# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=174

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 175

---

## [Synonym Graph giving incorrect results](https://discuss.elastic.co/t/synonym-graph-giving-incorrect-results/347966)

<div class="topic-metadata">

**Author:** [@bhavya](https://discuss.elastic.co/u/bhavya)\
**Replies:** 0\
**Last updated:** [November 25, 2023, 6:10am UTC](https://discuss.elastic.co/t/synonym-graph-giving-incorrect-results/347966 "2023-11-25T06:10:45Z")

</div>

I am trying to implement Multi-Word Synonyms This is the index setting { "settings": { "analysis": { "filter": { "synonym\_filter": { "type": "synonym\_graph", "synonyms": \[ …

---

## [Docker Plesk - ERROR: Elasticsearch exited unexpectedly](https://discuss.elastic.co/t/docker-plesk-error-elasticsearch-exited-unexpectedly/347954)

<div class="topic-metadata">

**Author:** [@appuni](https://discuss.elastic.co/u/appuni)\
**Replies:** 0\
**Last updated:** [November 24, 2023, 7:00pm UTC](https://discuss.elastic.co/t/docker-plesk-error-elasticsearch-exited-unexpectedly/347954 "2023-11-24T19:00:53Z")

</div>

Good afternoon Community, When launching the Elasticsearch image I am receiving the error message: ERROR: Elasticsearch exited unexpectedly I configured it in Docker Plesk for unlimited memory usage, but it didn't sol…

---

## [Mustache toJSON tag issue](https://discuss.elastic.co/t/mustache-tojson-tag-issue/347944)

<div class="topic-metadata">

**Author:** [@pszemesy](https://discuss.elastic.co/u/pszemesy)\
**Replies:** 0\
**Last updated:** [November 24, 2023, 4:27pm UTC](https://discuss.elastic.co/t/mustache-tojson-tag-issue/347944 "2023-11-24T16:27:54Z")

</div>

Hi All, I'm trying to create a search template: { "script": { "lang": "mustache", "source": """{ "query": { "bool": { "must": \[ {{#docyear}}{ "terms": { …

---

## [Grouping logs into sessions](https://discuss.elastic.co/t/grouping-logs-into-sessions/347934)

<div class="topic-metadata">

**Author:** [@Dor-Alter](https://discuss.elastic.co/u/Dor-Alter)\
**Replies:** 7\
**Last updated:** [November 24, 2023, 3:35pm UTC](https://discuss.elastic.co/t/grouping-logs-into-sessions/347934 "2023-11-24T15:35:24Z")

</div>

My entries in Elasticsearch are logs of different event. I am trying to group the logs into sessions of users based on an attribute of the logs. Each log has action attribute, everytime there is the action "session\_start…

---

## [Backup Of Index In Elasticsearch](https://discuss.elastic.co/t/backup-of-index-in-elasticsearch/347834)

<div class="topic-metadata">

**Author:** [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Replies:** 4\
**Last updated:** [November 24, 2023, 3:27pm UTC](https://discuss.elastic.co/t/backup-of-index-in-elasticsearch/347834 "2023-11-24T15:27:27Z")

</div>

Hi Team, I had a requirement where Elasticsearch is running as a container. I need to take backup of the one of the index and need to restore in Elasticsearch cluster which is running on VM. There is no Kibana configure…

---

## [Max suggested index sizes / document amount etc](https://discuss.elastic.co/t/max-suggested-index-sizes-document-amount-etc/347937)

<div class="topic-metadata">

**Author:** [@elk1985](https://discuss.elastic.co/u/elk1985)\
**Replies:** 2\
**Last updated:** [November 24, 2023, 2:56pm UTC](https://discuss.elastic.co/t/max-suggested-index-sizes-document-amount-etc/347937 "2023-11-24T14:56:57Z")

</div>

Hello. My cluster is reaching 2000 opened shards. I have two data nodes now. I don't want to add another data node and scale up the cluster. I'm thinking more like changing indexing strategy. Currently logstash is cre…

---

## [Datafeed has been retrieving no data for a while](https://discuss.elastic.co/t/datafeed-has-been-retrieving-no-data-for-a-while/347924)

<div class="topic-metadata">

**Author:** [@marmai16](https://discuss.elastic.co/u/marmai16)\
**Replies:** 2\
**Last updated:** [November 24, 2023, 12:30pm UTC](https://discuss.elastic.co/t/datafeed-has-been-retrieving-no-data-for-a-while/347924 "2023-11-24T12:30:53Z")

</div>

Hello everybody, i just created some anomaly detection jobs, however new records are not processed after the lookback was performed. New data is available in the source index the jobs are working on. If i reset the jo…

---

## [How best to Denormalize a SQL schema](https://discuss.elastic.co/t/how-best-to-denormalize-a-sql-schema/347922)

<div class="topic-metadata">

**Author:** [@cylon86](https://discuss.elastic.co/u/cylon86)\
**Replies:** 0\
**Last updated:** [November 24, 2023, 11:21am UTC](https://discuss.elastic.co/t/how-best-to-denormalize-a-sql-schema/347922 "2023-11-24T11:21:41Z")

</div>

Hi all, I'm building a new Index for a use case and I'm wondering what would be the best mapping to structure this index. I have no problem building this with SQL tables, links and joins; but I struggle finding the goo…

---

## [Problem with Search-time Synonyms](https://discuss.elastic.co/t/problem-with-search-time-synonyms/347654)

<div class="topic-metadata">

**Author:** [@elleWajexi](https://discuss.elastic.co/u/elleWajexi)\
**Replies:** 7\
**Last updated:** [November 24, 2023, 10:38am UTC](https://discuss.elastic.co/t/problem-with-search-time-synonyms/347654 "2023-11-24T10:38:07Z")

</div>

I have an index with synonyms : "index": { "analysis": { "analyzer": { "index\_analyzer": { "tokenizer": "standard", "filter": \[ "lowercase", "my\_stemmer" \] }…

---

## [Elasticsearch .Net v8.x client use for bulk indexing raw JSON data](https://discuss.elastic.co/t/elasticsearch-net-v8-x-client-use-for-bulk-indexing-raw-json-data/347914)

<div class="topic-metadata">

**Author:** [@askids](https://discuss.elastic.co/u/askids)\
**Replies:** 0\
**Last updated:** [November 24, 2023, 10:19am UTC](https://discuss.elastic.co/t/elasticsearch-net-v8-x-client-use-for-bulk-indexing-raw-json-data/347914 "2023-11-24T10:19:58Z")

</div>

hi, I am using .Net 6.0, running Elastic.Client 8.x connecting to 7.17 ES, which will be shortly upgraded to 8.4. I want to know how do I perform bulk indexing of raw json data? I could see some example under Java clien…

---

## [Elasticsearch Classic Plugin Development Documents](https://discuss.elastic.co/t/elasticsearch-classic-plugin-development-documents/347912)

<div class="topic-metadata">

**Author:** [@Zeus101](https://discuss.elastic.co/u/Zeus101)\
**Replies:** 0\
**Last updated:** [November 24, 2023, 9:17am UTC](https://discuss.elastic.co/t/elasticsearch-classic-plugin-development-documents/347912 "2023-11-24T09:17:57Z")

</div>

I have been trying to develop plugins for Elasticsearch, but was unable to as I couldn't find a proper documentation for the same. I have been using to cookiecutters' sample template to play around this but a proper docu…

---

## [Vault Logging using Elasticsearch](https://discuss.elastic.co/t/vault-logging-using-elasticsearch/347897)

<div class="topic-metadata">

**Author:** [@VijayIQA](https://discuss.elastic.co/u/VijayIQA)\
**Replies:** 0\
**Last updated:** [November 24, 2023, 5:17am UTC](https://discuss.elastic.co/t/vault-logging-using-elasticsearch/347897 "2023-11-24T05:17:42Z")

</div>

Hi team, As per elastic docs at vault audit enable socket address=${ELASTIC\_AGENT\_IP}:9007 socket\_type=tcp In the place of ELASTIC\_AGENT\_IP I placed Elasticsearch IP and port as 9200 in this case getting an error as …

---

## [Elasticsearch CPU usage](https://discuss.elastic.co/t/elasticsearch-cpu-usage/347689)

<div class="topic-metadata">

**Author:** [@VijayIQA](https://discuss.elastic.co/u/VijayIQA)\
**Replies:** 4\
**Last updated:** [November 24, 2023, 3:10am UTC](https://discuss.elastic.co/t/elasticsearch-cpu-usage/347689 "2023-11-24T03:10:17Z")

</div>

Hi Team, Cluster monitoring by Kibana stack monitoring in that able to get all parameters but not getting CPU usages of the nodes.

---

## [How to use LruRedux cache in ruby filter](https://discuss.elastic.co/t/how-to-use-lruredux-cache-in-ruby-filter/347893)

<div class="topic-metadata">

**Author:** [@Chen\_Wei](https://discuss.elastic.co/u/Chen_Wei)\
**Replies:** 0\
**Last updated:** [November 24, 2023, 2:44am UTC](https://discuss.elastic.co/t/how-to-use-lruredux-cache-in-ruby-filter/347893 "2023-11-24T02:44:03Z")

</div>

Somehow we have some logs having duplicated events, we want to dedup the events using fingerprint and LRU cache in the logstash pipeline, So I write a ruby file require "lru\_redux" def register(params) limit = para…

---

## [Index has disappeared](https://discuss.elastic.co/t/index-has-disappeared/347889)

<div class="topic-metadata">

**Author:** [@juancamiloll](https://discuss.elastic.co/u/juancamiloll)\
**Replies:** 5\
**Last updated:** [November 23, 2023, 10:47pm UTC](https://discuss.elastic.co/t/index-has-disappeared/347889 "2023-11-23T22:47:53Z")

</div>

Hello I have several sources that ELK processes, as you know from /etc/logstash/conf.d a .conf file is created for each of the sources to be processed either by GROK or CSV, I don't know if there is another way. One of…

---

## [Time fields show different time](https://discuss.elastic.co/t/time-fields-show-different-time/346651)

<div class="topic-metadata">

**Author:** [@juancamiloll](https://discuss.elastic.co/u/juancamiloll)\
**Replies:** 8\
**Last updated:** [November 23, 2023, 10:25pm UTC](https://discuss.elastic.co/t/time-fields-show-different-time/346651 "2023-11-23T22:25:01Z")

</div>

Hello again, I find a new problem where in the logs of a Paloalto I see that the "ReceivedTime" field and the "column103" field show a different time. I would appreciate your help input { file { path =\> "…

---

## [Logstash Multiline and line codec differences](https://discuss.elastic.co/t/logstash-multiline-and-line-codec-differences/347466)

<div class="topic-metadata">

**Author:** [@randomnamegenerator](https://discuss.elastic.co/u/randomnamegenerator)\
**Replies:** 6\
**Last updated:** [November 23, 2023, 7:42pm UTC](https://discuss.elastic.co/t/logstash-multiline-and-line-codec-differences/347466 "2023-11-23T19:42:09Z")

</div>

Hello All, We have application logs coming in from a number of different hosts (shipped with filebeat) and have obvserved a mixing of datastreams for one of the log types. We changed the logstash input.config from vers…

---

## [How to namespace indexes - Automatic not Manual](https://discuss.elastic.co/t/how-to-namespace-indexes-automatic-not-manual/347886)

<div class="topic-metadata">

**Author:** [@Alexander\_Mills](https://discuss.elastic.co/u/Alexander_Mills)\
**Replies:** 1\
**Last updated:** [November 23, 2023, 7:33pm UTC](https://discuss.elastic.co/t/how-to-namespace-indexes-automatic-not-manual/347886 "2023-11-23T19:33:31Z")

</div>

Mongo has namespacing via different databases on the same db server RabbitMQ has namespacing via different exhanges How can I automatically namespace indices with Elastic without manually namespacing keys with prod-x…

---

## [Cluster currently has \[1000\]/\[1000\] maximum normal shards open](https://discuss.elastic.co/t/cluster-currently-has-1000-1000-maximum-normal-shards-open/347719)

<div class="topic-metadata">

**Author:** [@DaddyYusk](https://discuss.elastic.co/u/DaddyYusk)\
**Replies:** 4\
**Last updated:** [November 23, 2023, 1:32pm UTC](https://discuss.elastic.co/t/cluster-currently-has-1000-1000-maximum-normal-shards-open/347719 "2023-11-23T13:32:03Z")

</div>

Hi, From the title, this is an error I usually encounter with my Elastic Proof Of Concept. The workaround is easy, I simply close and delete some indices from time to time... But now I'm currently deploying Elastic in…

---

## [Backing Up ES Indices](https://discuss.elastic.co/t/backing-up-es-indices/347815)

<div class="topic-metadata">

**Author:** [@Nijal](https://discuss.elastic.co/u/Nijal)\
**Replies:** 2\
**Last updated:** [November 23, 2023, 1:30pm UTC](https://discuss.elastic.co/t/backing-up-es-indices/347815 "2023-11-23T13:30:54Z")

</div>

I have a few questions about Snapshots, What is the correct approach to save snapshots to long term data store such as tape storage What is the correct proceedure to restore the snapshots stored in the tape storage. Ho…

---

## [Syncing Huge DataSet From MySQL to Elasticsearch](https://discuss.elastic.co/t/syncing-huge-dataset-from-mysql-to-elasticsearch/347853)

<div class="topic-metadata">

**Author:** [@Aswini\_Kumar\_Rout](https://discuss.elastic.co/u/Aswini_Kumar_Rout)\
**Replies:** 0\
**Last updated:** [November 23, 2023, 1:04pm UTC](https://discuss.elastic.co/t/syncing-huge-dataset-from-mysql-to-elasticsearch/347853 "2023-11-23T13:04:53Z")

</div>

Hi Team, We have one requirement to use Elasticsearch in our legacy application which has MySQL datbase and the size of the DB is around 300 GB and with 200 or more tables. So, here I am bit confused that - which would…

---

## [Editing a managed policy can break Kibana](https://discuss.elastic.co/t/editing-a-managed-policy-can-break-kibana/347828)

<div class="topic-metadata">

**Author:** [@DaddyYusk](https://discuss.elastic.co/u/DaddyYusk)\
**Replies:** 2\
**Last updated:** [November 23, 2023, 1:19pm UTC](https://discuss.elastic.co/t/editing-a-managed-policy-can-break-kibana/347828 "2023-11-23T13:19:57Z")

</div>

Hi, After a successful Fleet Server and Elastic Agent deployment, I wanted to tweak the ILM called "logs" and "metrics" which are both "Managed". But when trying to do so, I encounter this well known warning : So af…

---

## [Search template based on list](https://discuss.elastic.co/t/search-template-based-on-list/347852)

<div class="topic-metadata">

**Author:** [@pszemesy](https://discuss.elastic.co/u/pszemesy)\
**Replies:** 0\
**Last updated:** [November 23, 2023, 12:37pm UTC](https://discuss.elastic.co/t/search-template-based-on-list/347852 "2023-11-23T12:37:30Z")

</div>

Hi All, I have an index (contains translations) with the following mappings: document\_name: keyword, ... EN: { content: text, stored\_by: keyword, stored\_at: date, ... } \<\<lang code\>\>: { content: text, store…

---

## [Rollup then backup indices](https://discuss.elastic.co/t/rollup-then-backup-indices/346036)

<div class="topic-metadata">

**Author:** [@lstoneir](https://discuss.elastic.co/u/lstoneir)\
**Replies:** 1\
**Last updated:** [November 23, 2023, 12:09pm UTC](https://discuss.elastic.co/t/rollup-then-backup-indices/346036 "2023-11-23T12:09:57Z")

</div>

Hi there, I have a elastic cluster with 5 nodes (each node 1TB) I want to backup my indices, but I dont have enough resources to backup all indices. I want to rollup indices for example my main indices are hourly, I w…

---

## [Elasticsearch.yml configuration file is missing in linux](https://discuss.elastic.co/t/elasticsearch-yml-configuration-file-is-missing-in-linux/347839)

<div class="topic-metadata">

**Author:** [@krishnapro](https://discuss.elastic.co/u/krishnapro)\
**Replies:** 1\
**Last updated:** [November 23, 2023, 11:48am UTC](https://discuss.elastic.co/t/elasticsearch-yml-configuration-file-is-missing-in-linux/347839 "2023-11-23T11:48:47Z")

</div>

I have installed elasticsearch in linux mint but elasticsearch.yml file is missing. I have uninstall and reinstall it but same problem. I don't know what do please help me to fix it.

---

## [How to get a NodeClient inside a plugin?](https://discuss.elastic.co/t/how-to-get-a-nodeclient-inside-a-plugin/347703)

<div class="topic-metadata">

**Author:** [@Azizi\_BESSEM](https://discuss.elastic.co/u/Azizi_BESSEM)\
**Replies:** 5\
**Last updated:** [November 23, 2023, 10:13am UTC](https://discuss.elastic.co/t/how-to-get-a-nodeclient-inside-a-plugin/347703 "2023-11-23T10:13:36Z")

</div>

I am currently working on developing a schedule plugin for Elasticsearch. The objective is to display only the index number every 5 minutes. However, I am encountering an issue where the NodeClient is consistently null. …

---

## [Multy-tenany elasticsearch](https://discuss.elastic.co/t/multy-tenany-elasticsearch/347832)

<div class="topic-metadata">

**Author:** [@Azizi\_BESSEM](https://discuss.elastic.co/u/Azizi_BESSEM)\
**Replies:** 0\
**Last updated:** [November 23, 2023, 10:05am UTC](https://discuss.elastic.co/t/multy-tenany-elasticsearch/347832 "2023-11-23T10:05:24Z")

</div>

I am currently working on implementing multi-tenancy in Elasticsearch and have come across two prominent approaches: using a shared index across multiple tenants and having a dedicated index per tenant. As part of my res…

---

## [\["org.elasticsearch.bootstrap.StartupException: ElasticsearchException\[failed to bind service\]; nested: CorruptIndexException\[codec footer mismatch (file truncated?)](https://discuss.elastic.co/t/org-elasticsearch-bootstrap-startupexception-elasticsearchexception-failed-to-bind-service-nested-corruptindexexception-codec-footer-mismatch-file-truncated/347642)

<div class="topic-metadata">

**Author:** [@lins](https://discuss.elastic.co/u/lins)\
**Replies:** 11\
**Last updated:** [November 23, 2023, 8:23am UTC](https://discuss.elastic.co/t/org-elasticsearch-bootstrap-startupexception-elasticsearchexception-failed-to-bind-service-nested-corruptindexexception-codec-footer-mismatch-file-truncated/347642 "2023-11-23T08:23:18Z")

</div>

{"type": "server", "timestamp": "2023-11-21T09:52:52,412Z", "level": "ERROR", "component": "o.e.b.ElasticsearchUncaughtExceptionHandler", "cluster.name": "elasticsearch", "node.name": "elasticsearch-es-master-1", "messag…

---

## [SSL Certificate issues](https://discuss.elastic.co/t/ssl-certificate-issues/347390)

<div class="topic-metadata">

**Author:** [@nvanalphen](https://discuss.elastic.co/u/nvanalphen)\
**Replies:** 12\
**Last updated:** [November 23, 2023, 8:14am UTC](https://discuss.elastic.co/t/ssl-certificate-issues/347390 "2023-11-23T08:14:56Z")

</div>

I am trying to set up a server to evaluate and determine if/how we can use this solution. Unfortunately I am going mad trying to set it up. I have been trying, searching, reading and trying again for over a week now and…

---

## [How to debug http.max\_content\_length on elasticsearch](https://discuss.elastic.co/t/how-to-debug-http-max-content-length-on-elasticsearch/347754)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 0\
**Last updated:** [November 22, 2023, 3:03pm UTC](https://discuss.elastic.co/t/how-to-debug-http-max-content-length-on-elasticsearch/347754 "2023-11-22T15:03:21Z")

</div>

Hi Is it possible to trace a log on elasticsearch for http.max\_content\_length ? Thx!

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=173)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=175)
