# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=178

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 179

---

## [How to check bucket size condition and change email action in watcher?](https://discuss.elastic.co/t/how-to-check-bucket-size-condition-and-change-email-action-in-watcher/347183)

<div class="topic-metadata">

**Author:** [@helloworld3112](https://discuss.elastic.co/u/helloworld3112)\
**Replies:** 0\
**Last updated:** [November 15, 2023, 3:27am UTC](https://discuss.elastic.co/t/how-to-check-bucket-size-condition-and-change-email-action-in-watcher/347183 "2023-11-15T03:27:06Z")

</div>

Hello everyone, I have a watcher: { "input": { "search": { "request": { "search\_type": "query\_then\_fetch", "indices": \[ "index-\*" \], "body": { "query": {"…

---

## [Error Creating S3 Repository](https://discuss.elastic.co/t/error-creating-s3-repository/347178)

<div class="topic-metadata">

**Author:** [@Ben\_GSP](https://discuss.elastic.co/u/Ben_GSP)\
**Replies:** 0\
**Last updated:** [November 14, 2023, 11:57pm UTC](https://discuss.elastic.co/t/error-creating-s3-repository/347178 "2023-11-14T23:57:15Z")

</div>

I'm getting the following error when attempting to create a new s3 repository: { "error": { "root\_cause": \[ { "type": "repository\_exception", "reason": "\[s3\_01\] Could not determine repository…

---

## [Query with AND operator across inner hits of a document?](https://discuss.elastic.co/t/query-with-and-operator-across-inner-hits-of-a-document/347175)

<div class="topic-metadata">

**Author:** [@cphramington](https://discuss.elastic.co/u/cphramington)\
**Replies:** 0\
**Last updated:** [November 14, 2023, 11:40pm UTC](https://discuss.elastic.co/t/query-with-and-operator-across-inner-hits-of-a-document/347175 "2023-11-14T23:40:46Z")

</div>

I'm currently using a query like this to prioritize hits that contain multiple terms from the query string over those that contain fewer. "nested": { "path": "my\_nested\_fie…

---

## [GrokProcessor unescaped character](https://discuss.elastic.co/t/grokprocessor-unescaped-character/347171)

<div class="topic-metadata">

**Author:** [@gunlomboy](https://discuss.elastic.co/u/gunlomboy)\
**Replies:** 0\
**Last updated:** [November 14, 2023, 11:12pm UTC](https://discuss.elastic.co/t/grokprocessor-unescaped-character/347171 "2023-11-14T23:12:48Z")

</div>

Hi, Recently my elasticsearch logs are full of these. \[WARN \]\[o.e.i.c.GrokProcessor \] \[node01\] character class has '-' without escape Running 8.8.0, I wouldn't know where to start looking for an unescaped '-'. Any…

---

## [Default index template](https://discuss.elastic.co/t/default-index-template/347158)

<div class="topic-metadata">

**Author:** [@Milad\_Heydariaan](https://discuss.elastic.co/u/Milad_Heydariaan)\
**Replies:** 0\
**Last updated:** [November 14, 2023, 7:15pm UTC](https://discuss.elastic.co/t/default-index-template/347158 "2023-11-14T19:15:41Z")

</div>

With legacy templates, we used to have a "default template" (with \* pattern and order -10) which sets a few index settings including threshold for slowlogs, number of shard, and number of replicas. Then users could creat…

---

## [Unassigned shards -- and two shards rebalancing](https://discuss.elastic.co/t/unassigned-shards-and-two-shards-rebalancing/346555)

<div class="topic-metadata">

**Author:** [@Russell\_Fulton](https://discuss.elastic.co/u/Russell_Fulton)\
**Replies:** 6\
**Last updated:** [November 14, 2023, 7:00pm UTC](https://discuss.elastic.co/t/unassigned-shards-and-two-shards-rebalancing/346555 "2023-11-14T19:00:24Z")

</div>

My cluster has been stuck in Yellow for a couple of days. There are two shards that are being rebalanced (and have been for days ???) and this is appears to be causing the cluster to refuse to allocate replicas of prima…

---

## [Elasticsearch improvements from version 7.9 to 8.10](https://discuss.elastic.co/t/elasticsearch-improvements-from-version-7-9-to-8-10/347026)

<div class="topic-metadata">

**Author:** [@michele\_crudele](https://discuss.elastic.co/u/michele_crudele)\
**Replies:** 3\
**Last updated:** [November 14, 2023, 6:48pm UTC](https://discuss.elastic.co/t/elasticsearch-improvements-from-version-7-9-to-8-10/347026 "2023-11-14T18:48:28Z")

</div>

Is there a list somewhere of the Elasticsearch significant improvements from 7.9 version to 8.7

---

## [Using transforms and ingest pipelines on data that changes over time](https://discuss.elastic.co/t/using-transforms-and-ingest-pipelines-on-data-that-changes-over-time/347101)

<div class="topic-metadata">

**Author:** [@pulsy](https://discuss.elastic.co/u/pulsy)\
**Replies:** 5\
**Last updated:** [November 14, 2023, 1:55pm UTC](https://discuss.elastic.co/t/using-transforms-and-ingest-pipelines-on-data-that-changes-over-time/347101 "2023-11-14T13:55:36Z")

</div>

I'm thinking about using elastic transforms together with ingest pipelines to basically create views of mongodb collections that are spread over multiple database servers, so we can efficiently sort and filter by referen…

---

## [Random slow query after some time of idle](https://discuss.elastic.co/t/random-slow-query-after-some-time-of-idle/346783)

<div class="topic-metadata">

**Author:** [@LeoL](https://discuss.elastic.co/u/LeoL)\
**Replies:** 2\
**Last updated:** [November 14, 2023, 1:22pm UTC](https://discuss.elastic.co/t/random-slow-query-after-some-time-of-idle/346783 "2023-11-14T13:22:46Z")

</div>

Hello, I explain our stituation. We have a pod on OpenShift with a .NET application that uses the NEST library to connect to an Elasticsearch node. What happens is that after some idle time, the calls (any call) takes 1…

---

## [How can find out specific string in elastic](https://discuss.elastic.co/t/how-can-find-out-specific-string-in-elastic/347113)

<div class="topic-metadata">

**Author:** [@baber1223](https://discuss.elastic.co/u/baber1223)\
**Replies:** 0\
**Last updated:** [November 14, 2023, 11:59am UTC](https://discuss.elastic.co/t/how-can-find-out-specific-string-in-elastic/347113 "2023-11-14T11:59:45Z")

</div>

I am looking for a specific string in my log now how can define it ? because it is finding all words such as "validation" , "field" , "is" , "the" but I want just find specific string My pattern is " the validation is …

---

## [Does anyone use connection pooling in ElasticSearch8.5? How to use it?](https://discuss.elastic.co/t/does-anyone-use-connection-pooling-in-elasticsearch8-5-how-to-use-it/346974)

<div class="topic-metadata">

**Author:** [@maoqingjue](https://discuss.elastic.co/u/maoqingjue)\
**Replies:** 16\
**Last updated:** [November 14, 2023, 11:09am UTC](https://discuss.elastic.co/t/does-anyone-use-connection-pooling-in-elasticsearch8-5-how-to-use-it/346974 "2023-11-14T11:09:13Z")

</div>

Does anyone use connection pooling in Elasticsearch8.5? How to use it?

---

## [Sending AWS Cloud Watch Logs to Elasticsearch](https://discuss.elastic.co/t/sending-aws-cloud-watch-logs-to-elasticsearch/346459)

<div class="topic-metadata">

**Author:** [@laale1](https://discuss.elastic.co/u/laale1)\
**Replies:** 5\
**Last updated:** [November 14, 2023, 11:01am UTC](https://discuss.elastic.co/t/sending-aws-cloud-watch-logs-to-elasticsearch/346459 "2023-11-14T11:01:37Z")

</div>

Hello community. I want to send AWS Cloud Watch logs to my local Elasticsearch cluster? I have seen AWS integrations but my question is how I'm going to connect those integrations on my AWS Cloud Watch?

---

## [Server requirement for every node role](https://discuss.elastic.co/t/server-requirement-for-every-node-role/347075)

<div class="topic-metadata">

**Author:** [@psanggabuana](https://discuss.elastic.co/u/psanggabuana)\
**Replies:** 3\
**Last updated:** [November 14, 2023, 10:20am UTC](https://discuss.elastic.co/t/server-requirement-for-every-node-role/347075 "2023-11-14T10:20:29Z")

</div>

Hi all, I need information about master, data, inget, and coordination server requirements. Anyone can share with me about CPU and Memory needs of each role node? CPU RAM Master Data Coordinatin…

---

## [ES 7.8.1 crashing, insufficient memory... why?!](https://discuss.elastic.co/t/es-7-8-1-crashing-insufficient-memory-why/347050)

<div class="topic-metadata">

**Author:** [@jsamhall](https://discuss.elastic.co/u/jsamhall)\
**Replies:** 4\
**Last updated:** [November 14, 2023, 8:48am UTC](https://discuss.elastic.co/t/es-7-8-1-crashing-insufficient-memory-why/347050 "2023-11-14T08:48:12Z")

</div>

Hello, I am new to being a sysadmin for ES and in this case, it is backing a Magento2 installation running on Ubuntu 18.04 LTS Problem: Occasionally, and I'm not sure why, ES performance begins to degrade and then cra…

---

## [Reindex Api "didn't store \_source" error](https://discuss.elastic.co/t/reindex-api-didnt-store-source-error/347043)

<div class="topic-metadata">

**Author:** [@Hakan\_Kara](https://discuss.elastic.co/u/Hakan_Kara)\
**Replies:** 4\
**Last updated:** [November 14, 2023, 5:48am UTC](https://discuss.elastic.co/t/reindex-api-didnt-store-source-error/347043 "2023-11-14T05:48:46Z")

</div>

Hello, we are getting following error while using reindex api. Could we ignore these kind of errors with reindex api ? Or could we destroy the following doc with given id ? { "type" : "illegal\_argument\_exception", …

---

## [Failure on document\_parsing\_exception - dot\_product similarity on dense\_vector index field](https://discuss.elastic.co/t/failure-on-document-parsing-exception-dot-product-similarity-on-dense-vector-index-field/346718)

<div class="topic-metadata">

**Author:** [@ORipalta](https://discuss.elastic.co/u/ORipalta)\
**Replies:** 5\
**Last updated:** [November 13, 2023, 9:58pm UTC](https://discuss.elastic.co/t/failure-on-document-parsing-exception-dot-product-similarity-on-dense-vector-index-field/346718 "2023-11-13T21:58:00Z")

</div>

I'm trying to use dot-plot similarity on Elasticsearch. But after creating the index, the data/rows fail to load due to document\_parsing\_exception. The error message that is being returned is failed to parse: The \[dot\_p…

---

## [Can't delete or recover .kibana\_security\_session\_1 index](https://discuss.elastic.co/t/cant-delete-or-recover-kibana-security-session-1-index/347035)

<div class="topic-metadata">

**Author:** [@RRGTHWAR](https://discuss.elastic.co/u/RRGTHWAR)\
**Replies:** 2\
**Last updated:** [November 13, 2023, 9:26pm UTC](https://discuss.elastic.co/t/cant-delete-or-recover-kibana-security-session-1-index/347035 "2023-11-13T21:26:44Z")

</div>

My storage team badly botched an upgrade, and as a result the .kibana\_security\_session\_1 index in my ECK cluster was corrupted. I don't have any backups of it to restore, and I can't delete it because the superuser privi…

---

## [QueryPhaseCollector invokes lucene score() twice on every doc when min\_score is used](https://discuss.elastic.co/t/queryphasecollector-invokes-lucene-score-twice-on-every-doc-when-min-score-is-used/347062)

<div class="topic-metadata">

**Author:** [@Mike\_McMahon](https://discuss.elastic.co/u/Mike_McMahon)\
**Replies:** 0\
**Last updated:** [November 13, 2023, 8:56pm UTC](https://discuss.elastic.co/t/queryphasecollector-invokes-lucene-score-twice-on-every-doc-when-min-score-is-used/347062 "2023-11-13T20:56:42Z")

</div>

Elastic 8.10 introduced a major change QueryPhaseCollector (see https://github.com/elastic/elasticsearch/pull/97410) in how lucene queries are executed. I have observed that now, when using min\_score, each document gets …

---

## [Elasticsearch 8.10.2 synonyms not working when synonyms\_path is used](https://discuss.elastic.co/t/elasticsearch-8-10-2-synonyms-not-working-when-synonyms-path-is-used/346745)

<div class="topic-metadata">

**Author:** [@smritibhandari91](https://discuss.elastic.co/u/smritibhandari91)\
**Replies:** 1\
**Last updated:** [November 13, 2023, 6:35pm UTC](https://discuss.elastic.co/t/elasticsearch-8-10-2-synonyms-not-working-when-synonyms-path-is-used/346745 "2023-11-13T18:35:24Z")

</div>

We successfully deployed Elasticsearch 8.10.2 using the ECK operator. However, we encountered an issue when trying to access the synonyms\_path during the index creation process. Error: The problem is that the index crea…

---

## [No .PEM generated when using --pem mode in elasticsearch-certutil](https://discuss.elastic.co/t/no-pem-generated-when-using-pem-mode-in-elasticsearch-certutil/347046)

<div class="topic-metadata">

**Author:** [@carel0x53](https://discuss.elastic.co/u/carel0x53)\
**Replies:** 3\
**Last updated:** [November 13, 2023, 5:37pm UTC](https://discuss.elastic.co/t/no-pem-generated-when-using-pem-mode-in-elasticsearch-certutil/347046 "2023-11-13T17:37:08Z")

</div>

I'm trying to generate a PEM certificate for elasticsearch using elasticsearch-certutil by introducing the following line bin/elasticsearch-certutil ca --pem Then, the program asks me to set a name for the resulting .z…

---

## [How to migrate my information from one cluster to another?](https://discuss.elastic.co/t/how-to-migrate-my-information-from-one-cluster-to-another/347027)

<div class="topic-metadata">

**Author:** [@efrainMZ](https://discuss.elastic.co/u/efrainMZ)\
**Replies:** 1\
**Last updated:** [November 13, 2023, 3:52pm UTC](https://discuss.elastic.co/t/how-to-migrate-my-information-from-one-cluster-to-another/347027 "2023-11-13T15:52:58Z")

</div>

How to migrate information from a version 7.17 cluster to a version 8.10 cluster manually without using the cloud.

---

## [What is better, update or install from the beginning?](https://discuss.elastic.co/t/what-is-better-update-or-install-from-the-beginning/346820)

<div class="topic-metadata">

**Author:** [@efrainMZ](https://discuss.elastic.co/u/efrainMZ)\
**Replies:** 1\
**Last updated:** [November 13, 2023, 3:26pm UTC](https://discuss.elastic.co/t/what-is-better-update-or-install-from-the-beginning/346820 "2023-11-13T15:26:18Z")

</div>

Hello, good day, I have an elasticsearch cluster with version 7.17. I would like to know what is most convenient? upgrade the cluster to version 8.10 or perform a new installation with version 8.10 and only migrate the d…

---

## [Elastic Integration with Sentinel one deep visibility data](https://discuss.elastic.co/t/elastic-integration-with-sentinel-one-deep-visibility-data/346301)

<div class="topic-metadata">

**Author:** [@ksrawat88](https://discuss.elastic.co/u/ksrawat88)\
**Replies:** 2\
**Last updated:** [November 13, 2023, 3:05pm UTC](https://discuss.elastic.co/t/elastic-integration-with-sentinel-one-deep-visibility-data/346301 "2023-11-13T15:05:12Z")

</div>

Anyone has integrated Sentinel one deep visibility data with ELK stack.? or atlease able to search on sentinel one deep visibilty data from Kibana. ? We are looking in this option and right now we have open source ELK s…

---

## [Why is .transform-notifications in my snaphot?](https://discuss.elastic.co/t/why-is-transform-notifications-in-my-snaphot/347028)

<div class="topic-metadata">

**Author:** [@Alain\_Bod](https://discuss.elastic.co/u/Alain_Bod)\
**Replies:** 0\
**Last updated:** [November 13, 2023, 3:02pm UTC](https://discuss.elastic.co/t/why-is-transform-notifications-in-my-snaphot/347028 "2023-11-13T15:02:43Z")

</div>

Hi, I've created a snaphot policy with indices "index1, index2". But I get ".transform-notifications" as well in my snapshot. Why is that? ES version 8.11.0

---

## [Stats aggregation: as\_string fields missing when searching in multiple indices](https://discuss.elastic.co/t/stats-aggregation-as-string-fields-missing-when-searching-in-multiple-indices/347016)

<div class="topic-metadata">

**Author:** [@msh](https://discuss.elastic.co/u/msh)\
**Replies:** 0\
**Last updated:** [November 13, 2023, 1:23pm UTC](https://discuss.elastic.co/t/stats-aggregation-as-string-fields-missing-when-searching-in-multiple-indices/347016 "2023-11-13T13:23:19Z")

</div>

Hi, here are steps to reproduce: Fresh installation of ES v 8.11 Create an index "items" with a document containing a date: curl --location --request PUT 'localhost:9200/items/\_doc/1' \\ --header 'Content-Type: applic…

---

## [LDAP user authentication](https://discuss.elastic.co/t/ldap-user-authentication/347000)

<div class="topic-metadata">

**Author:** [@Manal\_A](https://discuss.elastic.co/u/Manal_A)\
**Replies:** 1\
**Last updated:** [November 13, 2023, 12:58pm UTC](https://discuss.elastic.co/t/ldap-user-authentication/347000 "2023-11-13T12:58:31Z")

</div>

Hello, I want to configure LDAP. Should the configuration be done at the Kibana level or the Elasticsearch level? And for the flow openings, should I create openings between LDAP and Kibana or LDAP and Elasticsearch? T…

---

## [How should I configure memory swapping?](https://discuss.elastic.co/t/how-should-i-configure-memory-swapping/347010)

<div class="topic-metadata">

**Author:** [@elasticsearchman](https://discuss.elastic.co/u/elasticsearchman)\
**Replies:** 0\
**Last updated:** [November 13, 2023, 12:24pm UTC](https://discuss.elastic.co/t/how-should-i-configure-memory-swapping/347010 "2023-11-13T12:24:47Z")

</div>

Hello, I want to build Elasticsearch and Kibana using Podman on RHEL 8.5. It is my understanding that disabling memory swapping is a best practice in Elasticsearch. I am planning to implement the following settings bas…

---

## [The state of the new Java Client (ES 8)](https://discuss.elastic.co/t/the-state-of-the-new-java-client-es-8/346689)

<div class="topic-metadata">

**Author:** [@rand0m86](https://discuss.elastic.co/u/rand0m86)\
**Replies:** 2\
**Last updated:** [November 13, 2023, 11:58am UTC](https://discuss.elastic.co/t/the-state-of-the-new-java-client-es-8/346689 "2023-11-13T11:58:41Z")

</div>

Hi there, I just want to hear back from ES maintainers on the current state of the new Elasticsearch Java Client. We did quite some effort migrating our app from ES 6.8 to 8.x in terms of switching to this new client, …

---

## [TSDS Best Compression On ILM Rollover?](https://discuss.elastic.co/t/tsds-best-compression-on-ilm-rollover/346886)

<div class="topic-metadata">

**Author:** [@BenB196](https://discuss.elastic.co/u/BenB196)\
**Replies:** 2\
**Last updated:** [November 13, 2023, 11:36am UTC](https://discuss.elastic.co/t/tsds-best-compression-on-ilm-rollover/346886 "2023-11-13T11:36:29Z")

</div>

Hi All, I recently saw this issue; Don't set index.codec: 'best\_compression' for TSDB data streams · Issue #160288 · elastic/kibana (github.com), and I was kind of curious. What is the guidance for compression as part o…

---

## [Kibana elasticseach inaccessible](https://discuss.elastic.co/t/kibana-elasticseach-inaccessible/346450)

<div class="topic-metadata">

**Author:** [@Epangilinangt](https://discuss.elastic.co/u/Epangilinangt)\
**Replies:** 6\
**Last updated:** [November 13, 2023, 10:28am UTC](https://discuss.elastic.co/t/kibana-elasticseach-inaccessible/346450 "2023-11-13T10:28:28Z")

</div>

{ "statusCode": 503, "error": "Service Unavailable", "message": "License is not available." } does anyone help me with this kind of error, tried a lot of troubleshooting still did not work

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=177)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=179)
