# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=167

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 168

---

## [Retention of -ds.monitoring\*](https://discuss.elastic.co/t/retention-of-ds-monitoring/349277)

<div class="topic-metadata">

**Author:** [@SteffiAutumn](https://discuss.elastic.co/u/SteffiAutumn)\
**Replies:** 0\
**Last updated:** [December 13, 2023, 3:02pm UTC](https://discuss.elastic.co/t/retention-of-ds-monitoring/349277 "2023-12-13T15:02:52Z")

</div>

Unfortunately our indices created by Metricbeat 8 are not cleaned up, although the policy looks ok. Looking at the responsible policy I'd expect the indices to be deleted after 6 days, but they're not and we need to clea…

---

## [Dense search for large documents](https://discuss.elastic.co/t/dense-search-for-large-documents/349248)

<div class="topic-metadata">

**Author:** [@mwon](https://discuss.elastic.co/u/mwon)\
**Replies:** 4\
**Last updated:** [December 13, 2023, 2:10pm UTC](https://discuss.elastic.co/t/dense-search-for-large-documents/349248 "2023-12-13T14:10:54Z")

</div>

Hi, I want to use ES to index documents and do semantic search with knn. For this type of search we need to encode every document with an embedding model and index each vector for future search of some also encoded quer…

---

## [Script processor for retaning relevant fields not working](https://discuss.elastic.co/t/script-processor-for-retaning-relevant-fields-not-working/348320)

<div class="topic-metadata">

**Author:** [@vishnuhngama](https://discuss.elastic.co/u/vishnuhngama)\
**Replies:** 1\
**Last updated:** [December 13, 2023, 1:35pm UTC](https://discuss.elastic.co/t/script-processor-for-retaning-relevant-fields-not-working/348320 "2023-12-13T13:35:10Z")

</div>

I am writing a script processor which will retain only the relevant fields and remove all the other fields . Here 'message','custom\_field','@timestamp','\_index','\_id','\_version','index\_name','tags', is getting retained b…

---

## [Is the precision of cardinality aggregation decided by total unique value count or filtered unique value count?](https://discuss.elastic.co/t/is-the-precision-of-cardinality-aggregation-decided-by-total-unique-value-count-or-filtered-unique-value-count/349073)

<div class="topic-metadata">

**Author:** [@henrhoi](https://discuss.elastic.co/u/henrhoi)\
**Replies:** 4\
**Last updated:** [December 13, 2023, 1:07pm UTC](https://discuss.elastic.co/t/is-the-precision-of-cardinality-aggregation-decided-by-total-unique-value-count-or-filtered-unique-value-count/349073 "2023-12-13T13:07:14Z")

</div>

Hi, We have an index with a field containing ~30,000 unique values. When doing a filtered cardinality aggregation on this field, which should return ~650 unique values, we experience non-deterministic results (±25). W…

---

## [Aggregations Migration ES7 to ES8.11.1](https://discuss.elastic.co/t/aggregations-migration-es7-to-es8-11-1/349255)

<div class="topic-metadata">

**Author:** [@Dev1234](https://discuss.elastic.co/u/Dev1234)\
**Replies:** 0\
**Last updated:** [December 13, 2023, 12:03pm UTC](https://discuss.elastic.co/t/aggregations-migration-es7-to-es8-11-1/349255 "2023-12-13T12:03:42Z")

</div>

Hello dear community, I am currently migrating our ES7 to ES8 and am now encountering the problem that I cannot find a solution as to how I can migrate SearchHits or the .get(String) method. public static Set\<Integer\> …

---

## [Changing from Elasticsearch 7.10.2 OSS to Basic version](https://discuss.elastic.co/t/changing-from-elasticsearch-7-10-2-oss-to-basic-version/347523)

<div class="topic-metadata">

**Author:** [@Talha1](https://discuss.elastic.co/u/Talha1)\
**Replies:** 3\
**Last updated:** [December 13, 2023, 11:55am UTC](https://discuss.elastic.co/t/changing-from-elasticsearch-7-10-2-oss-to-basic-version/347523 "2023-12-13T11:55:24Z")

</div>

Hi, I'm currently using Elasticsearch version 7.10. OSS version but when trying to implement security ran into challenges which turns out is because I am not on the basic version of Elasticsearch. Is there a way I can ch…

---

## [Is this the correct impl' for customizing \`\_id\` meta data field](https://discuss.elastic.co/t/is-this-the-correct-impl-for-customizing-id-meta-data-field/349059)

<div class="topic-metadata">

**Author:** [@iby\_dev](https://discuss.elastic.co/u/iby_dev)\
**Replies:** 17\
**Last updated:** [December 13, 2023, 10:48am UTC](https://discuss.elastic.co/t/is-this-the-correct-impl-for-customizing-id-meta-data-field/349059 "2023-12-13T10:48:33Z")

</div>

To get Elasticsearch docker image version: image: docker.elastic.co/elasticsearch/elasticsearch:7.16.2 To accept a client side customized UUID on the \_id field i had to change the: dynamic: strict property to true. Al…

---

## [org.apache.http.ConnectionClosedException: Connection is closed](https://discuss.elastic.co/t/org-apache-http-connectionclosedexception-connection-is-closed/348402)

<div class="topic-metadata">

**Author:** [@tcpeiris](https://discuss.elastic.co/u/tcpeiris)\
**Replies:** 4\
**Last updated:** [December 13, 2023, 9:06am UTC](https://discuss.elastic.co/t/org-apache-http-connectionclosedexception-connection-is-closed/348402 "2023-12-13T09:06:07Z")

</div>

org.apache.http.ConnectionClosedException: Connection is closed at org.elasticsearch.client.RestClient.extractAndWrapCause(RestClient.java:920) at org.elasticsearch.client.RestClient.performRequest(RestClient.java:300) …

---

## [Elasticsearch as vector db](https://discuss.elastic.co/t/elasticsearch-as-vector-db/349192)

<div class="topic-metadata">

**Author:** [@Alexander\_Gamanyuk1](https://discuss.elastic.co/u/Alexander_Gamanyuk1)\
**Replies:** 2\
**Last updated:** [December 13, 2023, 9:04am UTC](https://discuss.elastic.co/t/elasticsearch-as-vector-db/349192 "2023-12-13T09:04:05Z")

</div>

I've been using Elasticsearch since early 2010. We have multiple self-hosted clusters with a few terabytes of data, used for search, analytics, and other use cases. But recently, we started building Retrieval Augmented …

---

## [How to maintain product availability in Elasticsearch?](https://discuss.elastic.co/t/how-to-maintain-product-availability-in-elasticsearch/349226)

<div class="topic-metadata">

**Author:** [@Aadhar\_Bhatt](https://discuss.elastic.co/u/Aadhar_Bhatt)\
**Replies:** 0\
**Last updated:** [December 13, 2023, 7:27am UTC](https://discuss.elastic.co/t/how-to-maintain-product-availability-in-elasticsearch/349226 "2023-12-13T07:27:52Z")

</div>

Hey everyone, I'm setting up an eCommerce search system on Elasticsearch with about 6 million product listings across 3000 stores. I need advice on storing availability data efficiently within ES. This data updates freq…

---

## [Filebeat-god is stopped](https://discuss.elastic.co/t/filebeat-god-is-stopped/349153)

<div class="topic-metadata">

**Author:** [@Mursel](https://discuss.elastic.co/u/Mursel)\
**Replies:** 3\
**Last updated:** [December 13, 2023, 6:07am UTC](https://discuss.elastic.co/t/filebeat-god-is-stopped/349153 "2023-12-13T06:07:42Z")

</div>

I have installed wazuh in docker. After users count reached 100 filebeat has stopped. service filebeat start Failed to get D-Bus connection: Operation not permitted Starting filebeat: 2023-12-12T13:18:58.565Z INFO …

---

## [Date\_histogram: Unknown time-zone ID: Europe/Kyiv](https://discuss.elastic.co/t/date-histogram-unknown-time-zone-id-europe-kyiv/349188)

<div class="topic-metadata">

**Author:** [@Inbal](https://discuss.elastic.co/u/Inbal)\
**Replies:** 9\
**Last updated:** [December 12, 2023, 8:15pm UTC](https://discuss.elastic.co/t/date-histogram-unknown-time-zone-id-europe-kyiv/349188 "2023-12-12T20:15:57Z")

</div>

Hey, I have a es search with aggregations which contains date\_histogram with time\_zone parameter. When I'm choosing "Europe/Kyiv" as time\_zone I'm getting the following error reason: "Unknown time-zone ID: Europe/Kyiv"…

---

## [Elasticsearch first time run hangs adding index template](https://discuss.elastic.co/t/elasticsearch-first-time-run-hangs-adding-index-template/349169)

<div class="topic-metadata">

**Author:** [@MColeman](https://discuss.elastic.co/u/MColeman)\
**Replies:** 15\
**Last updated:** [December 12, 2023, 7:49pm UTC](https://discuss.elastic.co/t/elasticsearch-first-time-run-hangs-adding-index-template/349169 "2023-12-12T19:49:47Z")

</div>

Hi, Using the unzip install method. Unzip, run elasticsearch.bat and it seems to be hanging at \[o.e.c.m.MetadataIndexTemplateService\] adding index template \[logs\] for index patterns \[logs--\] for hours. I was expecting t…

---

## [MatchAllQuery is slow once segment size exceeds 1](https://discuss.elastic.co/t/matchallquery-is-slow-once-segment-size-exceeds-1/349095)

<div class="topic-metadata">

**Author:** [@jwSmith1](https://discuss.elastic.co/u/jwSmith1)\
**Replies:** 5\
**Last updated:** [December 12, 2023, 6:04pm UTC](https://discuss.elastic.co/t/matchallquery-is-slow-once-segment-size-exceeds-1/349095 "2023-12-12T18:04:14Z")

</div>

Hi, I'm managing an extra-small index and had some issues with the latency. The index has ~4000 documents (25mb in total) 1 shard low index and search traffic I need to periodically fetch all of the documents from th…

---

## [How to create a geoDistance sort search in java with elasticsearch 8.11.0](https://discuss.elastic.co/t/how-to-create-a-geodistance-sort-search-in-java-with-elasticsearch-8-11-0/348983)

<div class="topic-metadata">

**Author:** [@jasin](https://discuss.elastic.co/u/jasin)\
**Replies:** 6\
**Last updated:** [December 12, 2023, 4:40pm UTC](https://discuss.elastic.co/t/how-to-create-a-geodistance-sort-search-in-java-with-elasticsearch-8-11-0/348983 "2023-12-12T16:40:49Z")

</div>

here is my code but the sort doesn't work and throw an error SearchResponse\<HotelDoc\> response = client.search(s -\> s .index("hotel") .query(q -\> q …

---

## [Implement my own Hybrid Search](https://discuss.elastic.co/t/implement-my-own-hybrid-search/349100)

<div class="topic-metadata">

**Author:** [@r1ckC139](https://discuss.elastic.co/u/r1ckC139)\
**Replies:** 1\
**Last updated:** [December 12, 2023, 4:20pm UTC](https://discuss.elastic.co/t/implement-my-own-hybrid-search/349100 "2023-12-12T16:20:36Z")

</div>

Hi team, I've developed a hybrid search algorithm. Initially, I perform a BM25 search, obtaining the top k results (id, score). Subsequently, a k-nearest neighbors (KNN) search is executed, yielding another set of top k…

---

## [F5 load balancer SSL\_ERROR\_SYSCALL, errno 104 with Elasticsearch cluster](https://discuss.elastic.co/t/f5-load-balancer-ssl-error-syscall-errno-104-with-elasticsearch-cluster/349120)

<div class="topic-metadata">

**Author:** [@miksonx](https://discuss.elastic.co/u/miksonx)\
**Replies:** 4\
**Last updated:** [December 12, 2023, 4:14pm UTC](https://discuss.elastic.co/t/f5-load-balancer-ssl-error-syscall-errno-104-with-elasticsearch-cluster/349120 "2023-12-12T16:14:11Z")

</div>

We have configured F5 LB in front of Elasticsearch nodes cluster with re-encrypt of SSL traffic to the nodes. Nodes have SSL enabled on http. Direct communication to nodes i.e. API (curl) or sending data over https on po…

---

## [License Platinum Subscription 64 GB only for node?](https://discuss.elastic.co/t/license-platinum-subscription-64-gb-only-for-node/348422)

<div class="topic-metadata">

**Author:** [@Rossella\_Palmisano](https://discuss.elastic.co/u/Rossella_Palmisano)\
**Replies:** 7\
**Last updated:** [December 12, 2023, 2:28pm UTC](https://discuss.elastic.co/t/license-platinum-subscription-64-gb-only-for-node/348422 "2023-12-12T14:28:09Z")

</div>

For the calculation of elastic platinum licenses should only nodes count or should I also consider the GB RAM per node? Which nodes need to be licensed? I have both master nodes and worker nodes.

---

## [Possible bug with sorting dynamically mapped fields](https://discuss.elastic.co/t/possible-bug-with-sorting-dynamically-mapped-fields/349149)

<div class="topic-metadata">

**Author:** [@Evgeni\_Dzhelyov](https://discuss.elastic.co/u/Evgeni_Dzhelyov)\
**Replies:** 0\
**Last updated:** [December 12, 2023, 1:05pm UTC](https://discuss.elastic.co/t/possible-bug-with-sorting-dynamically-mapped-fields/349149 "2023-12-12T13:05:01Z")

</div>

We ingest a lot of custom logs in Elasticsearch. For the application logs we use a custom schema with dynamic mappings, but when sorting for some of the fields we hit a strange bug: Sort by a dext.duration#double field…

---

## [Can not create a document has mutlipolygon having hole](https://discuss.elastic.co/t/can-not-create-a-document-has-mutlipolygon-having-hole/349133)

<div class="topic-metadata">

**Author:** [@Sai\_Suvam\_Patnaik](https://discuss.elastic.co/u/Sai_Suvam_Patnaik)\
**Replies:** 1\
**Last updated:** [December 12, 2023, 11:47am UTC](https://discuss.elastic.co/t/can-not-create-a-document-has-mutlipolygon-having-hole/349133 "2023-12-12T11:47:05Z")

</div>

Hi all , can anyone help me I am facing a following issue . Summary Can not create a document has multipolygon having hole. This is the screenshot of the shp file in qgis: Expected behavior The document is succe…

---

## [Create a rule for stopped log alert](https://discuss.elastic.co/t/create-a-rule-for-stopped-log-alert/349009)

<div class="topic-metadata">

**Author:** [@Bhavani90](https://discuss.elastic.co/u/Bhavani90)\
**Replies:** 1\
**Last updated:** [December 12, 2023, 11:21am UTC](https://discuss.elastic.co/t/create-a-rule-for-stopped-log-alert/349009 "2023-12-12T11:21:29Z")

</div>

Hi, I'm trying to set up an alert for when my application logs haven't been updated in 1 hour. Could you please share the relevant query?

---

## [Does Cross Cluster Search Performance varies with number of clusters](https://discuss.elastic.co/t/does-cross-cluster-search-performance-varies-with-number-of-clusters/348954)

<div class="topic-metadata">

**Author:** [@siddhartha\_c](https://discuss.elastic.co/u/siddhartha_c)\
**Replies:** 3\
**Last updated:** [December 12, 2023, 11:19am UTC](https://discuss.elastic.co/t/does-cross-cluster-search-performance-varies-with-number-of-clusters/348954 "2023-12-12T11:19:08Z")

</div>

Hi Team, I have a query. We have around 5000 Nodes in our setup. If I distribute the Nodes across 30 different Clusters will the cross cluster search performance be significantly be faster as compared to if I have nod…

---

## [Exact replacement of LIKE with MATCH() / QUERY() in SQL query](https://discuss.elastic.co/t/exact-replacement-of-like-with-match-query-in-sql-query/349134)

<div class="topic-metadata">

**Author:** [@Grzegorz\_Kolakowski](https://discuss.elastic.co/u/Grzegorz_Kolakowski)\
**Replies:** 1\
**Last updated:** [December 12, 2023, 11:13am UTC](https://discuss.elastic.co/t/exact-replacement-of-like-with-match-query-in-sql-query/349134 "2023-12-12T11:13:21Z")

</div>

Hi! The documentation suggests to use MATCH()/QUERY() instead of LIKE for performance reasons. I am wondering if it is possible to translate expression from LIKE filter to either MATCH or QUERY in order to achieve exact…

---

## [Elastic's Tenable Vulnerability Management Integration - Re-injesting Lost Data](https://discuss.elastic.co/t/elastics-tenable-vulnerability-management-integration-re-injesting-lost-data/349131)

<div class="topic-metadata">

**Author:** [@longansoju](https://discuss.elastic.co/u/longansoju)\
**Replies:** 0\
**Last updated:** [December 12, 2023, 9:55am UTC](https://discuss.elastic.co/t/elastics-tenable-vulnerability-management-integration-re-injesting-lost-data/349131 "2023-12-12T09:55:42Z")

</div>

TDLR: is there a way to force elastic to injest all existing data for the past month from my tenable source? For those that prefer an in-depth explaination: I was tasked with coming out with a Tenable Dashboard that sh…

---

## [Elasticsearch throws error 503 Server Unavailable](https://discuss.elastic.co/t/elasticsearch-throws-error-503-server-unavailable/348896)

<div class="topic-metadata">

**Author:** [@Kalidastate](https://discuss.elastic.co/u/Kalidastate)\
**Replies:** 7\
**Last updated:** [December 12, 2023, 8:13am UTC](https://discuss.elastic.co/t/elasticsearch-throws-error-503-server-unavailable/348896 "2023-12-12T08:13:24Z")

</div>

I am facing one issue with the Elasticsearch in the production environment. Elasticsearch stops responding to the API calls and it needs to be restarted. Logs collected from Elasticsearch are as follows When the issue…

---

## [Suggestion on elastic cluster requirement](https://discuss.elastic.co/t/suggestion-on-elastic-cluster-requirement/349109)

<div class="topic-metadata">

**Author:** [@Ishaque\_Mohammed](https://discuss.elastic.co/u/Ishaque_Mohammed)\
**Replies:** 0\
**Last updated:** [December 12, 2023, 6:25am UTC](https://discuss.elastic.co/t/suggestion-on-elastic-cluster-requirement/349109 "2023-12-12T06:25:07Z")

</div>

I have GKE clusters in that I am getting total 50MB logs /second to elastic and for this I have setup a 6 node elastic cluster with 4core and 16GB RAM configuration still I am facing issue when a surge occurs however my…

---

## [Seeking advice on setting up the ELK Stack](https://discuss.elastic.co/t/seeking-advice-on-setting-up-the-elk-stack/348968)

<div class="topic-metadata">

**Author:** [@Carrier99](https://discuss.elastic.co/u/Carrier99)\
**Replies:** 1\
**Last updated:** [December 12, 2023, 12:30am UTC](https://discuss.elastic.co/t/seeking-advice-on-setting-up-the-elk-stack/348968 "2023-12-12T00:30:36Z")

</div>

Hey there. I want to set up the ELK stack, and I'm wondering about a good way to set it up. I'm running Proxmox so I have the options of either VMs or LXCs (was thinking of going with LXCs). My main question is should…

---

## [Disk space measure for Elasticsearch service](https://discuss.elastic.co/t/disk-space-measure-for-elasticsearch-service/349076)

<div class="topic-metadata">

**Author:** [@kaushalshriyan](https://discuss.elastic.co/u/kaushalshriyan)\
**Replies:** 1\
**Last updated:** [December 12, 2023, 12:11am UTC](https://discuss.elastic.co/t/disk-space-measure-for-elasticsearch-service/349076 "2023-12-12T00:11:07Z")

</div>

Hi, I have provisioned 300 GB of Hard disk storage to Elastic search stack. Is there a way to measure how much storage is consumed by ES service, as I need to work on Capacity planning. For example, how much memory and …

---

## [Problems with elasticsearch container](https://discuss.elastic.co/t/problems-with-elasticsearch-container/349080)

<div class="topic-metadata">

**Author:** [@Ergo\_Proxy](https://discuss.elastic.co/u/Ergo_Proxy)\
**Replies:** 1\
**Last updated:** [December 11, 2023, 6:06pm UTC](https://discuss.elastic.co/t/problems-with-elasticsearch-container/349080 "2023-12-11T18:06:39Z")

</div>

I have some trouble making a docker with elastic. Here is the .yaml and a fragment of the terminal log result that I think shows the problem. services: setup: image: docker.elastic.co/elasticsearc…

---

## [Migrate shards from one node set to another](https://discuss.elastic.co/t/migrate-shards-from-one-node-set-to-another/349065)

<div class="topic-metadata">

**Author:** [@hashworks](https://discuss.elastic.co/u/hashworks)\
**Replies:** 1\
**Last updated:** [December 11, 2023, 5:33pm UTC](https://discuss.elastic.co/t/migrate-shards-from-one-node-set-to-another/349065 "2023-12-11T17:33:54Z")

</div>

Hi, I have three sets of nodes: A, B and C. Over time, I want to migrate all shards on A and B to C (and remove A and B from the cluster). I could do that all at once by setting the cluster routing allocation setting: …

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=166)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=168)
