# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=172

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 173

---

## [Log.original field lost with upgrade 8.6.1 from 1.5.3](https://discuss.elastic.co/t/log-original-field-lost-with-upgrade-8-6-1-from-1-5-3/348363)

<div class="topic-metadata">

**Author:** [@ridvandev](https://discuss.elastic.co/u/ridvandev)\
**Replies:** 3\
**Last updated:** [November 30, 2023, 11:25pm UTC](https://discuss.elastic.co/t/log-original-field-lost-with-upgrade-8-6-1-from-1-5-3/348363 "2023-11-30T23:25:06Z")

</div>

We used to use the log.original field a lot for our searches in Kibana, but since the upgrade of Elastic.CommonSchema.Nlog package, I can't seem to find this field anymore. Also, it looks like the log template we depend …

---

## [NodeEnvironment.assertEnvIsLocked threw java.io.IOException: The device is not ready](https://discuss.elastic.co/t/nodeenvironment-assertenvislocked-threw-java-io-ioexception-the-device-is-not-ready/348089)

<div class="topic-metadata">

**Author:** [@blademan](https://discuss.elastic.co/u/blademan)\
**Replies:** 3\
**Last updated:** [November 30, 2023, 8:46pm UTC](https://discuss.elastic.co/t/nodeenvironment-assertenvislocked-threw-java-io-ioexception-the-device-is-not-ready/348089 "2023-11-30T20:46:15Z")

</div>

ES is deployed on an Azure VMSS (Windows VMs). It's throwing java.io.IOException "The device is not ready" on some VMs when creating shards, while working well on some other VMs at the same time. Here is what the except…

---

## [Filebeat Context Error](https://discuss.elastic.co/t/filebeat-context-error/348366)

<div class="topic-metadata">

**Author:** [@bigdaddy0918](https://discuss.elastic.co/u/bigdaddy0918)\
**Replies:** 0\
**Last updated:** [November 30, 2023, 8:41pm UTC](https://discuss.elastic.co/t/filebeat-context-error/348366 "2023-11-30T20:41:57Z")

</div>

I was able to push a new CEL input to Filebeat v8.7.1 via puppet. When we launch filebeat v.8.7.1 I see this message pop up in the log: {"log.level":"info","@timestamp":"2023-11-30T19:59:28.167Z","log.logger":"input.ce…

---

## [Can not create a document has mutlipolygon having hole](https://discuss.elastic.co/t/can-not-create-a-document-has-mutlipolygon-having-hole/348177)

<div class="topic-metadata">

**Author:** [@Sai\_Suvam\_Patnaik](https://discuss.elastic.co/u/Sai_Suvam_Patnaik)\
**Replies:** 2\
**Last updated:** [November 30, 2023, 6:31pm UTC](https://discuss.elastic.co/t/can-not-create-a-document-has-mutlipolygon-having-hole/348177 "2023-11-30T18:31:07Z")

</div>

Hi, can anyone help me I am facing a following. Summary Can not create a document has mutlipolygon having hole. I do not know why responses reason is correct or this is bug? I have visualize the multipolygon, using …

---

## [Mapping in the new .NET client V8](https://discuss.elastic.co/t/mapping-in-the-new-net-client-v8/348357)

<div class="topic-metadata">

**Author:** [@MountainMoon](https://discuss.elastic.co/u/MountainMoon)\
**Replies:** 0\
**Last updated:** [November 30, 2023, 6:29pm UTC](https://discuss.elastic.co/t/mapping-in-the-new-net-client-v8/348357 "2023-11-30T18:29:34Z")

</div>

I'm trying to write a mapping function using V8 client library. But there is not much i can configure. For example in the NEST V7, i can specify analyzer, multifields to a certain field via fluent mapping: ''' .Text(tt…

---

## [Failed to CompressedXContent on RestHighLevelClient 7.13](https://discuss.elastic.co/t/failed-to-compressedxcontent-on-resthighlevelclient-7-13/348345)

<div class="topic-metadata">

**Author:** [@avnere](https://discuss.elastic.co/u/avnere)\
**Replies:** 0\
**Last updated:** [November 30, 2023, 4:30pm UTC](https://discuss.elastic.co/t/failed-to-compressedxcontent-on-resthighlevelclient-7-13/348345 "2023-11-30T16:30:20Z")

</div>

Hi, I am getting the following exception when creatin new CompressedXContent for Template instance ElasticsearchParseException\[Failed to parse content to map\]; nested: JsonParseException\[Unexpected character ('p' (code…

---

## [How to use snapshot repo url](https://discuss.elastic.co/t/how-to-use-snapshot-repo-url/348274)

<div class="topic-metadata">

**Author:** [@Harper\_S1](https://discuss.elastic.co/u/Harper_S1)\
**Replies:** 1\
**Last updated:** [November 30, 2023, 4:19pm UTC](https://discuss.elastic.co/t/how-to-use-snapshot-repo-url/348274 "2023-11-30T16:19:03Z")

</div>

Hi, We are creating a parallel cluster and we need to migrate all the data. I saw the option where we can take the snapshot on existing cluster and create a repo url which can be used by another cluster and we can resto…

---

## [How can fill logstash output in filebeat.yml file](https://discuss.elastic.co/t/how-can-fill-logstash-output-in-filebeat-yml-file/346556)

<div class="topic-metadata">

**Author:** [@baber1223](https://discuss.elastic.co/u/baber1223)\
**Replies:** 1\
**Last updated:** [November 30, 2023, 4:05pm UTC](https://discuss.elastic.co/t/how-can-fill-logstash-output-in-filebeat-yml-file/346556 "2023-11-30T16:05:07Z")

</div>

This my elasticsearch output part in filebeat.yml file but I want to send logs to logstash # ---------------------------- Elasticsearch Output ---------------------------- output.elasticsearch: # Array of hosts to con…

---

## [Trouble Finding Most Efficient Way to Optimize My Elastic Stack](https://discuss.elastic.co/t/trouble-finding-most-efficient-way-to-optimize-my-elastic-stack/348342)

<div class="topic-metadata">

**Author:** [@jreyes25](https://discuss.elastic.co/u/jreyes25)\
**Replies:** 0\
**Last updated:** [November 30, 2023, 3:36pm UTC](https://discuss.elastic.co/t/trouble-finding-most-efficient-way-to-optimize-my-elastic-stack/348342 "2023-11-30T15:36:47Z")

</div>

Hello, I've been trying to play around with my settings to try to optimize my Elastic Stack. My main goal, right now, is to have my searches load faster. For example, when I load my dashboards, it takes 30 seconds to 1+…

---

## [ML Anomaly Job with exclude\_frequent option](https://discuss.elastic.co/t/ml-anomaly-job-with-exclude-frequent-option/348047)

<div class="topic-metadata">

**Author:** [@marmai16](https://discuss.elastic.co/u/marmai16)\
**Replies:** 1\
**Last updated:** [November 30, 2023, 2:53pm UTC](https://discuss.elastic.co/t/ml-anomaly-job-with-exclude-frequent-option/348047 "2023-11-30T14:53:51Z")

</div>

Hello everyone, i was reading through the docs and became curious Say i create two detectors. One detector is high\_sum(a) over b The other detector is high\_sum(a) by c. Now, if i define exclude\_frequent = over for …

---

## [Elasticsearch Query](https://discuss.elastic.co/t/elasticsearch-query/347768)

<div class="topic-metadata">

**Author:** [@Brian-cf1](https://discuss.elastic.co/u/Brian-cf1)\
**Replies:** 3\
**Last updated:** [November 30, 2023, 2:41pm UTC](https://discuss.elastic.co/t/elasticsearch-query/347768 "2023-11-30T14:41:57Z")

</div>

How do i exclude multiple keywords from a field ? I need the following logic but its not letting me include 2 wild cards "must\_not": \[ { "wildcard": { "error.message": { "value": …

---

## [Filebeat reads logs from various locations?](https://discuss.elastic.co/t/filebeat-reads-logs-from-various-locations/348332)

<div class="topic-metadata">

**Author:** [@Satsan](https://discuss.elastic.co/u/Satsan)\
**Replies:** 1\
**Last updated:** [November 30, 2023, 2:16pm UTC](https://discuss.elastic.co/t/filebeat-reads-logs-from-various-locations/348332 "2023-11-30T14:16:27Z")

</div>

Filebeat reads logs from various locations in same yml file and sends them to the ELK (Elasticsearch, Logstash, and Kibana) stack for processing and analysis? For instance: -log.file.path: /etc/home/usr/logs -log.fil…

---

## [Elastic docs in PDF](https://discuss.elastic.co/t/elastic-docs-in-pdf/348305)

<div class="topic-metadata">

**Author:** [@lduvnjak](https://discuss.elastic.co/u/lduvnjak)\
**Replies:** 3\
**Last updated:** [November 30, 2023, 11:58am UTC](https://discuss.elastic.co/t/elastic-docs-in-pdf/348305 "2023-11-30T11:58:32Z")

</div>

This is a very simple question but I just wanna make sure. Does Elasticsearch have it's documentation in PDF format available for download anywhere? Thanks for any help in advance! Cheers, Luka

---

## [Unable to connect to elastic search with certificates](https://discuss.elastic.co/t/unable-to-connect-to-elastic-search-with-certificates/348325)

<div class="topic-metadata">

**Author:** [@shrikar18](https://discuss.elastic.co/u/shrikar18)\
**Replies:** 0\
**Last updated:** [November 30, 2023, 10:48am UTC](https://discuss.elastic.co/t/unable-to-connect-to-elastic-search-with-certificates/348325 "2023-11-30T10:48:52Z")

</div>

hi everyone , iam new to elasticsearch i have Elasticsearch deployed as pod and iam trying to check the status with a curl command i used https curl --cacert /root/http\_ca.crt -u elastic:$ELASTIC\_PASSWORD protocol://…

---

## [Elastics/kibana coonect with IBM ace server thru the APM server](https://discuss.elastic.co/t/elastics-kibana-coonect-with-ibm-ace-server-thru-the-apm-server/348289)

<div class="topic-metadata">

**Author:** [@kasunpurnima](https://discuss.elastic.co/u/kasunpurnima)\
**Replies:** 0\
**Last updated:** [November 30, 2023, 5:55am UTC](https://discuss.elastic.co/t/elastics-kibana-coonect-with-ibm-ace-server-thru-the-apm-server/348289 "2023-11-30T05:55:40Z")

</div>

Hi is there anyone is connect elastc with IBM aces server ?

---

## [Elasticsearch statefulset deployment failed with 8.11.1 image version](https://discuss.elastic.co/t/elasticsearch-statefulset-deployment-failed-with-8-11-1-image-version/348286)

<div class="topic-metadata">

**Author:** [@Subhajit](https://discuss.elastic.co/u/Subhajit)\
**Replies:** 0\
**Last updated:** [November 30, 2023, 4:53am UTC](https://discuss.elastic.co/t/elasticsearch-statefulset-deployment-failed-with-8-11-1-image-version/348286 "2023-11-30T04:53:31Z")

</div>

Hello Team, currently I am facing this below error while deploying latest \[elasticsearch:8.11.1\] image with elasticsearch statefulset helm chart. 2023-11-27T17:50:15.202018883Z {"@timestamp":"2023-11-27T17:50:15.200Z",…

---

## [Fuzz and stemmer](https://discuss.elastic.co/t/fuzz-and-stemmer/348277)

<div class="topic-metadata">

**Author:** [@staix](https://discuss.elastic.co/u/staix)\
**Replies:** 0\
**Last updated:** [November 29, 2023, 9:59pm UTC](https://discuss.elastic.co/t/fuzz-and-stemmer/348277 "2023-11-29T21:59:36Z")

</div>

Hello. if there is a mistake in the word, then when using fuzz, is it possible to somehow launch a stemmer after fuzz

---

## [.NET Core - DefaultMappingFor\<T\> hits multiple indexes](https://discuss.elastic.co/t/net-core-defaultmappingfor-t-hits-multiple-indexes/348250)

<div class="topic-metadata">

**Author:** [@kruegeba](https://discuss.elastic.co/u/kruegeba)\
**Replies:** 0\
**Last updated:** [November 29, 2023, 3:22pm UTC](https://discuss.elastic.co/t/net-core-defaultmappingfor-t-hits-multiple-indexes/348250 "2023-11-29T15:22:46Z")

</div>

We are using the Elastic.Clients.Elasticsearch 8.1 package in our .NET Core application. We are trying to set up the ability to use a single Elastic client, and hit different indexes based on the model type. We have the …

---

## [Fetch multiples traces with a common id](https://discuss.elastic.co/t/fetch-multiples-traces-with-a-common-id/348202)

<div class="topic-metadata">

**Author:** [@casteillet](https://discuss.elastic.co/u/casteillet)\
**Replies:** 1\
**Last updated:** [November 29, 2023, 3:15pm UTC](https://discuss.elastic.co/t/fetch-multiples-traces-with-a-common-id/348202 "2023-11-29T15:15:58Z")

</div>

Hi, I'm new with the Elasticsearch web interface. I'm trying to display player session results on the dashboard. I have three dropdown filters, with difficulty, level selected and name of the player (actor). During a s…

---

## [Elasticsearch's Docuements count dosen't match the exact number of input log lines](https://discuss.elastic.co/t/elasticsearchs-docuements-count-dosent-match-the-exact-number-of-input-log-lines/348217)

<div class="topic-metadata">

**Author:** [@Dokh\_Ahmed](https://discuss.elastic.co/u/Dokh_Ahmed)\
**Replies:** 9\
**Last updated:** [November 29, 2023, 3:01pm UTC](https://discuss.elastic.co/t/elasticsearchs-docuements-count-dosent-match-the-exact-number-of-input-log-lines/348217 "2023-11-29T15:01:30Z")

</div>

have a log file containing 2044 lines, but after indexing into Elasticsearch using Logstash, I find only 2043 documents. I suspect that an empty line in the log file might have been skipped by Logstash during indexing. I…

---

## [ML Anomaly Detection count of Processed Records](https://discuss.elastic.co/t/ml-anomaly-detection-count-of-processed-records/348234)

<div class="topic-metadata">

**Author:** [@marmai16](https://discuss.elastic.co/u/marmai16)\
**Replies:** 0\
**Last updated:** [November 29, 2023, 1:27pm UTC](https://discuss.elastic.co/t/ml-anomaly-detection-count-of-processed-records/348234 "2023-11-29T13:27:31Z")

</div>

Hello everyone, i deployed several anomaly detection jobs with different query\_delay parameters to evaluate which one fits best without losing documents or being to much behind real-time. What's interesting here is tha…

---

## [LDAP Elasticsearch](https://discuss.elastic.co/t/ldap-elasticsearch/348205)

<div class="topic-metadata">

**Author:** [@Manal\_A](https://discuss.elastic.co/u/Manal_A)\
**Replies:** 2\
**Last updated:** [November 29, 2023, 12:22pm UTC](https://discuss.elastic.co/t/ldap-elasticsearch/348205 "2023-11-29T12:22:33Z")

</div>

Hello , I want to know how to connect Elasticsearch to an external LDAP, and if I am in a cluster that contains multiple nodes, do I need to configure LDAP on all Elasticsearch nodes or just one of them (and wich one :…

---

## [Updating entities indexed by Hibernate Search](https://discuss.elastic.co/t/updating-entities-indexed-by-hibernate-search/348207)

<div class="topic-metadata">

**Author:** [@Muhammad\_namjas](https://discuss.elastic.co/u/Muhammad_namjas)\
**Replies:** 0\
**Last updated:** [November 29, 2023, 9:25am UTC](https://discuss.elastic.co/t/updating-entities-indexed-by-hibernate-search/348207 "2023-11-29T09:25:38Z")

</div>

I created a new entity connected to Hibernate Elastic Search and indexed it. Upon retrieving the indexed data, I noticed that updating the entity using the student ID resulted in deleting the existing data and re-inserti…

---

## [FSCrawler, custom Tika parser](https://discuss.elastic.co/t/fscrawler-custom-tika-parser/348219)

<div class="topic-metadata">

**Author:** [@Eldar\_Madyarov](https://discuss.elastic.co/u/Eldar_Madyarov)\
**Replies:** 0\
**Last updated:** [November 29, 2023, 11:06am UTC](https://discuss.elastic.co/t/fscrawler-custom-tika-parser/348219 "2023-11-29T11:06:17Z")

</div>

I have created a custom Tika Parser, added a new type to custom-mimetypes.xml, built a jar. Then a put this jar to FSCrawler lib directory. But still FSCrawler doesn't see my Parser and using EmptyParser... What did I …

---

## [Search requests still get rejected at the same number of queued requests despite having increased \`queue\_size\`](https://discuss.elastic.co/t/search-requests-still-get-rejected-at-the-same-number-of-queued-requests-despite-having-increased-queue-size/346716)

<div class="topic-metadata">

**Author:** [@JvSPV](https://discuss.elastic.co/u/JvSPV)\
**Replies:** 1\
**Last updated:** [November 29, 2023, 10:43am UTC](https://discuss.elastic.co/t/search-requests-still-get-rejected-at-the-same-number-of-queued-requests-despite-having-increased-queue-size/346716 "2023-11-29T10:43:06Z")

</div>

We have a cluster of five nodes. For a lot of processing, our system sends search requests to Elasticsearch 7.17 in bursts, which fill up its queue\_size and Elasticsearch will start rejecting requests. However, our syst…

---

## [ELK Compatibility with Red Hat Java 8](https://discuss.elastic.co/t/elk-compatibility-with-red-hat-java-8/348198)

<div class="topic-metadata">

**Author:** [@swarali\_vartak](https://discuss.elastic.co/u/swarali_vartak)\
**Replies:** 1\
**Last updated:** [November 29, 2023, 8:22am UTC](https://discuss.elastic.co/t/elk-compatibility-with-red-hat-java-8/348198 "2023-11-29T08:22:50Z")

</div>

Hi, Current version of ELK Setup is 7.11.x Migrating OS from Oracle Java to Red Hat Java 8. Is elasticsearch 7.11 compatible with Red Hat java 8 ? Awaiting response. Thank you.

---

## [Frequent "No snapshot information" on default client- Azure repository](https://discuss.elastic.co/t/frequent-no-snapshot-information-on-default-client-azure-repository/348195)

<div class="topic-metadata">

**Author:** [@Anushree](https://discuss.elastic.co/u/Anushree)\
**Replies:** 0\
**Last updated:** [November 29, 2023, 6:48am UTC](https://discuss.elastic.co/t/frequent-no-snapshot-information-on-default-client-azure-repository/348195 "2023-11-29T06:48:31Z")

</div>

We are consistently encountering the "No snapshot information" message on the 'default' client for the 'Azure' repository type, even though snapshots exist in Azure containers. Despite the repository connection verificat…

---

## [Rollover Indexes Using ILM](https://discuss.elastic.co/t/rollover-indexes-using-ilm/348190)

<div class="topic-metadata">

**Author:** [@krish1](https://discuss.elastic.co/u/krish1)\
**Replies:** 1\
**Last updated:** [November 29, 2023, 5:51am UTC](https://discuss.elastic.co/t/rollover-indexes-using-ilm/348190 "2023-11-29T05:51:05Z")

</div>

I am currently using ES version 7.17.0 and trying out rollover indexes using the ILM. I have read through the documentation and my use case is to rollover my ES index every Monday midnight once a week i.e, rollover by ag…

---

## [Restoring a single index for a datastream cheatsheet](https://discuss.elastic.co/t/restoring-a-single-index-for-a-datastream-cheatsheet/348180)

<div class="topic-metadata">

**Author:** [@seanziee](https://discuss.elastic.co/u/seanziee)\
**Replies:** 0\
**Last updated:** [November 28, 2023, 9:52pm UTC](https://discuss.elastic.co/t/restoring-a-single-index-for-a-datastream-cheatsheet/348180 "2023-11-28T21:52:22Z")

</div>

I feel like it took me a long time to figure this out and it may be helpful for others. These are the sets of commands that I send when I need to get back an index that already got deleted by ILM but I want to see the da…

---

## [Not able to Add Node to Existing Cluster](https://discuss.elastic.co/t/not-able-to-add-node-to-existing-cluster/348068)

<div class="topic-metadata">

**Author:** [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Replies:** 7\
**Last updated:** [November 28, 2023, 4:35pm UTC](https://discuss.elastic.co/t/not-able-to-add-node-to-existing-cluster/348068 "2023-11-28T16:35:44Z")

</div>

Hi Team, I had requirement to create two node cluster of 8.9.2 version. we did Elasticsearch installation on both nodes through RPM based. I had generated enrollment token (elasticsearch-create-enrollment-token -s node …

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=171)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=173)
