# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=169

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 170

---

## [Enrolling Elastic Agent shows up in Fleet Agents but goes from "Updating" to "Offline"](https://discuss.elastic.co/t/enrolling-elastic-agent-shows-up-in-fleet-agents-but-goes-from-updating-to-offline/348728)

<div class="topic-metadata">

**Author:** [@olivettinho](https://discuss.elastic.co/u/olivettinho)\
**Replies:** 7\
**Last updated:** [December 8, 2023, 8:24am UTC](https://discuss.elastic.co/t/enrolling-elastic-agent-shows-up-in-fleet-agents-but-goes-from-updating-to-offline/348728 "2023-12-08T08:24:34Z")

</div>

Hello, I am trying to enroll Elastic Agent to different Windows Servers. I am running ELK and Fleet-Server via Docker. I am using the given commands by Kibana to install Elastic Agent and it says "Successfully enroled t…

---

## [Uptime alert recovers even though host is still down](https://discuss.elastic.co/t/uptime-alert-recovers-even-though-host-is-still-down/348866)

<div class="topic-metadata">

**Author:** [@Glychee](https://discuss.elastic.co/u/Glychee)\
**Replies:** 0\
**Last updated:** [December 8, 2023, 8:32am UTC](https://discuss.elastic.co/t/uptime-alert-recovers-even-though-host-is-still-down/348866 "2023-12-08T08:32:51Z")

</div>

Running Elasticsearch 8.2.3 and heartbeat 8.2 We've installed heartbeat on a server(manual install) which is polling multiple hosts every 30 seconds and sending the data to Elasticsearch, this data comes in at a steady …

---

## [Is there a way to find the id value of async search?](https://discuss.elastic.co/t/is-there-a-way-to-find-the-id-value-of-async-search/348858)

<div class="topic-metadata">

**Author:** [@SEUNGHYO](https://discuss.elastic.co/u/SEUNGHYO)\
**Replies:** 0\
**Last updated:** [December 8, 2023, 6:02am UTC](https://discuss.elastic.co/t/is-there-a-way-to-find-the-id-value-of-async-search/348858 "2023-12-08T06:02:12Z")

</div>

Hello. missed the async search ID . want to look up the entire registered async search. In such a case, I would like to know how I can look up the ID of async search again. I checked to find the task of async search,…

---

## [Match\_none and must\_not named queries](https://discuss.elastic.co/t/match-none-and-must-not-named-queries/348857)

<div class="topic-metadata">

**Author:** [@OS1](https://discuss.elastic.co/u/OS1)\
**Replies:** 0\
**Last updated:** [December 8, 2023, 5:33am UTC](https://discuss.elastic.co/t/match-none-and-must-not-named-queries/348857 "2023-12-08T05:33:06Z")

</div>

I'm building ES queries dynamically in code, and sometimes I choose to omit some part of the query. I've been using the "\_name" property for logging and debugging, however I wish I could also use it to tell which sub qu…

---

## [Failed to create client for go-elasticsearch](https://discuss.elastic.co/t/failed-to-create-client-for-go-elasticsearch/348848)

<div class="topic-metadata">

**Author:** [@Bosees](https://discuss.elastic.co/u/Bosees)\
**Replies:** 0\
**Last updated:** [December 8, 2023, 2:27am UTC](https://discuss.elastic.co/t/failed-to-create-client-for-go-elasticsearch/348848 "2023-12-08T02:27:00Z")

</div>

I'm trying to create a client using go-elasticsearch with a viewer permission user who can only play a read role. The problem is that I'm getting a 403 error. Here is the corresponding error log "type":"security\_excepti…

---

## [Snapshot backup via api not working as expacted](https://discuss.elastic.co/t/snapshot-backup-via-api-not-working-as-expacted/348841)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 2\
**Last updated:** [December 7, 2023, 9:14pm UTC](https://discuss.elastic.co/t/snapshot-backup-via-api-not-working-as-expacted/348841 "2023-12-07T21:14:16Z")

</div>

I am running backup via bash and it is working successfully but backing up lot of unwanted backup with it. here is code for indice in daily\_check\_index-2023 do curl -XPUT -u ${elk\_admin\_user}:${elk\_admin\_password} "${…

---

## [Guides on getting Elastic 8 working with a Java backend?](https://discuss.elastic.co/t/guides-on-getting-elastic-8-working-with-a-java-backend/348765)

<div class="topic-metadata">

**Author:** [@DenverCoder9](https://discuss.elastic.co/u/DenverCoder9)\
**Replies:** 10\
**Last updated:** [December 7, 2023, 8:44pm UTC](https://discuss.elastic.co/t/guides-on-getting-elastic-8-working-with-a-java-backend/348765 "2023-12-07T20:44:26Z")

</div>

Hello. Been working in Java to try getting Elasticsearch up and working in a Java backend and not having good luck with finding examples of how to have it working. A lot of the materials I've seen use RestHighLevelClien…

---

## [Elasticsearch curl output returning error](https://discuss.elastic.co/t/elasticsearch-curl-output-returning-error/348836)

<div class="topic-metadata">

**Author:** [@Kamesh\_Pratapa](https://discuss.elastic.co/u/Kamesh_Pratapa)\
**Replies:** 0\
**Last updated:** [December 7, 2023, 6:01pm UTC](https://discuss.elastic.co/t/elasticsearch-curl-output-returning-error/348836 "2023-12-07T18:01:13Z")

</div>

Hi all, I am trying to setup ELK cluster with 7.16 version with X-pack enabled and SSL certificates configured. I am doing it in ubuntu where we have ansible code to deploy the stack which was developed by a person ear…

---

## [ILM - Does not trigger rollover](https://discuss.elastic.co/t/ilm-does-not-trigger-rollover/348711)

<div class="topic-metadata">

**Author:** [@grumo35](https://discuss.elastic.co/u/grumo35)\
**Replies:** 7\
**Last updated:** [December 7, 2023, 4:53pm UTC](https://discuss.elastic.co/t/ilm-does-not-trigger-rollover/348711 "2023-12-07T16:53:32Z")

</div>

Hi, I've configured ILM on datastream and a rollover policy. The goal is to have my datastream backing indices to rollover daily. The ILM is configured as follow : Two weeks passed, still on the same backing indic…

---

## [Curl: (60) SSL certificate problem: self signed certificate in certificate chain](https://discuss.elastic.co/t/curl-60-ssl-certificate-problem-self-signed-certificate-in-certificate-chain/347472)

<div class="topic-metadata">

**Author:** [@Dasara\_Saarthak](https://discuss.elastic.co/u/Dasara_Saarthak)\
**Replies:** 17\
**Last updated:** [December 7, 2023, 4:36pm UTC](https://discuss.elastic.co/t/curl-60-ssl-certificate-problem-self-signed-certificate-in-certificate-chain/347472 "2023-12-07T16:36:58Z")

</div>

curl --cacert certs/ca/ca.crt -u elastic:"xyz" 'url' iam getting the below error while trying to execute the above curl command curl: (60) SSL certificate problem: self signed certificate in certificate chain but the…

---

## [Ignore\_inactive does not work in filebeat with filestream config type](https://discuss.elastic.co/t/ignore-inactive-does-not-work-in-filebeat-with-filestream-config-type/348822)

<div class="topic-metadata">

**Author:** [@josepcorrea](https://discuss.elastic.co/u/josepcorrea)\
**Replies:** 0\
**Last updated:** [December 7, 2023, 3:13pm UTC](https://discuss.elastic.co/t/ignore-inactive-does-not-work-in-filebeat-with-filestream-config-type/348822 "2023-12-07T15:13:10Z")

</div>

When I use the filestream type instead of the log type, filebeat always reads the entire log file from the beginning. - type: filestream id: test\_id enable: true paths: - "/usr/share/filebeat/inputs.d/\*.log" …

---

## [What is the max id for rollover in index name](https://discuss.elastic.co/t/what-is-the-max-id-for-rollover-in-index-name/348802)

<div class="topic-metadata">

**Author:** [@avnere](https://discuss.elastic.co/u/avnere)\
**Replies:** 3\
**Last updated:** [December 7, 2023, 2:58pm UTC](https://discuss.elastic.co/t/what-is-the-max-id-for-rollover-in-index-name/348802 "2023-12-07T14:58:46Z")

</div>

Hi, I have created index with rollover policy (with 9 digits: 000000001) : PUT /\<my-index-{now/d}-000000001\> After rollover it create the new index with 6 digits: 000002 Is there a way to increase the number of digit…

---

## [Logstash custom DATE fields (extracted by regex or custom patterns) how to convert it to DATE field](https://discuss.elastic.co/t/logstash-custom-date-fields-extracted-by-regex-or-custom-patterns-how-to-convert-it-to-date-field/348419)

<div class="topic-metadata">

**Author:** [@elk1985](https://discuss.elastic.co/u/elk1985)\
**Replies:** 7\
**Last updated:** [December 7, 2023, 12:45pm UTC](https://discuss.elastic.co/t/logstash-custom-date-fields-extracted-by-regex-or-custom-patterns-how-to-convert-it-to-date-field/348419 "2023-12-07T12:45:28Z")

</div>

Hello everyone. Currently, I'm in the stage of writing custom Grok filters in Logstash. I have many different logs - some of them have a date format that fits ISO8601 format. But unfortunately when I use this format in m…

---

## [Is there caching for knn search so it returns records if same querry is fired](https://discuss.elastic.co/t/is-there-caching-for-knn-search-so-it-returns-records-if-same-querry-is-fired/348783)

<div class="topic-metadata">

**Author:** [@Himanshu\_Pal](https://discuss.elastic.co/u/Himanshu_Pal)\
**Replies:** 1\
**Last updated:** [December 7, 2023, 12:22pm UTC](https://discuss.elastic.co/t/is-there-caching-for-knn-search-so-it-returns-records-if-same-querry-is-fired/348783 "2023-12-07T12:22:18Z")

</div>

i fired 100 querries to elastic knn search with 0.4 million records and calculated average time per querry which was about 200 ms for first iteration. i re fired same querries just after 5 sec and response time per quer…

---

## [Extract specific string from a field in ELK](https://discuss.elastic.co/t/extract-specific-string-from-a-field-in-elk/348799)

<div class="topic-metadata">

**Author:** [@Satheesh](https://discuss.elastic.co/u/Satheesh)\
**Replies:** 1\
**Last updated:** [December 7, 2023, 12:07pm UTC](https://discuss.elastic.co/t/extract-specific-string-from-a-field-in-elk/348799 "2023-12-07T12:07:43Z")

</div>

I am newbie in ELK. In my ELK, a single document has multiple fields (k8s.pod,k8s.ns,timestamp,logtag,stream and message etc.,). In the message field, I am getting the logs like below e\[36m15:25:47.508e\[0;39m e\[1;30m\[de…

---

## [Upsert a document when document id is autogenerated using upsert?](https://discuss.elastic.co/t/upsert-a-document-when-document-id-is-autogenerated-using-upsert/348747)

<div class="topic-metadata">

**Author:** [@iby\_dev](https://discuss.elastic.co/u/iby_dev)\
**Replies:** 2\
**Last updated:** [December 7, 2023, 9:46am UTC](https://discuss.elastic.co/t/upsert-a-document-when-document-id-is-autogenerated-using-upsert/348747 "2023-12-07T09:46:31Z")

</div>

According to the docs, on the Update API The \<\_id\> field is required. I have a bulk insert process which is sometimes known to insert duplicates given a particular scenario. The ids for us, are auto generated so how d…

---

## [ES create indexes\\reindex are slow when using a synonym file](https://discuss.elastic.co/t/es-create-indexes-reindex-are-slow-when-using-a-synonym-file/348718)

<div class="topic-metadata">

**Author:** [@ryzhovas](https://discuss.elastic.co/u/ryzhovas)\
**Replies:** 6\
**Last updated:** [December 7, 2023, 9:29am UTC](https://discuss.elastic.co/t/es-create-indexes-reindex-are-slow-when-using-a-synonym-file/348718 "2023-12-07T09:29:50Z")

</div>

We have synonym file 38M when we create index with filter "dictionary": { "expand": false, "lenient": true, "synonyms\_path": "linguistics/expert\_20231123/em\_dictionary.txt", …

---

## [Discuss: Security Vulnerabilities: ESA-2023-14 - CVE-2023-31419](https://discuss.elastic.co/t/discuss-security-vulnerabilities-esa-2023-14-cve-2023-31419/348769)

<div class="topic-metadata">

**Author:** [@devkgk](https://discuss.elastic.co/u/devkgk)\
**Replies:** 2\
**Last updated:** [December 7, 2023, 8:32am UTC](https://discuss.elastic.co/t/discuss-security-vulnerabilities-esa-2023-14-cve-2023-31419/348769 "2023-12-07T08:32:44Z")

</div>

Hello, everybody. According to the community's safety announcement: " Elasticsearch StackOverflow vulnerability (ESA-2023-14) A flaw was discovered in Elasticsearch, affecting the \_search API that allowed a specially …

---

## [Elastic search certificate issue](https://discuss.elastic.co/t/elastic-search-certificate-issue/348788)

<div class="topic-metadata">

**Author:** [@Dasara\_Saarthak](https://discuss.elastic.co/u/Dasara_Saarthak)\
**Replies:** 0\
**Last updated:** [December 7, 2023, 8:05am UTC](https://discuss.elastic.co/t/elastic-search-certificate-issue/348788 "2023-12-07T08:05:29Z")

</div>

hi iam using helm to deploy elasticsearch this is my statefulset.yml file apiVersion: apps/v1 kind: StatefulSet metadata: annotations: esMajorVersion: "8" meta.helm.sh/release-name: esarticle meta.helm.sh…

---

## [Does date-format of ES7.5.2 not support YYYY?](https://discuss.elastic.co/t/does-date-format-of-es7-5-2-not-support-yyyy/348787)

<div class="topic-metadata">

**Author:** [@MiuNice](https://discuss.elastic.co/u/MiuNice)\
**Replies:** 2\
**Last updated:** [December 7, 2023, 7:54am UTC](https://discuss.elastic.co/t/does-date-format-of-es7-5-2-not-support-yyyy/348787 "2023-12-07T07:54:02Z")

</div>

I created a field named "created" in the index as shown below: "created": { "type": "date", "format": "YYYY-MM-dd'T'HH:mm:ss'Z'" } When I used the range method for querying, I got unexpected results. There is a…

---

## [Elastic Search Indices Migration from Version 5.6 to Version 8.11 (New ES cluster)](https://discuss.elastic.co/t/elastic-search-indices-migration-from-version-5-6-to-version-8-11-new-es-cluster/348784)

<div class="topic-metadata">

**Author:** [@chateesh](https://discuss.elastic.co/u/chateesh)\
**Replies:** 1\
**Last updated:** [December 7, 2023, 7:01am UTC](https://discuss.elastic.co/t/elastic-search-indices-migration-from-version-5-6-to-version-8-11-new-es-cluster/348784 "2023-12-07T07:01:39Z")

</div>

Hi Team, Indices in ES version 5.6 are compatible with ES version 8.11 (New ES Cluster) if we restore these indices by pointing snapshot repository of ES 5.6 cluster to new ES 8.11 cluster? Can you please share the ste…

---

## [Elasticsearch false mapping](https://discuss.elastic.co/t/elasticsearch-false-mapping/348722)

<div class="topic-metadata">

**Author:** [@vladislav](https://discuss.elastic.co/u/vladislav)\
**Replies:** 6\
**Last updated:** [December 7, 2023, 6:50am UTC](https://discuss.elastic.co/t/elasticsearch-false-mapping/348722 "2023-12-07T06:50:20Z")

</div>

Hello everyone and thanks for help. I've installed latest versions of elasticsearch, kibana and logstash (8.11.1) on test cluster. Next, created new simple logstash pipeline that listens tcp port, next send data to elas…

---

## [Thread is missing when i send logs from ECS fargate to Elastic search](https://discuss.elastic.co/t/thread-is-missing-when-i-send-logs-from-ecs-fargate-to-elastic-search/348774)

<div class="topic-metadata">

**Author:** [@NitinKalburgii](https://discuss.elastic.co/u/NitinKalburgii)\
**Replies:** 1\
**Last updated:** [December 7, 2023, 4:47am UTC](https://discuss.elastic.co/t/thread-is-missing-when-i-send-logs-from-ecs-fargate-to-elastic-search/348774 "2023-12-07T04:47:57Z")

</div>

Hi! I was running my application in ECS fargate(AWS Service) and in AWS monitoring i was getting logs like 2023-12-06T15:28:53.745+05:30 06-12-2023 09:58:53.745 \[main\] INFO \[\] o.a.coyote.http11.Http11NioProtocol.log - I…

---

## [Can't Create Enrollment Token](https://discuss.elastic.co/t/cant-create-enrollment-token/348460)

<div class="topic-metadata">

**Author:** [@Bethanie\_Tipton](https://discuss.elastic.co/u/Bethanie_Tipton)\
**Replies:** 6\
**Last updated:** [December 6, 2023, 9:06pm UTC](https://discuss.elastic.co/t/cant-create-enrollment-token/348460 "2023-12-06T21:06:53Z")

</div>

When I try to open elasticsearch-create-enrollment-token, it crashes. I can't do anything with it; I click it, it pops up on my screen for half a second, and then closes.

---

## [Bundling elasticsearch into an offline Electronjs application](https://discuss.elastic.co/t/bundling-elasticsearch-into-an-offline-electronjs-application/348768)

<div class="topic-metadata">

**Author:** [@Joel\_Crawford](https://discuss.elastic.co/u/Joel_Crawford)\
**Replies:** 0\
**Last updated:** [December 7, 2023, 12:56am UTC](https://discuss.elastic.co/t/bundling-elasticsearch-into-an-offline-electronjs-application/348768 "2023-12-07T00:56:59Z")

</div>

Hello, We've been trying to bundle Elasticsearch into an offline Electron application without success. Our goal is to provide offline full-text search functionality in an Electron app. We've used Elasticsearch extensiv…

---

## [Pagination Search - page 1 to page 5](https://discuss.elastic.co/t/pagination-search-page-1-to-page-5/348668)

<div class="topic-metadata">

**Author:** [@Jasonespo](https://discuss.elastic.co/u/Jasonespo)\
**Replies:** 1\
**Last updated:** [December 6, 2023, 9:30pm UTC](https://discuss.elastic.co/t/pagination-search-page-1-to-page-5/348668 "2023-12-06T21:30:06Z")

</div>

Hi, We're trying to implement pagination for our application. We are displaying a table with 10 results per page. And we're wondering if it's possible to go from page 1 (record 1-10) to page 5 (record 51-60) in one jump…

---

## [Scroll inner\_hits in Elasticsearch](https://discuss.elastic.co/t/scroll-inner-hits-in-elasticsearch/348757)

<div class="topic-metadata">

**Author:** [@TomTom](https://discuss.elastic.co/u/TomTom)\
**Replies:** 0\
**Last updated:** [December 6, 2023, 7:38pm UTC](https://discuss.elastic.co/t/scroll-inner-hits-in-elasticsearch/348757 "2023-12-06T19:38:04Z")

</div>

I have a document that has nested items, and in some cases I need to query documents that have nested items that match the filter applied in the search and return all nested items that match. To do this, in the search q…

---

## [No d for data node anymore?](https://discuss.elastic.co/t/no-d-for-data-node-anymore/348736)

<div class="topic-metadata">

**Author:** [@Doc\_Kaos](https://discuss.elastic.co/u/Doc_Kaos)\
**Replies:** 1\
**Last updated:** [December 6, 2023, 7:20pm UTC](https://discuss.elastic.co/t/no-d-for-data-node-anymore/348736 "2023-12-06T19:20:53Z")

</div>

Looking at the documentation cat nodes API | Elasticsearch Guide \[8.11\] | Elastic It appears that a "Hot" node should have roles hd ... but that's not true in real life. Is a hot node not a "data" node? Are 'data\_content…

---

## [Logstash doesn't get logs from other container in Azure container group](https://discuss.elastic.co/t/logstash-doesnt-get-logs-from-other-container-in-azure-container-group/348755)

<div class="topic-metadata">

**Author:** [@TheNewGuy123](https://discuss.elastic.co/u/TheNewGuy123)\
**Replies:** 0\
**Last updated:** [December 6, 2023, 5:50pm UTC](https://discuss.elastic.co/t/logstash-doesnt-get-logs-from-other-container-in-azure-container-group/348755 "2023-12-06T17:50:34Z")

</div>

Hey, I'm trying to debug why my Azure container based Logstash being a side car to my test application that periodically sends out logs with gelf isn't consuming those logs. So both containers (logstash and my app) are h…

---

## [Updating to version 7.17.15 caused the 'Failed to publish events' issue caused connection reset by peer](https://discuss.elastic.co/t/updating-to-version-7-17-15-caused-the-failed-to-publish-events-issue-caused-connection-reset-by-peer/348740)

<div class="topic-metadata">

**Author:** [@Saleh\_Houshangi](https://discuss.elastic.co/u/Saleh_Houshangi)\
**Replies:** 0\
**Last updated:** [December 6, 2023, 4:10pm UTC](https://discuss.elastic.co/t/updating-to-version-7-17-15-caused-the-failed-to-publish-events-issue-caused-connection-reset-by-peer/348740 "2023-12-06T16:10:49Z")

</div>

After updating Elasticsearch and Logstash from version 7.17.5 to 7.17.15, all Filebeat instances sporadically encounter the following error in the log file: caa27ea3-c641-4ad2-9f03-578f008a4013'} 2023-12-06T16:06:56.260…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=168)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=170)
