# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=171

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 172

---

## [Nested inner\_hits more than 100 results](https://discuss.elastic.co/t/nested-inner-hits-more-than-100-results/348562)

<div class="topic-metadata">

**Author:** [@Vinicius\_Junges](https://discuss.elastic.co/u/Vinicius_Junges)\
**Replies:** 0\
**Last updated:** [December 4, 2023, 1:41pm UTC](https://discuss.elastic.co/t/nested-inner-hits-more-than-100-results/348562 "2023-12-04T13:41:52Z")

</div>

Hey guys. I don't know if I'm in the right place, is my first time here. I'm doing a nested query with inner\_hits, but the elasticsearch configuration is limited to 100 by default. Is there any way to get more than 100 r…

---

## [Alert changes in documents](https://discuss.elastic.co/t/alert-changes-in-documents/348561)

<div class="topic-metadata">

**Author:** [@tmslara.a](https://discuss.elastic.co/u/tmslara.a)\
**Replies:** 0\
**Last updated:** [December 4, 2023, 1:37pm UTC](https://discuss.elastic.co/t/alert-changes-in-documents/348561 "2023-12-04T13:37:47Z")

</div>

Hello, I'm trying to implement an alert system in Elasticsearch. I'll describe the key elements of the problem and my solution attempts until now. Scenario We are ingesting information into an Elasticsearch index usin…

---

## [Node.js Application Fail to Connect Elasticsearch](https://discuss.elastic.co/t/node-js-application-fail-to-connect-elasticsearch/348223)

<div class="topic-metadata">

**Author:** [@Burak\_Karatay](https://discuss.elastic.co/u/Burak_Karatay)\
**Replies:** 5\
**Last updated:** [December 4, 2023, 11:50am UTC](https://discuss.elastic.co/t/node-js-application-fail-to-connect-elasticsearch/348223 "2023-12-04T11:50:27Z")

</div>

I have very simple Node.js Application to connect my local Elasticsearch engine, when I try to use Kibana, I can connect after provide user and email but when I try to send ping from my Node.js app It gives following err…

---

## [NGramTokenFilter: Unknown field 'token\_chars'](https://discuss.elastic.co/t/ngramtokenfilter-unknown-field-token-chars/348532)

<div class="topic-metadata">

**Author:** [@Rohit\_Gaur](https://discuss.elastic.co/u/Rohit_Gaur)\
**Replies:** 0\
**Last updated:** [December 4, 2023, 8:43am UTC](https://discuss.elastic.co/t/ngramtokenfilter-unknown-field-token-chars/348532 "2023-12-04T08:43:53Z")

</div>

I am upgrading my Elasticsearch to 8.9 while creating documents using Elasticsearch client I faced the following error co.elastic.clients.json.JsonpMappingException: Error deserializing co.elastic.clients.elasticsearch.…

---

## [Does the functionality of converting documents into vector data in Elasticsearch require payment? How is it paid for in the self-managed type?](https://discuss.elastic.co/t/does-the-functionality-of-converting-documents-into-vector-data-in-elasticsearch-require-payment-how-is-it-paid-for-in-the-self-managed-type/348523)

<div class="topic-metadata">

**Author:** [@katherineadams](https://discuss.elastic.co/u/katherineadams)\
**Replies:** 1\
**Last updated:** [December 4, 2023, 6:56am UTC](https://discuss.elastic.co/t/does-the-functionality-of-converting-documents-into-vector-data-in-elasticsearch-require-payment-how-is-it-paid-for-in-the-self-managed-type/348523 "2023-12-04T06:56:32Z")

</div>

Does the functionality of converting documents into vector data in Elasticsearch require payment? How is it paid for in the self-managed type?

---

## [WARN and ERROR logs are not reflecting in Elasticsearch](https://discuss.elastic.co/t/warn-and-error-logs-are-not-reflecting-in-elasticsearch/348505)

<div class="topic-metadata">

**Author:** [@ErGeek](https://discuss.elastic.co/u/ErGeek)\
**Replies:** 1\
**Last updated:** [December 4, 2023, 3:37am UTC](https://discuss.elastic.co/t/warn-and-error-logs-are-not-reflecting-in-elasticsearch/348505 "2023-12-04T03:37:21Z")

</div>

Hi All, When we are sending logs from Kafka to Elasticsearch, the logs belonging to log-levels "WARN" and "ERRORS" are not reflecting in the Discover page. But the "INFO" and "FATAL" loglevels are reflecting as expected…

---

## [API key owner](https://discuss.elastic.co/t/api-key-owner/348167)

<div class="topic-metadata">

**Author:** [@mcosta](https://discuss.elastic.co/u/mcosta)\
**Replies:** 8\
**Last updated:** [December 3, 2023, 11:59pm UTC](https://discuss.elastic.co/t/api-key-owner/348167 "2023-12-03T23:59:14Z")

</div>

Hi all, Using Elastic Cloud V8.10.2 I need to create several API keys to be used on logstash. When API key is created on Kibana -\> Security -\> API Keys, it ends with the owner being my user. When API key is created o…

---

## [Big data on the one server without cluster](https://discuss.elastic.co/t/big-data-on-the-one-server-without-cluster/348512)

<div class="topic-metadata">

**Author:** [@habajol675](https://discuss.elastic.co/u/habajol675)\
**Replies:** 1\
**Last updated:** [December 3, 2023, 11:18pm UTC](https://discuss.elastic.co/t/big-data-on-the-one-server-without-cluster/348512 "2023-12-03T23:18:50Z")

</div>

Hello everyone, I am currently studying the work of elastic and plan to transfer the search to elastic. I'm calculating how much space my database will take up and realized that I need several disks. My database will wei…

---

## [Persistent CertificateException error on running any of the elasticsearch tools in docker](https://discuss.elastic.co/t/persistent-certificateexception-error-on-running-any-of-the-elasticsearch-tools-in-docker/348492)

<div class="topic-metadata">

**Author:** [@bere\_test](https://discuss.elastic.co/u/bere_test)\
**Replies:** 5\
**Last updated:** [December 3, 2023, 8:46pm UTC](https://discuss.elastic.co/t/persistent-certificateexception-error-on-running-any-of-the-elasticsearch-tools-in-docker/348492 "2023-12-03T20:46:17Z")

</div>

I have set up an Elasticsearch and Kibana stack with the docker-compose.yml file obtained from here - https://github.com/elastic/elasticsearch/blob/main/docs/reference/setup/install/docker/docker-compose.yml. I can run k…

---

## [Elasticsearch CPU 100% GC](https://discuss.elastic.co/t/elasticsearch-cpu-100-gc/348466)

<div class="topic-metadata">

**Author:** [@marcowiskhy](https://discuss.elastic.co/u/marcowiskhy)\
**Replies:** 5\
**Last updated:** [December 3, 2023, 7:56pm UTC](https://discuss.elastic.co/t/elasticsearch-cpu-100-gc/348466 "2023-12-03T19:56:23Z")

</div>

Hey guys, On the last day I decided to perform some operations in Elasticsearch. I had some indexes that were generated daily by Logstash, until I decided to use ILM to automatically manage and generate rollbacks. After…

---

## [Are we about to violate the Elastic License 2.0？](https://discuss.elastic.co/t/are-we-about-to-violate-the-elastic-license-2-0/348488)

<div class="topic-metadata">

**Author:** [@Chengbo\_He](https://discuss.elastic.co/u/Chengbo_He)\
**Replies:** 2\
**Last updated:** [December 3, 2023, 2:37pm UTC](https://discuss.elastic.co/t/are-we-about-to-violate-the-elastic-license-2-0/348488 "2023-12-03T14:37:05Z")

</div>

Our team plans to develop a product that is similar to a security situational awareness platform, and we will sell this product to customers as a commodity. However, customers cannot directly interact with Elasticsearch.…

---

## [Issues related to address location search in Elasticsearch](https://discuss.elastic.co/t/issues-related-to-address-location-search-in-elasticsearch/348469)

<div class="topic-metadata">

**Author:** [@fangyan](https://discuss.elastic.co/u/fangyan)\
**Replies:** 0\
**Last updated:** [December 2, 2023, 8:01am UTC](https://discuss.elastic.co/t/issues-related-to-address-location-search-in-elasticsearch/348469 "2023-12-02T08:01:50Z")

</div>

There is now a demand list for paginated queries. Within a 10 kilometer radius, the search is based on sales volume and LBS rules, while outside the 10 kilometer radius, the search is based on ratings and LBS rules. I no…

---

## [Email alert for exception](https://discuss.elastic.co/t/email-alert-for-exception/348077)

<div class="topic-metadata">

**Author:** [@kaushalshriyan](https://discuss.elastic.co/u/kaushalshriyan)\
**Replies:** 5\
**Last updated:** [December 2, 2023, 3:48am UTC](https://discuss.elastic.co/t/email-alert-for-exception/348077 "2023-12-02T03:48:38Z")

</div>

Hi, I am running the Elastic Stack on Red Hat Enterprise Linux release 8.8 (Ootpa) and the versions are as below. # rpm -qa | grep logstash logstash-8.11.0-1.x86\_64 # rpm -qa | grep elasticsearch elasticsearch-8.11.0-1…

---

## [Security update associated with CVE-2023-31418 has confusing wording](https://discuss.elastic.co/t/security-update-associated-with-cve-2023-31418-has-confusing-wording/348457)

<div class="topic-metadata">

**Author:** [@jlasica](https://discuss.elastic.co/u/jlasica)\
**Replies:** 1\
**Last updated:** [December 1, 2023, 8:48pm UTC](https://discuss.elastic.co/t/security-update-associated-with-cve-2023-31418-has-confusing-wording/348457 "2023-12-01T20:48:35Z")

</div>

According to this security update: Elasticsearch 8.9.0, 7.17.13 Security Update "Elastic Cloud Enterprise up to versions 2.13.3 and 3.6.0" -- does this mean that Elastic Cloud Enterprise is vulnerable all versions prior…

---

## [FScrawler "Failed to create elasticsearch client"](https://discuss.elastic.co/t/fscrawler-failed-to-create-elasticsearch-client/348438)

<div class="topic-metadata">

**Author:** [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Replies:** 1\
**Last updated:** [December 1, 2023, 5:42pm UTC](https://discuss.elastic.co/t/fscrawler-failed-to-create-elasticsearch-client/348438 "2023-12-01T17:42:45Z")

</div>

Hi, Im getting an error when I tried to run FScrawler to index a pdf to elasticsearch. Elastic version 8.9.2 on docker OS: redhat Firewall off Working curl: curl --cacert /u01/ca.crt https://localhost:9200 FScrawler…

---

## [I/O dispatch worker terminated abnormally](https://discuss.elastic.co/t/i-o-dispatch-worker-terminated-abnormally/348451)

<div class="topic-metadata">

**Author:** [@elaydi\_elagal](https://discuss.elastic.co/u/elaydi_elagal)\
**Replies:** 0\
**Last updated:** [December 1, 2023, 5:01pm UTC](https://discuss.elastic.co/t/i-o-dispatch-worker-terminated-abnormally/348451 "2023-12-01T17:01:18Z")

</div>

In our production environment we try to fetch all the records based on index, but getting exception "Request cannot be executed i/o reactor status stopped" with high concurrency, we've encountered occasional connection …

---

## [Optimizing Storage Costs for Historical Data in Elasticsearch on Azure: Seeking Community Advice](https://discuss.elastic.co/t/optimizing-storage-costs-for-historical-data-in-elasticsearch-on-azure-seeking-community-advice/348440)

<div class="topic-metadata">

**Author:** [@identifysun](https://discuss.elastic.co/u/identifysun)\
**Replies:** 0\
**Last updated:** [December 1, 2023, 3:41pm UTC](https://discuss.elastic.co/t/optimizing-storage-costs-for-historical-data-in-elasticsearch-on-azure-seeking-community-advice/348440 "2023-12-01T15:41:26Z")

</div>

I have an Elasticsearch cluster deployed on Azure. I need to retain historical data in Elasticsearch and currently use snapshot policies to store snapshots in Azure Blob storage. However, over time, I noticed that the st…

---

## [Transmission of logs in real time mode](https://discuss.elastic.co/t/transmission-of-logs-in-real-time-mode/348319)

<div class="topic-metadata">

**Author:** [@Aleksandr\_Terekhov](https://discuss.elastic.co/u/Aleksandr_Terekhov)\
**Replies:** 2\
**Last updated:** [December 1, 2023, 2:02pm UTC](https://discuss.elastic.co/t/transmission-of-logs-in-real-time-mode/348319 "2023-12-01T14:02:50Z")

</div>

Hello everybody Please tell me what the problem might be I have a mail server on which the filebeat agent is installed, it transfers data to another server on which logstash and elastic are installed I randomly displa…

---

## [How to change index rotation timezone for Elasticsearch 8.6 for UTC to localtimezone](https://discuss.elastic.co/t/how-to-change-index-rotation-timezone-for-elasticsearch-8-6-for-utc-to-localtimezone/348411)

<div class="topic-metadata">

**Author:** [@pix9](https://discuss.elastic.co/u/pix9)\
**Replies:** 3\
**Last updated:** [December 1, 2023, 1:49pm UTC](https://discuss.elastic.co/t/how-to-change-index-rotation-timezone-for-elasticsearch-8-6-for-utc-to-localtimezone/348411 "2023-12-01T13:49:57Z")

</div>

Hi everyone, I am facing an issue while running queries on Elasticsearch, we are unable to fetch data between 12:00 AM to 05:30 AM, issue no data can be retrived from index between given time. Upon further investigatio…

---

## [Change tie breaker on aggregation](https://discuss.elastic.co/t/change-tie-breaker-on-aggregation/348434)

<div class="topic-metadata">

**Author:** [@Raphael\_Fidelis](https://discuss.elastic.co/u/Raphael_Fidelis)\
**Replies:** 0\
**Last updated:** [December 1, 2023, 1:28pm UTC](https://discuss.elastic.co/t/change-tie-breaker-on-aggregation/348434 "2023-12-01T13:28:30Z")

</div>

Hello. As defined in the terms aggregation docs, Elastic uses alphabetical order as a tie-breaker for the aggregation results. However, I wanted to use the order that is returned by the query, i.e.: hits: \[ { …

---

## [How to correctly use \`search\_after\` for huge amount of records (100k+)?](https://discuss.elastic.co/t/how-to-correctly-use-search-after-for-huge-amount-of-records-100k/348426)

<div class="topic-metadata">

**Author:** [@MarinTakanov](https://discuss.elastic.co/u/MarinTakanov)\
**Replies:** 0\
**Last updated:** [December 1, 2023, 11:03am UTC](https://discuss.elastic.co/t/how-to-correctly-use-search-after-for-huge-amount-of-records-100k/348426 "2023-12-01T11:03:59Z")

</div>

Can someone explain how to use search\_after for more than 100k records without fetching 10k records just to get the sort value of the last record just to get the next 10k records? Here's an example: I have 100 100 reco…

---

## [Search on Array Field in ElasticSearch](https://discuss.elastic.co/t/search-on-array-field-in-elasticsearch/348406)

<div class="topic-metadata">

**Author:** [@Rakhshunda\_Noorein\_J](https://discuss.elastic.co/u/Rakhshunda_Noorein_J)\
**Replies:** 0\
**Last updated:** [December 1, 2023, 8:12am UTC](https://discuss.elastic.co/t/search-on-array-field-in-elasticsearch/348406 "2023-12-01T08:12:00Z")

</div>

Hello, I have inserted data to an index from a csv file. And I have an Ids field like this whose datatype is a text or a keyword. "IDs": \[ "a07f1c55-e34b-467d-bfe2-f65f7e01ae61,3e7083d6-4e0c-4f7f-ac81-0d7c131ab58…

---

## [Filebeat not working with pipeline nor \* in csv is working](https://discuss.elastic.co/t/filebeat-not-working-with-pipeline-nor-in-csv-is-working/348388)

<div class="topic-metadata">

**Author:** [@mastinder](https://discuss.elastic.co/u/mastinder)\
**Replies:** 5\
**Last updated:** [December 1, 2023, 7:59am UTC](https://discuss.elastic.co/t/filebeat-not-working-with-pipeline-nor-in-csv-is-working/348388 "2023-12-01T07:59:35Z")

</div>

PUT \_ingest/pipeline/csv\_pipeline { "description": "A pipeline to parse CSV data", "processors": \[ { "csv": { "field": "message", "target\_fields": \["cluster", "index", "ilm\_policy", "time\_si…

---

## [Cannot search my pdf files](https://discuss.elastic.co/t/cannot-search-my-pdf-files/348297)

<div class="topic-metadata">

**Author:** [@Mandy\_Poon](https://discuss.elastic.co/u/Mandy_Poon)\
**Replies:** 2\
**Last updated:** [December 1, 2023, 7:44am UTC](https://discuss.elastic.co/t/cannot-search-my-pdf-files/348297 "2023-12-01T07:44:33Z")

</div>

I have a pdf file and there is a wording "XXX Contract ID - 170458" on the pdf. However I cannot search my file if I use "Contract ID - 170458". (I can search the pdf file if I use "170458") Anyone can help? Thank yo…

---

## [Limit on number of remote clusters in Cross-cluster search](https://discuss.elastic.co/t/limit-on-number-of-remote-clusters-in-cross-cluster-search/348395)

<div class="topic-metadata">

**Author:** [@Naveen\_Kumar\_S](https://discuss.elastic.co/u/Naveen_Kumar_S)\
**Replies:** 0\
**Last updated:** [December 1, 2023, 5:52am UTC](https://discuss.elastic.co/t/limit-on-number-of-remote-clusters-in-cross-cluster-search/348395 "2023-12-01T05:52:03Z")

</div>

Brief Info: I am planning to create a multi-cluster (around 50 clusters) Elasticsearch setup to store a large amount of data (around 7 years of enterprise data). This number is based on thorough planning considering the…

---

## [How to limit the dataset size of elastic/security ESRally track](https://discuss.elastic.co/t/how-to-limit-the-dataset-size-of-elastic-security-esrally-track/348281)

<div class="topic-metadata">

**Author:** [@VidR](https://discuss.elastic.co/u/VidR)\
**Replies:** 0\
**Last updated:** [November 30, 2023, 1:01am UTC](https://discuss.elastic.co/t/how-to-limit-the-dataset-size-of-elastic-security-esrally-track/348281 "2023-11-30T01:01:05Z")

</div>

I am running esrally elastic/security track on ESRally version 2.7.0. By default, it downloads the following datasets, with total size of 128GB. but I only need ~30-50GB input dataset size. rally@benchmark-bqfd7:~/.ral…

---

## [Problema de thread\_pool.write.queue\_size](https://discuss.elastic.co/t/problema-de-thread-pool-write-queue-size/348387)

<div class="topic-metadata">

**Author:** [@Kelvin\_A\_Escobar\_Mor](https://discuss.elastic.co/u/Kelvin_A_Escobar_Mor)\
**Replies:** 0\
**Last updated:** [December 1, 2023, 3:41am UTC](https://discuss.elastic.co/t/problema-de-thread-pool-write-queue-size/348387 "2023-12-01T03:41:27Z")

</div>

Tengo problema con encolamiento en mis cluster esperimento problema de rendimeiento y en ocaciones mi cluster se cae por carga quisera saber cual es una buena alternativa para abordar temas de thread\_pool.write.queue\_siz…

---

## [When I try to mount some file to a docker elasticsearchcontainer, it always has some errors like no such file or directory](https://discuss.elastic.co/t/when-i-try-to-mount-some-file-to-a-docker-elasticsearchcontainer-it-always-has-some-errors-like-no-such-file-or-directory/348383)

<div class="topic-metadata">

**Author:** [@nmc10](https://discuss.elastic.co/u/nmc10)\
**Replies:** 2\
**Last updated:** [December 1, 2023, 3:39am UTC](https://discuss.elastic.co/t/when-i-try-to-mount-some-file-to-a-docker-elasticsearchcontainer-it-always-has-some-errors-like-no-such-file-or-directory/348383 "2023-12-01T03:39:14Z")

</div>

You can see these image to understand what I mean. I even run a test container and use ls command to check if the file existed but although it exist in the container, it still shows the error that it missed when I starte…

---

## [Auto email when get alerts on elastic](https://discuss.elastic.co/t/auto-email-when-get-alerts-on-elastic/348385)

<div class="topic-metadata">

**Author:** [@wang4321](https://discuss.elastic.co/u/wang4321)\
**Replies:** 0\
**Last updated:** [December 1, 2023, 3:38am UTC](https://discuss.elastic.co/t/auto-email-when-get-alerts-on-elastic/348385 "2023-12-01T03:38:01Z")

</div>

Hi! Can I know about auto emailing when I get alerts on elastic

---

## [How can I get a client ip of search request in ielasticsearch?](https://discuss.elastic.co/t/how-can-i-get-a-client-ip-of-search-request-in-ielasticsearch/348284)

<div class="topic-metadata">

**Author:** [@yunpeng.jiangyp](https://discuss.elastic.co/u/yunpeng.jiangyp)\
**Replies:** 3\
**Last updated:** [December 1, 2023, 2:44am UTC](https://discuss.elastic.co/t/how-can-i-get-a-client-ip-of-search-request-in-ielasticsearch/348284 "2023-12-01T02:44:12Z")

</div>

Hi guys: I found a slow search request , but i didn't know the search request's client ip . Can I get a client ip of search request in elasticsearch?

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=170)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=172)
