# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=17

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 18

---

## [No rollover with data stream lifecycle](https://discuss.elastic.co/t/no-rollover-with-data-stream-lifecycle/382165)

<div class="topic-metadata">

**Author:** [@mikehaertl](https://discuss.elastic.co/u/mikehaertl)\
**Replies:** 12\
**Last updated:** [September 30, 2025, 1:51pm UTC](https://discuss.elastic.co/t/no-rollover-with-data-stream-lifecycle/382165 "2025-09-30T13:51:56Z")

</div>

For testing purposes I’ve configured a lifecycle on a data stream with a retention time of 1h. But the backing index does not get rolled over. According to this doc Data stream lifecycle settings in Elasticsearch | Refe…

---

## [Understanding time\_in\_millis for ingest pipeline running embeddings](https://discuss.elastic.co/t/understanding-time-in-millis-for-ingest-pipeline-running-embeddings/382249)

<div class="topic-metadata">

**Author:** [@gueri](https://discuss.elastic.co/u/gueri)\
**Replies:** 2\
**Last updated:** [September 30, 2025, 1:32pm UTC](https://discuss.elastic.co/t/understanding-time-in-millis-for-ingest-pipeline-running-embeddings/382249 "2025-09-30T13:32:32Z")

</div>

Hi, I try to figured out the meaning of time\_in\_millis field about my ingest pipelines running embeddings. time\_in\_millis (integer) Total time, in milliseconds, spent preprocessing documents in the ingest pipeline. I…

---

## [Best practices for preprocessing data and monitoring resource usage in predefined ML jobs (security:host)](https://discuss.elastic.co/t/best-practices-for-preprocessing-data-and-monitoring-resource-usage-in-predefined-ml-jobs-security-host/382320)

<div class="topic-metadata">

**Author:** [@ilyes](https://discuss.elastic.co/u/ilyes)\
**Replies:** 0\
**Last updated:** [September 30, 2025, 1:31pm UTC](https://discuss.elastic.co/t/best-practices-for-preprocessing-data-and-monitoring-resource-usage-in-predefined-ml-jobs-security-host/382320 "2025-09-30T13:31:32Z")

</div>

Question 1: I am planning to use the predefined ML job from the security:host module. To avoid overloading the ML model with too much data, what would be the best approach in terms of data preprocessing? Should I fir…

---

## [After renewing certificates, Kibana shows multiple expiry dates (2028 vs 2125)](https://discuss.elastic.co/t/after-renewing-certificates-kibana-shows-multiple-expiry-dates-2028-vs-2125/382306)

<div class="topic-metadata">

**Author:** [@LimSuyun](https://discuss.elastic.co/u/LimSuyun)\
**Replies:** 1\
**Last updated:** [September 30, 2025, 1:25pm UTC](https://discuss.elastic.co/t/after-renewing-certificates-kibana-shows-multiple-expiry-dates-2028-vs-2125/382306 "2025-09-30T13:25:43Z")

</div>

We have currently set up 3 Elasticsearch clusters with master nodes on 1.1.1.10, 1.1.1.11, and 1.1.1.12. Since the certificates had expired, we generated new ones. On the master node (1.1.1.10), we created http.p12, tra…

---

## [How to track if {{server}} changes {{geo.location}}](https://discuss.elastic.co/t/how-to-track-if-server-changes-geo-location/382127)

<div class="topic-metadata">

**Author:** [@Elk\_huh](https://discuss.elastic.co/u/Elk_huh)\
**Replies:** 3\
**Last updated:** [September 29, 2025, 2:42pm UTC](https://discuss.elastic.co/t/how-to-track-if-server-changes-geo-location/382127 "2025-09-29T14:42:39Z")

</div>

Is there a functionality to track server / geolocation . I need an alert to go off if the geolocation changes, not sure what functionality will achieve this

---

## [Highlighting on ES8 much slower than ES7](https://discuss.elastic.co/t/highlighting-on-es8-much-slower-than-es7/375355)

<div class="topic-metadata">

**Author:** [@Bartosz\_Krakowiak](https://discuss.elastic.co/u/Bartosz_Krakowiak)\
**Replies:** 5\
**Last updated:** [September 29, 2025, 2:12pm UTC](https://discuss.elastic.co/t/highlighting-on-es8-much-slower-than-es7/375355 "2025-09-29T14:12:07Z")

</div>

Hi, I've updated my cluster from Elasticsearch 7.17.16 to 8.16.3 and noticed that Kibana is working way slower in ES 8, because most of the query time is spent in HighlightingPhase. The difference is even bigger when us…

---

## [Sorting on a scripted terms aggregation is lexically instead of numerically](https://discuss.elastic.co/t/sorting-on-a-scripted-terms-aggregation-is-lexically-instead-of-numerically/382256)

<div class="topic-metadata">

**Author:** [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Replies:** 3\
**Last updated:** [September 28, 2025, 10:10am UTC](https://discuss.elastic.co/t/sorting-on-a-scripted-terms-aggregation-is-lexically-instead-of-numerically/382256 "2025-09-28T10:10:25Z")

</div>

Hey, maybe this is intended behaviour but I would like to verify. If I am using a terms aggregation with a script and specify sorting by key, it does not take into account when the script is returning an integer value. …

---

## [Dynamic Template usage for nested fields](https://discuss.elastic.co/t/dynamic-template-usage-for-nested-fields/382229)

<div class="topic-metadata">

**Author:** [@Shweta\_Chadha](https://discuss.elastic.co/u/Shweta_Chadha)\
**Replies:** 3\
**Last updated:** [September 26, 2025, 8:21pm UTC](https://discuss.elastic.co/t/dynamic-template-usage-for-nested-fields/382229 "2025-09-26T20:21:48Z")

</div>

Hi folks! We are on Elastic version 8.17 and have an existing ES index that we are now introducing a dynamic attribute using dynamic template to. The dynamic fields would be added within an existing nested field. Our br…

---

## [Increased Read IOPS usage after upgrade from 8.19.3 to 9.1.3](https://discuss.elastic.co/t/increased-read-iops-usage-after-upgrade-from-8-19-3-to-9-1-3/382156)

<div class="topic-metadata">

**Author:** [@Paulo\_Guedes](https://discuss.elastic.co/u/Paulo_Guedes)\
**Replies:** 3\
**Last updated:** [September 25, 2025, 1:37pm UTC](https://discuss.elastic.co/t/increased-read-iops-usage-after-upgrade-from-8-19-3-to-9-1-3/382156 "2025-09-25T13:37:31Z")

</div>

Hi all, since upgrading from 8.19.3 to 9.1.3 i'm seeing a massive increase of read IOPS on the Hot node disks. I couldn't see anything obvious in the release notes that would lead to this outside of the new JDK version …

---

## [Microsfot dynamics to elastic](https://discuss.elastic.co/t/microsfot-dynamics-to-elastic/382215)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 0\
**Last updated:** [September 25, 2025, 9:04am UTC](https://discuss.elastic.co/t/microsfot-dynamics-to-elastic/382215 "2025-09-25T09:04:56Z")

</div>

Hi I checked the supported integrations and I do not see microsoft dynamics available. How to get my logs from microsoft dynamics to elastic? Please help

---

## [Updating records or check if exist and not write](https://discuss.elastic.co/t/updating-records-or-check-if-exist-and-not-write/382201)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 0\
**Last updated:** [September 24, 2025, 8:32pm UTC](https://discuss.elastic.co/t/updating-records-or-check-if-exist-and-not-write/382201 "2025-09-24T20:32:51Z")

</div>

I have case where I am trying to do following. job#:123, status:running, user:elastic → goes to job\_index in index \_id = job# case1: check if \_id:123 exist and status=running in job\_index and if is then don’t do anyt…

---

## [How to mock ElasticsearchServerError?](https://discuss.elastic.co/t/how-to-mock-elasticsearchservererror/382193)

<div class="topic-metadata">

**Author:** [@vedavathy](https://discuss.elastic.co/u/vedavathy)\
**Replies:** 0\
**Last updated:** [September 24, 2025, 9:23am UTC](https://discuss.elastic.co/t/how-to-mock-elasticsearchservererror/382193 "2025-09-24T09:23:21Z")

</div>

Hello, I am using .NET 8 and "Elastic.Clients.Elasticsearch" Version="8.13.2" Trying to mock test data for ElasticsearchServerError. As its a sealed class we can’t use Moq and dont want to create wrapper class. Do we h…

---

## [Enrich Indices have unassigned shards](https://discuss.elastic.co/t/enrich-indices-have-unassigned-shards/382137)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 3\
**Last updated:** [September 23, 2025, 6:19pm UTC](https://discuss.elastic.co/t/enrich-indices-have-unassigned-shards/382137 "2025-09-23T18:19:59Z")

</div>

Hello, I understand why Elastic manages the primary and replica shards of enrich indices. I get that the whole point is parallelism, but the end user should be able to manage the shard settings. It is causing an imbalan…

---

## [Index sorting on low cardinality fields](https://discuss.elastic.co/t/index-sorting-on-low-cardinality-fields/382047)

<div class="topic-metadata">

**Author:** [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Replies:** 7\
**Last updated:** [September 23, 2025, 1:46pm UTC](https://discuss.elastic.co/t/index-sorting-on-low-cardinality-fields/382047 "2025-09-23T13:46:12Z")

</div>

Hey, I have been playing around with index sorting and cannot make sense of my results. Basically I have a keyword field named is\_existing that is either true or false as possible values, or may not be set at all. Basic…

---

## [Requesting feedback on benchmark results: Hot vs Frozen(Cache) vs Frozen(No-Cache)](https://discuss.elastic.co/t/requesting-feedback-on-benchmark-results-hot-vs-frozen-cache-vs-frozen-no-cache/382169)

<div class="topic-metadata">

**Author:** [@dipayans](https://discuss.elastic.co/u/dipayans)\
**Replies:** 0\
**Last updated:** [September 23, 2025, 1:34pm UTC](https://discuss.elastic.co/t/requesting-feedback-on-benchmark-results-hot-vs-frozen-cache-vs-frozen-no-cache/382169 "2025-09-23T13:34:38Z")

</div>

Hi everyone, I recently ran a set of benchmark tests to evaluate performance across Hot tier and Frozen tier searchable snapshots (with and without cache). I’d really appreciate feedback from the community to understand…

---

## [Filebeat warning log "Cannot index event"](https://discuss.elastic.co/t/filebeat-warning-log-cannot-index-event/368808)

<div class="topic-metadata">

**Author:** [@rodolk](https://discuss.elastic.co/u/rodolk)\
**Replies:** 7\
**Last updated:** [September 23, 2025, 8:26am UTC](https://discuss.elastic.co/t/filebeat-warning-log-cannot-index-event/368808 "2025-09-23T08:26:58Z")

</div>

When sending logs from Filebeat to Elasticsearch, when there is an indexing error, Filebeat will log the message Cannot index event (status=400): dropping event! Look at the event log to view the event and cause." The …

---

## [Filter index by max field value](https://discuss.elastic.co/t/filter-index-by-max-field-value/381636)

<div class="topic-metadata">

**Author:** [@PMF](https://discuss.elastic.co/u/PMF)\
**Replies:** 7\
**Last updated:** [September 23, 2025, 6:18am UTC](https://discuss.elastic.co/t/filter-index-by-max-field-value/381636 "2025-09-23T06:18:58Z")

</div>

Ok, this seems easy from a relational perspective, but I'm becoming unable to achieve it on ES: I have an index where, among others, there is a numeric field called year. I want to filter my index data, retrieving only …

---

## [Upgrade thoughts](https://discuss.elastic.co/t/upgrade-thoughts/382118)

<div class="topic-metadata">

**Author:** [@arcsons](https://discuss.elastic.co/u/arcsons)\
**Replies:** 2\
**Last updated:** [September 23, 2025, 2:57am UTC](https://discuss.elastic.co/t/upgrade-thoughts/382118 "2025-09-23T02:57:09Z")

</div>

Hi, I’ve never upgraded an Elastic Stack before, and it seems quite challenging! Is it just me who thinks that? I guess there’s room for improvement. I’m currently running version 8.15 and considering an upgrade to 8.…

---

## [Elasticsearch enrich policy not reflecting updated source after \_execute (v9.1.3)](https://discuss.elastic.co/t/elasticsearch-enrich-policy-not-reflecting-updated-source-after-execute-v9-1-3/382141)

<div class="topic-metadata">

**Author:** [@Daniel\_Santos1](https://discuss.elastic.co/u/Daniel_Santos1)\
**Replies:** 2\
**Last updated:** [September 23, 2025, 12:01am UTC](https://discuss.elastic.co/t/elasticsearch-enrich-policy-not-reflecting-updated-source-after-execute-v9-1-3/382141 "2025-09-23T00:01:25Z")

</div>

Hi, I’m running into an issue with enrich policies in Elasticsearch v9.1.3. When I update the source index used by an enrich policy and then re-execute the policy, the enrich simulation still returns stale data. The upd…

---

## [Java API client - single metric aggregation zero or null deserializer](https://discuss.elastic.co/t/java-api-client-single-metric-aggregation-zero-or-null-deserializer/356207)

<div class="topic-metadata">

**Author:** [@Almog\_Oz](https://discuss.elastic.co/u/Almog_Oz)\
**Replies:** 2\
**Last updated:** [September 22, 2025, 1:44pm UTC](https://discuss.elastic.co/t/java-api-client-single-metric-aggregation-zero-or-null-deserializer/356207 "2025-09-22T13:44:39Z")

</div>

I am using elasticsearch-java api client (8.10.3) and facing a small issue and I hope someone has already encountered this issue before. I am trying to perform a min aggregation on documents that may not contain the fie…

---

## [Track ingest rate of data\_streams by size](https://discuss.elastic.co/t/track-ingest-rate-of-data-streams-by-size/382080)

<div class="topic-metadata">

**Author:** [@djkprojects](https://discuss.elastic.co/u/djkprojects)\
**Replies:** 1\
**Last updated:** [September 22, 2025, 10:26am UTC](https://discuss.elastic.co/t/track-ingest-rate-of-data-streams-by-size/382080 "2025-09-22T10:26:41Z")

</div>

Hello, We want to track ingest rate of data streams and other indices in our stack by volume (how much data in GB each data stream received e.g. daily). We are aware of various APIs that give certain information about i…

---

## [Elasticsearch v5.5.3 to v7.17.7](https://discuss.elastic.co/t/elasticsearch-v5-5-3-to-v7-17-7/382028)

<div class="topic-metadata">

**Author:** [@Gord1](https://discuss.elastic.co/u/Gord1)\
**Replies:** 2\
**Last updated:** [September 19, 2025, 3:04pm UTC](https://discuss.elastic.co/t/elasticsearch-v5-5-3-to-v7-17-7/382028 "2025-09-19T15:04:19Z")

</div>

Hello, I am new to Elasticsearch and need to perform an upgrade from v5.5.3 to v7.17.7. I want to upgrade directly from v5.5.3 to v7.17.7 in a windows cluster. Another team in out environment were not able to do the r…

---

## [Serialisation into SearchResponse takes a lot of time](https://discuss.elastic.co/t/serialisation-into-searchresponse-takes-a-lot-of-time/382083)

<div class="topic-metadata">

**Author:** [@karuna\_kukreja](https://discuss.elastic.co/u/karuna_kukreja)\
**Replies:** 2\
**Last updated:** [September 19, 2025, 1:55pm UTC](https://discuss.elastic.co/t/serialisation-into-searchresponse-takes-a-lot-of-time/382083 "2025-09-19T13:55:29Z")

</div>

I am using Elastic Search Java client to search for documents in elasticsearch. The search request itself on ES takes (took) 165ms, however the ovreall time taken to convert the same into SearchResponse takes about 121…

---

## [The Elasticsearch trial ends when I add an ML node after 10 minutes](https://discuss.elastic.co/t/the-elasticsearch-trial-ends-when-i-add-an-ml-node-after-10-minutes/381997)

<div class="topic-metadata">

**Author:** [@kheabrosec](https://discuss.elastic.co/u/kheabrosec)\
**Replies:** 5\
**Last updated:** [September 19, 2025, 1:15pm UTC](https://discuss.elastic.co/t/the-elasticsearch-trial-ends-when-i-add-an-ml-node-after-10-minutes/381997 "2025-09-19T13:15:22Z")

</div>

I'm playing around a bit with Elastic Cloud on K8s, and I decided to activate the trial. Ten minutes later, I decided to add a node with ML and Transform roles so I could run some jobs and do some testing. It's a test …

---

## [Running into "Request rate too high 503" S3 error during snapshots](https://discuss.elastic.co/t/running-into-request-rate-too-high-503-s3-error-during-snapshots/382062)

<div class="topic-metadata">

**Author:** [@indu\_s](https://discuss.elastic.co/u/indu_s)\
**Replies:** 1\
**Last updated:** [September 19, 2025, 7:22am UTC](https://discuss.elastic.co/t/running-into-request-rate-too-high-503-s3-error-during-snapshots/382062 "2025-09-19T07:22:28Z")

</div>

I’m running Elastic v8.8.2 on Kubernetes and sometimes, snapshots only partially succeed with error message AmazonS3Exception\\\[Please reduce your request rate. (Service: Amazon S3; Status Code: 503; Error Code: SlowDown;.…

---

## [Interleaving search results in ElasticSearch](https://discuss.elastic.co/t/interleaving-search-results-in-elasticsearch/382063)

<div class="topic-metadata">

**Author:** [@malaranjo](https://discuss.elastic.co/u/malaranjo)\
**Replies:** 0\
**Last updated:** [September 18, 2025, 4:40pm UTC](https://discuss.elastic.co/t/interleaving-search-results-in-elasticsearch/382063 "2025-09-18T16:40:50Z")

</div>

Hi Elasticsearch community, I’m implementing a search feature where items belong to groups, and some groups are marked as premium. I want search results to: Show all items from premium groups first, then non-premium …

---

## [How to pass the dynamic date in the body section of http input in the Watcher config](https://discuss.elastic.co/t/how-to-pass-the-dynamic-date-in-the-body-section-of-http-input-in-the-watcher-config/382024)

<div class="topic-metadata">

**Author:** [@Ria\_Shah](https://discuss.elastic.co/u/Ria_Shah)\
**Replies:** 1\
**Last updated:** [September 18, 2025, 11:08am UTC](https://discuss.elastic.co/t/how-to-pass-the-dynamic-date-in-the-body-section-of-http-input-in-the-watcher-config/382024 "2025-09-18T11:08:18Z")

</div>

The below is my watcher config and I want to pass the dynamic date in the body part so that it can take the current date in MM-dd-yyyy format to call the REST aPI endpoint: { "trigger": { "schedule": { "inte…

---

## [Facing this error "illegal\_argument\_exception: Fielddata is disabled"](https://discuss.elastic.co/t/facing-this-error-illegal-argument-exception-fielddata-is-disabled/382044)

<div class="topic-metadata">

**Author:** [@Mihir\_Mistry](https://discuss.elastic.co/u/Mihir_Mistry)\
**Replies:** 1\
**Last updated:** [September 18, 2025, 10:54am UTC](https://discuss.elastic.co/t/facing-this-error-illegal-argument-exception-fielddata-is-disabled/382044 "2025-09-18T10:54:15Z")

</div>

I am working on a website that uses Elasticsearch for searching functionality, and the project has been working fine, but I am facing this error. You can see the error in the attached screenshot. I just want to know if …

---

## [Elasticsearch Keystore error: Device or Resource Busy while upgrading](https://discuss.elastic.co/t/elasticsearch-keystore-error-device-or-resource-busy-while-upgrading/362884)

<div class="topic-metadata">

**Author:** [@Umang\_Pachaury](https://discuss.elastic.co/u/Umang_Pachaury)\
**Replies:** 4\
**Last updated:** [September 18, 2025, 7:35am UTC](https://discuss.elastic.co/t/elasticsearch-keystore-error-device-or-resource-busy-while-upgrading/362884 "2025-09-18T07:35:00Z")

</div>

Hello, I have a multi node Elasticsearch cluster running on version 8.13.4. The cluster needed Slack Integration and AD/LDAP integration so it also has elasticsearch.keystore file bind mount to it. The cluster is set u…

---

## [Can ES support the modification of the shard role for the ilm history index?](https://discuss.elastic.co/t/can-es-support-the-modification-of-the-shard-role-for-the-ilm-history-index/381951)

<div class="topic-metadata">

**Author:** [@EricTowns](https://discuss.elastic.co/u/EricTowns)\
**Replies:** 8\
**Last updated:** [September 18, 2025, 4:06am UTC](https://discuss.elastic.co/t/can-es-support-the-modification-of-the-shard-role-for-the-ilm-history-index/381951 "2025-09-18T04:06:00Z")

</div>

My ES cluster is currently running out of disk space. The new disks are still being purchased. I want to try my best to preserve my data, so I'm using the method of deleting replicas to cope with the current situation. T…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=16)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=18)
