# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=168

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 169

---

## [Memory spikes on ILM transition](https://discuss.elastic.co/t/memory-spikes-on-ilm-transition/349008)

<div class="topic-metadata">

**Author:** [@azhurbilo](https://discuss.elastic.co/u/azhurbilo)\
**Replies:** 7\
**Last updated:** [December 11, 2023, 11:38am UTC](https://discuss.elastic.co/t/memory-spikes-on-ilm-transition/349008 "2023-12-11T11:38:24Z")

</div>

We use hot-warm-cold architecture policy { "filebeat": { "version": 39128, "modified\_date": "2023-12-11T04:05:20.404Z", "policy": { "phases": { "hot": { "min\_age": "0ms", …

---

## [Expose Elasticsearch on GKE to Dataproc (Performantly )](https://discuss.elastic.co/t/expose-elasticsearch-on-gke-to-dataproc-performantly/349056)

<div class="topic-metadata">

**Author:** [@Pat\_Humphreys](https://discuss.elastic.co/u/Pat_Humphreys)\
**Replies:** 0\
**Last updated:** [December 11, 2023, 2:42pm UTC](https://discuss.elastic.co/t/expose-elasticsearch-on-gke-to-dataproc-performantly/349056 "2023-12-11T14:42:19Z")

</div>

What is the recomended way of exposing an elasticsearch cluster outside of the GKE cluster e.g. to use by a spark job running in dataproc (Using ES Hadoop libary) within the same VPC, without enabling the wan.only option…

---

## [Upgrade Single Node Docker Instance](https://discuss.elastic.co/t/upgrade-single-node-docker-instance/349041)

<div class="topic-metadata">

**Author:** [@litronics](https://discuss.elastic.co/u/litronics)\
**Replies:** 2\
**Last updated:** [December 11, 2023, 2:24pm UTC](https://discuss.elastic.co/t/upgrade-single-node-docker-instance/349041 "2023-12-11T14:24:23Z")

</div>

Hi, I am trying to upgrade a single node docker instance from 8.6.0 to the latest version. My first try was to update the docker containers to the latest version and start them on the old data. Kibana upgraded well and…

---

## [Uprading Elastic search upgrade from 6.6.1 to 7.16.3](https://discuss.elastic.co/t/uprading-elastic-search-upgrade-from-6-6-1-to-7-16-3/348851)

<div class="topic-metadata">

**Author:** [@Abhishek\_Gangadharai](https://discuss.elastic.co/u/Abhishek_Gangadharai)\
**Replies:** 3\
**Last updated:** [December 11, 2023, 1:20pm UTC](https://discuss.elastic.co/t/uprading-elastic-search-upgrade-from-6-6-1-to-7-16-3/348851 "2023-12-11T13:20:36Z")

</div>

Uprading Elastic search upgrade from 6.6.1 to 7.16.3 in Bitbucket datacenter cluster nodes we are facing challenges can please help for proper documentation for Upgrading Elastic search Instructions, It will help us fo…

---

## [Write structured log but field is never recognized as 'date'](https://discuss.elastic.co/t/write-structured-log-but-field-is-never-recognized-as-date/348920)

<div class="topic-metadata">

**Author:** [@Heija](https://discuss.elastic.co/u/Heija)\
**Replies:** 2\
**Last updated:** [December 11, 2023, 12:01pm UTC](https://discuss.elastic.co/t/write-structured-log-but-field-is-never-recognized-as-date/348920 "2023-12-11T12:01:29Z")

</div>

Hi! I have a .net application which write log entries per nlog direct to Elasticsearch. It works with strings, numbers and booleans. Now I need to transfer a 'date' as structured log entry to Elasticsearch, but it wil…

---

## [I am facing issue with apm related indices "illegal\_argument\_exception: index.lifecycle.rollover\_alias \[apm-7.9.1-transaction\] does not point to index \[apm-7.9.1-transaction-000087\]"](https://discuss.elastic.co/t/i-am-facing-issue-with-apm-related-indices-illegal-argument-exception-index-lifecycle-rollover-alias-apm-7-9-1-transaction-does-not-point-to-index-apm-7-9-1-transaction-000087/349039)

<div class="topic-metadata">

**Author:** [@vaiagr](https://discuss.elastic.co/u/vaiagr)\
**Replies:** 0\
**Last updated:** [December 11, 2023, 11:53am UTC](https://discuss.elastic.co/t/i-am-facing-issue-with-apm-related-indices-illegal-argument-exception-index-lifecycle-rollover-alias-apm-7-9-1-transaction-does-not-point-to-index-apm-7-9-1-transaction-000087/349039 "2023-12-11T11:53:28Z")

</div>

illegal\_argument\_exception: index.lifecycle.rollover\_alias \[apm-7.9.1-transaction\] does not point to index \[apm-7.9.1-transaction-000087\]

---

## [One of our nodes is constantly leaving with "master not discovered yet"](https://discuss.elastic.co/t/one-of-our-nodes-is-constantly-leaving-with-master-not-discovered-yet/349031)

<div class="topic-metadata">

**Author:** [@coudenysj](https://discuss.elastic.co/u/coudenysj)\
**Replies:** 1\
**Last updated:** [December 11, 2023, 10:58am UTC](https://discuss.elastic.co/t/one-of-our-nodes-is-constantly-leaving-with-master-not-discovered-yet/349031 "2023-12-11T10:58:22Z")

</div>

We have a cluster with 33 nodes, and one server (always the same one) is leaving the cluster quite often. After restarting the service, it joins immediately. The exact error is: \[2023-12-11T11:23:29,293\]\[WARN \]\[o.e.c.…

---

## [Elasticsearch node disconnect](https://discuss.elastic.co/t/elasticsearch-node-disconnect/349010)

<div class="topic-metadata">

**Author:** [@Farid\_Niasti](https://discuss.elastic.co/u/Farid_Niasti)\
**Replies:** 1\
**Last updated:** [December 11, 2023, 8:48am UTC](https://discuss.elastic.co/t/elasticsearch-node-disconnect/349010 "2023-12-11T08:48:47Z")

</div>

I have 3 nodes of Elasticsearch, sometimes one of my node leave cluster with bellow log: org.elasticsearch.cluster.block.ClusterBlockException: blocked by: \[SERVICE\_UNAVAILABLE/1/state not recovered / initialized\]; …

---

## [Lets Encrypt not working from console but does from firefox](https://discuss.elastic.co/t/lets-encrypt-not-working-from-console-but-does-from-firefox/349000)

<div class="topic-metadata">

**Author:** [@Donovan\_Hoare](https://discuss.elastic.co/u/Donovan_Hoare)\
**Replies:** 3\
**Last updated:** [December 11, 2023, 8:04am UTC](https://discuss.elastic.co/t/lets-encrypt-not-working-from-console-but-does-from-firefox/349000 "2023-12-11T08:04:42Z")

</div>

Good Day All. I have setup a 2-node cluster ith Elasticsearch and kibana. I took me quite some time on how to get lets-encrypt real certs to work. The cert now seems to be ok with kibana and Elasticsearch communicatio…

---

## [Custom Index Creation Issue](https://discuss.elastic.co/t/custom-index-creation-issue/348979)

<div class="topic-metadata">

**Author:** [@Mani\_Manikanta](https://discuss.elastic.co/u/Mani_Manikanta)\
**Replies:** 4\
**Last updated:** [December 11, 2023, 4:01am UTC](https://discuss.elastic.co/t/custom-index-creation-issue/348979 "2023-12-11T04:01:57Z")

</div>

Hello, I am New to ELK Stack, Trying to Setup ELK Stack in Single Server following Elastic Documentation and I am Stuck here now Can Anyone Please Look into this and help me out Unable to Create a Custom Index from Lo…

---

## [CCR - auto-follow problem on data streams](https://discuss.elastic.co/t/ccr-auto-follow-problem-on-data-streams/348789)

<div class="topic-metadata">

**Author:** [@Wojciech\_Kwiecien](https://discuss.elastic.co/u/Wojciech_Kwiecien)\
**Replies:** 5\
**Last updated:** [December 11, 2023, 1:13am UTC](https://discuss.elastic.co/t/ccr-auto-follow-problem-on-data-streams/348789 "2023-12-11T01:13:10Z")

</div>

I found this topic Elastic Cross Cluster Replication of Data Stream But I do not find a solution for me. I was able to create CCR auto-follow pattern and nothing happened when I ran GET /\_ccr/stats After I follow inst…

---

## [Gave up on setting up ELK](https://discuss.elastic.co/t/gave-up-on-setting-up-elk/348984)

<div class="topic-metadata">

**Author:** [@Aamira](https://discuss.elastic.co/u/Aamira)\
**Replies:** 2\
**Last updated:** [December 10, 2023, 10:38pm UTC](https://discuss.elastic.co/t/gave-up-on-setting-up-elk/348984 "2023-12-10T22:38:45Z")

</div>

After 12 years of Linux background and infrastructure management, I accepted defeat setting up ELK for monitoring. I struggled for over 2 weeks trying every guide. but it seems that ELK is not worth the headache. The g…

---

## [What is the impact on a live system doing a change in elasticsearch.yml file to change the node.attr.storage\_term: to be none?](https://discuss.elastic.co/t/what-is-the-impact-on-a-live-system-doing-a-change-in-elasticsearch-yml-file-to-change-the-node-attr-storage-term-to-be-none/348980)

<div class="topic-metadata">

**Author:** [@mpniel](https://discuss.elastic.co/u/mpniel)\
**Replies:** 3\
**Last updated:** [December 10, 2023, 2:25pm UTC](https://discuss.elastic.co/t/what-is-the-impact-on-a-live-system-doing-a-change-in-elasticsearch-yml-file-to-change-the-node-attr-storage-term-to-be-none/348980 "2023-12-10T14:25:17Z")

</div>

Hello, I run GET /\_cat/nodeattrs?v and found that the node have storage\_term attribute as cold. What is the impact on a live system doing a change in elasticsearch.yml file to change the node.attr.storage\_term: to be…

---

## [Error: master not discovered yet , Elasticsearch cluster using docker swarm with three nodes on three separate servers](https://discuss.elastic.co/t/error-master-not-discovered-yet-elasticsearch-cluster-using-docker-swarm-with-three-nodes-on-three-separate-servers/348973)

<div class="topic-metadata">

**Author:** [@hossein\_rahmatei](https://discuss.elastic.co/u/hossein_rahmatei)\
**Replies:** 1\
**Last updated:** [December 10, 2023, 12:42pm UTC](https://discuss.elastic.co/t/error-master-not-discovered-yet-elasticsearch-cluster-using-docker-swarm-with-three-nodes-on-three-separate-servers/348973 "2023-12-10T12:42:24Z")

</div>

I want to set up an elasticsearch cluster using docker swarm with three nodes on three separate servers. But when I do the docker stack deploy command and the service comes up, but I get docker logs from the containe…

---

## [Kibana UI Dashboard Access Issue](https://discuss.elastic.co/t/kibana-ui-dashboard-access-issue/348971)

<div class="topic-metadata">

**Author:** [@Mani\_Manikanta](https://discuss.elastic.co/u/Mani_Manikanta)\
**Replies:** 11\
**Last updated:** [December 10, 2023, 8:55am UTC](https://discuss.elastic.co/t/kibana-ui-dashboard-access-issue/348971 "2023-12-10T08:55:27Z")

</div>

Unable to Access Kibana UI Dashboard Getting Below Error, Getting Please upgrade browser in Google Chrome/Edge/Firefox Kibana - 8.3.3 Elasticsearch - 8.3.3 No Domain Mapped Trying to Access using kibana-ip:5601

---

## [Could you advise me on determining which version of JDK is embedded with Elasticsearch 7.17.14 on RHEL7 - OpenJDK 20 or 21?](https://discuss.elastic.co/t/could-you-advise-me-on-determining-which-version-of-jdk-is-embedded-with-elasticsearch-7-17-14-on-rhel7-openjdk-20-or-21/347294)

<div class="topic-metadata">

**Author:** [@Domnic\_Raj\_D](https://discuss.elastic.co/u/Domnic_Raj_D)\
**Replies:** 3\
**Last updated:** [December 9, 2023, 5:52pm UTC](https://discuss.elastic.co/t/could-you-advise-me-on-determining-which-version-of-jdk-is-embedded-with-elasticsearch-7-17-14-on-rhel7-openjdk-20-or-21/347294 "2023-12-09T17:52:37Z")

</div>

I have collected all breaking changes and deprecations of the ELK stack (Elasticsearch, Kibana, Logstash, Beats) for 7.9 to 7.17.14. Is there anything I need to focus on before moving to the upgrade plan? If you don't mi…

---

## [Elasticsearch Query DSL Filter Including Middle Occurrences](https://discuss.elastic.co/t/elasticsearch-query-dsl-filter-including-middle-occurrences/348143)

<div class="topic-metadata">

**Author:** [@Dokh\_Ahmed](https://discuss.elastic.co/u/Dokh_Ahmed)\
**Replies:** 1\
**Last updated:** [December 9, 2023, 4:18pm UTC](https://discuss.elastic.co/t/elasticsearch-query-dsl-filter-including-middle-occurrences/348143 "2023-12-09T16:18:18Z")

</div>

Hello I am facing an issue with Elastisearch Query DSL while using a prefix filter for the "log\_message" field. The goal is to display logs where the "log\_message" field has a prefix of "Started". However, the filter i…

---

## [Index rollover due to policy does not copy mapping](https://discuss.elastic.co/t/index-rollover-due-to-policy-does-not-copy-mapping/348932)

<div class="topic-metadata">

**Author:** [@twilight](https://discuss.elastic.co/u/twilight)\
**Replies:** 15\
**Last updated:** [December 9, 2023, 3:18pm UTC](https://discuss.elastic.co/t/index-rollover-due-to-policy-does-not-copy-mapping/348932 "2023-12-09T15:18:39Z")

</div>

Hello, I have setup an index with a 'date' field in milliseconds (epoch\_millis), I did set this explicitly while creating the index. Then I attached a policy to rollover after x days. After x days, a new index is creat…

---

## [ELSER2 | Ingest - Cannot switch alias for sparse\_vector](https://discuss.elastic.co/t/elser2-ingest-cannot-switch-alias-for-sparse-vector/348948)

<div class="topic-metadata">

**Author:** [@Rakesh\_Nayak](https://discuss.elastic.co/u/Rakesh_Nayak)\
**Replies:** 2\
**Last updated:** [December 9, 2023, 1:13pm UTC](https://discuss.elastic.co/t/elser2-ingest-cannot-switch-alias-for-sparse-vector/348948 "2023-12-09T13:13:14Z")

</div>

Hello Team, We use elasticsearch-java client 8.1.3 to ingest the data and switch the alias. We are utilising the same logic with additional mapping and pipeline added for ingesting the data for Elser2. We observed that …

---

## [PHP-FPM (or nginx) isn't able to index to elasticsearch](https://discuss.elastic.co/t/php-fpm-or-nginx-isnt-able-to-index-to-elasticsearch/348938)

<div class="topic-metadata">

**Author:** [@Ahriss](https://discuss.elastic.co/u/Ahriss)\
**Replies:** 12\
**Last updated:** [December 9, 2023, 1:08pm UTC](https://discuss.elastic.co/t/php-fpm-or-nginx-isnt-able-to-index-to-elasticsearch/348938 "2023-12-09T13:08:27Z")

</div>

Hi, it's me again, and still having the same issue I was having in this topic: File not found when attempting to index . However, I have made some progress. I now know that when I attempt to, I get the following: 2023-1…

---

## [Using official nodejs elasticsearch npm package on AWS Lambda Docker container sets the Content-Type header to \[text/plain\]](https://discuss.elastic.co/t/using-official-nodejs-elasticsearch-npm-package-on-aws-lambda-docker-container-sets-the-content-type-header-to-text-plain/348766)

<div class="topic-metadata">

**Author:** [@asnyameeteen](https://discuss.elastic.co/u/asnyameeteen)\
**Replies:** 1\
**Last updated:** [December 8, 2023, 11:12pm UTC](https://discuss.elastic.co/t/using-official-nodejs-elasticsearch-npm-package-on-aws-lambda-docker-container-sets-the-content-type-header-to-text-plain/348766 "2023-12-08T23:12:43Z")

</div>

I am trying to publish a document to my self-hosted elasticsearch running on AWS. I wrote my code in nodejs, using v18 LTS, using @elastic/elasticsearch npm module version 8.10.0. When I run my code locally, outside of D…

---

## [Advance settings - Time filter quick ranges - Date math](https://discuss.elastic.co/t/advance-settings-time-filter-quick-ranges-date-math/348939)

<div class="topic-metadata">

**Author:** [@Amphagory](https://discuss.elastic.co/u/Amphagory)\
**Replies:** 3\
**Last updated:** [December 8, 2023, 9:50pm UTC](https://discuss.elastic.co/t/advance-settings-time-filter-quick-ranges-date-math/348939 "2023-12-08T21:50:15Z")

</div>

Hello, I'm try to create some custom time range filters. I would like to create two new ones named as follows: This Year - Time range is from the beginning of the current year to now. Last Year - Time range is from t…

---

## [Removal of packages from the tar file due to vulnerability (log4j)](https://discuss.elastic.co/t/removal-of-packages-from-the-tar-file-due-to-vulnerability-log4j/348902)

<div class="topic-metadata">

**Author:** [@Vijeya\_Nidhi](https://discuss.elastic.co/u/Vijeya_Nidhi)\
**Replies:** 5\
**Last updated:** [December 8, 2023, 7:02pm UTC](https://discuss.elastic.co/t/removal-of-packages-from-the-tar-file-due-to-vulnerability-log4j/348902 "2023-12-08T19:02:19Z")

</div>

So we are deploying elasticsearch using docker file. it is the same steps followed in the official docker file linked below. We are trying to do a Version upgrade from 8.2.0 to 8.11.2 The problem is that the scans re…

---

## [Elasticsearch NEST client 7.17 productivity investigation](https://discuss.elastic.co/t/elasticsearch-nest-client-7-17-productivity-investigation/347868)

<div class="topic-metadata">

**Author:** [@Vadym\_Romanenko](https://discuss.elastic.co/u/Vadym_Romanenko)\
**Replies:** 2\
**Last updated:** [December 8, 2023, 3:10pm UTC](https://discuss.elastic.co/t/elasticsearch-nest-client-7-17-productivity-investigation/347868 "2023-12-08T15:10:10Z")

</div>

Hi, Team! We created solution that generates documents and posts them to Elastic. After that users can search for data located in Elastic. Our solution is web app implemented with ASP.NET, c# on the backend. We use Elas…

---

## [Elasticsearch throws 503 Server Unavailable error](https://discuss.elastic.co/t/elasticsearch-throws-503-server-unavailable-error/348898)

<div class="topic-metadata">

**Author:** [@Kalidastate](https://discuss.elastic.co/u/Kalidastate)\
**Replies:** 1\
**Last updated:** [December 8, 2023, 2:37pm UTC](https://discuss.elastic.co/t/elasticsearch-throws-503-server-unavailable-error/348898 "2023-12-08T14:37:48Z")

</div>

I am facing one issue with the Elasticsearch in the production environment. Elasticsearch stops responding to the API calls and it needs to be restarted. Logs collected from Elasticsearch are as follows When the issue…

---

## [Elasticsearch upgrade](https://discuss.elastic.co/t/elasticsearch-upgrade/348815)

<div class="topic-metadata">

**Author:** [@Siva\_Karan](https://discuss.elastic.co/u/Siva_Karan)\
**Replies:** 3\
**Last updated:** [December 8, 2023, 2:02pm UTC](https://discuss.elastic.co/t/elasticsearch-upgrade/348815 "2023-12-08T14:02:46Z")

</div>

Hi Team, We are using the ES version as 7.3.2 for our environment. Now we are planning to upgrade our elasticsearch to 7.17.3. May i know is there any search speed or indexing speed will increase after upgrade?

---

## [Hi! i want to write dynamic query help me!](https://discuss.elastic.co/t/hi-i-want-to-write-dynamic-query-help-me/348895)

<div class="topic-metadata">

**Author:** [@slowup](https://discuss.elastic.co/u/slowup)\
**Replies:** 0\
**Last updated:** [December 8, 2023, 1:50pm UTC](https://discuss.elastic.co/t/hi-i-want-to-write-dynamic-query-help-me/348895 "2023-12-08T13:50:37Z")

</div>

hi! I want to create logic to create dynamic queries, for example ("a": "1" or "b": "2" and "h": "3") and ("d": "5" and "e": "6") When the above input comes in as a keyword, I want to make it into querydsl. Like Kiban…

---

## [Search Not Applying Scores Properly - Ignoring Boosts](https://discuss.elastic.co/t/search-not-applying-scores-properly-ignoring-boosts/348097)

<div class="topic-metadata">

**Author:** [@mmobley](https://discuss.elastic.co/u/mmobley)\
**Replies:** 2\
**Last updated:** [December 8, 2023, 1:37pm UTC](https://discuss.elastic.co/t/search-not-applying-scores-properly-ignoring-boosts/348097 "2023-12-08T13:37:40Z")

</div>

I'm working on a complex query with multiple keyword fields that are weighted differently (one for category, one for brand, etc) but the query seems to be ignoring the boosts and scoring weird. Here's my query: Summary{…

---

## [How do rollover up index everyday on index lifeincycle](https://discuss.elastic.co/t/how-do-rollover-up-index-everyday-on-index-lifeincycle/348863)

<div class="topic-metadata">

**Author:** [@vanhaiit90](https://discuss.elastic.co/u/vanhaiit90)\
**Replies:** 1\
**Last updated:** [December 8, 2023, 1:27pm UTC](https://discuss.elastic.co/t/how-do-rollover-up-index-everyday-on-index-lifeincycle/348863 "2023-12-08T13:27:14Z")

</div>

Hi everyone! I have an elasticsearch index that needs to be rolled over every day, but after I configured it and observed the policy, it doesn't seem to work And Details are in the following picture: The problem…

---

## [Does ElasticSearch support lemmatization? If yes, then how can I search for docs using this?](https://discuss.elastic.co/t/does-elasticsearch-support-lemmatization-if-yes-then-how-can-i-search-for-docs-using-this/348880)

<div class="topic-metadata">

**Author:** [@prabhuaxm](https://discuss.elastic.co/u/prabhuaxm)\
**Replies:** 0\
**Last updated:** [December 8, 2023, 10:35am UTC](https://discuss.elastic.co/t/does-elasticsearch-support-lemmatization-if-yes-then-how-can-i-search-for-docs-using-this/348880 "2023-12-08T10:35:04Z")

</div>

I am using Python wherein I am searching for a string in a list of string using lemmatization (through SpaCy). I want to do the same thing for Elasticsearch but all the documents I have come across till now say that Lemm…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=167)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=169)
