div class="topic-metadata">

**Author:** [@gurungo\_lovemore](https://discuss.elastic.co/u/gurungo_lovemore)\
**Replies:** 0\
**Last updated:** [December 18, 2023, 8:58pm UTC](https://discuss.elastic.co/t/secure-elk-stack-with-cloudflare-wildcard-ssl-failing-on-an-ubuntu-setup/349597 "2023-12-18T20:58:57Z")

</div>

I have a cloudflare wildcard ssl for my organization that i have configured on my elasticsearch and Kibana as follows: ''''''''' Elasticsearch # Enable security features xpack.security.enabled: true xpack.security.en…

---

## [Issue while running a pipeline](https://discuss.elastic.co/t/issue-while-running-a-pipeline/347650)

<div class="topic-metadata">

**Author:** [@Manasa4](https://discuss.elastic.co/u/Manasa4)\
**Replies:** 1\
**Last updated:** [December 18, 2023, 10:34pm UTC](https://discuss.elastic.co/t/issue-while-running-a-pipeline/347650 "2023-12-18T22:34:50Z")

</div>

Hi Team, I'm trying to run elser and ner pipelines through the reindexing and I'm having the following error : pipeline with id \[elser\_pipeline\_peopleagg\] could not be loaded, caused by \[org.elasticsearch.Elasticsearch…

---

## [Enrich table size](https://discuss.elastic.co/t/enrich-table-size/349600)

<div class="topic-metadata">

**Author:** [@lkw](https://discuss.elastic.co/u/lkw)\
**Replies:** 1\
**Last updated:** [December 18, 2023, 10:33pm UTC](https://discuss.elastic.co/t/enrich-table-size/349600 "2023-12-18T22:33:32Z")

</div>

I am ingesting time-series data and want to enrich it. But my enrich table could be quite large. Are there any rules of thumb regarding the size an index used for enrich in an ingress pipeline can be? Is 10k documents …

---

## [ES 8.8.2 high query latency](https://discuss.elastic.co/t/es-8-8-2-high-query-latency/349191)

<div class="topic-metadata">

**Author:** [@darshanypatel](https://discuss.elastic.co/u/darshanypatel)\
**Replies:** 3\
**Last updated:** [December 18, 2023, 10:19pm UTC](https://discuss.elastic.co/t/es-8-8-2-high-query-latency/349191 "2023-12-18T22:19:42Z")

</div>

I am encountering degraded query latency in v8. We are upgrading our cluster from 7.16.2 to 8.8.2 by standing up a new duplicate cluster with the new version and reindexing the data to it. The latency is 500ms to several…

---

## [Elasticsearch Query Multiple Must Nots](https://discuss.elastic.co/t/elasticsearch-query-multiple-must-nots/349570)

<div class="topic-metadata">

**Author:** [@Elk\_huh](https://discuss.elastic.co/u/Elk_huh)\
**Replies:** 7\
**Last updated:** [December 18, 2023, 7:28pm UTC](https://discuss.elastic.co/t/elasticsearch-query-multiple-must-nots/349570 "2023-12-18T19:28:37Z")

</div>

Is it possible to have 2 different must not query strings across two different fields I have this but it doesnt let me have 2 query strings GET winevents/\_search { "query": { "bool": { "must": \[ { …

---

## [OIDC without TLS](https://discuss.elastic.co/t/oidc-without-tls/349580)

<div class="topic-metadata">

**Author:** [@Jo\_han](https://discuss.elastic.co/u/Jo_han)\
**Replies:** 0\
**Last updated:** [December 18, 2023, 4:39pm UTC](https://discuss.elastic.co/t/oidc-without-tls/349580 "2023-12-18T16:39:01Z")

</div>

Hello, I am deploying ECK in an on-premise Kubernetes cluster with Istio installed. We drew a security perimeter at our gateway. Meaning all the services are only reachable through the gateway, where TLS and authentica…

---

## [Massive performance degradation when terms filter has over 16 values?](https://discuss.elastic.co/t/massive-performance-degradation-when-terms-filter-has-over-16-values/349106)

<div class="topic-metadata">

**Author:** [@elastic\_dude](https://discuss.elastic.co/u/elastic_dude)\
**Replies:** 9\
**Last updated:** [December 18, 2023, 4:19pm UTC](https://discuss.elastic.co/t/massive-performance-degradation-when-terms-filter-has-over-16-values/349106 "2023-12-18T16:19:50Z")

</div>

Came across some odd behavior. We have a query that performs in the tens of milliseconds until we go over 16 values in our terms filter. When 17 or more are included the performance degrades by 15-20 multiples. Here is …

---

## [Index template - settings](https://discuss.elastic.co/t/index-template-settings/349568)

<div class="topic-metadata">

**Author:** [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Replies:** 0\
**Last updated:** [December 18, 2023, 2:56pm UTC](https://discuss.elastic.co/t/index-template-settings/349568 "2023-12-18T14:56:12Z")

</div>

Hi All, I set up ILM for a particular index pattern. After applying this when I check index settings I see the following output: GET abc-90010-2023.12.18/\_settings { "abc-90010-2023.12.18": { "settings": { …

---

## [Runtime script: access list of fields](https://discuss.elastic.co/t/runtime-script-access-list-of-fields/349561)

<div class="topic-metadata">

**Author:** [@dao](https://discuss.elastic.co/u/dao)\
**Replies:** 1\
**Last updated:** [December 18, 2023, 2:44pm UTC](https://discuss.elastic.co/t/runtime-script-access-list-of-fields/349561 "2023-12-18T14:44:51Z")

</div>

hello, I try to create a field that is an array of strings. Each string is the name of a field example: I have docs like this: { a: 1, b:2, toto: 'processed', tata:'processed' } I want to create a field that will be…

---

## [Help needed for certificate configuration](https://discuss.elastic.co/t/help-needed-for-certificate-configuration/349194)

<div class="topic-metadata">

**Author:** [@litronics](https://discuss.elastic.co/u/litronics)\
**Replies:** 13\
**Last updated:** [December 18, 2023, 2:14pm UTC](https://discuss.elastic.co/t/help-needed-for-certificate-configuration/349194 "2023-12-18T14:14:11Z")

</div>

Elasticsearch drives me nuts when it comes to certificates and how they are used / configured. This is my current configuration: ## Cluster Settings cluster.name: "elk-tls-cluster" node.name: node-1 network.host: "0.0.…

---

## [Manually execute ILM policy](https://discuss.elastic.co/t/manually-execute-ilm-policy/349560)

<div class="topic-metadata">

**Author:** [@rschirin](https://discuss.elastic.co/u/rschirin)\
**Replies:** 1\
**Last updated:** [December 18, 2023, 1:44pm UTC](https://discuss.elastic.co/t/manually-execute-ilm-policy/349560 "2023-12-18T13:44:59Z")

</div>

Hey there, is there a way to manually execute an ILMm policy? If I modify the mapping template for example, I would like to immediately create and use a new updated index, avoiding to wait for example date threshold or …

---

## [Elastic service stops unexpectedly](https://discuss.elastic.co/t/elastic-service-stops-unexpectedly/349555)

<div class="topic-metadata">

**Author:** [@mreddy9](https://discuss.elastic.co/u/mreddy9)\
**Replies:** 0\
**Last updated:** [December 18, 2023, 12:35pm UTC](https://discuss.elastic.co/t/elastic-service-stops-unexpectedly/349555 "2023-12-18T12:35:51Z")

</div>

Hi all, Sometime Elasticsearch service stops unexpectedly in the weekend and there are no details in logs to identify the exact issue. Please suggest any solution if you already come across this issue in past. log deta…

---

## [Merge two buckets muli\_level inside buckets](https://discuss.elastic.co/t/merge-two-buckets-muli-level-inside-buckets/349547)

<div class="topic-metadata">

**Author:** [@Azizi\_BESSEM](https://discuss.elastic.co/u/Azizi_BESSEM)\
**Replies:** 0\
**Last updated:** [December 18, 2023, 10:14am UTC](https://discuss.elastic.co/t/merge-two-buckets-muli-level-inside-buckets/349547 "2023-12-18T10:14:55Z")

</div>

{ "aggregations" : { "alert\_types" : { "doc\_count\_error\_upper\_bound" : 0, "sum\_other\_doc\_count" : 0, "buckets" : \[ { "key" : "1", "doc\_count" : 3, "device\_ref…

---

## [Upgrade from 7.17.14 to 8.11.3 failes](https://discuss.elastic.co/t/upgrade-from-7-17-14-to-8-11-3-failes/349538)

<div class="topic-metadata">

**Author:** [@Ingo\_Voland](https://discuss.elastic.co/u/Ingo_Voland)\
**Replies:** 1\
**Last updated:** [December 18, 2023, 9:39am UTC](https://discuss.elastic.co/t/upgrade-from-7-17-14-to-8-11-3-failes/349538 "2023-12-18T09:39:22Z")

</div>

We have a 1 node elastic installation (7.17.14), upgrading to 8.11.3 failes wiith the error message Caused by: org.elasticsearch.gateway.CorruptStateException: Format version is not supported. Upgrading to \[8.11.3\] is o…

---

## [Elastic 8.11.3 on docker in OSX silicon has disk volume sizing issues](https://discuss.elastic.co/t/elastic-8-11-3-on-docker-in-osx-silicon-has-disk-volume-sizing-issues/349522)

<div class="topic-metadata">

**Author:** [@matthal](https://discuss.elastic.co/u/matthal)\
**Replies:** 6\
**Last updated:** [December 18, 2023, 3:09am UTC](https://discuss.elastic.co/t/elastic-8-11-3-on-docker-in-osx-silicon-has-disk-volume-sizing-issues/349522 "2023-12-18T03:09:07Z")

</div>

Trying to run elasticsearch locally for development using docker compose (Getting started with the Elastic Stack and Docker-Compose | Elastic Blog) I end up getting disk pressure issues, well a warning, but it ends up …

---

## [Date time with time multifield](https://discuss.elastic.co/t/date-time-with-time-multifield/349513)

<div class="topic-metadata">

**Author:** [@RRGTHWAR1](https://discuss.elastic.co/u/RRGTHWAR1)\
**Replies:** 1\
**Last updated:** [December 18, 2023, 1:18am UTC](https://discuss.elastic.co/t/date-time-with-time-multifield/349513 "2023-12-18T01:18:58Z")

</div>

This has come up from time to time, but I haven’t seen any definitive answers. Is it possible to have a time-only multi-field in a date time field? For example, created\_date would be the full datetime, and created\_date.t…

---

## [Circuit breaker in Elasticsearch](https://discuss.elastic.co/t/circuit-breaker-in-elasticsearch/349508)

<div class="topic-metadata">

**Author:** [@pksinghal](https://discuss.elastic.co/u/pksinghal)\
**Replies:** 9\
**Last updated:** [December 17, 2023, 5:01pm UTC](https://discuss.elastic.co/t/circuit-breaker-in-elasticsearch/349508 "2023-12-17T17:01:15Z")

</div>

we are running an Elasticsearch cluster with 3 nodes. sometimes a heavy agg query comes(run manually from Kibana dev tools) and one of the nodes becomes inaccessible. So full cluster becomes inaccessible as ES takes so…

---

## [Best data structure for sensor data](https://discuss.elastic.co/t/best-data-structure-for-sensor-data/349497)

<div class="topic-metadata">

**Author:** [@allatrue](https://discuss.elastic.co/u/allatrue)\
**Replies:** 1\
**Last updated:** [December 17, 2023, 5:10pm UTC](https://discuss.elastic.co/t/best-data-structure-for-sensor-data/349497 "2023-12-17T17:10:18Z")

</div>

Hello everyone, We are setting up a cluster for collecting of IoT/sensor data. And I'm not sure what is the best structure for this kind of data. The simplest way would be to use single index for all similar (numeric) d…

---

## [Cannot login to Elastic Cloud](https://discuss.elastic.co/t/cannot-login-to-elastic-cloud/349439)

<div class="topic-metadata">

**Author:** [@develop-finline](https://discuss.elastic.co/u/develop-finline)\
**Replies:** 4\
**Last updated:** [December 17, 2023, 3:50pm UTC](https://discuss.elastic.co/t/cannot-login-to-elastic-cloud/349439 "2023-12-17T15:50:09Z")

</div>

Hi team, I'm not able to reach out to any of my clusters, I'm not able to login to Elastic Cloud. Endpoints of clusters aren't available. I've tried to reset my elastic cloud account password but still cannot login a…

---

## [Not able to search a specific log file in Kibana UI](https://discuss.elastic.co/t/not-able-to-search-a-specific-log-file-in-kibana-ui/347428)

<div class="topic-metadata">

**Author:** [@kaushalshriyan](https://discuss.elastic.co/u/kaushalshriyan)\
**Replies:** 3\
**Last updated:** [December 17, 2023, 5:02am UTC](https://discuss.elastic.co/t/not-able-to-search-a-specific-log-file-in-kibana-ui/347428 "2023-12-17T05:02:03Z")

</div>

Hi, I am running the Elastic Stack on Red Hat Enterprise Linux release 8.8 (Ootpa) and the versions are as below. # rpm -qa | grep logstash logstash-8.11.0-1.x86\_64 # rpm -qa | grep elasticsearch elasticsearch-8.11.0-1…

---

## [Elasticsearch upgrade assistant](https://discuss.elastic.co/t/elasticsearch-upgrade-assistant/349447)

<div class="topic-metadata">

**Author:** [@jaykb77](https://discuss.elastic.co/u/jaykb77)\
**Replies:** 2\
**Last updated:** [December 16, 2023, 11:26pm UTC](https://discuss.elastic.co/t/elasticsearch-upgrade-assistant/349447 "2023-12-16T23:26:59Z")

</div>

Hi all, We are trying to upgrade our Elasticsearch cluster from 7.17 to 8.X and found that its recommended to use Upgrade assistant for this. But we do not use Kibana in our cluster. The ES is acting as a search backend…

---

## [Plugin installation issue, probably related to YAML](https://discuss.elastic.co/t/plugin-installation-issue-probably-related-to-yaml/349404)

<div class="topic-metadata">

**Author:** [@jediD83](https://discuss.elastic.co/u/jediD83)\
**Replies:** 4\
**Last updated:** [December 15, 2023, 10:38pm UTC](https://discuss.elastic.co/t/plugin-installation-issue-probably-related-to-yaml/349404 "2023-12-15T22:38:05Z")

</div>

Good day. The installation of the Elasticsearch's plugin for Zammad should be straightforward. After apt install elasticsearch using Set up Elasticsearch guide, its just sudo /usr/share/elasticsearch/bin/elasticsearch-p…

---

## [Search any term startswith including special char](https://discuss.elastic.co/t/search-any-term-startswith-including-special-char/349288)

<div class="topic-metadata">

**Author:** [@Sankar\_S](https://discuss.elastic.co/u/Sankar_S)\
**Replies:** 4\
**Last updated:** [December 15, 2023, 4:48pm UTC](https://discuss.elastic.co/t/search-any-term-startswith-including-special-char/349288 "2023-12-15T16:48:45Z")

</div>

Hello All, I have a field called title and it has value "title" : "Toddler- $kitkat @taste &roll ^yart !here #you %ice ^oops \*jam (pot) \[beat\] pep |old {jet} \`egg /lol" For given input i would like to match any term s…

---

## [Implementing Custom BERT-Based Text Embedding Model for Semantic Search in Elasticsearch](https://discuss.elastic.co/t/implementing-custom-bert-based-text-embedding-model-for-semantic-search-in-elasticsearch/349434)

<div class="topic-metadata">

**Author:** [@Ali\_Zare](https://discuss.elastic.co/u/Ali_Zare)\
**Replies:** 1\
**Last updated:** [December 15, 2023, 4:10pm UTC](https://discuss.elastic.co/t/implementing-custom-bert-based-text-embedding-model-for-semantic-search-in-elasticsearch/349434 "2023-12-15T16:10:22Z")

</div>

Hello everyone, I'm exploring the possibility of setting up a custom text embedding model using the BERT architecture for semantic search within Elasticsearch. I'm curious if it's feasible to integrate a personalized te…

---

## [Issue with Date Formatting in Transform Script on Elasticsearch 8.6.1](https://discuss.elastic.co/t/issue-with-date-formatting-in-transform-script-on-elasticsearch-8-6-1/349463)

<div class="topic-metadata">

**Author:** [@Behnam.R](https://discuss.elastic.co/u/Behnam.R)\
**Replies:** 0\
**Last updated:** [December 15, 2023, 2:49pm UTC](https://discuss.elastic.co/t/issue-with-date-formatting-in-transform-script-on-elasticsearch-8-6-1/349463 "2023-12-15T14:49:39Z")

</div>

Hello, I'm encountering an issue with date formatting in a transform script on Elasticsearch 8.6.1 (licensed version). My goal is to pivot existing index and store the date as it is. However, the output in the transform…

---

## [License is not available](https://discuss.elastic.co/t/license-is-not-available/349449)

<div class="topic-metadata">

**Author:** [@secsec](https://discuss.elastic.co/u/secsec)\
**Replies:** 2\
**Last updated:** [December 15, 2023, 1:55pm UTC](https://discuss.elastic.co/t/license-is-not-available/349449 "2023-12-15T13:55:28Z")

</div>

Hello im using ELK 8.11 version, only one node and under tail -f /var/log/syslog | grep license i can see this so many problems with licence (im using basic): Dec 15 12:37:03 SPTWS-ELK-NODE01 metricbeat\[607\]: {"log.l…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=164)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=166)
