# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=173

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 174

---

## [CCS requires wildcard after index name to search or always returns 404](https://discuss.elastic.co/t/ccs-requires-wildcard-after-index-name-to-search-or-always-returns-404/348091)

<div class="topic-metadata">

**Author:** [@Doc\_Kaos](https://discuss.elastic.co/u/Doc_Kaos)\
**Replies:** 1\
**Last updated:** [November 28, 2023, 2:12pm UTC](https://discuss.elastic.co/t/ccs-requires-wildcard-after-index-name-to-search-or-always-returns-404/348091 "2023-11-28T14:12:31Z")

</div>

Quick bit about the setup: Dedicated CCS cluster (no local indices, except for monitoring) v7.17.10 Two clusters clusterA and clusterB are connected as remote clusters v7.4.1 All of these searches are performed on the…

---

## [Create a new index with the query's result](https://discuss.elastic.co/t/create-a-new-index-with-the-querys-result/347353)

<div class="topic-metadata">

**Author:** [@Mathieu64](https://discuss.elastic.co/u/Mathieu64)\
**Replies:** 1\
**Last updated:** [November 28, 2023, 2:00pm UTC](https://discuss.elastic.co/t/create-a-new-index-with-the-querys-result/347353 "2023-11-28T14:00:26Z")

</div>

Hi, I want to send the query's result in a new index : GET myindex/\_search { "size" : 0, "\_source" : false, "aggregations" : { "groupby" : { "composite" : { "size" : 1000, "sources" : \[ …

---

## [Elasticsearch NEST client GetSnapshotRequest method is not returning index\_details](https://discuss.elastic.co/t/elasticsearch-nest-client-getsnapshotrequest-method-is-not-returning-index-details/348015)

<div class="topic-metadata">

**Author:** [@EVINDX](https://discuss.elastic.co/u/EVINDX)\
**Replies:** 1\
**Last updated:** [November 28, 2023, 1:49pm UTC](https://discuss.elastic.co/t/elasticsearch-nest-client-getsnapshotrequest-method-is-not-returning-index-details/348015 "2023-11-28T13:49:00Z")

</div>

I'm using NEST version 7.17 to communicate with Elasticsearch 7.17 I have a snapshot created without any issues. I'm able to restore the snapshot as well. I can get the Elasticsearch index details in the snapshot via t…

---

## [No alive nodes. All the 5 nodes seem to be down](https://discuss.elastic.co/t/no-alive-nodes-all-the-5-nodes-seem-to-be-down/348138)

<div class="topic-metadata">

**Author:** [@Test\_Owner](https://discuss.elastic.co/u/Test_Owner)\
**Replies:** 1\
**Last updated:** [November 28, 2023, 1:15pm UTC](https://discuss.elastic.co/t/no-alive-nodes-all-the-5-nodes-seem-to-be-down/348138 "2023-11-28T13:15:56Z")

</div>

"No alive nodes. All the 5 nodes seem to be down". I get such a problem when executing a request. Previously, the request was executed correctly, but with the increase in records, I have such a problem. What can you adv…

---

## [Drastic reduction in query performance when using replicas](https://discuss.elastic.co/t/drastic-reduction-in-query-performance-when-using-replicas/348090)

<div class="topic-metadata">

**Author:** [@diegomansua](https://discuss.elastic.co/u/diegomansua)\
**Replies:** 6\
**Last updated:** [November 28, 2023, 1:03pm UTC](https://discuss.elastic.co/t/drastic-reduction-in-query-performance-when-using-replicas/348090 "2023-11-28T13:03:15Z")

</div>

Hi everyone. We're facing an issue whereby having replicas drastically decreases query performance. Our set up consists of 3 nodes running ES 7.16 with 4GB heap each. We have around 1.6 million documents that contain a…

---

## [Anomaly Jobs - General Strategies to reduce false positives](https://discuss.elastic.co/t/anomaly-jobs-general-strategies-to-reduce-false-positives/348094)

<div class="topic-metadata">

**Author:** [@marmai16](https://discuss.elastic.co/u/marmai16)\
**Replies:** 2\
**Last updated:** [November 28, 2023, 12:58pm UTC](https://discuss.elastic.co/t/anomaly-jobs-general-strategies-to-reduce-false-positives/348094 "2023-11-28T12:58:30Z")

</div>

Hello everybody, i'am struggling to baseline an anomaly detection job (filters are not really helping so far). What are the general strategies or factors which drive the model to become, simply put, more "insensitive" …

---

## [Problem in send log consistently with filebeat](https://discuss.elastic.co/t/problem-in-send-log-consistently-with-filebeat/348121)

<div class="topic-metadata">

**Author:** [@behzad\_alipoor](https://discuss.elastic.co/u/behzad_alipoor)\
**Replies:** 0\
**Last updated:** [November 28, 2023, 10:07am UTC](https://discuss.elastic.co/t/problem-in-send-log-consistently-with-filebeat/348121 "2023-11-28T10:07:30Z")

</div>

i have problem in sending logs with filebeat to elasticsearch . it sends data and pauses and after miliseconds it sends again data . i set this config : scan\_frequency: 10s close\_inactive: 20s ignore\_older: 30s …

---

## [OpenAI connect with elastic search datasource](https://discuss.elastic.co/t/openai-connect-with-elastic-search-datasource/347901)

<div class="topic-metadata">

**Author:** [@Saurabh\_Agrawal2](https://discuss.elastic.co/u/Saurabh_Agrawal2)\
**Replies:** 5\
**Last updated:** [November 28, 2023, 9:59am UTC](https://discuss.elastic.co/t/openai-connect-with-elastic-search-datasource/347901 "2023-11-28T09:59:18Z")

</div>

I am trying call openAI with my custom index created on Elastic search but when I try to run it I am getting following error: openai.BadRequestError: Error code: 400 - {'error': {'requestid': 'aaa-bbb-404d-8a12-3da23608…

---

## [Eck on kubeadm](https://discuss.elastic.co/t/eck-on-kubeadm/348104)

<div class="topic-metadata">

**Author:** [@Swapnil2](https://discuss.elastic.co/u/Swapnil2)\
**Replies:** 0\
**Last updated:** [November 28, 2023, 4:41am UTC](https://discuss.elastic.co/t/eck-on-kubeadm/348104 "2023-11-28T04:41:06Z")

</div>

I created 3 node kubeadm cluster. I starting setup elasticsearch using eck.when I changed count 1from 3 then other pod in pending status...plz give

---

## [Elasticsearch TSDS and geo\_point as dimension](https://discuss.elastic.co/t/elasticsearch-tsds-and-geo-point-as-dimension/347674)

<div class="topic-metadata">

**Author:** [@berg](https://discuss.elastic.co/u/berg)\
**Replies:** 2\
**Last updated:** [November 27, 2023, 10:54pm UTC](https://discuss.elastic.co/t/elasticsearch-tsds-and-geo-point-as-dimension/347674 "2023-11-27T22:54:33Z")

</div>

We are migrating some data sources across to a new cluster, and we have some wireless metrics that count the number of connected devices on each floor of each building. This seemed like an effective use case for TSDS, a…

---

## [Alerting on compared aggregations](https://discuss.elastic.co/t/alerting-on-compared-aggregations/348075)

<div class="topic-metadata">

**Author:** [@GD\_DV](https://discuss.elastic.co/u/GD_DV)\
**Replies:** 1\
**Last updated:** [November 27, 2023, 8:51pm UTC](https://discuss.elastic.co/t/alerting-on-compared-aggregations/348075 "2023-11-27T20:51:06Z")

</div>

Hello folks, I'm hoping to get a little insight from experienced folks as to how to approach my problem. I have a bunch of devices creating documents in my index. Each document is identified as belonging to a particular…

---

## [Unable to search phrase anywhere in the text](https://discuss.elastic.co/t/unable-to-search-phrase-anywhere-in-the-text/348081)

<div class="topic-metadata">

**Author:** [@Mistgun\_Scripts](https://discuss.elastic.co/u/Mistgun_Scripts)\
**Replies:** 0\
**Last updated:** [November 27, 2023, 8:10pm UTC](https://discuss.elastic.co/t/unable-to-search-phrase-anywhere-in-the-text/348081 "2023-11-27T20:10:12Z")

</div>

So I'm trying to search for a given phrase in text, already tried different methods e.g match\_phrase/query\_string but I still get invalid results. Let's say we have such documents with titles: "This is a phrase" "Anot…

---

## [Unable to connect to Elasticsearch. Error: index\_not\_found\_exception index\_not\_found\_exception: no such index \[.kibana\]](https://discuss.elastic.co/t/unable-to-connect-to-elasticsearch-error-index-not-found-exception-index-not-found-exception-no-such-index-kibana/348026)

<div class="topic-metadata">

**Author:** [@abkrim](https://discuss.elastic.co/u/abkrim)\
**Replies:** 1\
**Last updated:** [November 27, 2023, 6:31pm UTC](https://discuss.elastic.co/t/unable-to-connect-to-elasticsearch-error-index-not-found-exception-index-not-found-exception-no-such-index-kibana/348026 "2023-11-27T18:31:54Z")

</div>

I'm trying to install and configure a simple node on my local machine using Docker, following the documentation. However, when I try to execute the first step of the Kibana configuration and paste the enrollment token, …

---

## [Failed migration of system indices (.triggered\_watches) with Upgrade Assistant using v7.17.14](https://discuss.elastic.co/t/failed-migration-of-system-indices-triggered-watches-with-upgrade-assistant-using-v7-17-14/346966)

<div class="topic-metadata">

**Author:** [@AEA27](https://discuss.elastic.co/u/AEA27)\
**Replies:** 3\
**Last updated:** [November 27, 2023, 4:37pm UTC](https://discuss.elastic.co/t/failed-migration-of-system-indices-triggered-watches-with-upgrade-assistant-using-v7-17-14/346966 "2023-11-27T16:37:55Z")

</div>

Using the upgrade assistant the migration of system indices fails for watcher which we're using. We're using elastic cloud and trying to migrate to Elasticsearch 8. Another fun fact is that the index that is failing to …

---

## [How to view file content](https://discuss.elastic.co/t/how-to-view-file-content/348036)

<div class="topic-metadata">

**Author:** [@min\_liu](https://discuss.elastic.co/u/min_liu)\
**Replies:** 4\
**Last updated:** [November 27, 2023, 3:45pm UTC](https://discuss.elastic.co/t/how-to-view-file-content/348036 "2023-11-27T15:45:03Z")

</div>

I would like to know what is written inside the Elasticsearch data directory file. Is there a tool available to view the file content? thanks

---

## [Elastic Forwarder for Cloudwatch](https://discuss.elastic.co/t/elastic-forwarder-for-cloudwatch/348056)

<div class="topic-metadata">

**Author:** [@Jasonespo](https://discuss.elastic.co/u/Jasonespo)\
**Replies:** 0\
**Last updated:** [November 27, 2023, 1:49pm UTC](https://discuss.elastic.co/t/elastic-forwarder-for-cloudwatch/348056 "2023-11-27T13:49:39Z")

</div>

Hi, We're using the Elastic Serverless forwarder with Cloudwatch and I was wondering if anyone can clarify these questions? What are the parameters around the subscription filter, is it every time a new log hits Cloud…

---

## [Metricbeat, filebeat](https://discuss.elastic.co/t/metricbeat-filebeat/348049)

<div class="topic-metadata">

**Author:** [@Haytham\_Shammout](https://discuss.elastic.co/u/Haytham_Shammout)\
**Replies:** 1\
**Last updated:** [November 27, 2023, 2:42pm UTC](https://discuss.elastic.co/t/metricbeat-filebeat/348049 "2023-11-27T14:42:28Z")

</div>

I am trying to find Metricbeat and filebeat versions for AIX systems, with no luck is elastic support AIX servers with filebeat and metricbeat?

---

## [Custom date\_format for parse\_origination\_date](https://discuss.elastic.co/t/custom-date-format-for-parse-origination-date/348042)

<div class="topic-metadata">

**Author:** [@tbabic](https://discuss.elastic.co/u/tbabic)\
**Replies:** 1\
**Last updated:** [November 27, 2023, 12:50pm UTC](https://discuss.elastic.co/t/custom-date-format-for-parse-origination-date/348042 "2023-11-27T12:50:05Z")

</div>

Currently date\_format is yyyy.MM.dd in index.lifecycle.parse\_origination\_date which is great if you have logs in format like logs-2016.10.31-000002, but since index name is custom and can be like eg logs-2016-10-31-00 th…

---

## [Elastic serverless forwarder json formatting](https://discuss.elastic.co/t/elastic-serverless-forwarder-json-formatting/347959)

<div class="topic-metadata">

**Author:** [@vsv0001](https://discuss.elastic.co/u/vsv0001)\
**Replies:** 1\
**Last updated:** [November 27, 2023, 11:45am UTC](https://discuss.elastic.co/t/elastic-serverless-forwarder-json-formatting/347959 "2023-11-27T11:45:01Z")

</div>

we write our logs in json format to cloudwatch. does elastic serverless forwarder have any way (Deploy Elastic Serverless Forwarder | Elastic Serverless Forwarder Guide | Elastic) to send the logs in a json structure to…

---

## [Keyword typed field partially matching user query](https://discuss.elastic.co/t/keyword-typed-field-partially-matching-user-query/348033)

<div class="topic-metadata">

**Author:** [@spino17](https://discuss.elastic.co/u/spino17)\
**Replies:** 0\
**Last updated:** [November 27, 2023, 10:03am UTC](https://discuss.elastic.co/t/keyword-typed-field-partially-matching-user-query/348033 "2023-11-27T10:03:25Z")

</div>

I am using ES 7.9 version. I have a category index with document like doc\_1 = { "value": "laptops" } doc-2 = { "value": "air cooler" } with following schema: { "mappings": { "properties": { "v…

---

## [Elasticsearch configure 2 network host](https://discuss.elastic.co/t/elasticsearch-configure-2-network-host/348024)

<div class="topic-metadata">

**Author:** [@avnere](https://discuss.elastic.co/u/avnere)\
**Replies:** 1\
**Last updated:** [November 27, 2023, 9:31am UTC](https://discuss.elastic.co/t/elasticsearch-configure-2-network-host/348024 "2023-11-27T09:31:09Z")

</div>

Hi, Is it possible to configure elasticsearch to be accessible for both localhost and and ip address?

---

## [Run Rally races against an ES cluster built on OpenShift](https://discuss.elastic.co/t/run-rally-races-against-an-es-cluster-built-on-openshift/348028)

<div class="topic-metadata">

**Author:** [@benelastic](https://discuss.elastic.co/u/benelastic)\
**Replies:** 0\
**Last updated:** [November 27, 2023, 9:18am UTC](https://discuss.elastic.co/t/run-rally-races-against-an-es-cluster-built-on-openshift/348028 "2023-11-27T09:18:37Z")

</div>

Here is how I do benchmarking with my existing ES cluster: I have an existing ES cluster built on OpenShift environment The cluster has 5 nodes and each is having exactly same resources The ES cluster is being exposed …

---

## [NVMe storage with bitnami helm chart](https://discuss.elastic.co/t/nvme-storage-with-bitnami-helm-chart/347952)

<div class="topic-metadata">

**Author:** [@O\_K](https://discuss.elastic.co/u/O_K)\
**Replies:** 2\
**Last updated:** [November 26, 2023, 6:01pm UTC](https://discuss.elastic.co/t/nvme-storage-with-bitnami-helm-chart/347952 "2023-11-26T18:01:14Z")

</div>

Does bitnami helm chart support NVMe storage?

---

## [Slow elasticsearch search performance](https://discuss.elastic.co/t/slow-elasticsearch-search-performance/347902)

<div class="topic-metadata">

**Author:** [@habibkka1234](https://discuss.elastic.co/u/habibkka1234)\
**Replies:** 4\
**Last updated:** [November 26, 2023, 4:37pm UTC](https://discuss.elastic.co/t/slow-elasticsearch-search-performance/347902 "2023-11-26T16:37:02Z")

</div>

i have a eck operator based Elasticsearch cluster with 4 nodes - each with 6 cpu cores and 16 gb ram configured on eck operator. Note: Configured ILM with alias, and have 3 index already created when max size is great…

---

## [An internal error while attempting to create policy](https://discuss.elastic.co/t/an-internal-error-while-attempting-to-create-policy/347991)

<div class="topic-metadata">

**Author:** [@amarnath](https://discuss.elastic.co/u/amarnath)\
**Replies:** 0\
**Last updated:** [November 26, 2023, 11:42am UTC](https://discuss.elastic.co/t/an-internal-error-while-attempting-to-create-policy/347991 "2023-11-26T11:42:08Z")

</div>

{"service":{"node":{"roles":\["background\_tasks","ui"\]}},"ecs":{"version":"8.6.1"},"@timestamp":"2023-11-26T11:27:03.939+00:00","message":"Cannot read properties of undefined (reading 'split')","error":{"message":"Cannot …

---

## [How to calculate how much data a single data node in an elasticsearch cluster can store?](https://discuss.elastic.co/t/how-to-calculate-how-much-data-a-single-data-node-in-an-elasticsearch-cluster-can-store/347916)

<div class="topic-metadata">

**Author:** [@qq\_123456](https://discuss.elastic.co/u/qq_123456)\
**Replies:** 1\
**Last updated:** [November 26, 2023, 10:05am UTC](https://discuss.elastic.co/t/how-to-calculate-how-much-data-a-single-data-node-in-an-elasticsearch-cluster-can-store/347916 "2023-11-26T10:05:52Z")

</div>

I now want to install an elasticsearch cluster. How to evaluate the cluster size and resources? How to calculate how much data a single data node in an elasticsearch cluster can store? How to determine the ratio of memor…

---

## [Increase in shard count vs increase in shard size - Performance comparison](https://discuss.elastic.co/t/increase-in-shard-count-vs-increase-in-shard-size-performance-comparison/347984)

<div class="topic-metadata">

**Author:** [@sriapr98](https://discuss.elastic.co/u/sriapr98)\
**Replies:** 1\
**Last updated:** [November 26, 2023, 7:34am UTC](https://discuss.elastic.co/t/increase-in-shard-count-vs-increase-in-shard-size-performance-comparison/347984 "2023-11-26T07:34:08Z")

</div>

Currently we are creating an index which will take space of around 900GB. We are not able to use ILM because there are updates possible to any older data as well. So the only option left to us is sharding optimization w…

---

## [Dealing with high number of deleted documents](https://discuss.elastic.co/t/dealing-with-high-number-of-deleted-documents/347973)

<div class="topic-metadata">

**Author:** [@Dishant\_18](https://discuss.elastic.co/u/Dishant_18)\
**Replies:** 8\
**Last updated:** [November 25, 2023, 6:15pm UTC](https://discuss.elastic.co/t/dealing-with-high-number-of-deleted-documents/347973 "2023-11-25T18:15:55Z")

</div>

Hello everyone! We have an elasticsearch index with 40 shards and 1 replica. We index live email data in this ES index - so the volume of deletes is also high! We have 2 data nodes and 3 master nodes in our cluster. For…

---

## [Search template in elastic 8.10](https://discuss.elastic.co/t/search-template-in-elastic-8-10/347969)

<div class="topic-metadata">

**Author:** [@ashish9333](https://discuss.elastic.co/u/ashish9333)\
**Replies:** 0\
**Last updated:** [November 25, 2023, 9:13am UTC](https://discuss.elastic.co/t/search-template-in-elastic-8-10/347969 "2023-11-25T09:13:41Z")

</div>

Greetings to all I have an issue with my search template in ES 8.11, It appears that there is data on the docName parameter, but there is no data when I search using the fulltext parameter and the docName parameter. I…

---

## [Aws managed elastic search](https://discuss.elastic.co/t/aws-managed-elastic-search/347812)

<div class="topic-metadata">

**Author:** [@Hariharan\_Raj](https://discuss.elastic.co/u/Hariharan_Raj)\
**Replies:** 8\
**Last updated:** [November 25, 2023, 6:31am UTC](https://discuss.elastic.co/t/aws-managed-elastic-search/347812 "2023-11-25T06:31:28Z")

</div>

Hi, I am trying to create a 2 node aws managed elasticsearch. I am having trouble creating it. I am running my backend services inside a VPC. the filter service has all the elasticsearch codes and resides in a private …

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=172)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=174)
